Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Aurora.1548

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:07.641186704Z 224 PC: 12ae8 | UNKNOWN!
2018-12-17T22:53:07.642639007Z 53 PC: 12f77 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:07.643838563Z 37 PC: 12f8d | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:53:07.645318764Z 53 PC: 12fac | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:53:07.647579408Z 37 PC: 12fc2 | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:53:07.649113823Z 74 PC: 12fcf | Reallocate memory
2018-12-17T22:53:07.650810288Z 75 PC: 13038 | Execute program
2018-12-17T22:53:07.664726484Z 238 PC: 42b18 | UNKNOWN!
2018-12-17T22:53:07.665987306Z 9 PC: 42a77 | Display string (String= ' Ths is Jerusalem.PiPi.1548 Virus........... ')
2018-12-17T22:53:07.671217534Z 76 PC: 42a7c | Terminate with return code (Return code = '0')
2018-12-17T22:53:07.674127728Z 73 PC: 1303e | Release memory
2018-12-17T22:53:07.676023534Z 77 PC: 13042 | Get program return code
2018-12-17T22:53:07.67712013Z 49 PC: 13049 | Terminate and stay resident (Return code = '0' | Memory size = '128')