Sample viewer

vx.netlux.org/Virus.DOS.Kohntark.K-CMOS.933

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:27.854173025Z 26 PC: 12a81 | Set disk transfer address
2018-12-17T21:55:27.856520508Z 78 PC: 12d44 | Find first file
2018-12-17T21:55:27.862403457Z 67 PC: 12b19 | Get or set file attributes
2018-12-17T21:55:27.877769304Z 61 PC: 12b20 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:55:27.884615714Z 63 PC: 12b2e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T21:55:27.891859006Z 66 PC: 12b8c | Move file pointer
2018-12-17T21:55:27.893380975Z 64 PC: 12c35 | Write file or device (Write 16 bytes on handle 5)
2018-12-17T21:55:27.898980976Z 64 PC: 12c58 | Write file or device (Write 917 bytes on handle 5)
2018-12-17T21:55:27.908080839Z 66 PC: 12c63 | Move file pointer
2018-12-17T21:55:27.90971916Z 64 PC: 12c89 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T21:55:27.916291904Z 87 PC: 12c9c | Get or set file date and time
2018-12-17T21:55:27.918715099Z 62 PC: 12ca1 | Close file
2018-12-17T21:55:27.926318518Z 67 PC: 12cb0 | Get or set file attributes
2018-12-17T21:55:27.936055875Z 78 PC: 12d44 | Find first file
2018-12-17T21:55:27.943078866Z 78 PC: 12d44 | Find first file
2018-12-17T21:55:27.952407146Z 67 PC: 12b19 | Get or set file attributes
2018-12-17T21:55:28.296409651Z 61 PC: 12b20 | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T21:55:28.305855641Z 63 PC: 12b2e | Read file or device (Read 28 bytes on handle 5)
2018-12-17T21:55:28.312200756Z 66 PC: 12b8c | Move file pointer
2018-12-17T21:55:28.31427626Z 64 PC: 12c35 | Write file or device (Write 16 bytes on handle 5)
2018-12-17T21:55:28.321259572Z 64 PC: 12c58 | Write file or device (Write 917 bytes on handle 5)
2018-12-17T21:55:28.327534802Z 66 PC: 12c63 | Move file pointer
2018-12-17T21:55:28.328522495Z 64 PC: 12c89 | Write file or device (Write 28 bytes on handle 5)
2018-12-17T21:55:28.330813801Z 87 PC: 12c9c | Get or set file date and time
2018-12-17T21:55:28.332155715Z 62 PC: 12ca1 | Close file
2018-12-17T21:55:28.336595902Z 67 PC: 12cb0 | Get or set file attributes
2018-12-17T21:55:28.344310162Z 26 PC: 12a9e | Set disk transfer address
2018-12-17T21:55:28.345601356Z 76 PC: 12a4d | Terminate with return code (Return code = '0')