Sample viewer

vx.netlux.org/Trojan.DOS.Sparki

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:10:12.028723856Z 48 PC: 162ac | Get DOS version
2018-12-17T23:10:12.0315344Z 74 PC: 162fc | Reallocate memory
2018-12-17T23:10:12.033880688Z 48 PC: 16360 | Get DOS version
2018-12-17T23:10:12.035503022Z 53 PC: 16368 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:12.037732687Z 37 PC: 1637a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:12.03956705Z 68 PC: 1640b | I/O control for devices (Set for = 'WJWUWW')
2018-12-17T23:10:12.042094444Z 68 PC: 1640b | I/O control for devices
2018-12-17T23:10:12.044547748Z 68 PC: 1640b | I/O control for devices
2018-12-17T23:10:12.046457071Z 68 PC: 1640b | I/O control for devices
2018-12-17T23:10:12.048391961Z 68 PC: 1640b | I/O control for devices
2018-12-17T23:10:12.050902427Z 53 PC: 14854 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:12.052499579Z 53 PC: 14861 | Get interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:10:12.053814439Z 53 PC: 1486e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:12.055157613Z 37 PC: 14883 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:12.056877028Z 37 PC: 1488b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:10:12.058458594Z 37 PC: 14893 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:12.060236064Z 53 PC: 15312 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:10:12.062979277Z 53 PC: 1531f | Get interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:10:12.064221725Z 53 PC: 1532e | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:10:12.065385733Z 37 PC: 1533b | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:10:12.067170176Z 53 PC: 15342 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:10:12.068538587Z 37 PC: 1534f | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:10:12.069827721Z 53 PC: 1535b | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:10:12.074956395Z 48 PC: 1541d | Get DOS version
2018-12-17T23:10:12.076503522Z 68 PC: 147ca | I/O control for devices (Set for = 'j { � N   2 �3')
2018-12-17T23:10:12.078159002Z 68 PC: 147ca | I/O control for devices (Set for = '�')
2018-12-17T23:10:12.081426817Z 51 PC: 147e8 | Get or set Ctrl-Break
2018-12-17T23:10:12.082635796Z 51 PC: 147f4 | Get or set Ctrl-Break
2018-12-17T23:10:12.086211928Z 61 PC: 131fa | Open file (Filename = 'C:\AUTOEXEC.BAT')
2018-12-17T23:10:12.098228461Z 68 PC: 13153 | I/O control for devices (Set for = '  ')
2018-12-17T23:10:12.102179551Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.103915028Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.107880863Z 63 PC: 12ff6 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T23:10:12.112249842Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.114833738Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.117377165Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.119700549Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.121774602Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.124424116Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.126924168Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.12897894Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.131578167Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.134747064Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.136841001Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.13938285Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.142553098Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.145513764Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.147649419Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.150526882Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.152905164Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.155011291Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.157327419Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.160204927Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.162294164Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.164388526Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.167091204Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.169111164Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.171144192Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.17416616Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.175958698Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.177702875Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.180267992Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.18207997Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.183797097Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.186968807Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.188690994Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.190368072Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.192079465Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.194456937Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.196160196Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.197821167Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.200902678Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.202928128Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.204956225Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.20772848Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.210176152Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.212314276Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.215585285Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.221246295Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.22342915Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.225692639Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.228037589Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.229780973Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.231465061Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.234180078Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.236283723Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.238352972Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.241189633Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.243302953Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.245428816Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.248386289Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.250455129Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.25242387Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.254972924Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.256852773Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.258632431Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.261547621Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.263369372Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.265128251Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.267179383Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.270050491Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.272182372Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.274369396Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.276818798Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.278565739Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.280337334Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.283055372Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.285206456Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.287257047Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.290155598Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.292245703Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.294370898Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.296913512Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.299648967Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.301691893Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.304205699Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.306115055Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.307853711Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.309770032Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.312377461Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.314368656Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.316219007Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.318472315Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.320478806Z 63 PC: 12ff6 | Read file or device (Read 512 bytes on handle 5)
2018-12-17T23:10:12.323250359Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.330008449Z 64 PC: 1301c | Write file or device (Write 97 bytes on handle 5)
2018-12-17T23:10:12.34433889Z 66 PC: 12dcf | Move file pointer
2018-12-17T23:10:12.346222949Z 62 PC: 1302d | Close file
2018-12-17T23:10:12.694605318Z 37 PC: 155ed | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:10:12.696420627Z 53 PC: 155f4 | Get interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:10:12.698260807Z 37 PC: 15601 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T23:10:12.70029465Z 37 PC: 1560c | Set interrupt vector (Interrupt = '239' AKA 'UNKNOWN!')
2018-12-17T23:10:12.701745306Z 37 PC: 15617 | Set interrupt vector (Interrupt = '240' AKA 'UNKNOWN!')
2018-12-17T23:10:12.703157768Z 51 PC: 147ff | Get or set Ctrl-Break
2018-12-17T23:10:12.705922045Z 37 PC: 14a81 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:12.707577376Z 37 PC: 14a8b | Set interrupt vector (Interrupt = '4' AKA 'Auxiliary output')
2018-12-17T23:10:12.710049112Z 37 PC: 14a95 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:10:12.712305092Z 37 PC: 164bc | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T23:10:12.713579612Z 76 PC: 164a5 | Terminate with return code (Return code = '0')