Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.998

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:02.607054979Z 224 PC: 12a59 | UNKNOWN!
2018-12-17T22:46:02.608302881Z 224 PC: 12a9c | UNKNOWN!
2018-12-17T22:46:02.609120123Z 74 PC: 12b14 | Reallocate memory
2018-12-17T22:46:02.610289892Z 53 PC: 12b19 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:02.611903227Z 37 PC: 12b29 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:02.612999092Z 75 PC: 12b51 | Execute program
2018-12-17T22:46:02.627334793Z 48 PC: 13003 | Get DOS version
2018-12-17T22:46:02.628826996Z 9 PC: 1301a | Display string (String= ' --=[ Selfchecking AntiStealth Goat COM/EXE file, 01/06/01 ]=------------------ (c) 1995-2001 by ROSE SWE, Dipl.-Ing. Ralph Roth - Version 1.18 - Freeware ')
2018-12-17T22:46:02.637957899Z 61 PC: 13257 | Open file (Filename = '')
2018-12-17T22:46:02.644510293Z 9 PC: 13028 | Display string (String= 'Self test: ')
2018-12-17T22:46:02.646983802Z 93 PC: 130c4 | File sharing functions
2018-12-17T22:46:02.648756571Z 9 PC: 130a3 | Display string (String= 'Size change=+03E6h/00998d. Virus might be activ? ')
2018-12-17T22:46:02.654029891Z 76 PC: 130a9 | Terminate with return code (Return code = '1')
2018-12-17T22:46:02.657218068Z 73 PC: 12b57 | Release memory
2018-12-17T22:46:02.658705638Z 77 PC: 12b5b | Get program return code
2018-12-17T22:46:02.659761473Z 49 PC: 12b62 | Terminate and stay resident (Return code = '1' | Memory size = '80')