.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T21:51:16.013936956Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T21:51:16.016075835Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T21:51:16.017681296Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T21:51:16.018904246Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T21:51:16.028277593Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T21:51:16.029952492Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T21:51:16.031000458Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T21:51:16.032286746Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T21:51:16.033642717Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T21:51:16.034930518Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T21:51:16.036049758Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T21:51:16.0378831Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T21:51:16.03935721Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T21:51:16.040510024Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T21:51:16.042073396Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T21:51:16.042924961Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T21:51:16.043750818Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T21:51:16.045828346Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T21:51:16.047016896Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T21:51:16.048592534Z | 37 | PC: 13f1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T21:51:16.050530307Z | 37 | PC: 13f27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T21:51:16.051699692Z | 37 | PC: 13f2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T21:51:16.052632803Z | 37 | PC: 13f37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T21:51:16.054621796Z | 68 | PC: 14be1 | I/O control for devices (Set for = '�') |
2018-12-17T21:51:16.056456517Z | 44 | PC: 14d18 | Get time 0x14d18: mov word ptr [0x8a], cx 0x14d1c: mov word ptr [0x8c], dx 0x14d20: retf 0x14d21: call 0x14d68 0x14d24: jb 0x14d35 0x14d26: mov cx, word ptr es:[di + 4] 0x14d2a: cmp cx, 1 0x14d2d: je 0x14d35 0x14d2f: xor bx, bx 0x14d31: push cs 0x14d32: call 0x248a4 0x14d35: retf 4 0x14d38: call 0x14d68 0x14d3b: jb 0x14d50 0x14d3d: mov ax, cx 0x14d3f: mov dx, bx 0x14d41: mov cx, word ptr es:[di + 4] 0x14d45: cmp cx, 1 0x14d48: je 0x14d50 0x14d4a: xor bx, bx |
2018-12-17T21:51:16.059058654Z | 48 | PC: 147f2 | Get DOS version |
2018-12-17T21:51:16.060768296Z | 67 | PC: 13cdf | Get or set file attributes |
2018-12-17T21:51:16.066835594Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T21:51:16.083285714Z | 61 | PC: 14630 | Open file (Filename = 'A:\TEST.EXE') |
2018-12-17T21:51:16.090042391Z | 63 | PC: 14703 | Read file or device (Read 8 bytes on handle 5) |
2018-12-17T21:51:16.096428854Z | 66 | PC: 14762 | Move file pointer |
2018-12-17T21:51:16.097891547Z | 63 | PC: 14703 | Read file or device (Read 1 bytes on handle 5) |
2018-12-17T21:51:16.101382286Z | 63 | PC: 14703 | Read file or device (Read 6810 bytes on handle 5) |
2018-12-17T21:51:16.10394904Z | 60 | PC: 14630 | Create or truncate file |
2018-12-17T21:51:16.115685424Z | 63 | PC: 14703 | Read file or device (Read 10000 bytes on handle 5) |
2018-12-17T21:51:16.119179383Z | 66 | PC: 14d82 | Move file pointer |
2018-12-17T21:51:16.120943847Z | 66 | PC: 14d90 | Move file pointer |
2018-12-17T21:51:16.122609421Z | 66 | PC: 14d9e | Move file pointer |
2018-12-17T21:51:16.124903601Z | 62 | PC: 14680 | Close file |
2018-12-17T21:51:16.127008227Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T21:51:16.137001427Z | 62 | PC: 14680 | Close file |
2018-12-17T21:51:16.141521119Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T21:51:16.143037462Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T21:51:16.144273709Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T21:51:16.148349149Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T21:51:16.149556569Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T21:51:16.150825875Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T21:51:16.15395555Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T21:51:16.155145293Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T21:51:16.156198532Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T21:51:16.157931249Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T21:51:16.158908559Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T21:51:16.159887592Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T21:51:16.161430402Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T21:51:16.16251029Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T21:51:16.163465382Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T21:51:16.165093597Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T21:51:16.166855681Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T21:51:16.168190975Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T21:51:16.17426199Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T21:51:16.17561761Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T21:51:16.177307473Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T21:51:16.180491402Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T21:51:16.18180804Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T21:51:16.183188613Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T21:51:16.185454407Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T21:51:16.186843924Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T21:51:16.18817648Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T21:51:16.190463198Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T21:51:16.191878286Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T21:51:16.193643618Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T21:51:16.194952206Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T21:51:16.197103151Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T21:51:16.198265312Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T21:51:16.199726603Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T21:51:16.201561387Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T21:51:16.203913233Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T21:51:16.211574483Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T21:51:16.213981105Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T21:51:16.215650054Z | 41 | PC: 13e35 | Parse filename |
