Sample viewer

vx.netlux.org/Virus.DOS.Kaos4.697

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:50:09.668220957Z 26 PC: 12bfd | Set disk transfer address
2018-12-17T22:50:09.669668302Z 78 PC: 12e2c | Find first file
2018-12-17T22:50:09.6739237Z 67 PC: 12c79 | Get or set file attributes
2018-12-17T22:50:10.182423439Z 61 PC: 12c80 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:50:10.190492376Z 63 PC: 12c8e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:50:10.198134742Z 66 PC: 12cf0 | Move file pointer
2018-12-17T22:50:10.200457469Z 64 PC: 12d50 | Write file or device (Write 697 bytes on handle 5)
2018-12-17T22:50:10.314888624Z 66 PC: 12d59 | Move file pointer
2018-12-17T22:50:10.316907236Z 64 PC: 12d7f | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:50:10.324711788Z 87 PC: 12d95 | Get or set file date and time
2018-12-17T22:50:10.327776768Z 62 PC: 12d9a | Close file
2018-12-17T22:50:10.35027679Z 67 PC: 12dac | Get or set file attributes
2018-12-17T22:50:10.361456218Z 78 PC: 12e2c | Find first file
2018-12-17T22:50:10.372843663Z 78 PC: 12e2c | Find first file
2018-12-17T22:50:10.39661709Z 67 PC: 12c79 | Get or set file attributes
2018-12-17T22:50:10.75932623Z 61 PC: 12c80 | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:50:10.769093305Z 63 PC: 12c8e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:50:10.773648333Z 66 PC: 12cf0 | Move file pointer
2018-12-17T22:50:10.776520445Z 64 PC: 12d50 | Write file or device (Write 697 bytes on handle 5)
2018-12-17T22:50:10.789340441Z 66 PC: 12d59 | Move file pointer
2018-12-17T22:50:10.791309503Z 64 PC: 12d7f | Write file or device (Write 26 bytes on handle 5)
2018-12-17T22:50:10.795708085Z 87 PC: 12d95 | Get or set file date and time
2018-12-17T22:50:10.798104316Z 62 PC: 12d9a | Close file
2018-12-17T22:50:10.806277166Z 67 PC: 12dac | Get or set file attributes
2018-12-17T22:50:10.819569147Z 26 PC: 12c24 | Set disk transfer address
2018-12-17T22:50:10.821235571Z 76 PC: 12b0e | Terminate with return code (Return code = '0')