Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.l

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:17.046528639Z 243 PC: 12ad6 | UNKNOWN!
2018-12-17T22:47:17.047909363Z 243 PC: 12b2a | UNKNOWN!
2018-12-17T22:47:17.050452769Z 74 PC: 12bab | Reallocate memory
2018-12-17T22:47:17.052133734Z 53 PC: 12bb0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:17.05415679Z 37 PC: 12bc4 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:17.055658673Z 42 PC: 12bf4 | Get date 0x12bf4: mov byte ptr cs:[0xe], 0
0x12bfa: cmp cx, 0x7c5
0x12bfe: je 0x12c28
0x12c00: cmp al, 1
0x12c02: jne 0x12c28
0x12c04: inc byte ptr cs:[0xe]
0x12c09: mov ax, 0x3508
0x12c0c: int 0x21
0x12c0e: mov word ptr cs:[0x13], bx
0x12c13: mov word ptr cs:[0x15], es
0x12c18: push cs
0x12c19: pop ds
0x12c1a: mov word ptr [0x1f], 0x2ff
0x12c20: mov ax, 0x2508
0x12c23: mov dx, 0x20f
0x12c26: int 0x21
0x12c28: pop dx
0x12c29: pop cx
0x12c2a: pop bx
0x12c2b: pop ax
2018-12-17T22:47:17.058171933Z 53 PC: 12c0e | Get interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:47:17.060782939Z 37 PC: 12c28 | Set interrupt vector (Interrupt = '8' AKA 'Console input without echo')
2018-12-17T22:47:17.062330752Z 75 PC: 12c34 | Execute program
2018-12-17T22:47:17.081290181Z 9 PC: 13586 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-17T22:47:17.090307799Z 73 PC: 12c3a | Release memory
2018-12-17T22:47:17.092211863Z 77 PC: 12c3e | Get program return code
2018-12-17T22:47:17.093678642Z 49 PC: 12c4c | Terminate and stay resident (Return code = '0' | Memory size = '109')