Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.1962

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:48.697514245Z 224 PC: 12c4b | UNKNOWN!
2018-12-17T22:45:48.698522733Z 74 PC: 12bc0 | Reallocate memory
2018-12-17T22:45:48.701086372Z 53 PC: 12bc5 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:48.702427445Z 37 PC: 12bd9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:45:48.703862083Z 42 PC: 12c09 | Get date 0x12c09: mov byte ptr cs:[0xe], 0
0x12c0f: cmp cx, 0x7c3
0x12c13: je 0x12c4d
0x12c15: cmp al, 5
0x12c17: jne 0x12c2e
0x12c19: cmp dl, 0xd
0x12c1c: jne 0x12c2e
0x12c1e: inc byte ptr cs:[0xe]
0x12c23: mov dx, 0x238
0x12c26: push cs
0x12c27: pop ds
0x12c28: mov ah, 9
0x12c2a: int 0x21
0x12c2c: jmp 0x12c4d
0x12c2e: mov ax, 0x3508
0x12c31: int 0x21
0x12c33: mov word ptr cs:[0x13], bx
0x12c38: mov word ptr cs:[0x15], es
0x12c3d: push cs
0x12c3e: pop ds
2018-12-17T22:45:48.707134405Z 53 PC: 12c33 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:45:48.708554731Z 37 PC: 12c4d | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:45:48.710057438Z 75 PC: 12c59 | Execute program
2018-12-17T22:45:48.727492217Z 76 PC: 132a4 | Terminate with return code (Return code = '0')
2018-12-17T22:45:48.731008953Z 73 PC: 12c5f | Release memory
2018-12-17T22:45:48.732594969Z 77 PC: 12c63 | Get program return code
2018-12-17T22:45:48.735084772Z 49 PC: 12c6a | Terminate and stay resident (Return code = '0' | Memory size = '128')