Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Roger.2000

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:07.203289842Z 176 PC: 12d0a | UNKNOWN!
2018-12-17T23:01:07.20460153Z 74 PC: 12b9e | Reallocate memory
2018-12-17T23:01:07.206119016Z 53 PC: 12ba3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:07.207372337Z 37 PC: 12bb7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:01:07.209105848Z 42 PC: 12bf8 | Get date 0x12bf8: mov byte ptr cs:[0x2e], 0
0x12bfe: cmp dl, 0x1e
0x12c01: je 0x12c0b
0x12c03: cmp dl, 0x11
0x12c06: je 0x12c0b
0x12c08: jmp 0x12c4a
0x12c0a: nop
0x12c0b: xor ax, ax
0x12c0d: mov es, ax
0x12c0f: mov ax, 0x449
0x12c12: mov si, ax
0x12c14: mov al, byte ptr es:[si]
0x12c17: cmp al, 7
0x12c19: je 0x12c25
0x12c1b: mov word ptr cs:[0x27c], 0xb800
0x12c22: jmp 0x12c2c
0x12c24: nop
0x12c25: mov word ptr cs:[0x27c], 0xb000
0x12c2c: inc byte ptr cs:[0x2e]
0x12c31: mov ax, 0x351c
2018-12-17T23:01:07.211822008Z 53 PC: 12c36 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:01:07.213364877Z 37 PC: 12c4a | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:01:07.214503907Z 75 PC: 12c57 | Execute program
2018-12-17T23:01:07.232069962Z 9 PC: 13542 | Display string (Could not find end pointer)
2018-12-17T23:01:07.236785393Z 76 PC: 13548 | Terminate with return code (Return code = '0')
2018-12-17T23:01:07.239104721Z 73 PC: 12c5d | Release memory
2018-12-17T23:01:07.240883607Z 77 PC: 12c61 | Get program return code
2018-12-17T23:01:07.242011113Z 49 PC: 12c6f | Terminate and stay resident (Return code = '0' | Memory size = '124')