Sample viewer

vx.netlux.org/Trojan.DOS.Courz

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:47.476599274Z 48 PC: 12a4c | Get DOS version
2018-12-17T22:46:47.478861948Z 53 PC: 12ba8 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:47.481053857Z 53 PC: 12bb5 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:46:47.489876772Z 53 PC: 12bc2 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:46:47.492749454Z 53 PC: 12bcf | Get interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:46:47.494891035Z 37 PC: 12be3 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:47.496895207Z 74 PC: 12b19 | Reallocate memory
2018-12-17T22:46:47.509277256Z 25 PC: 13eac | Get default drive
2018-12-17T22:46:47.523813641Z 67 PC: 13544 | Get or set file attributes
2018-12-17T22:46:47.529532809Z 67 PC: 13544 | Get or set file attributes
2018-12-17T22:46:47.873422587Z 65 PC: 13526 | Delete file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:46:47.884195357Z 68 PC: 131ad | I/O control for devices (Set for = 'C:\COMMAND.COM')
2018-12-17T22:46:47.886418315Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.890619763Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.895257886Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.899345032Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.902904384Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.912611827Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.91704562Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.920936343Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.923895914Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.927121839Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.929926137Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.939231646Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.94237205Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.94542039Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.950057555Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.953094099Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.956162239Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.96005275Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.963068604Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.966251029Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.970299075Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.973978682Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.977038802Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.980674755Z 64 PC: 133ed | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:46:47.984015962Z 37 PC: 12bef | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:46:47.985091533Z 37 PC: 12bfa | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T22:46:47.986533693Z 37 PC: 12c05 | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:46:47.987580604Z 37 PC: 12c10 | Set interrupt vector (Interrupt = '6' AKA 'Direct console I/O')
2018-12-17T22:46:47.988658374Z 76 PC: 12b98 | Terminate with return code (Return code = '1')