Sample viewer

vx.netlux.org/Virus.DOS.Witch.1140

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:39:29.259847732Z 44 PC: 1786d | Get time 0x1786d: or ch, ch
0x1786f: jne 0x17881
0x17871: mov ax, 0xc08
0x17874: call 0x277cd
0x17877: lea dx, word ptr [si + 6]
0x1787a: mov ah, 9
0x1787c: int 0x21
0x1787e: jmp 0x177aa
0x17881: mov ah, 0x2a
0x17883: int 0x21
0x17885: cmp dl, 1
0x17888: jne 0x178a8
0x1788a: cmp dh, 4
0x1788d: jne 0x178a8
0x1788f: mov ax, 0xb12
0x17892: call 0x277cd
0x17895: lea dx, word ptr [si + 0x47]
0x17898: mov ah, 9
0x1789a: int 0x21
0x1789c: mov dx, 0xd0c
2018-12-17T22:39:29.264881381Z 9 PC: 1787e | Display string (Could not find end pointer)
2018-12-17T22:39:29.270481566Z 37 PC: 177b2 | Set interrupt vector (Interrupt = '25' AKA 'Get default drive')