Sample viewer

vx.netlux.org/Virus.DOS.Aids.872

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:13.899037561Z 47 PC: 12f37 | Get disk transfer address
2018-12-17T22:53:13.9011453Z 26 PC: 12f45 | Set disk transfer address
2018-12-17T22:53:13.903186254Z 78 PC: 1300a | Find first file
2018-12-17T22:53:13.914882544Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:13.922486288Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:13.924564071Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:13.926343954Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:13.932595377Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:13.942075085Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:13.944429667Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:13.945777008Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.298544302Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.303731596Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.311401634Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.314180293Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.316081144Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.322932754Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.325574146Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.332196326Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.33415215Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.341366401Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.346525062Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.354007607Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.355593005Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.358557183Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.36636Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.368270189Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.37654385Z 66 PC: 130f8 | Move file pointer
2018-12-17T22:53:14.378309637Z 64 PC: 1310e | Write file or device (Write 872 bytes on handle 5)
2018-12-17T22:53:14.389815951Z 66 PC: 1311d | Move file pointer
2018-12-17T22:53:14.392577238Z 64 PC: 1313b | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:53:14.395973398Z 66 PC: 1314e | Move file pointer
2018-12-17T22:53:14.397785011Z 64 PC: 1316e | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:53:14.404879748Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.407526389Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.41540049Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.420450937Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.431581235Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.433521189Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.435397303Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.445860478Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.447445164Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.451970926Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.454292777Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.459423194Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.464258327Z 78 PC: 1300a | Find first file
2018-12-17T22:53:14.469288065Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.475169934Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.476566337Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.478118362Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.483952251Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.485346781Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.488058895Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.490144192Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.502735724Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.505984117Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.51267249Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.514256836Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.515642249Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.524195486Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.526084364Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.529209143Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.531721162Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.538982613Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.541311777Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.547298814Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.548593997Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.549881956Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.555845629Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.557472705Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.559757206Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.56112229Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.567858193Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.570101447Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.575150412Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.577127386Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.578512026Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.583633998Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.585494933Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.587802788Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.589158705Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.598400466Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.600905681Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.606314802Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.609065519Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.610634596Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.617096405Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.619832404Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.624053123Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.62700106Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.636035972Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.640909306Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.650390456Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.652622018Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.656558732Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.66474506Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.668172238Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.6713516Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.672816602Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.678853031Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.681382723Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.686797284Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.688143853Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.689725795Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.69556831Z 66 PC: 130b6 | Move file pointer
2018-12-17T22:53:14.696765729Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:14.699367506Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.702315184Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.710448181Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.713750895Z 61 PC: 13053 | Open file (Filename = '')
2018-12-17T22:53:14.722332625Z 87 PC: 1305f | Get or set file date and time
2018-12-17T22:53:14.724222395Z 66 PC: 13076 | Move file pointer
2018-12-17T22:53:14.726101595Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:53:14.734701209Z 87 PC: 13182 | Get or set file date and time
2018-12-17T22:53:14.737929112Z 62 PC: 13189 | Close file
2018-12-17T22:53:14.746021083Z 79 PC: 13046 | Find next file
2018-12-17T22:53:14.749636845Z 42 PC: 12e74 | Get date 0x12e74: cmp dl, 0xa
0x12e77: je 0x12e7b
0x12e79: jmp 0x12e89
0x12e7b: mov ah, 0x2c
0x12e7d: int 0x21
0x12e7f: cmp dl, 0xa
0x12e82: jl 0x12e86
0x12e84: jmp 0x12e84
0x12e86: call 0x12e8f
0x12e89: add sp, 0x200
0x12e8d: pop bp
0x12e8e: ret
0x12e8f: mov ah, 0
0x12e91: mov dl, 0x80
0x12e93: int 0x13
0x12e95: mov ah, 8
0x12e97: mov dl, 0x80
0x12e99: int 0x13
0x12e9b: mov byte ptr [bp + 0x147], cl
0x12e9f: and byte ptr [bp + 0x147], 0x3f
2018-12-17T22:53:14.752306991Z 9 PC: 12e26 | Display string (Could not find end pointer)

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11152,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:01.622708441Z 47 PC: 12f37 | Get disk transfer address
2018-12-25T12:30:01.624261614Z 26 PC: 12f45 | Set disk transfer address
