Sample viewer

vx.netlux.org/Virus.DOS.Vienna.757

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:36.009130004Z 26 PC: 12e5a | Set disk transfer address
2018-12-17T22:29:36.011057428Z 53 PC: 12e60 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:36.012057869Z 37 PC: 12e74 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:29:36.013080452Z 78 PC: 12ef8 | Find first file
2018-12-17T22:29:36.019759022Z 79 PC: 12efe | Find next file
2018-12-17T22:29:36.022177659Z 79 PC: 12efe | Find next file
2018-12-17T22:29:36.024459583Z 79 PC: 12efe | Find next file
2018-12-17T22:29:36.026960875Z 79 PC: 12efe | Find next file
2018-12-17T22:29:36.029345784Z 79 PC: 12efe | Find next file
2018-12-17T22:29:36.031594515Z 79 PC: 12efe | Find next file
2018-12-17T22:29:36.033873053Z 79 PC: 12efe | Find next file
2018-12-17T22:29:36.036389657Z 67 PC: 12f5b | Get or set file attributes
2018-12-17T22:29:36.041691277Z 67 PC: 12f6c | Get or set file attributes
2018-12-17T22:29:36.056710894Z 61 PC: 12f78 | Open file (Filename = 'TEST.COM')
2018-12-17T22:29:36.061194809Z 87 PC: 12f84 | Get or set file date and time
2018-12-17T22:29:36.062143128Z 42 PC: 12f90 | Get date 0x12f90: cmp dl, byte ptr [si + 0x5a]
0x12f93: nop
0x12f94: jne 0x12f99
0x12f96: jmp 0x13036
0x12f99: mov byte ptr [si + 0x5a], dl
0x12f9c: nop
0x12f9d: mov al, byte ptr [si + 0x37]
0x12fa0: nop
0x12fa1: dec al
0x12fa3: and al, 7
0x12fa5: mov byte ptr [si + 0x37], al
0x12fa8: nop
0x12fa9: jne 0x12fc0
0x12fab: mov ah, 9
0x12fad: mov dx, si
0x12faf: add dx, 8
0x12fb2: nop
0x12fb3: int 0x21
0x12fb5: mov ah, 1
0x12fb7: int 0x21
2018-12-17T22:29:36.063541577Z 63 PC: 12fcc | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:29:36.06550704Z 66 PC: 12fdc | Move file pointer
2018-12-17T22:29:36.066620125Z 64 PC: 13000 | Write file or device (Write 757 bytes on handle 5)
2018-12-17T22:29:36.074752068Z 66 PC: 13010 | Move file pointer
2018-12-17T22:29:36.076438533Z 64 PC: 1301f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:29:36.07895422Z 87 PC: 13032 | Get or set file date and time
2018-12-17T22:29:36.08020505Z 62 PC: 13036 | Close file
2018-12-17T22:29:36.08824673Z 67 PC: 13044 | Get or set file attributes
2018-12-17T22:29:36.097881585Z 26 PC: 1304c | Set disk transfer address
2018-12-17T22:29:36.099003924Z 37 PC: 1305b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')