Sample viewer

vx.netlux.org/Virus.DOS.Crash.543

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:29:46.702612851Z 47 PC: 18f44 | Get disk transfer address
2018-12-17T22:29:46.718052776Z 26 PC: 18f53 | Set disk transfer address
2018-12-17T22:29:46.719425752Z 42 PC: 18eff | Get date 0x18eff: cmp al, 5
0x18f01: clc
0x18f02: jne 0x18f0b
0x18f04: cmp dl, 0xd
0x18f07: clc
0x18f08: jne 0x18f0b
0x18f0a: stc
0x18f0b: ret
0x18f0c: push sp
0x18f0d: push 0x7461
0x18f10: and byte ptr [bp + di + 0x6f], ah
0x18f13: jne 0x18f81
0x18f15: and byte ptr fs:[bp + si + 0x65], ah
0x18f19: and byte ptr [bx + di + 0x20], ah
0x18f1c: arpl word ptr [bp + si + 0x61], si
0x18f1f: jae 0x18f89
0x18f21: sub al, 0x20
0x18f23: arpl word ptr [bp + si + 0x61], si
0x18f26: jae 0x18f90
0x18f28: sub al, 0x20
2018-12-17T22:29:46.721825821Z 98 PC: 18e4c | Get current PSP
2018-12-17T22:29:46.723511569Z 78 PC: 18ed7 | Find first file
2018-12-17T22:29:46.732575869Z 61 PC: 18dcc | Open file (Filename = 'C:\DOS\EDIT.COM')
2018-12-17T22:29:46.7391554Z 63 PC: 18de1 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:29:46.744866995Z 66 PC: 18deb | Move file pointer
2018-12-17T22:29:46.746261602Z 64 PC: 18e06 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:29:46.748840492Z 64 PC: 18e13 | Write file or device (Write 543 bytes on handle 5)
2018-12-17T22:29:47.095206068Z 66 PC: 18e1f | Move file pointer
2018-12-17T22:29:47.097625156Z 64 PC: 18e2a | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:29:47.103483683Z 87 PC: 18e3c | Get or set file date and time
2018-12-17T22:29:47.106165975Z 62 PC: 18e41 | Close file
2018-12-17T22:29:47.112575543Z 26 PC: 18f5d | Set disk transfer address
2018-12-17T22:29:47.113680431Z 48 PC: 13777 | Get DOS version
2018-12-17T22:29:47.115648745Z 9 PC: 13783 | Display string (String= 'Incorrect DOS version ')