2018-12-25T12:30:01.626186243Z 78 PC: 1300a | Find first file
2018-12-25T12:30:01.636072397Z 61 PC: 13053 | Open file (Filename = '')
2018-12-25T12:30:01.643536443Z 87 PC: 1305f | Get or set file date and time
2018-12-25T12:30:01.646020697Z 66 PC: 13076 | Move file pointer
2018-12-25T12:30:01.647442244Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:30:01.653276945Z 66 PC: 130b6 | Move file pointer
2018-12-25T12:30:01.656012368Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:01.658710671Z 87 PC: 13182 | Get or set file date and time
2018-12-25T12:30:01.660261068Z 62 PC: 13189 | Close file
2018-12-25T12:30:02.016754009Z 79 PC: 13046 | Find next file
2018-12-25T12:30:02.020373526Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.028640518Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.031041104Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.033339136Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.040029495Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.04161852Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.061736239Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.063661631Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.07042906Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.074515307Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.0825046Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.084377579Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.08686839Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.099227227Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.100765878Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.107684794Z 66 PC: 130f8 | Move file pointer
2018-12-25T12:30:02.109708726Z 64 PC: 1310e | Write file or device (Write 872 bytes on handle 5)
2018-12-25T12:30:02.120606028Z 66 PC: 1311d | Move file pointer
2018-12-25T12:30:02.124189274Z 64 PC: 1313b | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:02.127721846Z 66 PC: 1314e | Move file pointer
2018-12-25T12:30:02.130078658Z 64 PC: 1316e | Write file or device (Write 2 bytes on handle 5)
2018-12-25T12:30:02.138587116Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.140824276Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.1496761Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.156933681Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.166561948Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.168700435Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.17090915Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.17883347Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.180410158Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.186633555Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.189452878Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.195120222Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.199468053Z 78 PC: 1300a | Find first file (See above)
2018-12-25T12:30:02.204194895Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.211443523Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.213051963Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.215032079Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.222188113Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.223418302Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.225927724Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.227284424Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.238843207Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.240988887Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.246767707Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.248032038Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.249243895Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.254246415Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.255377252Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.257355021Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.259223629Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.264201694Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.26622353Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.280029443Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.281271956Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.282475017Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.291750436Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.29402872Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.297217876Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.300239629Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.30833815Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.31144622Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.319741435Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.328703432Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.330357391Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.337344506Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.339634718Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.342319158Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.343857861Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.351895645Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.354809763Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.362254283Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.365295805Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.367283685Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.374837025Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.37740407Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.380682584Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.381843409Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.387965619Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.390993753Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.395510785Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.396566094Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.398149555Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.402224215Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.403147041Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.40534643Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.409027851Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.416635037Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.420097439Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.427214465Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.428639757Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.430898992Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.437901777Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.439260203Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.442250915Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.443760814Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.451497491Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.45507675Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.463071439Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.464552914Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.46657051Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.469861117Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.471558462Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.480329219Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.483066922Z 42 PC: 12e74 | Get date 0x12e74: cmp dl, 0xa
0x12e77: je 0x12e7b
0x12e79: jmp 0x12e89
0x12e7b: mov ah, 0x2c
0x12e7d: int 0x21
0x12e7f: cmp dl, 0xa
0x12e82: jl 0x12e86
0x12e84: jmp 0x12e84
0x12e86: call 0x12e8f
0x12e89: add sp, 0x200
0x12e8d: pop bp
0x12e8e: ret
0x12e8f: mov ah, 0
0x12e91: mov dl, 0x80
0x12e93: int 0x13
0x12e95: mov ah, 8
0x12e97: mov dl, 0x80
0x12e99: int 0x13
0x12e9b: mov byte ptr [bp + 0x147], cl
0x12e9f: and byte ptr [bp + 0x147], 0x3f
2018-12-25T12:30:02.485574973Z 9 PC: 12e26 | Display string (Could not find end pointer)

{"DateBased":true,"Day":10,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11152,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:01.983270158Z 47 PC: 12f37 | Get disk transfer address
2018-12-25T12:30:01.98490918Z 26 PC: 12f45 | Set disk transfer address
2018-12-25T12:30:01.986542994Z 78 PC: 1300a | Find first file
2018-12-25T12:30:01.995084149Z 61 PC: 13053 | Open file (Filename = '')
