Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.2187

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:29.180561485Z 61 PC: 12b48 | Open file (Filename = 'is started by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-17T22:52:29.184078973Z 61 PC: 12b99 | Open file (Filename = 'is started by using +the SHELL command in the CONFIG.SYS file. F##¸#ã#,$z$À$%U% %à%,&y&')
2018-12-17T22:52:29.187325206Z 74 PC: 12c17 | Reallocate memory
2018-12-17T22:52:29.188450421Z 171 PC: 12c1e | UNKNOWN!
2018-12-17T22:52:29.197988334Z 53 PC: 12c41 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:29.199218688Z 37 PC: 12c85 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:52:29.200414583Z 53 PC: 12cb8 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:52:29.20320388Z 53 PC: 12d28 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:52:29.204409481Z 37 PC: 12d3a | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:52:29.205676529Z 75 PC: 12d49 | Execute program
2018-12-17T22:52:29.21712254Z 9 PC: 13437 | Display string (String= '2187 (Friday Related) Come in!!! Caught by Joey Yu ............!!!')
2018-12-17T22:52:29.223020243Z 73 PC: 12d4f | Release memory
2018-12-17T22:52:29.224318141Z 77 PC: 12d53 | Get program return code
2018-12-17T22:52:29.225514469Z 49 PC: 12d62 | Terminate and stay resident (Return code = '0' | Memory size = '137')