Sample viewer

vx.netlux.org/Virus.DOS.Dutch_Tiny.Brenda

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:43:28.211495813Z 78 PC: 12a62 | Find first file
2018-12-17T22:43:28.217952999Z 61 PC: 12a6c | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:43:28.225328223Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:43:28.231676412Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.235874989Z 61 PC: 12a6c | Open file (Filename = 'PRINT.COM')
2018-12-17T22:43:28.242880894Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 6)
2018-12-17T22:43:28.24941197Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.253026302Z 61 PC: 12a6c | Open file (Filename = 'HELLO.COM')
2018-12-17T22:43:28.259858556Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 7)
2018-12-17T22:43:28.266737193Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.269889693Z 61 PC: 12a6c | Open file (Filename = 'PHANG.COM')
2018-12-17T22:43:28.277563093Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 8)
2018-12-17T22:43:28.284402973Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.294453315Z 61 PC: 12a6c | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:43:28.30181697Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 9)
2018-12-17T22:43:28.308133186Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.311013497Z 61 PC: 12a6c | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:43:28.317975027Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 10)
2018-12-17T22:43:28.324528845Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.327364832Z 61 PC: 12a6c | Open file (Filename = 'PAH.COM')
2018-12-17T22:43:28.335044958Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 11)
2018-12-17T22:43:28.341410967Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.344789177Z 61 PC: 12a6c | Open file (Filename = 'TEST.COM')
2018-12-17T22:43:28.352191094Z 63 PC: 12a81 | Read file or device (Read 3 bytes on handle 12)
2018-12-17T22:43:28.354987188Z 79 PC: 12a62 | Find next file
2018-12-17T22:43:28.357598519Z 44 PC: 12af0 | Get time 0x12af0: cmp dl, 5
0x12af3: je 0x12af7
0x12af5: jmp bp
0x12af7: mov ah, 2
0x12af9: xor bx, bx
0x12afb: mov dl, byte ptr [bx + si + 0x1d6]
0x12aff: cmp dl, 0
0x12b02: je 0x12b0c
0x12b04: sub dl, 0x64
0x12b07: int 0x21
0x12b09: inc bx
0x12b0a: jmp 0x12afb
0x12b0c: jmp 0x12af5
0x12b0e: add byte ptr [bx + si], al
0x12b10: sub ch, byte ptr [0x4f43]
0x12b14: dec bp
0x12b15: add byte ptr [bx + di + 0x6e], dh
0x12b18: mov word ptr [bx - 0x7b73], fs
0x12b1c: mov bx, word ptr [di - 0x6f6a]
0x12b20: test byte ptr [bx - 0x3228], dh