Sample viewer

vx.netlux.org/Virus.DOS.HLLP.Lcamtuf.21037

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:51:16.658490715Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:16.661318025Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:16.662971637Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:16.664685934Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:16.66755186Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:16.669251709Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:16.670951289Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:16.672893444Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:16.675381773Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:16.677099272Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:16.678863384Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:16.681718659Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:16.684371442Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:16.686795548Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:16.690292915Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:16.692322922Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:16.693958368Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:16.696711171Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:16.698322204Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:16.699901279Z 37 PC: 1b46f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:16.702317699Z 37 PC: 1b477 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:16.704834066Z 37 PC: 1b47f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:16.70699422Z 37 PC: 1b487 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:16.710210715Z 68 PC: 1be55 | I/O control for devices (Set for = '')
2018-12-17T22:51:16.71282478Z 51 PC: 12ad9 | Get or set Ctrl-Break
2018-12-17T22:51:16.713874178Z 42 PC: 12add | Get date 0x12add: cmp al, 0
0x12adf: jne 0x12b18
0x12ae1: mov ax, 0x13
0x12ae4: int 0x10
0x12ae6: mov ax, 0x12a4
0x12ae9: mov es, ax
0x12aeb: mov dx, 0x695
0x12aee: mov ax, 0x1012
0x12af1: mov bx, 0
0x12af4: mov cx, 0x100
0x12af7: int 0x10
0x12af9: mov ax, 0xa000
0x12afc: mov es, ax
0x12afe: mov di, 0x34ae
0x12b01: mov ax, 0x12a4
0x12b04: mov ds, ax
0x12b06: mov si, 0x995
0x12b09: mov cx, 0x7eef
0x12b0c: cld
0x12b0d: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-17T22:51:16.716328983Z 48 PC: 1ba6b | Get DOS version
2018-12-17T22:51:16.719087633Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:16.726458787Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:16.743963858Z 61 PC: 1b91d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:51:16.752166469Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 5)
2018-12-17T22:51:16.761438646Z 66 PC: 1c0b3 | Move file pointer
2018-12-17T22:51:16.763392127Z 66 PC: 1c0c1 | Move file pointer
2018-12-17T22:51:16.7661806Z 66 PC: 1c0cf | Move file pointer
2018-12-17T22:51:16.767966016Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:16.770137355Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 5)
2018-12-17T22:51:16.785060126Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:16.786825752Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 5)
2018-12-17T22:51:16.798350929Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:16.801105587Z 64 PC: 1b94e | Write file or device (Write 0 bytes on handle 5)
2018-12-17T22:51:16.810050626Z 62 PC: 1b96d | Close file
2018-12-17T22:51:16.818457538Z 75 PC: 12c3c | Execute program
2018-12-17T22:51:16.829466209Z 71 PC: 12c58 | Get current directory
2018-12-17T22:51:16.833746703Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:16.845331976Z 61 PC: 1b91d | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:51:16.859849913Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 5)
2018-12-17T22:51:16.863153018Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:16.865049485Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 5)
2018-12-17T22:51:16.876078327Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:16.879143596Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 5)
2018-12-17T22:51:16.890372765Z 62 PC: 1b96d | Close file
2018-12-17T22:51:16.899789799Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:16.912744582Z 26 PC: 1b337 | Set disk transfer address
2018-12-17T22:51:16.914375059Z 78 PC: 1b343 | Find first file
2018-12-17T22:51:16.917791488Z 26 PC: 1b337 | Set disk transfer address
2018-12-17T22:51:16.920188181Z 78 PC: 1b343 | Find first file
2018-12-17T22:51:16.928615855Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:16.935369249Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:16.947394185Z 61 PC: 1b91d | Open file (Filename = '\TEST.EXE')
2018-12-17T22:51:16.955518474Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:16.957153238Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:16.961102829Z 26 PC: 1b337 | Set disk transfer address
2018-12-17T22:51:16.963175894Z 78 PC: 1b343 | Find first file
2018-12-17T22:51:16.978697594Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:16.990707583Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.693587658Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\ATTRIB.EXE')
2018-12-17T22:51:17.707564035Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:17.717258938Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.728598529Z 62 PC: 1b96d | Close file
2018-12-17T22:51:17.730940222Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:17.732572086Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:17.739680319Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:17.747316985Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.758217348Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\CHKDSK.EXE')
2018-12-17T22:51:17.767072645Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:17.777012554Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.788393237Z 62 PC: 1b96d | Close file
2018-12-17T22:51:17.791556161Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:17.793427863Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:17.798548753Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:17.805446051Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.817136022Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\DEBUG.EXE')
2018-12-17T22:51:17.825485516Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:17.83493052Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.846572837Z 62 PC: 1b96d | Close file
2018-12-17T22:51:17.84882015Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:17.850280717Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:17.855762592Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:17.863770381Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.874474822Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\EXPAND.EXE')
2018-12-17T22:51:17.88298573Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:17.893909487Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.905159725Z 62 PC: 1b96d | Close file
2018-12-17T22:51:17.907789573Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:17.909694143Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:17.914600861Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:17.922287175Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:17.937277083Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\FDISK.EXE')
