Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.2368

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:24.371315212Z 226 PC: 12ada | UNKNOWN!
2018-12-17T23:09:24.372778083Z 226 PC: 12b2f | UNKNOWN!
2018-12-17T23:09:24.37365603Z 74 PC: 12bb8 | Reallocate memory
2018-12-17T23:09:24.374658214Z 53 PC: 12bbd | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:24.376338498Z 37 PC: 12bd1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:09:24.378480757Z 42 PC: 12c25 | Get date 0x12c25: mov word ptr cs:[bx + si], dx
0x12c28: inc si
0x12c29: inc si
0x12c2a: mov word ptr cs:[bx + si], cx
0x12c2d: inc si
0x12c2e: inc si
0x12c2f: cmp word ptr cs:[bx + si], 0
0x12c33: jne 0x12c92
0x12c35: mov word ptr cs:[bx + si], 0x7c9
0x12c3a: inc si
0x12c3b: inc si
0x12c3c: mov ah, 0x2c
0x12c3e: int 0x21
0x12c40: mov word ptr cs:[bx + si], dx
0x12c43: jmp 0x12c92
0x12c45: mov ah, 0x2a
0x12c47: int 0x21
0x12c49: mov si, 0x13c
0x12c4c: cmp cx, word ptr cs:[bx + si]
0x12c4f: je 0x12c5a
2018-12-17T23:09:24.380123108Z 44 PC: 12c40 | Get time 0x12c40: mov word ptr cs:[bx + si], dx
0x12c43: jmp 0x12c92
0x12c45: mov ah, 0x2a
0x12c47: int 0x21
0x12c49: mov si, 0x13c
0x12c4c: cmp cx, word ptr cs:[bx + si]
0x12c4f: je 0x12c5a
0x12c51: cmp al, 5
0x12c53: jne 0x12c5a
0x12c55: cmp dl, 9
0x12c58: je 0x12c63
0x12c5a: mov si, 0x136
0x12c5d: cmp word ptr cs:[bx + si], 0
0x12c61: jne 0x12c8c
0x12c63: mov si, 0x1c2
0x12c66: cmp byte ptr cs:[bx + si], 0
0x12c6a: je 0x12c97
0x12c6c: mov cx, 0x20
0x12c6f: mov si, 0x1be
0x12c72: mov di, 0x18e
2018-12-17T23:09:24.714736764Z 75 PC: 12ca3 | Execute program
2018-12-17T23:09:24.73028191Z 9 PC: 13512 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T23:09:24.734447826Z 76 PC: 13516 | Terminate with return code (Return code = '36')
2018-12-17T23:09:24.737370321Z 73 PC: 12ca9 | Release memory
2018-12-17T23:09:24.739218324Z 77 PC: 12cad | Get program return code
2018-12-17T23:09:24.740377238Z 49 PC: 12cbb | Terminate and stay resident (Return code = '36' | Memory size = '147')