Sample viewer

vx.netlux.org/Virus.DOS.Leprosy.Seneca.483.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:52.734809917Z 42 PC: 12a73 | Get date 0x12a73: cmp cx, 0x7bc
0x12a77: jle 0x12a87
0x12a79: jmp 0x12a7b
0x12a7b: mov ah, 0x2a
0x12a7d: int 0x21
0x12a7f: cmp dx, 0xb19
0x12a83: je 0x12ac1
0x12a85: jmp 0x12a92
0x12a87: mov ah, 0x2c
0x12a89: int 0x21
0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
2018-12-17T22:49:52.738353574Z 42 PC: 12a7f | Get date 0x12a7f: cmp dx, 0xb19
0x12a83: je 0x12ac1
0x12a85: jmp 0x12a92
0x12a87: mov ah, 0x2c
0x12a89: int 0x21
0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
0x12aa2: mov ah, 0x3b
0x12aa4: int 0x21
0x12aa6: jb 0x12aec
0x12aa8: jmp 0x12a92
0x12aaa: push ax
2018-12-17T22:49:52.740467163Z 78 PC: 12a9b | Find first file
2018-12-17T22:49:52.746438859Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.752877731Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.75478547Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.757340515Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.76710592Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.769419203Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.776253818Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.781696377Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.784440391Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.787632521Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.792938875Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.795355135Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.797972865Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.803015147Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.806196079Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.810179958Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.815146078Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.817806619Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.820964574Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.834445384Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.845371628Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.856858848Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.864155541Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.8699227Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.872533569Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-17T22:49:52.876028487Z 62 PC: 12b29 | Close file
2018-12-17T22:49:52.878014625Z 79 PC: 12aba | Find next file
2018-12-17T22:49:52.880003547Z 59 PC: 12aa6 | Change current directory
2018-12-17T22:49:52.883025675Z 44 PC: 12af0 | Get time 0x12af0: cmp dh, 0xa
0x12af3: ja 0x12afb
0x12af5: mov bx, 0x2ae
0x12af8: call 0x22acd
0x12afb: int 0x20
0x12afd: mov bx, 0x80
0x12b00: mov ax, word ptr [bx + 0x15]
0x12b03: mov word ptr [0x2db], ax
0x12b06: mov ax, word ptr [bx + 0x16]
0x12b09: mov word ptr [0x2dd], ax
0x12b0c: mov ax, word ptr [bx + 0x18]
0x12b0f: mov word ptr [0x2df], ax
0x12b12: mov ax, word ptr [bx + 0x1a]
0x12b15: mov word ptr [0x2e1], ax
0x12b18: mov al, 2
0x12b1a: mov ah, 0x3d
0x12b1c: int 0x21
0x12b1e: mov word ptr [0x2e3], ax
0x12b21: mov bx, word ptr [0x2e3]
0x12b25: mov ah, 0x3e

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":11,"TimeBased":true,"OriginalID":10035,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:27:07.14669208Z 42 PC: 12a73 | Get date 0x12a73: cmp cx, 0x7bc
0x12a77: jle 0x12a87
0x12a79: jmp 0x12a7b
0x12a7b: mov ah, 0x2a
0x12a7d: int 0x21
0x12a7f: cmp dx, 0xb19
0x12a83: je 0x12ac1
0x12a85: jmp 0x12a92
0x12a87: mov ah, 0x2c
0x12a89: int 0x21
0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
2018-12-25T12:27:07.14882758Z 44 PC: 12a8b | Get time 0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
0x12aa2: mov ah, 0x3b
0x12aa4: int 0x21
0x12aa6: jb 0x12aec
0x12aa8: jmp 0x12a92
0x12aaa: push ax
0x12aab: push bx
0x12aac: mov bx, 0x25d
0x12aaf: call 0x12acd
0x12ab2: pop bx
0x12ab3: pop ax
2018-12-25T12:27:07.151127832Z 78 PC: 12a9b | Find first file
2018-12-25T12:27:07.170584658Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-25T12:27:07.175805769Z 62 PC: 12b29 | Close file
2018-12-25T12:27:07.178770636Z 79 PC: 12aba | Find next file
2018-12-25T12:27:07.182791027Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.188196978Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.190123479Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.194030038Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.199396628Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.201281434Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.204309587Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.211322576Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.216004067Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.218602077Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.239648059Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.241510831Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.245544169Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.266318513Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.272970059Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.278305082Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.284260402Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.285934744Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.288695256Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.294396473Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.295973219Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.299459647Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.310499958Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.312429917Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.314678296Z 59 PC: 12aa6 | Change current directory
