Sample viewer

vx.netlux.org/Virus.DOS.StoneHeart.1490

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:02:25.560090765Z 98 PC: 12a44 | Get current PSP
2018-12-17T22:02:25.561858534Z 42 PC: 12a66 | Get date 0x12a66: cmp bx, 0x4d45
0x12a6a: je 0x12aa2
0x12a6c: pop si
0x12a6d: push si
0x12a6e: sub si, 0x1f
0x12a71: push es
0x12a72: mov ax, word ptr [2]
0x12a75: sub ax, 0x5e
0x12a78: mov es, ax
0x12a7a: call 0x12b87
0x12a7d: pop ds
0x12a7e: mov si, 0xa
0x12a81: mov di, 0x17c
0x12a84: movsw word ptr es:[di], word ptr [si]
0x12a85: movsw word ptr es:[di], word ptr [si]
0x12a86: mov word ptr [si - 4], 0x15e
0x12a8b: mov word ptr [si - 2], es
0x12a8e: mov ds, cx
0x12a90: mov si, 0x84
0x12a93: mov di, 0x19e
2018-12-17T22:02:25.565540998Z 53 PC: 12b13 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:25.566729785Z 37 PC: 12b1d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:25.568260955Z 47 PC: 12b21 | Get disk transfer address
2018-12-17T22:02:25.569960963Z 26 PC: 12b2b | Set disk transfer address
2018-12-17T22:02:25.570880985Z 78 PC: 12b39 | Find first file
2018-12-17T22:02:25.57626217Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T22:02:25.57775605Z 79 PC: 12b6b | Find next file
2018-12-17T22:02:25.580234782Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T22:02:25.582447981Z 79 PC: 12b6b | Find next file
2018-12-17T22:02:25.585118997Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T22:02:25.586318612Z 79 PC: 12b6b | Find next file
2018-12-17T22:02:25.58907543Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T22:02:25.590335439Z 79 PC: 12b6b | Find next file
2018-12-17T22:02:25.592175438Z 47 PC: 12b3f | Get disk transfer address
2018-12-17T22:02:25.593123289Z 79 PC: 12b6b | Find next file
2018-12-17T22:02:25.59644896Z 78 PC: 12b39 | Find first file
2018-12-17T22:02:25.598747704Z 26 PC: 12b7d | Set disk transfer address
2018-12-17T22:02:25.600167915Z 37 PC: 12b84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:02:25.602513183Z 76 PC: 13d40 | Terminate with return code (Return code = '0')
2018-12-17T22:02:25.606227817Z 72 PC: 9f785 | Allocate memory