2018-12-25T12:30:02.009612273Z 87 PC: 1305f | Get or set file date and time
2018-12-25T12:30:02.010954269Z 66 PC: 13076 | Move file pointer
2018-12-25T12:30:02.012263582Z 63 PC: 13088 | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:30:02.01803347Z 66 PC: 130b6 | Move file pointer
2018-12-25T12:30:02.020152484Z 63 PC: 130c4 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:02.023342179Z 87 PC: 13182 | Get or set file date and time
2018-12-25T12:30:02.030418475Z 62 PC: 13189 | Close file
2018-12-25T12:30:02.356401394Z 79 PC: 13046 | Find next file
2018-12-25T12:30:02.359895016Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.367418936Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.369959773Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.371431589Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.377402038Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.388658995Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.394266414Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.395743325Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.402772161Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.406046611Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.413653021Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.416184198Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.417691817Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.423644703Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.426420135Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.431846131Z 66 PC: 130f8 | Move file pointer
2018-12-25T12:30:02.433141698Z 64 PC: 1310e | Write file or device (Write 872 bytes on handle 5)
2018-12-25T12:30:02.445143083Z 66 PC: 1311d | Move file pointer
2018-12-25T12:30:02.446800931Z 64 PC: 1313b | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:02.450604549Z 66 PC: 1314e | Move file pointer
2018-12-25T12:30:02.453013762Z 64 PC: 1316e | Write file or device (Write 2 bytes on handle 5)
2018-12-25T12:30:02.459343871Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.46115754Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.469580358Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.475526926Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.482199505Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.484665125Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.486262746Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.492048925Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.494074099Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.499644274Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.501151619Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.508162857Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.514055437Z 78 PC: 1300a | Find first file (See above)
2018-12-25T12:30:02.52109632Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.527996898Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.52936672Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.530742986Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.537220086Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.53906644Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.541401675Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.543080749Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.556143406Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.559277376Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.566758461Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.568118316Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.569500613Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.576940018Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.57832022Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.580706921Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.583187093Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.589979003Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.592739609Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.600755065Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.602110416Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.603509353Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.609895036Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.611820138Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.614283883Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.615890745Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.624049055Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.627118492Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.63403048Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.635949378Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.637819364Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.648445812Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.650132438Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.65258334Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.654432819Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.662031081Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.66472789Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.673202986Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.674917632Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.676407836Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.682930099Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.684729437Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.687916312Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.689449764Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.696793494Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.699466122Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.705900507Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.707381772Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.708915189Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.71513144Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.717381496Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.719855429Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.721276455Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.72905575Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.731493683Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.737527639Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.739361156Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.741303167Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.74761902Z 66 PC: 130b6 | Move file pointer (See above)
2018-12-25T12:30:02.74932163Z 63 PC: 130c4 | Read file or device (See above)
2018-12-25T12:30:02.751522062Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.752744948Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.760014434Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.7624514Z 61 PC: 13053 | Open file (See above)
2018-12-25T12:30:02.768886565Z 87 PC: 1305f | Get or set file date and time (See above)
2018-12-25T12:30:02.770565213Z 66 PC: 13076 | Move file pointer (See above)
2018-12-25T12:30:02.771726482Z 63 PC: 13088 | Read file or device (See above)
2018-12-25T12:30:02.774269164Z 87 PC: 13182 | Get or set file date and time (See above)
2018-12-25T12:30:02.775946239Z 62 PC: 13189 | Close file (See above)
2018-12-25T12:30:02.782860909Z 79 PC: 13046 | Find next file (See above)
2018-12-25T12:30:02.785665894Z 42 PC: 12e74 | Get date 0x12e74: cmp dl, 0xa
0x12e77: je 0x12e7b
0x12e79: jmp 0x12e89
0x12e7b: mov ah, 0x2c
0x12e7d: int 0x21
0x12e7f: cmp dl, 0xa
0x12e82: jl 0x12e86
0x12e84: jmp 0x12e84
0x12e86: call 0x12e8f
0x12e89: add sp, 0x200
0x12e8d: pop bp
0x12e8e: ret
0x12e8f: mov ah, 0
0x12e91: mov dl, 0x80
0x12e93: int 0x13
0x12e95: mov ah, 8
0x12e97: mov dl, 0x80
0x12e99: int 0x13
0x12e9b: mov byte ptr [bp + 0x147], cl
0x12e9f: and byte ptr [bp + 0x147], 0x3f
2018-12-25T12:30:02.78911221Z 44 PC: 12e7f | Get time 0x12e7f: cmp dl, 0xa
0x12e82: jl 0x12e86
0x12e84: jmp 0x12e84
0x12e86: call 0x12e8f
0x12e89: add sp, 0x200
0x12e8d: pop bp
0x12e8e: ret
0x12e8f: mov ah, 0
0x12e91: mov dl, 0x80
0x12e93: int 0x13
0x12e95: mov ah, 8
0x12e97: mov dl, 0x80
0x12e99: int 0x13
0x12e9b: mov byte ptr [bp + 0x147], cl
0x12e9f: and byte ptr [bp + 0x147], 0x3f
0x12ea4: mov byte ptr [bp + 0x148], 0
0x12ea9: xchg cl, ch
0x12eab: shr ch, 1
0x12ead: shr ch, 1
0x12eaf: shr ch, 1