2018-12-17T22:51:17.946248723Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:17.959935091Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:17.963080165Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:17.984424165Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:17.986740376Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.000881802Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.01477873Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.022802275Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:18.024926577Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:18.030370733Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:18.038039594Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.049750972Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\MEM.EXE')
2018-12-17T22:51:18.060535393Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:18.07287119Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.074827295Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.090595782Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.09306835Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.106219414Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.120872112Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.13050237Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:18.13209443Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:18.140641685Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:18.148018459Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.159593901Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\NLSFUNC.EXE')
2018-12-17T22:51:18.169401257Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:18.178882067Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.191857045Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.194475454Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:18.197432556Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:18.202548645Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:18.210036Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.22259106Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\QBASIC.EXE')
2018-12-17T22:51:18.230728086Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:18.242382042Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.245575633Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.259495387Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.261598145Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.274736737Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.28779594Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.295618183Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:18.298341456Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:18.30383562Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:18.311327331Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.324754704Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\REPLACE.EXE')
2018-12-17T22:51:18.333010627Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:18.34418911Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.356778373Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.359194688Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:18.361146635Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:18.366943373Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:18.375105577Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.388078641Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\RESTORE.EXE')
2018-12-17T22:51:18.396798417Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:18.410950676Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.412747243Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.428259737Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.431015525Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.442929282Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.45763576Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.467342461Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:18.468760805Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:18.473342175Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:18.481432009Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.492840775Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\SCANDISK.EXE')
2018-12-17T22:51:18.50133375Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:18.516188808Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.518416592Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.53168478Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.535008272Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.547551494Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.560466031Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.570060903Z 26 PC: 1b35b | Set disk transfer address
2018-12-17T22:51:18.571936575Z 79 PC: 1b360 | Find next file
2018-12-17T22:51:18.577326243Z 67 PC: 1b2df | Get or set file attributes
2018-12-17T22:51:18.585460332Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.596730228Z 61 PC: 1b91d | Open file (Filename = 'C:\DOS\SETUP.EXE')
2018-12-17T22:51:18.604937335Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 6)
2018-12-17T22:51:18.618165008Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.620644439Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.634630591Z 66 PC: 1ba4f | Move file pointer
2018-12-17T22:51:18.63717849Z 64 PC: 1b9f0 | Write file or device (Write 21037 bytes on handle 6)
2018-12-17T22:51:18.649717152Z 67 PC: 1b306 | Get or set file attributes
2018-12-17T22:51:18.662246205Z 62 PC: 1b96d | Close file
2018-12-17T22:51:18.670195001Z 64 PC: 1b878 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:51:18.672894852Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:51:18.674550054Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:51:18.676163199Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:51:18.678125394Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:51:18.679716197Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:51:18.681366684Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:51:18.683244863Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:51:18.684891774Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:51:18.686502282Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:51:18.688481882Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:51:18.690078116Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:51:18.691683979Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:51:18.693531602Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:51:18.695085356Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:51:18.696582836Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:51:18.698081821Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:51:18.699621406Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:51:18.701222066Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:51:18.7037343Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:51:18.705336848Z 76 PC: 1b5f0 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10503,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:13.511110533Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:28:13.519483118Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.520499537Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.521233379Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.522373474Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.523186845Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.523950758Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.525315058Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.526644609Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.527666687Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.528878822Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.530899456Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.532226218Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.534174696Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.538638563Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.539652504Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.540586036Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.54197739Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.543153306Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.544830708Z 37 PC: 1b46f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:28:13.549494036Z 37 PC: 1b477 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:28:13.550527548Z 37 PC: 1b47f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:28:13.551405655Z 37 PC: 1b487 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-25T12:28:13.553070567Z 68 PC: 1be55 | I/O control for devices (Set for = '')