2018-12-25T12:27:07.319451166Z 44 PC: 12af0 | Get time 0x12af0: cmp dh, 0xa
0x12af3: ja 0x12afb
0x12af5: mov bx, 0x2ae
0x12af8: call 0x22acd
0x12afb: int 0x20
0x12afd: mov bx, 0x80
0x12b00: mov ax, word ptr [bx + 0x15]
0x12b03: mov word ptr [0x2db], ax
0x12b06: mov ax, word ptr [bx + 0x16]
0x12b09: mov word ptr [0x2dd], ax
0x12b0c: mov ax, word ptr [bx + 0x18]
0x12b0f: mov word ptr [0x2df], ax
0x12b12: mov ax, word ptr [bx + 0x1a]
0x12b15: mov word ptr [0x2e1], ax
0x12b18: mov al, 2
0x12b1a: mov ah, 0x3d
0x12b1c: int 0x21
0x12b1e: mov word ptr [0x2e3], ax
0x12b21: mov bx, word ptr [0x2e3]
0x12b25: mov ah, 0x3e

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":11,"TimeBased":true,"OriginalID":10035,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:27:07.314680418Z 42 PC: 12a73 | Get date 0x12a73: cmp cx, 0x7bc
0x12a77: jle 0x12a87
0x12a79: jmp 0x12a7b
0x12a7b: mov ah, 0x2a
0x12a7d: int 0x21
0x12a7f: cmp dx, 0xb19
0x12a83: je 0x12ac1
0x12a85: jmp 0x12a92
0x12a87: mov ah, 0x2c
0x12a89: int 0x21
0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
2018-12-25T12:27:07.320440847Z 44 PC: 12a8b | Get time 0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
0x12aa2: mov ah, 0x3b
0x12aa4: int 0x21
0x12aa6: jb 0x12aec
0x12aa8: jmp 0x12a92
0x12aaa: push ax
0x12aab: push bx
0x12aac: mov bx, 0x25d
0x12aaf: call 0x12acd
0x12ab2: pop bx
0x12ab3: pop ax
2018-12-25T12:27:07.325882973Z 78 PC: 12a9b | Find first file
2018-12-25T12:27:07.333162951Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-25T12:27:07.339563481Z 62 PC: 12b29 | Close file
2018-12-25T12:27:07.342676936Z 79 PC: 12aba | Find next file
2018-12-25T12:27:07.345953558Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.357045949Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.359922831Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.367459345Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.372850776Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.37599002Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.378819311Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.384278341Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.387736147Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.390487945Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.39606494Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.397839005Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.401016028Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.406502378Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.408127065Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.411298136Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.422393714Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.424412106Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.433060858Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.438897061Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.440938257Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.447806815Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.453559124Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.455269552Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.464928296Z 59 PC: 12aa6 | Change current directory
2018-12-25T12:27:07.469626396Z 44 PC: 12af0 | Get time 0x12af0: cmp dh, 0xa
0x12af3: ja 0x12afb
0x12af5: mov bx, 0x2ae
0x12af8: call 0x22acd
0x12afb: int 0x20
0x12afd: mov bx, 0x80
0x12b00: mov ax, word ptr [bx + 0x15]
0x12b03: mov word ptr [0x2db], ax
0x12b06: mov ax, word ptr [bx + 0x16]
0x12b09: mov word ptr [0x2dd], ax
0x12b0c: mov ax, word ptr [bx + 0x18]
0x12b0f: mov word ptr [0x2df], ax
0x12b12: mov ax, word ptr [bx + 0x1a]
0x12b15: mov word ptr [0x2e1], ax
0x12b18: mov al, 2
0x12b1a: mov ah, 0x3d
0x12b1c: int 0x21
0x12b1e: mov word ptr [0x2e3], ax
0x12b21: mov bx, word ptr [0x2e3]
0x12b25: mov ah, 0x3e

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":10035,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:27:07.34737231Z 42 PC: 12a73 | Get date 0x12a73: cmp cx, 0x7bc
0x12a77: jle 0x12a87
0x12a79: jmp 0x12a7b
0x12a7b: mov ah, 0x2a
0x12a7d: int 0x21
0x12a7f: cmp dx, 0xb19
0x12a83: je 0x12ac1
0x12a85: jmp 0x12a92
0x12a87: mov ah, 0x2c
0x12a89: int 0x21
0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
2018-12-25T12:27:07.353153127Z 44 PC: 12a8b | Get time 0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
0x12aa2: mov ah, 0x3b
0x12aa4: int 0x21
0x12aa6: jb 0x12aec
0x12aa8: jmp 0x12a92
0x12aaa: push ax
0x12aab: push bx
0x12aac: mov bx, 0x25d
0x12aaf: call 0x12acd
0x12ab2: pop bx
0x12ab3: pop ax
2018-12-25T12:27:07.356062699Z 78 PC: 12a9b | Find first file
