Sample viewer

vx.netlux.org/Virus.DOS.Dotter.4611

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:15:57.232118463Z 81 PC: 13e8a | Get current PSP
2018-12-17T23:15:57.233186674Z 98 PC: 13e98 | Get current PSP
2018-12-17T23:15:57.234865928Z 74 PC: 13ea1 | Reallocate memory
2018-12-17T23:15:57.23748117Z 74 PC: 13eac | Reallocate memory
2018-12-17T23:15:57.239153283Z 72 PC: 13ec3 | Allocate memory
2018-12-17T23:15:57.243569861Z 53 PC: 9ed1a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:15:57.244907965Z 37 PC: 9ed2f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:15:57.246130514Z 44 PC: 9ed33 | Get time 0x9ed33: mov word ptr cs:[0x381], cx
0x9ed38: retf
0x9ed39: clc
0x9ed3a: inc ax
0x9ed3b: sbb word ptr [bx + si], ax
0x9ed3d: add byte ptr [bx + si], al
0x9ed3f: add byte ptr [bx + si], al
0x9ed41: adc word ptr [si], ax
0x9ed43: add byte ptr [bx + si], al
0x9ed45: add byte ptr [bp + di + 0x59], dl
0x9ed48: push bx
0x9ed49: push sp
0x9ed4a: inc bp
0x9ed4b: dec bp
0x9ed4c: add byte ptr [bx + di], al
0x9ed4e: cmp ah, 0x4b
0x9ed51: je 0x9ed6a
0x9ed53: nop
0x9ed54: nop
0x9ed55: nop
2018-12-17T23:15:57.25368274Z 9 PC: 12a82 | Display string (String= 'Bait File 1388h/5000 byte long EXE bait file . ')
2018-12-17T23:15:57.258235282Z 76 PC: 12a86 | Terminate with return code (Return code = '36')