Sample viewer

vx.netlux.org/Virus.DOS.Elmo.329

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:52:55.970085297Z 42 PC: 1516b | Get date 0x1516b: cmp dl, 0xb
0x1516e: je 0x15175
0x15170: cmp dl, 0x15
0x15173: jne 0x1518b
0x15175: mov ah, 0x2c
0x15177: int 0x21
0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
2018-12-17T22:52:55.974355669Z 26 PC: 1519d | Set disk transfer address
2018-12-17T22:52:55.976142385Z 71 PC: 151a7 | Get current directory
2018-12-17T22:52:55.97934425Z 78 PC: 151b1 | Find first file
2018-12-17T22:52:55.986465106Z 61 PC: 151bc | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:52:56.000201159Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.007445277Z 66 PC: 151f2 | Move file pointer
2018-12-17T22:52:56.009444252Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:56.013747254Z 66 PC: 15206 | Move file pointer
2018-12-17T22:52:56.015750808Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:52:56.03099815Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.041488816Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.044980645Z 61 PC: 151bc | Open file (Filename = 'PRINT.COM')
2018-12-17T22:52:56.053243637Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.061894357Z 66 PC: 151f2 | Move file pointer
2018-12-17T22:52:56.063704688Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:56.066612851Z 66 PC: 15206 | Move file pointer
2018-12-17T22:52:56.069413081Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:52:56.076926314Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.091394482Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.094382816Z 61 PC: 151bc | Open file (Filename = 'HELLO.COM')
2018-12-17T22:52:56.108117356Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.116013147Z 66 PC: 151f2 | Move file pointer
2018-12-17T22:52:56.11760642Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:56.121621613Z 66 PC: 15206 | Move file pointer
2018-12-17T22:52:56.123428056Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:52:56.126596257Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.137189336Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.140507569Z 61 PC: 151bc | Open file (Filename = 'PHANG.COM')
2018-12-17T22:52:56.148127342Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.156954514Z 66 PC: 151f2 | Move file pointer
2018-12-17T22:52:56.159391211Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:56.162817147Z 66 PC: 15206 | Move file pointer
2018-12-17T22:52:56.165603601Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:52:56.169159271Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.177915799Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.181326236Z 61 PC: 151bc | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:52:56.1900219Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.197089265Z 66 PC: 151f2 | Move file pointer
2018-12-17T22:52:56.198909475Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:56.202878841Z 66 PC: 15206 | Move file pointer
2018-12-17T22:52:56.205359872Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:52:56.208512283Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.218404205Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.221960115Z 61 PC: 151bc | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:52:56.230336239Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.238857997Z 66 PC: 151f2 | Move file pointer
2018-12-17T22:52:56.240813771Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:56.244281685Z 66 PC: 15206 | Move file pointer
2018-12-17T22:52:56.24737206Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:52:56.257761837Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.267450948Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.271106855Z 61 PC: 151bc | Open file (Filename = 'PAH.COM')
2018-12-17T22:52:56.280148129Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.288346709Z 66 PC: 151f2 | Move file pointer
2018-12-17T22:52:56.290339543Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:52:56.29458609Z 66 PC: 15206 | Move file pointer
2018-12-17T22:52:56.296628426Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-17T22:52:56.299814982Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.309399777Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.312496664Z 61 PC: 151bc | Open file (Filename = 'TEST.COM')
2018-12-17T22:52:56.319746713Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:52:56.324385467Z 62 PC: 1520d | Close file
2018-12-17T22:52:56.326965043Z 79 PC: 151b1 | Find next file
2018-12-17T22:52:56.329829273Z 59 PC: 15219 | Change current directory
2018-12-17T22:52:56.335324696Z 26 PC: 15224 | Set disk transfer address
2018-12-17T22:52:56.337145336Z 59 PC: 1522c | Change current directory
2018-12-17T22:52:56.339304662Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-17T22:52:56.342246619Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11045,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:47.309553771Z 42 PC: 1516b | Get date 0x1516b: cmp dl, 0xb
0x1516e: je 0x15175
0x15170: cmp dl, 0x15
0x15173: jne 0x1518b
0x15175: mov ah, 0x2c
0x15177: int 0x21
0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
2018-12-25T12:29:47.313301733Z 26 PC: 1519d | Set disk transfer address
2018-12-25T12:29:47.314612233Z 71 PC: 151a7 | Get current directory
2018-12-25T12:29:47.317840223Z 78 PC: 151b1 | Find first file
2018-12-25T12:29:47.325550845Z 61 PC: 151bc | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:47.332962099Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:29:47.340480016Z 66 PC: 151f2 | Move file pointer
2018-12-25T12:29:47.342856896Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:29:47.346994563Z 66 PC: 15206 | Move file pointer
2018-12-25T12:29:47.349997352Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-25T12:29:47.366970945Z 62 PC: 1520d | Close file
2018-12-25T12:29:47.377127098Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.38930099Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.398173993Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.406532784Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.408749475Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.412011656Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.414337596Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.417665435Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.427219268Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.432368072Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.440368346Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.448679685Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.450845534Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.454494121Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.456174052Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.459443513Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.473129404Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.476884114Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.484419164Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.492682546Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.494268803Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.497511991Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.504437554Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.508792099Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.517865834Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.521680646Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.528984446Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.536009213Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.538526405Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.541738141Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.543623609Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.547102821Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.556449227Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.559431029Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.567068098Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.575653003Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.577244262Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.580415506Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.582962682Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.592493131Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.601586624Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.605415151Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.613022181Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.620705041Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.622704041Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.626171564Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.628403905Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.632215614Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.641782359Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.646126784Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.653922514Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.657727952Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.660214973Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.663355264Z 59 PC: 15219 | Change current directory
2018-12-25T12:29:47.669121194Z 26 PC: 15224 | Set disk transfer address
2018-12-25T12:29:47.670573325Z 59 PC: 1522c | Change current directory
2018-12-25T12:29:47.672875655Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T12:29:47.676562368Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":11,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11045,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:47.421681528Z 42 PC: 1516b | Get date 0x1516b: cmp dl, 0xb
0x1516e: je 0x15175
0x15170: cmp dl, 0x15
0x15173: jne 0x1518b
0x15175: mov ah, 0x2c
0x15177: int 0x21
0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
2018-12-25T12:29:47.424475485Z 44 PC: 15179 | Get time 0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
0x1519b: int 0x21
0x1519d: mov ah, 0x47
0x1519f: sub dl, dl
0x151a1: lea si, word ptr [bp + 0x277]
0x151a5: int 0x21
0x151a7: xor cx, cx
2018-12-25T12:29:47.426790809Z 26 PC: 1519d | Set disk transfer address
2018-12-25T12:29:47.427817484Z 71 PC: 151a7 | Get current directory
2018-12-25T12:29:47.431292444Z 78 PC: 151b1 | Find first file
2018-12-25T12:29:47.435133236Z 61 PC: 151bc | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:47.441294878Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:29:47.44770388Z 66 PC: 151f2 | Move file pointer
2018-12-25T12:29:47.449045412Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:29:47.451432436Z 66 PC: 15206 | Move file pointer
2018-12-25T12:29:47.45347838Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-25T12:29:47.466971641Z 62 PC: 1520d | Close file
2018-12-25T12:29:47.474373818Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.477418905Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.488471414Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.494715195Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.496999908Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.49971655Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.501331114Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.504755556Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.512717581Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.515497199Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.522207028Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.52912777Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.530303641Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.532877017Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.534934868Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.537701445Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.545831603Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.54899627Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.556004808Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.562261191Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.564407478Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.566901584Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.568379108Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.571900611Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.579500697Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.581940545Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.588951456Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.594933724Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.596244047Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.599833373Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.601958956Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.605079649Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.613321731Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.616028999Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.623535299Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.631088237Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.632565334Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.635223136Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.637538731Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.64583414Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.651091592Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.653743551Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.657889703Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.662069036Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.663706372Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.665544087Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.666712799Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.669104353Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.674386758Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.676161418Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.680524996Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.684715381Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.686142367Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.688520431Z 59 PC: 15219 | Change current directory