2018-12-25T12:27:07.361856839Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-25T12:27:07.373864958Z 62 PC: 12b29 | Close file
2018-12-25T12:27:07.375854694Z 79 PC: 12aba | Find next file
2018-12-25T12:27:07.378225748Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.383890796Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.385540574Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.388302092Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.394211179Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.396099538Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.398591209Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.40465764Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.406916198Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.409641101Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.414780045Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.41678724Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.419277106Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.424276998Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.426418409Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.429058846Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.434026153Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.436402707Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.438931143Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.443748892Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.447937564Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.450330632Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.455443126Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.457550739Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.45988761Z 59 PC: 12aa6 | Change current directory
2018-12-25T12:27:07.463783307Z 44 PC: 12af0 | Get time 0x12af0: cmp dh, 0xa
0x12af3: ja 0x12afb
0x12af5: mov bx, 0x2ae
0x12af8: call 0x22acd
0x12afb: int 0x20
0x12afd: mov bx, 0x80
0x12b00: mov ax, word ptr [bx + 0x15]
0x12b03: mov word ptr [0x2db], ax
0x12b06: mov ax, word ptr [bx + 0x16]
0x12b09: mov word ptr [0x2dd], ax
0x12b0c: mov ax, word ptr [bx + 0x18]
0x12b0f: mov word ptr [0x2df], ax
0x12b12: mov ax, word ptr [bx + 0x1a]
0x12b15: mov word ptr [0x2e1], ax
0x12b18: mov al, 2
0x12b1a: mov ah, 0x3d
0x12b1c: int 0x21
0x12b1e: mov word ptr [0x2e3], ax
0x12b21: mov bx, word ptr [0x2e3]
0x12b25: mov ah, 0x3e
2018-12-25T12:27:07.467143973Z 2 PC: 12adb | Character output (Char = '0d')
2018-12-25T12:27:07.469080214Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.472519618Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.474963298Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.479860761Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.481888165Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.484220072Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.486452234Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.488467139Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.490887363Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.493401793Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.49558579Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.498069404Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.500317967Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.502390489Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.504587695Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.506994902Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.509131656Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.511092297Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.513564551Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.515932082Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.51829795Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.521337968Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.523730828Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.526107463Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.52879418Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.530832369Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.532864306Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.536527938Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.538536406Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.540612786Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.544074159Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.546163667Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.548178318Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.552376511Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.556660524Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.561395942Z 2 PC: 12adb | Character output (See above)

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":10035,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:27:07.744045112Z 42 PC: 12a73 | Get date 0x12a73: cmp cx, 0x7bc
0x12a77: jle 0x12a87
0x12a79: jmp 0x12a7b
0x12a7b: mov ah, 0x2a
0x12a7d: int 0x21
0x12a7f: cmp dx, 0xb19
0x12a83: je 0x12ac1
0x12a85: jmp 0x12a92
0x12a87: mov ah, 0x2c
0x12a89: int 0x21
0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
2018-12-25T12:27:07.747466488Z 44 PC: 12a8b | Get time 0x12a8b: cmp cl, 0x1e
