Sample viewer

vx.netlux.org/Virus.DOS.StoneHeart.1437

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:10:16.437709371Z 98 PC: 16b81 | Get current PSP
2018-12-17T22:10:16.439630605Z 42 PC: 16ba3 | Get date 0x16ba3: cmp bx, 0x4d45
0x16ba7: je 0x16bdc
0x16ba9: pop si
0x16baa: push si
0x16bab: sub si, 0x1f
0x16bae: push es
0x16baf: mov ax, word ptr [2]
0x16bb2: sub ax, 0x5a
0x16bb5: mov es, ax
0x16bb7: call 0x16c9c
0x16bba: pop ds
0x16bbb: mov si, 0xa
0x16bbe: mov di, 0x154
0x16bc1: movsw word ptr es:[di], word ptr [si]
0x16bc2: movsw word ptr es:[di], word ptr [si]
0x16bc3: mov word ptr [si - 4], 0x136
0x16bc8: mov word ptr [si - 2], es
0x16bcb: mov ds, cx
0x16bcd: mov si, 0x84
0x16bd0: mov di, 0x176
2018-12-17T22:10:16.442540712Z 9 PC: 12a82 | Display string (String= 'Goat file (EXE). Size=000042D7h/0000017111d bytes. ')
2018-12-17T22:10:16.446533954Z 76 PC: 12a86 | Terminate with return code (Return code = '36')