Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.1808

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:37.834858915Z 224 PC: 12ad3 | UNKNOWN!
2018-12-17T22:55:37.837239711Z 224 PC: 12b27 | UNKNOWN!
2018-12-17T22:55:37.838206655Z 74 PC: 12bab | Reallocate memory
2018-12-17T22:55:37.839552755Z 53 PC: 12bb0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:37.84515779Z 37 PC: 12bc4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:55:37.846912985Z 42 PC: 12bf4 | Get date 0x12bf4: mov byte ptr cs:[7], 0
0x12bfa: cmp cx, 0x7c3
0x12bfe: je 0x12c30
0x12c00: cmp al, 5
0x12c02: jne 0x12c11
0x12c04: cmp dl, 0xd
0x12c07: jne 0x12c11
0x12c09: inc byte ptr cs:[7]
0x12c0e: jmp 0x12c30
0x12c10: nop
0x12c11: mov ax, 0x3508
0x12c14: int 0x21
0x12c16: mov word ptr cs:[0xc], bx
0x12c1b: mov word ptr cs:[0xe], es
0x12c20: push cs
0x12c21: pop ds
0x12c22: mov word ptr [0x18], 0x7e90
0x12c28: mov ax, 0x2508
0x12c2b: mov dx, 0x217
0x12c2e: int 0x21
2018-12-17T22:55:37.849550519Z 53 PC: 12c16 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:55:37.851339858Z 37 PC: 12c30 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:55:37.854082477Z 75 PC: 12c3c | Execute program
2018-12-17T22:55:37.87180904Z 9 PC: 132e2 | Display string (String= 'Goat file (COM). Size=00000064h/0000000100d bytes. ')
2018-12-17T22:55:37.876370866Z 76 PC: 132e6 | Terminate with return code (Return code = '36')
2018-12-17T22:55:37.8796278Z 73 PC: 12c42 | Release memory
2018-12-17T22:55:37.881094685Z 77 PC: 12c46 | Get program return code
2018-12-17T22:55:37.882463978Z 49 PC: 12c54 | Terminate and stay resident (Return code = '36' | Memory size = '112')