Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.1264

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:47:40.414646066Z 255 PC: 12ab4 | UNKNOWN!
2018-12-17T22:47:40.415715181Z 53 PC: 12b29 | Get interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-17T22:47:40.417193198Z 37 PC: 12b40 | Set interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-17T22:47:40.418569384Z 37 PC: 12b6e | Set interrupt vector (Interrupt = '255' AKA 'UNKNOWN!')
2018-12-17T22:47:40.419837263Z 74 PC: 12b75 | Reallocate memory
2018-12-17T22:47:40.421876978Z 53 PC: 12b7f | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:40.423159009Z 37 PC: 12b93 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:47:40.424448224Z 75 PC: 12bc7 | Execute program
2018-12-17T22:47:40.441558904Z 9 PC: 13197 | Display string (String= ' == [Fri_1264] Virus == 1) Infect : .com .exe 2) Type : tsr == Taiwan Power Virus Organization. == ')
2018-12-17T22:47:40.457245539Z 76 PC: 1319c | Terminate with return code (Return code = '0')
2018-12-17T22:47:40.460522023Z 73 PC: 12bcd | Release memory
2018-12-17T22:47:40.463016523Z 77 PC: 12bd1 | Get program return code
2018-12-17T22:47:40.46477758Z 49 PC: 12bd8 | Terminate and stay resident (Return code = '0' | Memory size = '111')