.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:54:44.316097428Z | 25 | PC: 13e4b | Get default drive |
2018-12-17T22:54:44.330633058Z | 82 | PC: 13ee0 | Get DOS internal pointers (SYSVARS) |
2018-12-17T22:54:44.33486413Z | 48 | PC: 13f21 | Get DOS version |
2018-12-17T22:54:44.336723859Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.337968447Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.340138861Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.341418705Z | 9 | PC: 12a85 | Display string (String= 'Sophos Ltd, Oxford sacrificial COM goat 1400H bytes long ') |
2018-12-17T22:54:44.347626312Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.349798091Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.351998887Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.353440295Z | 0 | PC: 12a89 | Program terminate |
2018-12-17T22:54:44.357351126Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.358984971Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.360745216Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.362891909Z | 77 | PC: 11fe0 | Get program return code |
2018-12-17T22:54:44.364327766Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.365643716Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.368110471Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.369500308Z | 72 | PC: 12174 | Allocate memory |
2018-12-17T22:54:44.371454989Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.373999345Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.375648746Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.377365791Z | 72 | PC: 1218d | Allocate memory |
2018-12-17T22:54:44.380386676Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.38275557Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.384738194Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.386547148Z | 37 | PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write') |
2018-12-17T22:54:44.389444084Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.391321723Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.393111208Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.395849304Z | 37 | PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:54:44.397481811Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.399083151Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.402037316Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.403647384Z | 37 | PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.405441551Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.407691995Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.412794439Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.414272717Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.417217372Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.419052882Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.421425411Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.422928054Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.424902269Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.42619293Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.427973244Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.429940255Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.431715409Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.433117357Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.438723212Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.440427188Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.442529364Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.447707962Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.450015954Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.451424344Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.454141158Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.455551798Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.457491368Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.45960583Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.461381486Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.462724681Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.464635752Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.466412968Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.468872713Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.470470865Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.473327197Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.475189279Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.478172895Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.480717941Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.483196058Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.485037119Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.488420732Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.490261566Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.492466576Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.494560291Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.496788709Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.498561282Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.501960296Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.503519396Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.505562412Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.507388776Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.50975917Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.511406691Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.513674607Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.515853649Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.518927845Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.520592565Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.522380831Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.52341738Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.524978153Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.526649859Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.527954603Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.528916897Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.531483201Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.532514593Z | 62 | PC: 122ab | Close file |
2018-12-17T22:54:44.534368658Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.536170827Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.538419464Z | 67 | PC: 9af84 | Get or set file attributes |
2018-12-17T22:54:44.545053508Z | 67 | PC: 9af84 | Get or set file attributes |
2018-12-17T22:54:44.887704048Z | 61 | PC: 9af84 | Open file (Filename = 'C:\COMMAND.COM') |
2018-12-17T22:54:44.895334036Z | 87 | PC: 9af84 | Get or set file date and time |
2018-12-17T22:54:44.897108145Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.899475734Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.90107966Z | 63 | PC: 9af84 | Read file or device (Read 8 bytes on handle 5) |
2018-12-17T22:54:44.904327009Z | 87 | PC: 9af84 | Get or set file date and time |
2018-12-17T22:54:44.905980741Z | 62 | PC: 9af84 | Close file |
2018-12-17T22:54:44.91291673Z | 67 | PC: 9af84 | Get or set file attributes |
2018-12-17T22:54:44.917751514Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.918911772Z | 61 | PC: 12354 | Open file (Filename = 'C:\COMMAND.COM') |
2018-12-17T22:54:44.927499263Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.928822528Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.930254744Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.93268359Z | 66 | PC: 12372 | Move file pointer |
2018-12-17T22:54:44.934387302Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.935808225Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.937888635Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.939345815Z | 63 | PC: 12383 | Read file or device (Read 44693 bytes on handle 5) |
2018-12-17T22:54:44.954921316Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.957574332Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:44.959967848Z | 42 | PC: 9af84 | Get date 0x9af84: ret 0x9af85: lcall 0x19:0x40f8 0x9af8a: ret 0x9af8b: pushf 0x9af8c: cmp ah, 0x30 0x9af8f: jne 0x9afad 0x9af91: cmp si, 0xdead 0x9af95: jne 0x9afad 0x9af97: cmp di, 0x7ce 0x9af9b: jne 0x9afad 0x9af9d: xor di, 0xc710 0x9afa1: push di 0x9afa2: sub di, si 0x9afa4: add di, 0x436 0x9afa8: not di 0x9afaa: pop si 0x9afab: popf 0x9afac: iret 0x9afad: call 0x9b3bb 0x9afb0: push cs |
2018-12-17T22:54:44.962433121Z | 87 | PC: 9af84 | Get or set file date and time |
2018-12-17T22:54:44.964194161Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.96629429Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.967632875Z | 63 | PC: 9af84 | Read file or device (Read 8 bytes on handle 5) |
2018-12-17T22:54:44.96973702Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.971381494Z | 63 | PC: 9af84 | Read file or device (Read 5 bytes on handle 5) |
2018-12-17T22:54:44.973396233Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.974641413Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.976358306Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:44.97749134Z | 64 | PC: 9af84 | Write file or device (Write 3 bytes on handle 5) |
2018-12-17T22:54:44.979395668Z | 66 | PC: 9af84 | Move file pointer |
2018-12-17T22:54:45.006639073Z | 64 | PC: 9af84 | Write file or device (Write 9736 bytes on handle 5) |
2018-12-17T22:54:45.024194511Z | 64 | PC: 9af84 | Write file or device (Write 8 bytes on handle 5) |
2018-12-17T22:54:45.027502196Z | 87 | PC: 9af84 | Get or set file date and time |
2018-12-17T22:54:45.029795142Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.03168178Z | 62 | PC: 1238a | Close file |
2018-12-17T22:54:45.043104655Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.045530765Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.04727031Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.048934377Z | 99 | PC: 95807 | Get DBCS lead byte table pointer |
2018-12-17T22:54:45.051896202Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.053356649Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.054951773Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.058152013Z | 56 | PC: 90029 | Get or set country info |
2018-12-17T22:54:45.061013959Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.063124553Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.065374973Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.067165398Z | 64 | PC: 95a78 | Write file or device (Write 2 bytes on handle 1) |
2018-12-17T22:54:45.073699182Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.077530277Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.080068817Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.08168792Z | 25 | PC: 90092 | Get default drive |
2018-12-17T22:54:45.084764824Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.086798685Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.088792656Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.091017339Z | 71 | PC: 9230d | Get current directory |
2018-12-17T22:54:45.096243765Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.098157107Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.101586822Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.10349224Z | 64 | PC: 95a78 | Write file or device (Write 3 bytes on handle 1) |
2018-12-17T22:54:45.107768561Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.111525228Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.11375489Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.115686641Z | 2 | PC: 922e2 | Character output (Char = '3e') |
2018-12-17T22:54:45.118728299Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.121163146Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.123198383Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.124893814Z | 93 | PC: 90150 | File sharing functions |
2018-12-17T22:54:45.128432976Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.130143493Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.132040565Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.135661794Z | 93 | PC: 90157 | File sharing functions |
2018-12-17T22:54:45.13780869Z | 53 | PC: 9af84 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.139248704Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.141837103Z | 37 | PC: 9af84 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:54:45.144095678Z | 10 | PC: 90169 | Buffered keyboard input |