Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Plastique.3004

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:46:05.319018292Z 75 PC: 13311 | Execute program
2018-12-17T22:46:05.321238331Z 75 PC: 13362 | Execute program
2018-12-17T22:46:05.421091189Z 74 PC: 13416 | Reallocate memory
2018-12-17T22:46:05.422957074Z 53 PC: 1341b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:05.424631649Z 37 PC: 1342f | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:46:05.427233025Z 42 PC: 13461 | Get date 0x13461: sub cx, 0x7bc
0x13465: mov ax, cx
0x13467: mov bx, dx
0x13469: mov cx, 0x168
0x1346c: mul cx
0x1346e: xchg ax, bx
0x1346f: add bl, al
0x13471: adc bh, 0
0x13474: mov al, ah
0x13476: mov cl, 0x1e
0x13478: mul cl
0x1347a: add ax, bx
0x1347c: sub ax, word ptr [0x30]
0x13480: ja 0x13485
0x13482: jmp 0x13508
0x13485: add word ptr [0x30], ax
0x13489: cmp ax, 7
0x1348c: ja 0x13491
0x1348e: jmp 0x13508
0x13490: nop
2018-12-17T22:46:05.430112132Z 53 PC: 13496 | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:46:05.431805713Z 44 PC: 134a4 | Get time 0x134a4: mov cl, dh
0x134a6: and cl, 1
0x134a9: cmp cl, 0
0x134ac: mov dx, 0x2ae
0x134af: mov byte ptr [0x69], 0
0x134b4: jne 0x134be
0x134b6: mov dx, 0x2d2
0x134b9: mov byte ptr [0x69], 1
0x134be: mov word ptr [3], 1
0x134c4: mov word ptr [0x122], 0
0x134ca: mov byte ptr [0x121], 1
0x134cf: mov byte ptr [0x68], 0
0x134d4: mov byte ptr [0x6a], 0
0x134d9: mov ax, 0x2508
0x134dc: int 0x21
0x134de: mov ax, 0x3509
0x134e1: int 0x21
0x134e3: mov word ptr [6], bx
0x134e7: mov word ptr [8], es
0x134eb: mov dx, 0x35d
2018-12-17T22:46:05.435923286Z 37 PC: 134de | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:46:05.437571091Z 53 PC: 134e3 | Get interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:46:05.439192046Z 37 PC: 134f3 | Set interrupt vector (Interrupt = '9' AKA 'Display string')
2018-12-17T22:46:05.441738298Z 53 PC: 134f8 | Get interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:46:05.443715221Z 37 PC: 13508 | Set interrupt vector (Interrupt = '19' AKA 'Delete file')
2018-12-17T22:46:05.44553038Z 75 PC: 13514 | Execute program
2018-12-17T22:46:05.463480953Z 73 PC: 1351a | Release memory
2018-12-17T22:46:05.4656622Z 77 PC: 1351e | Get program return code
2018-12-17T22:46:05.467466028Z 49 PC: 1352c | Terminate and stay resident (Return code = '0' | Memory size = '203')