Sample viewer

vx.netlux.org/Virus.DOS.Vienna.612

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:44:01.239892235Z 48 PC: 12a71 | Get DOS version
2018-12-17T22:44:01.242266899Z 47 PC: 12a7d | Get disk transfer address
2018-12-17T22:44:01.249056996Z 26 PC: 12a8c | Set disk transfer address
2018-12-17T22:44:01.250457184Z 78 PC: 12b0d | Find first file
2018-12-17T22:44:01.258126558Z 67 PC: 12b45 | Get or set file attributes
2018-12-17T22:44:01.266243965Z 67 PC: 12b56 | Get or set file attributes
2018-12-17T22:44:01.284089324Z 61 PC: 12b60 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:44:01.290554411Z 87 PC: 12b6c | Get or set file date and time
2018-12-17T22:44:01.292842881Z 44 PC: 12b76 | Get time 0x12b76: and dh, 7
0x12b79: jne 0x12b8b
0x12b7b: jmp 0x12b8c
0x12b7d: mov ah, 0x40
0x12b7f: mov cx, 5
0x12b82: mov dx, si
0x12b84: add dx, 0x8a
0x12b88: int 0x21
0x12b8a: jmp 0x12bed
0x12b8c: mov ah, 0x3f
0x12b8e: mov cx, 3
0x12b91: mov dx, 0xa
0x12b94: add dx, si
0x12b96: int 0x21
0x12b98: jb 0x12bed
0x12b9a: cmp ax, 3
0x12b9d: jne 0x12bed
0x12b9f: mov ax, 0x4202
0x12ba2: mov cx, 0
0x12ba5: mov dx, 0
2018-12-17T22:44:01.295277408Z 63 PC: 12b98 | Read file or device (Read 3 bytes on handle 39424)
2018-12-17T22:44:01.296996915Z 87 PC: 12c00 | Get or set file date and time
2018-12-17T22:44:01.299783289Z 62 PC: 12c04 | Close file
2018-12-17T22:44:01.30187595Z 67 PC: 12c11 | Get or set file attributes
2018-12-17T22:44:01.311483503Z 26 PC: 12c1b | Set disk transfer address
2018-12-17T22:44:01.31357839Z 0 PC: 12a57 | Program terminate

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8081,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:19.878892452Z 48 PC: 12a71 | Get DOS version
2018-12-25T12:03:19.881031898Z 47 PC: 12a7d | Get disk transfer address
2018-12-25T12:03:19.882120925Z 26 PC: 12a8c | Set disk transfer address
2018-12-25T12:03:19.88321481Z 78 PC: 12b0d | Find first file
2018-12-25T12:03:19.889774921Z 67 PC: 12b45 | Get or set file attributes
2018-12-25T12:03:19.908481453Z 67 PC: 12b56 | Get or set file attributes
2018-12-25T12:03:21.15493928Z 61 PC: 12b60 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:03:21.161470331Z 87 PC: 12b6c | Get or set file date and time
2018-12-25T12:03:21.163463662Z 44 PC: 12b76 | Get time 0x12b76: and dh, 7
0x12b79: jne 0x12b8b
0x12b7b: jmp 0x12b8c
0x12b7d: mov ah, 0x40
0x12b7f: mov cx, 5
0x12b82: mov dx, si
0x12b84: add dx, 0x8a
0x12b88: int 0x21
0x12b8a: jmp 0x12bed
0x12b8c: mov ah, 0x3f
0x12b8e: mov cx, 3
0x12b91: mov dx, 0xa
0x12b94: add dx, si
0x12b96: int 0x21
0x12b98: jb 0x12bed
0x12b9a: cmp ax, 3
0x12b9d: jne 0x12bed
0x12b9f: mov ax, 0x4202
0x12ba2: mov cx, 0
0x12ba5: mov dx, 0
2018-12-25T12:03:21.16581439Z 63 PC: 12b98 | Read file or device (Read 3 bytes on handle 39424)
2018-12-25T12:03:21.167452803Z 87 PC: 12c00 | Get or set file date and time
2018-12-25T12:03:21.169390092Z 62 PC: 12c04 | Close file
2018-12-25T12:03:21.17096737Z 67 PC: 12c11 | Get or set file attributes
2018-12-25T12:03:21.175371469Z 26 PC: 12c1b | Set disk transfer address
2018-12-25T12:03:21.177267544Z 0 PC: 12a57 | Program terminate

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":7,"TimeBased":true,"OriginalID":8081,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:03:20.145165458Z 48 PC: 12a71 | Get DOS version
2018-12-25T12:03:20.151579566Z 47 PC: 12a7d | Get disk transfer address
2018-12-25T12:03:20.152977517Z 26 PC: 12a8c | Set disk transfer address
2018-12-25T12:03:20.154622935Z 78 PC: 12b0d | Find first file
2018-12-25T12:03:20.161658146Z 67 PC: 12b45 | Get or set file attributes
2018-12-25T12:03:20.168889549Z 67 PC: 12b56 | Get or set file attributes
2018-12-25T12:03:20.196573747Z 61 PC: 12b60 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:03:20.205748028Z 87 PC: 12b6c | Get or set file date and time
2018-12-25T12:03:20.207708807Z 44 PC: 12b76 | Get time 0x12b76: and dh, 7
0x12b79: jne 0x12b8b
0x12b7b: jmp 0x12b8c
0x12b7d: mov ah, 0x40
0x12b7f: mov cx, 5
0x12b82: mov dx, si
0x12b84: add dx, 0x8a
0x12b88: int 0x21
0x12b8a: jmp 0x12bed
0x12b8c: mov ah, 0x3f
0x12b8e: mov cx, 3
0x12b91: mov dx, 0xa
0x12b94: add dx, si
0x12b96: int 0x21
0x12b98: jb 0x12bed
0x12b9a: cmp ax, 3
0x12b9d: jne 0x12bed
0x12b9f: mov ax, 0x4202
0x12ba2: mov cx, 0
0x12ba5: mov dx, 0
2018-12-25T12:03:20.210025853Z 63 PC: 12b98 | Read file or device (Read 3 bytes on handle 39424)
2018-12-25T12:03:20.211530603Z 87 PC: 12c00 | Get or set file date and time
2018-12-25T12:03:20.213733635Z 62 PC: 12c04 | Close file
2018-12-25T12:03:20.215982117Z 67 PC: 12c11 | Get or set file attributes
2018-12-25T12:03:20.221329939Z 26 PC: 12c1b | Set disk transfer address
2018-12-25T12:03:20.224114487Z 0 PC: 12a57 | Program terminate