Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Cookie.2472

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:26.165734354Z 224 PC: 12ba5 | UNKNOWN!
2018-12-17T22:32:26.16781132Z 224 PC: 12bf7 | UNKNOWN!
2018-12-17T22:32:26.168814268Z 74 PC: 12c80 | Reallocate memory
2018-12-17T22:32:26.170133284Z 53 PC: 12c85 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:26.17200786Z 37 PC: 12c99 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:32:26.173336927Z 42 PC: 12cdc | Get date 0x12cdc: mov byte ptr cs:[0xe], 0
0x12ce2: cmp dh, 0xc
0x12ce5: jne 0x12cf4
0x12ce7: cmp dl, 0x1a
0x12cea: jne 0x12cf4
0x12cec: inc byte ptr cs:[0xe]
0x12cf1: jmp 0x12d27
0x12cf3: nop
0x12cf4: cmp dh, 0xb
0x12cf7: jne 0x12d07
0x12cf9: cmp dl, 0xc
0x12cfc: jne 0x12d07
0x12cfe: inc byte ptr cs:[0xe]
0x12d03: jmp 0x12d27
0x12d05: nop
0x12d06: nop
0x12d07: mov ax, 0x3508
0x12d0a: int 0x21
0x12d0c: mov word ptr cs:[0x13], bx
0x12d11: mov word ptr cs:[0x15], es
2018-12-17T22:32:26.176000547Z 53 PC: 12d0c | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:32:26.178275088Z 37 PC: 12d27 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:32:26.179651018Z 75 PC: 12d33 | Execute program
2018-12-17T22:32:26.194793172Z 73 PC: 12d39 | Release memory
2018-12-17T22:32:26.196931297Z 82 PC: 12d3d | Get DOS internal pointers (SYSVARS)
2018-12-17T22:32:26.199379296Z 77 PC: 12d55 | Get program return code
2018-12-17T22:32:26.200779854Z 49 PC: 12d63 | Terminate and stay resident (Return code = '0' | Memory size = '153')