Sample viewer

vx.netlux.org/Virus.DOS.Vienna.1533

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:08.08104334Z 47 PC: 12eb3 | Get disk transfer address
2018-12-17T22:43:08.097396757Z 26 PC: 12ec2 | Set disk transfer address
2018-12-17T22:43:08.098825694Z 78 PC: 12f49 | Find first file
2018-12-17T22:43:08.104899217Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.108349703Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.112894075Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.115958032Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.120654868Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.124346437Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.127100292Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.130932695Z 67 PC: 12fa5 | Get or set file attributes
2018-12-17T22:43:08.137982879Z 67 PC: 12fb5 | Get or set file attributes
2018-12-17T22:43:08.169562054Z 61 PC: 12fbf | Open file (Filename = 'TEST.COM')
2018-12-17T22:43:08.177026367Z 87 PC: 12fce | Get or set file date and time
2018-12-17T22:43:08.179485266Z 44 PC: 12fd8 | Get time 0x12fd8: mov cx, 3
0x12fdb: mov ah, 0x3f
0x12fdd: mov dx, 0xa
0x12fe0: add dx, si
0x12fe2: push dx
0x12fe3: int 0x21
0x12fe5: pop bp
0x12fe6: jb 0x1300c
0x12fe8: cmp byte ptr [bp], 0x4d
0x12fec: jne 0x12ffa
0x12fee: cmp byte ptr [bp + 1], 0x5a
0x12ff2: je 0x1300c
0x12ff4: jmp 0x12ffa
0x12ff6: jmp 0x13048
0x12ff8: jmp 0x13046
0x12ffa: cmp ax, 3
0x12ffd: jne 0x1304a
0x12fff: xor cx, cx
0x13001: mov ax, 0x4202
0x13004: xor dx, dx
2018-12-17T22:43:08.181590731Z 63 PC: 12fe5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:43:08.184143784Z 66 PC: 13008 | Move file pointer
2018-12-17T22:43:08.186659574Z 64 PC: 13061 | Write file or device (Write 1533 bytes on handle 5)
2018-12-17T22:43:08.205788095Z 66 PC: 13071 | Move file pointer
2018-12-17T22:43:08.207462971Z 64 PC: 1307f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:08.210762914Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:08.213309143Z 62 PC: 13094 | Close file
2018-12-17T22:43:08.220924731Z 67 PC: 130a1 | Get or set file attributes
2018-12-17T22:43:08.230721519Z 26 PC: 130ab | Set disk transfer address
2018-12-17T22:43:08.233155902Z 47 PC: 12eb3 | Get disk transfer address
2018-12-17T22:43:08.237904879Z 26 PC: 12ec2 | Set disk transfer address
2018-12-17T22:43:08.239417592Z 78 PC: 12f49 | Find first file
2018-12-17T22:43:08.247183712Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.250210187Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.253254096Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.257064288Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.263193746Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.267809945Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.271096433Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.273755153Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.276332477Z 78 PC: 12f49 | Find first file
2018-12-17T22:43:08.28564018Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.288641783Z 67 PC: 12fa5 | Get or set file attributes
2018-12-17T22:43:08.294501069Z 67 PC: 12fb5 | Get or set file attributes
2018-12-17T22:43:08.651938809Z 61 PC: 12fbf | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:43:08.657273195Z 87 PC: 12fce | Get or set file date and time
2018-12-17T22:43:08.658736234Z 44 PC: 12fd8 | Get time 0x12fd8: mov cx, 3
0x12fdb: mov ah, 0x3f
0x12fdd: mov dx, 0xa
