Sample viewer

vx.netlux.org/Virus.DOS.Lucretia

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:15.197774574Z 98 PC: 13414 | Get current PSP
2018-12-17T23:04:15.19943141Z 61 PC: 58e | Open file (Filename = 'A:\TEST.COM')
2018-12-17T23:04:15.20781568Z 66 PC: 59d | Move file pointer
2018-12-17T23:04:15.209890433Z 63 PC: 5a6 | Read file or device (Read 395 bytes on handle 5)
2018-12-17T23:04:15.21896424Z 62 PC: 5c5 | Close file
2018-12-17T23:04:15.223473882Z 9 PC: 13411 | Display string (String= 'Standard "goat" file by Dmitry O. Gryaznov ATTENTION! This COM program might be infected with the 'GENERIC (TM)' virus! The virus could go memory resident and/or infect some of your files! ')
2018-12-17T23:04:15.234662186Z 76 PC: 12a4d | Terminate with return code (Return code = '0')
2018-12-17T23:04:15.238096797Z 61 PC: 610 | Open file (Filename = '')
2018-12-17T23:04:15.247411618Z 72 PC: 61a | Allocate memory
2018-12-17T23:04:15.250049539Z 66 PC: 635 | Move file pointer
2018-12-17T23:04:15.25219229Z 63 PC: 63d | Read file or device (Read 2168 bytes on handle 5)
2018-12-17T23:04:15.261760437Z 62 PC: 12ad4 | Close file
2018-12-17T23:04:15.26715831Z 53 PC: 12ad9 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:04:15.269101995Z 37 PC: 12ae9 | Set interrupt vector (Interrupt = '33' AKA 'Random read')