2018-12-25T12:28:13.554604089Z 51 PC: 12ad9 | Get or set Ctrl-Break
2018-12-25T12:28:13.555610402Z 42 PC: 12add | Get date 0x12add: cmp al, 0
0x12adf: jne 0x12b18
0x12ae1: mov ax, 0x13
0x12ae4: int 0x10
0x12ae6: mov ax, 0x12a4
0x12ae9: mov es, ax
0x12aeb: mov dx, 0x695
0x12aee: mov ax, 0x1012
0x12af1: mov bx, 0
0x12af4: mov cx, 0x100
0x12af7: int 0x10
0x12af9: mov ax, 0xa000
0x12afc: mov es, ax
0x12afe: mov di, 0x34ae
0x12b01: mov ax, 0x12a4
0x12b04: mov ds, ax
0x12b06: mov si, 0x995
0x12b09: mov cx, 0x7eef
0x12b0c: cld
0x12b0d: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-25T12:28:13.558846285Z 48 PC: 1ba6b | Get DOS version
2018-12-25T12:28:13.560379842Z 67 PC: 1b2df | Get or set file attributes
2018-12-25T12:28:13.56626293Z 67 PC: 1b306 | Get or set file attributes
2018-12-25T12:28:13.580049805Z 61 PC: 1b91d | Open file (Filename = 'A:\TEST.EXE')
2018-12-25T12:28:13.585315995Z 63 PC: 1b9f0 | Read file or device (Read 21037 bytes on handle 5)
2018-12-25T12:28:13.590306973Z 66 PC: 1c0b3 | Move file pointer
2018-12-25T12:28:13.591789018Z 66 PC: 1c0c1 | Move file pointer
2018-12-25T12:28:13.592923082Z 66 PC: 1c0cf | Move file pointer
2018-12-25T12:28:13.594029293Z 66 PC: 1ba4f | Move file pointer
2018-12-25T12:28:13.595934833Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:13.60185857Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:13.602903305Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:13.609592872Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:13.610733082Z 64 PC: 1b94e | Write file or device (Write 0 bytes on handle 5)
2018-12-25T12:28:13.615628648Z 62 PC: 1b96d | Close file
2018-12-25T12:28:13.620610738Z 75 PC: 12c3c | Execute program
2018-12-25T12:28:13.627859991Z 71 PC: 12c58 | Get current directory
2018-12-25T12:28:13.630866759Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:13.641594116Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:13.648584937Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:13.649970121Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:13.651749878Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:13.65778264Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:13.658867135Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:13.666811902Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:13.675485707Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:13.689442789Z 26 PC: 1b337 | Set disk transfer address
2018-12-25T12:28:13.691421765Z 78 PC: 1b343 | Find first file
2018-12-25T12:28:13.69405509Z 26 PC: 1b337 | Set disk transfer address (See above)
2018-12-25T12:28:13.695133738Z 78 PC: 1b343 | Find first file (See above)
2018-12-25T12:28:13.701904379Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:13.707896008Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:13.719727354Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:13.732488261Z 26 PC: 1b35b | Set disk transfer address
2018-12-25T12:28:13.733822773Z 79 PC: 1b360 | Find next file
2018-12-25T12:28:13.737042735Z 26 PC: 1b337 | Set disk transfer address (See above)
2018-12-25T12:28:13.739050764Z 78 PC: 1b343 | Find first file (See above)
2018-12-25T12:28:13.748702851Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:13.754435367Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.72556995Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:14.732948054Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:14.740712411Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.752190799Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:14.754200506Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:14.755466184Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:14.75939996Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:14.765510949Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.774837287Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:14.782458399Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:14.790589143Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.800253585Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:14.80243455Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:14.803782379Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:14.807240801Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:14.813256151Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.823553929Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:14.830212994Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:14.839277966Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.849610097Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:14.851469508Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:14.852654895Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:14.85679836Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:14.863332482Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.87494211Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:14.883573836Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:14.8927332Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.903813976Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:14.90563383Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:14.906700966Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:14.910155582Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:14.91663581Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.925946284Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:14.932669559Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:14.943941205Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:14.945683474Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:14.96142758Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:14.963925917Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:14.974551675Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:14.98543182Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:14.992760181Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:14.993868625Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:14.997467189Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:15.006923301Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.017870352Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:15.025151395Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:15.035818045Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.037299513Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.047905671Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.050205167Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.063565864Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.075029712Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:15.0828364Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:15.084025619Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:15.090465582Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:15.096270492Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.106537737Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:15.113287365Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:15.121413324Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.131702711Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:15.133769793Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:15.135962079Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:15.139482277Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:15.145417978Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.155632648Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:15.162526655Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:15.173164221Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.175170456Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.186271135Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.18758398Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.197980688Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.208533559Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:15.215359062Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:15.217805787Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:15.221706285Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:15.228016383Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.246839433Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:15.252648334Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:15.258693591Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.2667374Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:15.268162943Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:15.269077491Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:15.272088348Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:15.275918162Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.282019557Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:15.288315093Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:15.294462061Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.295576036Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.302725352Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.303838496Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.310696618Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.318607622Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:15.323692715Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:15.325067073Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:15.329910788Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:15.336153265Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.345905778Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:15.354059339Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:15.363567566Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.365343214Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.376701776Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.378108209Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.388454303Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.399120486Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:15.406111048Z 26 PC: 1b35b | Set disk transfer address (See above)
2018-12-25T12:28:15.407158963Z 79 PC: 1b360 | Find next file (See above)
2018-12-25T12:28:15.410831959Z 67 PC: 1b2df | Get or set file attributes (See above)
2018-12-25T12:28:15.416844616Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.426327786Z 61 PC: 1b91d | Open file (See above)
2018-12-25T12:28:15.433675104Z 63 PC: 1b9f0 | Read file or device (See above)
2018-12-25T12:28:15.443106886Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.44438808Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.456487576Z 66 PC: 1ba4f | Move file pointer (See above)
2018-12-25T12:28:15.457849784Z 64 PC: 1b9f0 | Write file or device (See above)
2018-12-25T12:28:15.468016789Z 67 PC: 1b306 | Get or set file attributes (See above)
2018-12-25T12:28:15.479678082Z 62 PC: 1b96d | Close file (See above)
2018-12-25T12:28:15.486700556Z 64 PC: 1b878 | Write file or device (Write 0 bytes on handle 1)
2018-12-25T12:28:15.488640635Z 37 PC: 1b5b1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:28:15.503076218Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.504457401Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.505836614Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.507970783Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.50925577Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.510522551Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.512719226Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.513761781Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.514696683Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.516121068Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.517466313Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.518981312Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.520469298Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.521467538Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.523283048Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.524838085Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.525773952Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.527227526Z 37 PC: 1b5b1 | Set interrupt vector (See above)
2018-12-25T12:28:15.528692113Z 76 PC: 1b5f0 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":6,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":10503,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:28:13.621762523Z 53 PC: 1b45a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:28:13.624666393Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.626011047Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.627507708Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.629707494Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.631596073Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.633177059Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.634967413Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.637024678Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.638612575Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.640171521Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.646095477Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.648615318Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.651290799Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.656736552Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.658354664Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.659960102Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.662334111Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.663983356Z 53 PC: 1b45a | Get interrupt vector (See above)
2018-12-25T12:28:13.665602095Z 37 PC: 1b46f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:28:13.668062504Z 37 PC: 1b477 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:28:13.669315514Z 37 PC: 1b47f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:28:13.670480331Z 37 PC: 1b487 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-25T12:28:13.672795354Z 68 PC: 1be55 | I/O control for devices (Set for = '')
2018-12-25T12:28:13.675006862Z 51 PC: 12ad9 | Get or set Ctrl-Break
2018-12-25T12:28:13.676441679Z 42 PC: 12add | Get date 0x12add: cmp al, 0
0x12adf: jne 0x12b18
0x12ae1: mov ax, 0x13
0x12ae4: int 0x10
0x12ae6: mov ax, 0x12a4
0x12ae9: mov es, ax
0x12aeb: mov dx, 0x695
0x12aee: mov ax, 0x1012
0x12af1: mov bx, 0
0x12af4: mov cx, 0x100
0x12af7: int 0x10
0x12af9: mov ax, 0xa000
0x12afc: mov es, ax
0x12afe: mov di, 0x34ae
0x12b01: mov ax, 0x12a4
0x12b04: mov ds, ax
0x12b06: mov si, 0x995
0x12b09: mov cx, 0x7eef
0x12b0c: cld
0x12b0d: rep movsb byte ptr es:[di], byte ptr [si]
2018-12-25T12:28:13.68718771Z 8 PC: 12b13 | Console input without echo