2018-12-17T21:51:16.217474273Z | 41 | PC: 13e43 | Parse filename |
2018-12-17T21:51:16.218958803Z | 75 | PC: 13e4e | Execute program |
2018-12-17T21:51:16.227659886Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T21:51:16.229369593Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T21:51:16.234861969Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T21:51:16.236512079Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T21:51:16.241130019Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T21:51:16.244641146Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T21:51:16.24649206Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T21:51:16.247717396Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T21:51:16.250965474Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T21:51:16.25288487Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T21:51:16.254305383Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T21:51:16.257175241Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T21:51:16.25845499Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T21:51:16.259839159Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T21:51:16.261889832Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T21:51:16.263189008Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T21:51:16.264475078Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T21:51:16.266927317Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T21:51:16.268141032Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T21:51:16.26939523Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T21:51:16.271191689Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T21:51:16.272616572Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T21:51:16.27399376Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T21:51:16.275933918Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T21:51:16.276974896Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T21:51:16.278236577Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T21:51:16.28647061Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T21:51:16.287898252Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T21:51:16.289504528Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T21:51:16.29116915Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T21:51:16.292286884Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T21:51:16.293697211Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T21:51:16.295645095Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T21:51:16.296830975Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T21:51:16.297907374Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T21:51:16.299629731Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T21:51:16.300625106Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T21:51:16.301903958Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T21:51:16.304045603Z | 65 | PC: 14779 | Delete file (Filename = 'Victim.Exe') |
2018-12-17T21:51:16.319994346Z | 26 | PC: 13d7d | Set disk transfer address |
2018-12-17T21:51:16.320993284Z | 78 | PC: 13d89 | Find first file |
2018-12-17T21:51:16.327421588Z | 86 | PC: 147bd | Rename file |
2018-12-17T21:51:16.339020246Z | 60 | PC: 14630 | Create or truncate file |
2018-12-17T21:51:16.349597544Z | 67 | PC: 13cdf | Get or set file attributes |
2018-12-17T21:51:16.355713427Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T21:51:16.365197983Z | 61 | PC: 14630 | Open file (Filename = 'Victim.Exe') |
2018-12-17T21:51:16.371633556Z | 64 | PC: 14703 | Write file or device (Write 4852 bytes on handle 5) |
2018-12-17T21:51:16.380051234Z | 64 | PC: 14703 | Write file or device (Write 1 bytes on handle 5) |
2018-12-17T21:51:16.382688606Z | 64 | PC: 14703 | Write file or device (Write 6810 bytes on handle 5) |
2018-12-17T21:51:16.39285055Z | 63 | PC: 14703 | Read file or device (Read 10000 bytes on handle 6) |
2018-12-17T21:51:16.401412506Z | 64 | PC: 14703 | Write file or device (Write 9744 bytes on handle 5) |
2018-12-17T21:51:16.410144521Z | 66 | PC: 14d82 | Move file pointer |
2018-12-17T21:51:16.411554411Z | 66 | PC: 14d90 | Move file pointer |
2018-12-17T21:51:16.414134926Z | 66 | PC: 14d9e | Move file pointer |
2018-12-17T21:51:16.415503452Z | 87 | PC: 13d4d | Get or set file date and time |
2018-12-17T21:51:16.416968625Z | 62 | PC: 14680 | Close file |
2018-12-17T21:51:16.419712575Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T21:51:16.429969237Z | 62 | PC: 14680 | Close file |
2018-12-17T21:51:16.437296676Z | 65 | PC: 14779 | Delete file (Filename = 'Victim.Exe') |
2018-12-17T21:51:16.449153146Z | 26 | PC: 13da1 | Set disk transfer address |
2018-12-17T21:51:16.450660687Z | 79 | PC: 13da6 | Find next file |
2018-12-17T21:51:16.453367347Z | 26 | PC: 13da1 | Set disk transfer address |
2018-12-17T21:51:16.45816488Z | 79 | PC: 13da6 | Find next file |
2018-12-17T21:51:16.461904666Z | 64 | PC: 1458b | Write file or device (Write 0 bytes on handle 1) |
2018-12-17T21:51:16.463235264Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T21:51:16.465260528Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T21:51:16.466498332Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T21:51:16.467521894Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T21:51:16.469120839Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T21:51:16.470231215Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T21:51:16.471225837Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T21:51:16.473071Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T21:51:16.4745584Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T21:51:16.476067786Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T21:51:16.478340096Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T21:51:16.479827211Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T21:51:16.481289295Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T21:51:16.483193551Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T21:51:16.48465673Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T21:51:16.48616194Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T21:51:16.487945901Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T21:51:16.489359524Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T21:51:16.490705214Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T21:51:16.492695069Z | 76 | PC: 140a0 | Terminate with return code (Return code = '0') |