Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Atb.2389

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:27:12.773539942Z 240 PC: 12a45 | UNKNOWN!
2018-12-17T22:27:12.775182445Z 240 PC: 12a90 | UNKNOWN!
2018-12-17T22:27:12.777043872Z 74 PC: 132f1 | Reallocate memory
2018-12-17T22:27:12.778648679Z 53 PC: 132f8 | Get interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:27:12.780733861Z 37 PC: 1330a | Set interrupt vector (Interrupt = '28' AKA 'Get allocation info for specified drive')
2018-12-17T22:27:12.78188495Z 53 PC: 13311 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:12.782887566Z 37 PC: 13323 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:27:12.78419111Z 75 PC: 1335b | Execute program
2018-12-17T22:27:12.799742768Z 9 PC: 13932 | Display string (String= 'Goat file (COM). Size=0000014Dh/0000000333d bytes. ')
2018-12-17T22:27:12.803763496Z 76 PC: 13936 | Terminate with return code (Return code = '36')
2018-12-17T22:27:12.806604Z 73 PC: 13361 | Release memory
2018-12-17T22:27:12.810530995Z 77 PC: 13365 | Get program return code
2018-12-17T22:27:12.815386991Z 49 PC: 13373 | Terminate and stay resident (Return code = '36' | Memory size = '165')