Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.1511

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:28:47.76795982Z 243 PC: 12ad6 | UNKNOWN!
2018-12-17T22:28:47.769419351Z 243 PC: 12b2a | UNKNOWN!
2018-12-17T22:28:47.770504387Z 74 PC: 12bab | Reallocate memory
2018-12-17T22:28:47.771856382Z 53 PC: 12bb0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:47.773611992Z 37 PC: 12bc4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:28:47.775142442Z 42 PC: 12bf4 | Get date 0x12bf4: mov byte ptr cs:[0xe], 0
0x12bfa: cmp cx, 0x7c5
0x12bfe: je 0x12c28
0x12c00: cmp al, 1
0x12c02: jne 0x12c28
0x12c04: inc byte ptr cs:[0xe]
0x12c09: mov ax, 0x3508
0x12c0c: int 0x21
0x12c0e: mov word ptr cs:[0x13], bx
0x12c13: mov word ptr cs:[0x15], es
0x12c18: push cs
0x12c19: pop ds
0x12c1a: mov word ptr [0x1f], 0x2ff
0x12c20: mov ax, 0x2508
0x12c23: mov dx, 0x20f
0x12c26: int 0x21
0x12c28: pop dx
0x12c29: pop cx
0x12c2a: pop bx
0x12c2b: pop ax
2018-12-17T22:28:47.777756353Z 53 PC: 12c0e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:28:47.780510672Z 37 PC: 12c28 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:28:47.782096711Z 75 PC: 12c34 | Execute program
2018-12-17T22:28:47.797238589Z 73 PC: 12c3a | Release memory
2018-12-17T22:28:47.801699079Z 77 PC: 12c3e | Get program return code
2018-12-17T22:28:47.803800421Z 49 PC: 12c4c | Terminate and stay resident (Return code = '0' | Memory size = '110')