Sample viewer

vx.netlux.org/Virus.DOS.Vienna.846

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:33:05.289726004Z 47 PC: 13a26 | Get disk transfer address
2018-12-17T22:33:05.29424575Z 26 PC: 13a35 | Set disk transfer address
2018-12-17T22:33:05.296437053Z 78 PC: 13abe | Find first file
2018-12-17T22:33:05.302865185Z 79 PC: 13ac8 | Find next file
2018-12-17T22:33:05.30540376Z 79 PC: 13ac8 | Find next file
2018-12-17T22:33:05.308553157Z 79 PC: 13ac8 | Find next file
2018-12-17T22:33:05.311336763Z 79 PC: 13ac8 | Find next file
2018-12-17T22:33:05.313986717Z 79 PC: 13ac8 | Find next file
2018-12-17T22:33:05.317164082Z 79 PC: 13ac8 | Find next file
2018-12-17T22:33:05.320017301Z 79 PC: 13ac8 | Find next file
2018-12-17T22:33:05.323177994Z 67 PC: 13b20 | Get or set file attributes
2018-12-17T22:33:05.330846918Z 67 PC: 13b30 | Get or set file attributes
2018-12-17T22:33:05.350673675Z 61 PC: 13b3a | Open file (Filename = 'TEST.COM')
2018-12-17T22:33:05.358069978Z 87 PC: 13b49 | Get or set file date and time
2018-12-17T22:33:05.364103369Z 44 PC: 13b53 | Get time 0x13b53: mov cx, 3
0x13b56: mov ah, 0x3f
0x13b58: mov dx, 0xa
0x13b5b: add dx, si
0x13b5d: push dx
0x13b5e: int 0x21
0x13b60: pop bp
0x13b61: jb 0x13b87
0x13b63: cmp byte ptr [bp], 0x4d
0x13b67: jne 0x13b75
0x13b69: cmp byte ptr [bp + 1], 0x5a
0x13b6d: je 0x13b87
0x13b6f: jmp 0x13b75
0x13b71: jmp 0x13bc3
0x13b73: jmp 0x13bc1
0x13b75: cmp ax, 3
0x13b78: jne 0x13bc5
0x13b7a: xor cx, cx
0x13b7c: mov ax, 0x4202
0x13b7f: xor dx, dx
2018-12-17T22:33:05.36709667Z 63 PC: 13b60 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:33:05.370242399Z 66 PC: 13b83 | Move file pointer
2018-12-17T22:33:05.372843559Z 64 PC: 13bdc | Write file or device (Write 846 bytes on handle 5)
2018-12-17T22:33:05.383165666Z 66 PC: 13bec | Move file pointer
2018-12-17T22:33:05.389458622Z 64 PC: 13bfa | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:33:05.392826048Z 87 PC: 13c08 | Get or set file date and time
2018-12-17T22:33:05.395211943Z 62 PC: 13c0c | Close file
2018-12-17T22:33:05.404047824Z 67 PC: 13c19 | Get or set file attributes
2018-12-17T22:33:05.419811849Z 26 PC: 13c23 | Set disk transfer address
2018-12-17T22:33:05.422478833Z 9 PC: 13908 | Display string (String= 'Goat file (COM/b...). Size=00000FA0h/0000004000d bytes. ')
2018-12-17T22:33:05.428804933Z 48 PC: 13911 | Get DOS version
2018-12-17T22:33:05.430238933Z 61 PC: 139de | Open file (Filename = '')
2018-12-17T22:33:05.44281368Z 93 PC: 13980 | File sharing functions
2018-12-17T22:33:05.446375238Z 9 PC: 13908 | Display string (String= 'Size change=069Ch/01692d. ')
2018-12-17T22:33:05.451351139Z 76 PC: 13965 | Terminate with return code (Return code = '1')