2018-12-25T12:29:47.69485673Z 26 PC: 15224 | Set disk transfer address
2018-12-25T12:29:47.695797488Z 59 PC: 1522c | Change current directory
2018-12-25T12:29:47.697725578Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T12:29:47.699401046Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":21,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11045,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:47.771256096Z 42 PC: 1516b | Get date 0x1516b: cmp dl, 0xb
0x1516e: je 0x15175
0x15170: cmp dl, 0x15
0x15173: jne 0x1518b
0x15175: mov ah, 0x2c
0x15177: int 0x21
0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
2018-12-25T12:29:47.775106449Z 44 PC: 15179 | Get time 0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
0x1519b: int 0x21
0x1519d: mov ah, 0x47
0x1519f: sub dl, dl
0x151a1: lea si, word ptr [bp + 0x277]
0x151a5: int 0x21
0x151a7: xor cx, cx
2018-12-25T12:29:47.778339367Z 26 PC: 1519d | Set disk transfer address
2018-12-25T12:29:47.779950017Z 71 PC: 151a7 | Get current directory
2018-12-25T12:29:47.783836655Z 78 PC: 151b1 | Find first file
2018-12-25T12:29:47.791732273Z 61 PC: 151bc | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:47.799902833Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:29:47.807366203Z 66 PC: 151f2 | Move file pointer
2018-12-25T12:29:47.810251134Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:29:47.81361408Z 66 PC: 15206 | Move file pointer
2018-12-25T12:29:47.815807203Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-25T12:29:47.832132508Z 62 PC: 1520d | Close file
2018-12-25T12:29:47.841680232Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.845056213Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.853848449Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.86135968Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.863232931Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.867297067Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.869768294Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.87326009Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.882561745Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.888905257Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.897504545Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.90500353Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.908215927Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.911930259Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.914093524Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.918306557Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.927558011Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.930960585Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.939384837Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.946778336Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:47.948539232Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:47.951824988Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:47.954557838Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:47.958256971Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:47.968111274Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:47.980553603Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:47.988142155Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:47.995510157Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.000356577Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.003938387Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.006181313Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.010477073Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.019260513Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.022391877Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.030773367Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.038963512Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.041190434Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.045517814Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.048202791Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.057767846Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.067553787Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.071691054Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.079418813Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.091132256Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.093755053Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.096822929Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.098634469Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.102653143Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.111886201Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.114840296Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.123848899Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.127552215Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.130080923Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.134023645Z 59 PC: 15219 | Change current directory
2018-12-25T12:29:48.139041475Z 26 PC: 15224 | Set disk transfer address
2018-12-25T12:29:48.1406986Z 59 PC: 1522c | Change current directory
2018-12-25T12:29:48.1439533Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T12:29:48.147155213Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11045,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:47.961801633Z 42 PC: 1516b | Get date 0x1516b: cmp dl, 0xb
0x1516e: je 0x15175
0x15170: cmp dl, 0x15
0x15173: jne 0x1518b
0x15175: mov ah, 0x2c
0x15177: int 0x21
0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
2018-12-25T12:29:47.969102865Z 26 PC: 1519d | Set disk transfer address
2018-12-25T12:29:47.971063561Z 71 PC: 151a7 | Get current directory
2018-12-25T12:29:47.974455661Z 78 PC: 151b1 | Find first file
2018-12-25T12:29:47.980945418Z 61 PC: 151bc | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:47.987806392Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:29:48.000966569Z 66 PC: 151f2 | Move file pointer
2018-12-25T12:29:48.00316425Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:29:48.01111728Z 66 PC: 15206 | Move file pointer
2018-12-25T12:29:48.013161189Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-25T12:29:48.150456525Z 62 PC: 1520d | Close file
