Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Eun.2027

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:54:12.179460122Z 240 PC: 12a84 | UNKNOWN!
2018-12-17T22:54:12.181532273Z 240 PC: 12ad5 | UNKNOWN!
2018-12-17T22:54:12.182767563Z 224 PC: 1316b | UNKNOWN!
2018-12-17T22:54:12.18374066Z 255 PC: 1317b | UNKNOWN!
2018-12-17T22:54:12.184737332Z 74 PC: 12b59 | Reallocate memory
2018-12-17T22:54:12.187292781Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:12.188729474Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:54:12.190155427Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T22:54:12.194189751Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:54:12.196353921Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T22:54:12.197743457Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T22:54:12.211041742Z 75 PC: 12bcb | Execute program
2018-12-17T22:54:12.238427548Z 224 PC: 1316b | UNKNOWN!
2018-12-17T22:54:12.239823953Z 255 PC: 1317b | UNKNOWN!
2018-12-17T22:54:12.243824836Z 73 PC: 12bd1 | Release memory
2018-12-17T22:54:12.245575443Z 77 PC: 12bd5 | Get program return code
2018-12-17T22:54:12.247327203Z 224 PC: 1316b | UNKNOWN!
2018-12-17T22:54:12.248718479Z 255 PC: 1317b | UNKNOWN!
2018-12-17T22:54:12.258677501Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '144')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11474,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:48.512876071Z 240 PC: 12a84 | UNKNOWN!
2018-12-25T12:30:48.519602453Z 240 PC: 12ad5 | UNKNOWN!
2018-12-25T12:30:48.52188914Z 224 PC: 1316b | UNKNOWN!
2018-12-25T12:30:48.52301083Z 255 PC: 1317b | UNKNOWN!
2018-12-25T12:30:48.524795969Z 74 PC: 12b59 | Reallocate memory
2018-12-25T12:30:48.526548449Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:48.5279806Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:30:48.530151576Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:30:48.5313728Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:48.532564027Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:30:48.534283677Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:30:48.535462938Z 75 PC: 12bcb | Execute program
2018-12-25T12:30:48.549285385Z 224 PC: 1316b | UNKNOWN! (See above)
2018-12-25T12:30:48.551390901Z 255 PC: 1317b | UNKNOWN! (See above)
2018-12-25T12:30:48.554669448Z 73 PC: 12bd1 | Release memory
2018-12-25T12:30:48.55626607Z 77 PC: 12bd5 | Get program return code
2018-12-25T12:30:48.559585551Z 224 PC: 1316b | UNKNOWN! (See above)
2018-12-25T12:30:48.560394795Z 255 PC: 1317b | UNKNOWN! (See above)
2018-12-25T12:30:48.561176307Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '144')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11474,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:48.623772362Z 240 PC: 12a84 | UNKNOWN!
2018-12-25T12:30:48.625188838Z 240 PC: 12ad5 | UNKNOWN!
2018-12-25T12:30:48.625860824Z 224 PC: 1316b | UNKNOWN!
2018-12-25T12:30:48.626578507Z 255 PC: 1317b | UNKNOWN!
2018-12-25T12:30:48.627754064Z 74 PC: 12b59 | Reallocate memory
2018-12-25T12:30:48.629197775Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:48.630280785Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:30:48.632326745Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:30:48.633594385Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:48.635181133Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:30:48.636439245Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:30:48.638380366Z 75 PC: 12bcb | Execute program
2018-12-25T12:30:48.648721793Z 224 PC: 1316b | UNKNOWN! (See above)
2018-12-25T12:30:48.650001703Z 255 PC: 1317b | UNKNOWN! (See above)
2018-12-25T12:30:48.653773668Z 73 PC: 12bd1 | Release memory
2018-12-25T12:30:48.655186484Z 77 PC: 12bd5 | Get program return code
2018-12-25T12:30:48.656387264Z 224 PC: 1316b | UNKNOWN! (See above)
2018-12-25T12:30:48.660722664Z 255 PC: 1317b | UNKNOWN! (See above)
2018-12-25T12:30:48.661503359Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '144')

{"DateBased":true,"Day":30,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11474,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:48.940497401Z 240 PC: 12a84 | UNKNOWN!
2018-12-25T12:30:48.941953456Z 240 PC: 12ad5 | UNKNOWN!
2018-12-25T12:30:48.943196634Z 224 PC: 1316b | UNKNOWN!
2018-12-25T12:30:48.943963419Z 255 PC: 1317b | UNKNOWN!
2018-12-25T12:30:48.945318626Z 74 PC: 12b59 | Reallocate memory
2018-12-25T12:30:48.947064743Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:48.948608962Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:30:48.950434646Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:30:48.952482093Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:30:48.953787282Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:30:48.955203414Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:30:48.957835554Z 75 PC: 12bcb | Execute program
2018-12-25T12:30:48.973866271Z 224 PC: 1316b | UNKNOWN! (See above)
2018-12-25T12:30:48.975112047Z 255 PC: 1317b | UNKNOWN! (See above)
2018-12-25T12:30:48.980047553Z 73 PC: 12bd1 | Release memory
2018-12-25T12:30:48.981699492Z 77 PC: 12bd5 | Get program return code
2018-12-25T12:30:48.983277299Z 224 PC: 1316b | UNKNOWN! (See above)
2018-12-25T12:30:48.986954935Z 255 PC: 1317b | UNKNOWN! (See above)
2018-12-25T12:30:48.988121788Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '144')