0x12fe0: add dx, si
0x12fe2: push dx
0x12fe3: int 0x21
0x12fe5: pop bp
0x12fe6: jb 0x1300c
0x12fe8: cmp byte ptr [bp], 0x4d
0x12fec: jne 0x12ffa
0x12fee: cmp byte ptr [bp + 1], 0x5a
0x12ff2: je 0x1300c
0x12ff4: jmp 0x12ffa
0x12ff6: jmp 0x13048
0x12ff8: jmp 0x13046
0x12ffa: cmp ax, 3
0x12ffd: jne 0x1304a
0x12fff: xor cx, cx
0x13001: mov ax, 0x4202
0x13004: xor dx, dx
2018-12-17T22:43:08.661191103Z 63 PC: 12fe5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:43:08.665472545Z 66 PC: 13008 | Move file pointer
2018-12-17T22:43:08.667879645Z 64 PC: 13061 | Write file or device (Write 1533 bytes on handle 5)
2018-12-17T22:43:08.674084654Z 66 PC: 13071 | Move file pointer
2018-12-17T22:43:08.676120691Z 64 PC: 1307f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:08.678998687Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:08.6804378Z 62 PC: 13094 | Close file
2018-12-17T22:43:08.685662262Z 67 PC: 130a1 | Get or set file attributes
2018-12-17T22:43:08.692381819Z 26 PC: 130ab | Set disk transfer address
2018-12-17T22:43:08.693343659Z 47 PC: 12eb3 | Get disk transfer address
2018-12-17T22:43:08.695038224Z 26 PC: 12ec2 | Set disk transfer address
2018-12-17T22:43:08.696018Z 78 PC: 12f49 | Find first file
2018-12-17T22:43:08.699802846Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.702914308Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.704733161Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.706520574Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.70928346Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.711264337Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.71304015Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.715606765Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.717573581Z 78 PC: 12f49 | Find first file
2018-12-17T22:43:08.722122787Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.725078941Z 79 PC: 12f54 | Find next file
2018-12-17T22:43:08.727150743Z 67 PC: 12fa5 | Get or set file attributes
2018-12-17T22:43:08.731029649Z 67 PC: 12fb5 | Get or set file attributes
2018-12-17T22:43:08.740806608Z 61 PC: 12fbf | Open file (Filename = 'C:\DOS\KEYB.COM')
2018-12-17T22:43:08.747536532Z 87 PC: 12fce | Get or set file date and time
2018-12-17T22:43:08.748844147Z 44 PC: 12fd8 | Get time 0x12fd8: mov cx, 3
0x12fdb: mov ah, 0x3f
0x12fdd: mov dx, 0xa
0x12fe0: add dx, si
0x12fe2: push dx
0x12fe3: int 0x21
0x12fe5: pop bp
0x12fe6: jb 0x1300c
0x12fe8: cmp byte ptr [bp], 0x4d
0x12fec: jne 0x12ffa
0x12fee: cmp byte ptr [bp + 1], 0x5a
0x12ff2: je 0x1300c
0x12ff4: jmp 0x12ffa
0x12ff6: jmp 0x13048
0x12ff8: jmp 0x13046
0x12ffa: cmp ax, 3
0x12ffd: jne 0x1304a
0x12fff: xor cx, cx
0x13001: mov ax, 0x4202
0x13004: xor dx, dx
2018-12-17T22:43:08.75747621Z 63 PC: 12fe5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:43:08.763006231Z 66 PC: 13008 | Move file pointer
2018-12-17T22:43:08.76464444Z 64 PC: 13061 | Write file or device (Write 1533 bytes on handle 5)
2018-12-17T22:43:08.775852906Z 66 PC: 13071 | Move file pointer
2018-12-17T22:43:08.777405689Z 64 PC: 1307f | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:43:08.780251283Z 87 PC: 13090 | Get or set file date and time
2018-12-17T22:43:08.782488873Z 62 PC: 13094 | Close file
2018-12-17T22:43:08.789899741Z 67 PC: 130a1 | Get or set file attributes
2018-12-17T22:43:08.800385358Z 26 PC: 130ab | Set disk transfer address
2018-12-17T22:43:08.802636267Z 7 PC: 1312c | Direct console input without echo