Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.1518

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:06.301953044Z 224 PC: 12ec2 | UNKNOWN!
2018-12-17T23:02:06.303417512Z 74 PC: 12b76 | Reallocate memory
2018-12-17T23:02:06.30460878Z 53 PC: 12b7b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:06.305652763Z 37 PC: 12b8f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:06.307112175Z 42 PC: 12bbf | Get date 0x12bbf: mov byte ptr cs:[0xb], 0
0x12bc5: cmp cx, 0x7c3
0x12bc9: je 0x12bfb
0x12bcb: cmp al, 5
0x12bcd: jne 0x12bdc
0x12bcf: cmp dl, 0xd
0x12bd2: jne 0x12bdc
0x12bd4: inc byte ptr cs:[0xb]
0x12bd9: jmp 0x12bfb
0x12bdb: nop
0x12bdc: mov ax, 0x3508
0x12bdf: int 0x21
0x12be1: mov word ptr cs:[0x10], bx
0x12be6: mov word ptr cs:[0x12], es
0x12beb: push cs
0x12bec: pop ds
0x12bed: mov word ptr [0x1c], 0x7e90
0x12bf3: mov ax, 0x2508
0x12bf6: mov dx, 0x1e2
0x12bf9: int 0x21
2018-12-17T23:02:06.308571167Z 53 PC: 12be1 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:02:06.309455153Z 37 PC: 12bfb | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T23:02:06.310765502Z 75 PC: 12c07 | Execute program
2018-12-17T23:02:06.319574188Z 9 PC: 132e2 | Display string (String= 'Goat file (EXE). Size=000003E8h/0000001000d bytes. ')
2018-12-17T23:02:06.323417706Z 76 PC: 132e6 | Terminate with return code (Return code = '36')
2018-12-17T23:02:06.326762569Z 73 PC: 12c0d | Release memory
2018-12-17T23:02:06.328067929Z 77 PC: 12c11 | Get program return code
2018-12-17T23:02:06.329115286Z 49 PC: 12c1f | Terminate and stay resident (Return code = '36' | Memory size = '112')