Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.2Tigers.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:05.734760332Z 240 PC: 12ada | UNKNOWN!
2018-12-17T22:51:05.7364453Z 240 PC: 12b2d | UNKNOWN!
2018-12-17T22:51:05.737946879Z 74 PC: 12bb1 | Reallocate memory
2018-12-17T22:51:05.739565654Z 53 PC: 12bb6 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:05.741914579Z 37 PC: 12bca | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:05.743249816Z 42 PC: 33c4 | Get date 0x33c4: or ax, 0x6f7
0x33c7: das
0x33c8: add ax, 0x80
0x33cb: je 0x33d2
0x33cd: mov byte ptr [0x536], 1
0x33d2: xor ax, ax
0x33d4: xor bx, bx
0x33d6: mov word ptr [0x537], bx
0x33da: call 0x341c
0x33dd: mov byte ptr [0x536], 0
0x33e2: ret
0x33e3: mov ah, 1
0x33e5: jmp 0x30f5
0x33e8: mov byte ptr [0x120], 2
0x33ed: jmp 0x33f4
0x33ef: mov byte ptr [0x120], 3
0x33f4: push es
0x33f5: les bx, ptr [0x12]
0x33f9: les bx, ptr es:[bx + 0x13]
0x33fd: mov ax, word ptr es:[bx + 3]