Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.1968

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:06:07.272017106Z 176 PC: 12ac6 | UNKNOWN!
2018-12-17T23:06:07.273356321Z 176 PC: 12b1a | UNKNOWN!
2018-12-17T23:06:07.274614786Z 74 PC: 12b9e | Reallocate memory
2018-12-17T23:06:07.276113897Z 53 PC: 12ba3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:07.277643023Z 37 PC: 12bb7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:06:07.279709956Z 42 PC: 12be9 | Get date 0x12be9: mov byte ptr cs:[0x2e], 0
0x12bef: cmp dl, 0x1e
0x12bf2: je 0x12bfc
0x12bf4: cmp dl, 0x11
0x12bf7: je 0x12bfc
0x12bf9: jmp 0x12c3b
0x12bfb: nop
0x12bfc: xor ax, ax
0x12bfe: mov es, ax
0x12c00: mov ax, 0x449
0x12c03: mov si, ax
0x12c05: mov al, byte ptr es:[si]
0x12c08: cmp al, 7
0x12c0a: je 0x12c16
0x12c0c: mov word ptr cs:[0x26b], 0xb800
0x12c13: jmp 0x12c1d
0x12c15: nop
0x12c16: mov word ptr cs:[0x26b], 0xb000
0x12c1d: inc byte ptr cs:[0x2e]
0x12c22: mov ax, 0x351c
2018-12-17T23:06:07.281995173Z 53 PC: 12c27 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:06:07.283332987Z 37 PC: 12c3b | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T23:06:07.285690197Z 75 PC: 12c48 | Execute program
2018-12-17T23:06:07.307419136Z 9 PC: 13382 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T23:06:07.311598754Z 76 PC: 13386 | Terminate with return code (Return code = '36')
2018-12-17T23:06:07.315606432Z 73 PC: 12c4e | Release memory
2018-12-17T23:06:07.317068591Z 77 PC: 12c52 | Get program return code
2018-12-17T23:06:07.31823162Z 49 PC: 12c60 | Terminate and stay resident (Return code = '36' | Memory size = '122')