Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Dengue

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:52:52.651881181Z 75 PC: 12ada | Execute program
2018-12-17T21:52:52.654083543Z 75 PC: 12b2b | Execute program
2018-12-17T21:52:52.756630054Z 74 PC: 12bdd | Reallocate memory
2018-12-17T21:52:52.7577427Z 53 PC: 12be2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:52:52.759157172Z 37 PC: 12bf6 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T21:52:52.760605476Z 53 PC: 12c27 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:52:52.761828833Z 44 PC: 12c37 | Get time 0x12c37: mov cl, dh
0x12c39: and cl, 1
0x12c3c: cmp cl, 0
0x12c3f: mov dx, 0x241
0x12c42: jne 0x12c44
0x12c44: mov word ptr [0x14], 1
0x12c4a: mov word ptr [0x92], 0
0x12c50: mov byte ptr [0x91], 1
0x12c55: mov ax, 0x2508
0x12c58: int 0x21
0x12c5a: pop dx
0x12c5b: pop cx
0x12c5c: pop bx
0x12c5d: pop ax
0x12c5e: pop es
0x12c5f: pop ds
0x12c60: pushf
0x12c61: lcall ptr cs:[0x3b]
0x12c66: push ds
0x12c67: pop es
2018-12-17T21:52:52.763629752Z 37 PC: 12c5a | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T21:52:52.764988682Z 75 PC: 12c66 | Execute program
2018-12-17T21:52:52.776915589Z 73 PC: 12c6c | Release memory
2018-12-17T21:52:52.77824436Z 77 PC: 12c70 | Get program return code
2018-12-17T21:52:52.779844671Z 49 PC: 12c7e | Terminate and stay resident (Return code = '0' | Memory size = '181')