2018-12-25T12:29:48.159326445Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.162517354Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.169371996Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.177061285Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.1785905Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.181483553Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.184104271Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.187564841Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.195593261Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.198897611Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.206585486Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.213494732Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.215723723Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.218392754Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.219969658Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.223310347Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.231115381Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.233736241Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.240470983Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.248663612Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.249993221Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.257818455Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.259839675Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.262817825Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.270989867Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.274109037Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.280413877Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.286374663Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.287999784Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.290405208Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.292001285Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.295469232Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.302744346Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.305566326Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.312704289Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.318950702Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.32056004Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.324111084Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.325917137Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.334298685Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.340171934Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.342023354Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.346532813Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.351507221Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.352682792Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.354862598Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.35726721Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.359723254Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.36559807Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.367956542Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.37231885Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.374122064Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.376052711Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.377875371Z 59 PC: 15219 | Change current directory
2018-12-25T12:29:48.380596299Z 26 PC: 15224 | Set disk transfer address
2018-12-25T12:29:48.381646524Z 59 PC: 1522c | Change current directory
2018-12-25T12:29:48.383529349Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T12:29:48.385081088Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":11,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11045,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:48.066302125Z 42 PC: 1516b | Get date 0x1516b: cmp dl, 0xb
0x1516e: je 0x15175
0x15170: cmp dl, 0x15
0x15173: jne 0x1518b
0x15175: mov ah, 0x2c
0x15177: int 0x21
0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
2018-12-25T12:29:48.069430358Z 44 PC: 15179 | Get time 0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
0x1519b: int 0x21
0x1519d: mov ah, 0x47
0x1519f: sub dl, dl
0x151a1: lea si, word ptr [bp + 0x277]
0x151a5: int 0x21
0x151a7: xor cx, cx
2018-12-25T12:29:48.072091693Z 26 PC: 1519d | Set disk transfer address
2018-12-25T12:29:48.073609552Z 71 PC: 151a7 | Get current directory
2018-12-25T12:29:48.07993956Z 78 PC: 151b1 | Find first file
2018-12-25T12:29:48.086321453Z 61 PC: 151bc | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:48.098054853Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:29:48.105395484Z 66 PC: 151f2 | Move file pointer
2018-12-25T12:29:48.106914373Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:29:48.110035488Z 66 PC: 15206 | Move file pointer
2018-12-25T12:29:48.113571562Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-25T12:29:48.150872624Z 62 PC: 1520d | Close file
2018-12-25T12:29:48.159075172Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.162013213Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.169812535Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.178327645Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.180072616Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.184136226Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.186030878Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.189147755Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.197759996Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.201473794Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.20813344Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.22373598Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.225448117Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.228408973Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.231065717Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.234625524Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.243148063Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.246332258Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.252712631Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.259062066Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.268403521Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.274702028Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.281701631Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.285280012Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.293579058Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.296131945Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.300969425Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.305309489Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.306458568Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.308839789Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.310333422Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.313016431Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.318373204Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.320673511Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.325180295Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.32982544Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.330966927Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.332759324Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.334877214Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.343996599Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.353011751Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.355928317Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.36344427Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.369715786Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.371229403Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.374581481Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.37642179Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.379767647Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.387877804Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.39045013Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.396939618Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.404066077Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.405735678Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.408520352Z 59 PC: 15219 | Change current directory
2018-12-25T12:29:48.414368381Z 26 PC: 15224 | Set disk transfer address
2018-12-25T12:29:48.415374954Z 59 PC: 1522c | Change current directory
2018-12-25T12:29:48.417018586Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T12:29:48.420078976Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":21,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11045,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:29:48.081016299Z 42 PC: 1516b | Get date 0x1516b: cmp dl, 0xb
0x1516e: je 0x15175
0x15170: cmp dl, 0x15
0x15173: jne 0x1518b
0x15175: mov ah, 0x2c
0x15177: int 0x21
0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
2018-12-25T12:29:48.084342978Z 44 PC: 15179 | Get time 0x15179: cmp cl, 0xa
0x1517c: jg 0x1518b
0x1517e: cmp dh, 0x1e
0x15181: jg 0x1518b
0x15183: mov ah, 9
0x15185: lea dx, word ptr [bp + 0x1f2]
0x15189: int 0x21
0x1518b: lea si, word ptr [bp + 0x1ea]
0x1518f: mov di, 0x100
0x15192: push di
0x15193: movsw word ptr es:[di], word ptr [si]
0x15194: movsw word ptr es:[di], word ptr [si]
0x15195: mov ah, 0x1a
0x15197: lea dx, word ptr [bp + 0x24d]
0x1519b: int 0x21
0x1519d: mov ah, 0x47
0x1519f: sub dl, dl
0x151a1: lea si, word ptr [bp + 0x277]
0x151a5: int 0x21
0x151a7: xor cx, cx
2018-12-25T12:29:48.08751542Z 26 PC: 1519d | Set disk transfer address
2018-12-25T12:29:48.088900853Z 71 PC: 151a7 | Get current directory
2018-12-25T12:29:48.092351699Z 78 PC: 151b1 | Find first file
2018-12-25T12:29:48.10270722Z 61 PC: 151bc | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:29:48.110180709Z 63 PC: 151c7 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:29:48.118183292Z 66 PC: 151f2 | Move file pointer
2018-12-25T12:29:48.120828785Z 64 PC: 151fd | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:29:48.124599374Z 66 PC: 15206 | Move file pointer
2018-12-25T12:29:48.126653462Z 64 PC: 1527c | Write file or device (Write 329 bytes on handle 5)
2018-12-25T12:29:48.142249062Z 62 PC: 1520d | Close file
2018-12-25T12:29:48.150917396Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.153908171Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.162854403Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.170270102Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.172293262Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.176590293Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.197237725Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.200515326Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.209434603Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.217647383Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.224970341Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.232587124Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.245753909Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.249002315Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.263582841Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.267725482Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.277047027Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.280480519Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.289208142Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.296548248Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.298356582Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.302271889Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.304242421Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.30853088Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.318383617Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.321477741Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.328986044Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.336565032Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.338407799Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.34143676Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.343488148Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.348048733Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.356801593Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.360085501Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.368615119Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.376325188Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.378058901Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.381877734Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.383962364Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.393317937Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.4036858Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.407251803Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.414937517Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.422296202Z 66 PC: 151f2 | Move file pointer (See above)
2018-12-25T12:29:48.424153192Z 64 PC: 151fd | Write file or device (See above)
2018-12-25T12:29:48.427448213Z 66 PC: 15206 | Move file pointer (See above)
2018-12-25T12:29:48.429617484Z 64 PC: 1527c | Write file or device (See above)
2018-12-25T12:29:48.433553741Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.442584241Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.445465077Z 61 PC: 151bc | Open file (See above)
2018-12-25T12:29:48.453414028Z 63 PC: 151c7 | Read file or device (See above)
2018-12-25T12:29:48.456346782Z 62 PC: 1520d | Close file (See above)
2018-12-25T12:29:48.458375898Z 79 PC: 151b1 | Find next file (See above)
2018-12-25T12:29:48.46229804Z 59 PC: 15219 | Change current directory
2018-12-25T12:29:48.466767874Z 26 PC: 15224 | Set disk transfer address
2018-12-25T12:29:48.467987401Z 59 PC: 1522c | Change current directory
2018-12-25T12:29:48.47091452Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T12:29:48.473428829Z 76 PC: 12a56 | Terminate with return code (Return code = '0')