Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Taiwan.2454

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:00:01.664431713Z 75 PC: 12adb | Execute program
2018-12-17T23:00:01.666380165Z 75 PC: 12b2c | Execute program
2018-12-17T23:00:01.773452502Z 74 PC: 12bde | Reallocate memory
2018-12-17T23:00:01.7753888Z 53 PC: 12be3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:01.777209292Z 37 PC: 12bf7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:00:01.779079697Z 53 PC: 12c28 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:01.781904846Z 44 PC: 12c38 | Get time 0x12c38: mov cl, dh
0x12c3a: and cl, 1
0x12c3d: cmp cl, 0
0x12c40: mov dx, 0x242
0x12c43: jne 0x12c45
0x12c45: mov word ptr [0x14], 1
0x12c4b: mov word ptr [0x93], 0
0x12c51: mov byte ptr [0x92], 1
0x12c56: mov ax, 0x2508
0x12c59: int 0x21
0x12c5b: pop dx
0x12c5c: pop cx
0x12c5d: pop bx
0x12c5e: pop ax
0x12c5f: pop es
0x12c60: pop ds
0x12c61: pushf
0x12c62: lcall ptr cs:[0x3b]
0x12c67: push ds
0x12c68: pop es
2018-12-17T23:00:01.785677355Z 37 PC: 12c5b | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:00:01.788205857Z 75 PC: 12c67 | Execute program
2018-12-17T23:00:01.80553373Z 9 PC: 13627 | Display string (String= 'Warning!! Plastique II come in !! Caught By [Peter Ferng] !!')
2018-12-17T23:00:01.812721779Z 73 PC: 12c6d | Release memory
2018-12-17T23:00:01.814899922Z 77 PC: 12c71 | Get program return code
2018-12-17T23:00:01.817577824Z 49 PC: 12c7f | Terminate and stay resident (Return code = '0' | Memory size = '169')