0x12a8e: jge 0x12aaa
0x12a90: jmp 0x12a92
0x12a92: mov dx, 0x2d4
0x12a95: mov ah, 0x4e
0x12a97: xor cx, cx
0x12a99: int 0x21
0x12a9b: jb 0x12a9f
0x12a9d: jmp 0x12afd
0x12a9f: mov dx, 0x2d8
0x12aa2: mov ah, 0x3b
0x12aa4: int 0x21
0x12aa6: jb 0x12aec
0x12aa8: jmp 0x12a92
0x12aaa: push ax
0x12aab: push bx
0x12aac: mov bx, 0x25d
0x12aaf: call 0x12acd
0x12ab2: pop bx
0x12ab3: pop ax
2018-12-25T12:27:07.750261248Z 78 PC: 12a9b | Find first file
2018-12-25T12:27:07.757519727Z 61 PC: 12b1e | Open file (Filename = '*.*')
2018-12-25T12:27:07.76422489Z 62 PC: 12b29 | Close file
2018-12-25T12:27:07.766399187Z 79 PC: 12aba | Find next file
2018-12-25T12:27:07.768823106Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.772582529Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.774014408Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.775904747Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.779563876Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.781687675Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.78471419Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.796405795Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.798360592Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.805975428Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.81141078Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.814001513Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.81683601Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.822337699Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.825067841Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.828011021Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.833535408Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.835438513Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.838921925Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.844535652Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.846164601Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.849301899Z 61 PC: 12b1e | Open file (See above)
2018-12-25T12:27:07.860621483Z 62 PC: 12b29 | Close file (See above)
2018-12-25T12:27:07.862301765Z 79 PC: 12aba | Find next file (See above)
2018-12-25T12:27:07.871997204Z 59 PC: 12aa6 | Change current directory
2018-12-25T12:27:07.876466981Z 44 PC: 12af0 | Get time 0x12af0: cmp dh, 0xa
0x12af3: ja 0x12afb
0x12af5: mov bx, 0x2ae
0x12af8: call 0x22acd
0x12afb: int 0x20
0x12afd: mov bx, 0x80
0x12b00: mov ax, word ptr [bx + 0x15]
0x12b03: mov word ptr [0x2db], ax
0x12b06: mov ax, word ptr [bx + 0x16]
0x12b09: mov word ptr [0x2dd], ax
0x12b0c: mov ax, word ptr [bx + 0x18]
0x12b0f: mov word ptr [0x2df], ax
0x12b12: mov ax, word ptr [bx + 0x1a]
0x12b15: mov word ptr [0x2e1], ax
0x12b18: mov al, 2
0x12b1a: mov ah, 0x3d
0x12b1c: int 0x21
0x12b1e: mov word ptr [0x2e3], ax
0x12b21: mov bx, word ptr [0x2e3]
0x12b25: mov ah, 0x3e
2018-12-25T12:27:07.878737782Z 2 PC: 12adb | Character output (Char = '0d')
2018-12-25T12:27:07.881506771Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.885589477Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.887829649Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.890902126Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.89346446Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.895706556Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.901208163Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.903860801Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.906564822Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.909840706Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.912082155Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.914491418Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.917100864Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.920107233Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.922306274Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.924510339Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.927028781Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.929361988Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.931534664Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.934089169Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.935802264Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.93802966Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.940796424Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.94626035Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.949362361Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.95218586Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.954528298Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.958259972Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.960899848Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.963212031Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.965400847Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.969311071Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.971710804Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.973907179Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.979154305Z 2 PC: 12adb | Character output (See above)
2018-12-25T12:27:07.981411839Z 2 PC: 12adb | Character output (See above)