Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Roger.2128

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:33.305443385Z 250 PC: 14c5a | UNKNOWN!
2018-12-17T22:30:33.306905523Z 74 PC: 12b9e | Reallocate memory
2018-12-17T22:30:33.318634893Z 53 PC: 12ba3 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:30:33.319809246Z 37 PC: 12bb7 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:30:33.32113725Z 42 PC: 12be8 | Get date 0x12be8: mov byte ptr cs:[0x2e], 0
0x12bee: cmp dl, 0xb
0x12bf1: je 0x12bfb
0x12bf3: cmp dl, 0x17
0x12bf6: je 0x12bfb
0x12bf8: jmp 0x12c19
0x12bfa: nop
0x12bfb: inc byte ptr cs:[0x2e]
0x12c00: mov ax, 0x3513
0x12c03: int 0x21
0x12c05: mov word ptr cs:[0x22], bx
0x12c0a: mov word ptr cs:[0x24], es
0x12c0f: push cs
0x12c10: pop ds
0x12c11: mov ax, 0x2513
0x12c14: mov dx, 0x200
0x12c17: int 0x21
0x12c19: pop bx
0x12c1a: pop ax
0x12c1b: pop cx
2018-12-17T22:30:33.325206485Z 75 PC: 12c25 | Execute program
2018-12-17T22:30:33.337345028Z 74 PC: 144e2 | Reallocate memory
2018-12-17T22:30:33.3390191Z 48 PC: 1450a | Get DOS version
2018-12-17T22:30:33.341653183Z 74 PC: 14cfe | Reallocate memory
2018-12-17T22:30:33.343770676Z 68 PC: 14e33 | I/O control for devices (Set for = '')
2018-12-17T22:30:33.34561274Z 68 PC: 14e33 | I/O control for devices (Set for = '')
2018-12-17T22:30:33.351021053Z 68 PC: 14e33 | I/O control for devices (Set for = '')
2018-12-17T22:30:33.353304497Z 68 PC: 14e33 | I/O control for devices (Set for = '')
2018-12-17T22:30:33.355020599Z 68 PC: 14e33 | I/O control for devices (Set for = '')
2018-12-17T22:30:33.366993835Z 25 PC: 138f9 | Get default drive
2018-12-17T22:30:33.369212415Z 71 PC: 13921 | Get current directory
2018-12-17T22:30:33.372474557Z 26 PC: 1379b | Set disk transfer address
2018-12-17T22:30:33.373978333Z 78 PC: 137a4 | Find first file
2018-12-17T22:30:33.382323899Z 26 PC: 1379b | Set disk transfer address
2018-12-17T22:30:33.383602161Z 78 PC: 137a4 | Find first file
2018-12-17T22:30:33.391298058Z 53 PC: 1468f | Get interrupt vector (Interrupt = '103' AKA 'Set handle count')
2018-12-17T22:30:33.394776917Z 64 PC: 13474 | Write file or device (Write 45 bytes on handle 1)
2018-12-17T22:30:33.400173019Z 76 PC: 14610 | Terminate with return code (Return code = '1')
2018-12-17T22:30:33.403520224Z 73 PC: 12c2b | Release memory
2018-12-17T22:30:33.404750895Z 77 PC: 12c2f | Get program return code
2018-12-17T22:30:33.40583286Z 49 PC: 12c3d | Terminate and stay resident (Return code = '1' | Memory size = '132')