Sample viewer

vx.netlux.org/Virus.DOS.Tunnel.823

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:20.507902695Z 48 PC: 12e2f | Get DOS version
2018-12-17T23:04:20.510026673Z 26 PC: 12e6f | Set disk transfer address
2018-12-17T23:04:20.510968653Z 78 PC: 12e86 | Find first file
2018-12-17T23:04:20.515511879Z 61 PC: 12e9b | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:20.520301104Z 63 PC: 12ed7 | Read file or device (Read 20 bytes on handle 5)
2018-12-17T23:04:20.52466606Z 66 PC: 130ce | Move file pointer
2018-12-17T23:04:20.526721752Z 64 PC: 12f20 | Write file or device (Write 823 bytes on handle 5)
2018-12-17T23:04:20.542174435Z 66 PC: 130ce | Move file pointer
2018-12-17T23:04:20.543988186Z 64 PC: 12f57 | Write file or device (Write 20 bytes on handle 5)
2018-12-17T23:04:20.551367555Z 87 PC: 12f5e | Get or set file date and time
2018-12-17T23:04:20.553686512Z 62 PC: 12ebe | Close file
2018-12-17T23:04:20.561406274Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.56464659Z 61 PC: 12e9b | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:20.571879969Z 62 PC: 12ebe | Close file
2018-12-17T23:04:20.573518508Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.576290674Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.579512552Z 61 PC: 12e9b | Open file (Filename = 'PHANG.COM')
2018-12-17T23:04:20.585972872Z 62 PC: 12ebe | Close file
2018-12-17T23:04:20.587829196Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.590796315Z 61 PC: 12e9b | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:04:20.598839938Z 62 PC: 12ebe | Close file
2018-12-17T23:04:20.600467277Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.603168684Z 61 PC: 12e9b | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:04:20.610726281Z 63 PC: 12ed7 | Read file or device (Read 20 bytes on handle 5)
2018-12-17T23:04:20.616982901Z 66 PC: 130ce | Move file pointer
2018-12-17T23:04:20.6184065Z 64 PC: 12f20 | Write file or device (Write 823 bytes on handle 5)
2018-12-17T23:04:20.627932153Z 66 PC: 130ce | Move file pointer
2018-12-17T23:04:20.629415373Z 64 PC: 12f57 | Write file or device (Write 20 bytes on handle 5)
2018-12-17T23:04:20.636851788Z 87 PC: 12f5e | Get or set file date and time
2018-12-17T23:04:20.639726637Z 62 PC: 12ebe | Close file
2018-12-17T23:04:20.646600785Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.64964815Z 61 PC: 12e9b | Open file (Filename = 'PAH.COM')
2018-12-17T23:04:20.65744953Z 62 PC: 12ebe | Close file
2018-12-17T23:04:20.659303058Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.662254926Z 79 PC: 12e86 | Find next file
2018-12-17T23:04:20.665981496Z 26 PC: 130c6 | Set disk transfer address
2018-12-17T23:04:20.6671509Z 9 PC: 12a82 | Display string (String= 'Goat file (COM). Size=000003E8h/0000001000d bytes. ')
2018-12-17T23:04:20.672439552Z 76 PC: 12a86 | Terminate with return code (Return code = '36')