Sample viewer

vx.netlux.org/Trojan.DOS.WolfCheat

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:04:19.63367978Z 53 PC: 15292 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:19.635634025Z 53 PC: 15292 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:04:19.636829593Z 53 PC: 15292 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:04:19.638021342Z 53 PC: 15292 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:04:19.639734541Z 53 PC: 15292 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:19.640857499Z 53 PC: 15292 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:19.642009055Z 53 PC: 15292 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:04:19.643362816Z 53 PC: 15292 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:04:19.64579096Z 53 PC: 15292 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:04:19.647706484Z 53 PC: 15292 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:04:19.649628568Z 53 PC: 15292 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:04:19.652069175Z 53 PC: 15292 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:04:19.653998004Z 53 PC: 15292 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:04:19.655910409Z 53 PC: 15292 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:04:19.657995022Z 53 PC: 15292 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:04:19.659094874Z 53 PC: 15292 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:04:19.660137087Z 53 PC: 15292 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:04:19.666132357Z 53 PC: 15292 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:04:19.667369127Z 53 PC: 15292 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:04:19.66841282Z 37 PC: 152a7 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:19.670497295Z 37 PC: 152af | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:19.671571353Z 37 PC: 152b7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:19.672576253Z 37 PC: 152bf | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:04:19.674438057Z 68 PC: 15892 | I/O control for devices (Set for = '')
2018-12-17T22:04:19.675924712Z 51 PC: 15164 | Get or set Ctrl-Break
2018-12-17T22:04:19.676680591Z 51 PC: 15179 | Get or set Ctrl-Break
2018-12-17T22:04:19.679268996Z 37 PC: 150e4 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:04:19.727626394Z 53 PC: 15202 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:19.729336321Z 47 PC: 13dce | Get disk transfer address
2018-12-17T22:04:19.731512557Z 53 PC: 13dfe | Get interrupt vector (Interrupt = '51' AKA 'Get or set Ctrl-Break')
2018-12-17T22:04:19.733287714Z 53 PC: 13e37 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:04:19.734669318Z 53 PC: 13e47 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:04:19.736879582Z 53 PC: 13e57 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:19.739435967Z 53 PC: 13e67 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:19.74059028Z 53 PC: 13e77 | Get interrupt vector (Interrupt = '16' AKA 'Close file')
2018-12-17T22:04:19.741835922Z 53 PC: 13e87 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:04:19.743102116Z 53 PC: 13e97 | Get interrupt vector (Interrupt = '20' AKA 'Sequential read')
2018-12-17T22:04:19.74433075Z 53 PC: 13ea7 | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:04:19.746003696Z 53 PC: 13eb7 | Get interrupt vector (Interrupt = '23' AKA 'Rename file')
2018-12-17T22:04:19.747381014Z 53 PC: 13ec7 | Get interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:04:19.748697456Z 53 PC: 13ed7 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:04:19.750506415Z 53 PC: 13ee7 | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:04:19.752193611Z 53 PC: 13ef7 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:04:19.753553943Z 53 PC: 13f07 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:04:19.754915353Z 53 PC: 13f17 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:04:19.769694921Z 53 PC: 13f27 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:04:19.771050461Z 53 PC: 13f37 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:04:19.772230368Z 53 PC: 13f47 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:04:19.774133494Z 53 PC: 13f57 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:04:19.775530287Z 53 PC: 13f67 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:04:19.776921987Z 53 PC: 13f77 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:04:19.778238857Z 53 PC: 13f87 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:04:19.779289602Z 53 PC: 13f97 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:04:19.780434283Z 53 PC: 13fa7 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:04:19.782284207Z 48 PC: 13fb5 | Get DOS version
2018-12-17T22:04:19.783224107Z 52 PC: 13fbf | Get InDOS flag pointer
2018-12-17T22:04:19.78434775Z 53 PC: 15202 | Get interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:04:19.785871568Z 37 PC: 1521e | Set interrupt vector (Interrupt = '5' AKA 'Printer output')
2018-12-17T22:04:19.787170865Z 53 PC: 15202 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:19.78836662Z 37 PC: 1521e | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:04:19.791157541Z 53 PC: 15202 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:19.792327476Z 37 PC: 1521e | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:04:19.79357757Z 53 PC: 15202 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:04:19.795401034Z 37 PC: 1521e | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:04:19.796894301Z 53 PC: 15202 | Get interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:04:19.798282823Z 37 PC: 1521e | Set interrupt vector (Interrupt = '22' AKA 'Create or truncate file')
2018-12-17T22:04:19.800659121Z 53 PC: 15202 | Get interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:04:19.802051468Z 37 PC: 1521e | Set interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:04:19.803600728Z 53 PC: 15202 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:04:19.805766174Z 37 PC: 1521e | Set interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:04:19.807607838Z 53 PC: 15202 | Get interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:04:19.808987282Z 37 PC: 1521e | Set interrupt vector (Interrupt = '40' AKA 'Random block write')
2018-12-17T22:04:19.81110867Z 48 PC: 12ca5 | Get DOS version
2018-12-17T22:04:19.812688602Z 56 PC: 12cb3 | Get or set country info
2018-12-17T22:04:19.814274281Z 26 PC: 151a2 | Set disk transfer address
2018-12-17T22:04:19.816014106Z 78 PC: 151ae | Find first file
2018-12-17T22:04:19.822498251Z 53 PC: 15202 | Get interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:04:19.823904288Z 37 PC: 1521e | Set interrupt vector (Interrupt = '37' AKA 'Set interrupt vector')
2018-12-17T22:04:19.826084417Z 53 PC: 15202 | Get interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:04:19.827788469Z 37 PC: 1521e | Set interrupt vector (Interrupt = '38' AKA 'Create PSP')
2018-12-17T22:04:19.829352428Z 37 PC: 1521e | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:04:19.83090641Z 37 PC: 1521e | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:04:19.833490345Z 37 PC: 1521e | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:04:19.834636896Z 37 PC: 1521e | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:04:19.835666198Z 37 PC: 1521e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:04:19.837428243Z 37 PC: 1521e | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:04:19.838641124Z 37 PC: 1521e | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:04:19.839944036Z 37 PC: 1521e | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:04:19.841968452Z 37 PC: 1521e | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:04:19.8438472Z 37 PC: 1521e | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:04:19.845237996Z 37 PC: 1521e | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:04:19.847415755Z 37 PC: 1521e | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:04:19.848540616Z 37 PC: 1521e | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:04:19.849487299Z 37 PC: 1521e | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:04:19.851468687Z 37 PC: 1521e | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:04:19.852589991Z 37 PC: 1521e | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:04:19.85366269Z 37 PC: 1521e | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:04:19.855601746Z 37 PC: 1521e | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:04:19.856836769Z 49 PC: 15135 | Terminate and stay resident (Return code = '0' | Memory size = '1130')