Jerusalem is a historic MS-DOS memory-resident file-infecting virus first detected at the Hebrew University of Jerusalem in 1987. Executing an infected program installs the virus in memory, allowing it to infect subsequently executed DOS applications. It appends its code to targeted programs and redirects execution to the viral code; its flawed handling of certain executables can corrupt programs, while repeated reinfection of some applications causes continual file growth and eventual execution failures. The original strain contains a date-triggered logic-bomb payload associated with Friday the 13th that deletes programs launched on the trigger date. Jerusalem also hooks low-level DOS services, which can degrade performance and interfere with networked DOS environments. It was widely prevalent in the late 1980s and early 1990s, generated numerous variants and aliases, and is now obsolete on modern systems that do not rely on its DOS interrupt-based execution model.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
4 distinct techniques documented for this family, organized by ATT&CK tactic.
Yes, both file-infecting and boot sector viruses can infect HPFS partitions. File-infecting viruses function normally and can activate and do their dirty deeds... any DOS session that executes a program infected by a virus that makes itself memory resident would itself become infected.
Yes, both file-infecting and boot sector viruses can infect HPFS partitions. File-infecting viruses function normally and can activate and do their dirty deeds... most of the well-behaved resident viruses that infect only COM files (Cascade is an excellent example), will work perfectly in a 'DOS box'.
Yes, both file-infecting and boot sector viruses can infect HPFS partitions. File-infecting viruses function normally and can activate and do their dirty deeds... any DOS session that executes a program infected by a virus that makes itself memory resident would itself become infected.
24 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Historical virus mentioned in a list without further technical detail.
Named 1980s-era malware (listed as part of a historical timeline). No behavior details provided in the content.
Computer virus (only referenced by name in the 1980s malware timeline; no additional details provided).
Hacking in the 1980s ... Malware ... HyperCard viruses ... Jerusalem ... Lamer Exterminator
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.