Sample viewer

vx.netlux.org/Virus.DOS.Vienna.730

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:42.370363833Z 48 PC: 12a6b | Get DOS version
2018-12-17T22:31:42.371399995Z 47 PC: 12a77 | Get disk transfer address
2018-12-17T22:31:42.374521319Z 26 PC: 12a8a | Set disk transfer address
2018-12-17T22:31:42.375609152Z 78 PC: 12b1c | Find first file
2018-12-17T22:31:42.381467124Z 67 PC: 12b5a | Get or set file attributes
2018-12-17T22:31:42.387948624Z 67 PC: 12b6c | Get or set file attributes
2018-12-17T22:31:42.402931707Z 61 PC: 12b77 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:31:42.40948009Z 87 PC: 12b83 | Get or set file date and time
2018-12-17T22:31:42.411123343Z 42 PC: 12b8f | Get date 0x12b8f: cmp dh, 2
0x12b92: je 0x12b9b
0x12b94: cmp al, 1
0x12b96: je 0x12bc5
0x12b98: jmp 0x12bd5
0x12b9a: nop
0x12b9b: mov al, 2
0x12b9d: mov cx, 0x96
0x12ba0: mov dx, 0
0x12ba3: int 0x26
0x12ba5: mov al, 3
0x12ba7: mov cx, 0x96
0x12baa: mov dx, 0
0x12bad: int 0x26
0x12baf: mov al, 4
0x12bb1: mov cx, 0x96
0x12bb4: mov dx, 0
0x12bb7: int 0x26
0x12bb9: mov al, 0
0x12bbb: mov cx, 0x96
2018-12-17T22:31:42.413470771Z 60 PC: 12bcf | Create or truncate file
2018-12-17T22:31:42.426768837Z 62 PC: 12bd5 | Close file
2018-12-17T22:31:42.428812882Z 63 PC: 12be2 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:31:42.431479112Z 87 PC: 12c4c | Get or set file date and time
2018-12-17T22:31:42.433149163Z 62 PC: 12c50 | Close file
2018-12-17T22:31:42.434876257Z 67 PC: 12c5f | Get or set file attributes
2018-12-17T22:31:42.44671801Z 26 PC: 12c6c | Set disk transfer address