Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.2000.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:02:54.41747899Z 240 PC: 12a84 | UNKNOWN!
2018-12-17T23:02:54.418566451Z 240 PC: 12ad5 | UNKNOWN!
2018-12-17T23:02:54.420593864Z 224 PC: 13150 | UNKNOWN!
2018-12-17T23:02:54.421580326Z 255 PC: 13160 | UNKNOWN!
2018-12-17T23:02:54.423479331Z 74 PC: 12b59 | Reallocate memory
2018-12-17T23:02:54.426039306Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:54.427946913Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:02:54.429841845Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T23:02:54.432455873Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:02:54.434219566Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-17T23:02:54.435839731Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-17T23:02:54.439730772Z 75 PC: 12bcb | Execute program
2018-12-17T23:02:54.456536963Z 224 PC: 13150 | UNKNOWN!
2018-12-17T23:02:54.457949095Z 255 PC: 13160 | UNKNOWN!
2018-12-17T23:02:54.460560195Z 73 PC: 12bd1 | Release memory
2018-12-17T23:02:54.462520905Z 77 PC: 12bd5 | Get program return code
2018-12-17T23:02:54.464295629Z 224 PC: 13150 | UNKNOWN!
2018-12-17T23:02:54.465566764Z 255 PC: 13160 | UNKNOWN!
2018-12-17T23:02:54.467343891Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '143')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14365,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:22.28836321Z 240 PC: 12a84 | UNKNOWN!
2018-12-25T12:40:22.290006523Z 240 PC: 12ad5 | UNKNOWN!
2018-12-25T12:40:22.291108624Z 224 PC: 13150 | UNKNOWN!
2018-12-25T12:40:22.292062667Z 255 PC: 13160 | UNKNOWN!
2018-12-25T12:40:22.292951672Z 74 PC: 12b59 | Reallocate memory
2018-12-25T12:40:22.295526627Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:22.2970519Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:40:22.298166346Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:40:22.300170438Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:22.301949242Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:40:22.303471309Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:40:22.305511964Z 75 PC: 12bcb | Execute program
2018-12-25T12:40:22.321183385Z 224 PC: 13150 | UNKNOWN! (See above)
2018-12-25T12:40:22.322235281Z 255 PC: 13160 | UNKNOWN! (See above)
2018-12-25T12:40:22.32498797Z 73 PC: 12bd1 | Release memory
2018-12-25T12:40:22.326677905Z 77 PC: 12bd5 | Get program return code
2018-12-25T12:40:22.327892231Z 224 PC: 13150 | UNKNOWN! (See above)
2018-12-25T12:40:22.328999399Z 255 PC: 13160 | UNKNOWN! (See above)
2018-12-25T12:40:22.330521934Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '143')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14365,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:22.901895301Z 240 PC: 12a84 | UNKNOWN!
2018-12-25T12:40:22.903337287Z 240 PC: 12ad5 | UNKNOWN!
2018-12-25T12:40:22.90483758Z 224 PC: 13150 | UNKNOWN!
2018-12-25T12:40:22.905839322Z 255 PC: 13160 | UNKNOWN!
2018-12-25T12:40:22.907162148Z 74 PC: 12b59 | Reallocate memory
2018-12-25T12:40:22.909135215Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:22.910550541Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:40:22.912004234Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:40:22.914424079Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:22.915768096Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:40:22.9173377Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:40:22.920085105Z 75 PC: 12bcb | Execute program
2018-12-25T12:40:22.936749796Z 224 PC: 13150 | UNKNOWN! (See above)
2018-12-25T12:40:22.937989287Z 255 PC: 13160 | UNKNOWN! (See above)
2018-12-25T12:40:22.94282071Z 73 PC: 12bd1 | Release memory
2018-12-25T12:40:22.944739803Z 77 PC: 12bd5 | Get program return code
2018-12-25T12:40:22.946545953Z 224 PC: 13150 | UNKNOWN! (See above)
2018-12-25T12:40:22.949023915Z 255 PC: 13160 | UNKNOWN! (See above)
2018-12-25T12:40:22.950043151Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '143')

{"DateBased":true,"Day":30,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14365,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:40:23.158360181Z 240 PC: 12a84 | UNKNOWN!
2018-12-25T12:40:23.159477745Z 240 PC: 12ad5 | UNKNOWN!
2018-12-25T12:40:23.160654071Z 224 PC: 13150 | UNKNOWN!
2018-12-25T12:40:23.161391336Z 255 PC: 13160 | UNKNOWN!
2018-12-25T12:40:23.162306968Z 74 PC: 12b59 | Reallocate memory
2018-12-25T12:40:23.164377095Z 53 PC: 12b5e | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:23.165729288Z 53 PC: 12b6d | Get interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:40:23.167017612Z 53 PC: 12b7c | Get interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:40:23.169224013Z 37 PC: 12b90 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:40:23.18022506Z 37 PC: 12b98 | Set interrupt vector (Interrupt = '32' AKA 'Reserved')
2018-12-25T12:40:23.19071849Z 37 PC: 12ba0 | Set interrupt vector (Interrupt = '39' AKA 'Random block read')
2018-12-25T12:40:23.192841669Z 75 PC: 12bcb | Execute program
2018-12-25T12:40:23.208838344Z 224 PC: 13150 | UNKNOWN! (See above)
2018-12-25T12:40:23.20997329Z 255 PC: 13160 | UNKNOWN! (See above)
2018-12-25T12:40:23.213759791Z 73 PC: 12bd1 | Release memory
2018-12-25T12:40:23.216146258Z 77 PC: 12bd5 | Get program return code
2018-12-25T12:40:23.217620575Z 224 PC: 13150 | UNKNOWN! (See above)
2018-12-25T12:40:23.219497486Z 255 PC: 13160 | UNKNOWN! (See above)
2018-12-25T12:40:23.220518169Z 49 PC: 12be3 | Terminate and stay resident (Return code = '0' | Memory size = '143')