.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:55:09.476121436Z | 44 | PC: 12b9a | Get time 0x12b9a: cmp byte ptr [0x107], 0 0x12b9f: je 0x12ba6 0x12ba1: cmp dh, 0xf 0x12ba4: jg 0x12baf 0x12ba6: cmp dl, 0 0x12ba9: je 0x12b96 0x12bab: mov byte ptr [0x107], dl 0x12baf: mov byte ptr [0x24b], 0 0x12bb4: mov byte ptr [0x24c], 4 0x12bb9: mov byte ptr [0x255], 0 0x12bbe: mov cx, 0x27 0x12bc1: mov dx, 0x134 0x12bc4: mov ah, 0x4e 0x12bc6: int 0x21 0x12bc8: cmp ax, 0x12 0x12bcb: je 0x12bd0 0x12bcd: call 0x12bf2 0x12bd0: mov cx, 0x27 0x12bd3: mov dx, 0x13a 0x12bd6: mov ah, 0x4e |
2018-12-17T22:55:09.478735123Z | 78 | PC: 12bc8 | Find first file |
2018-12-17T22:55:09.485869291Z | 78 | PC: 12bda | Find first file |
2018-12-17T22:55:09.49243435Z | 67 | PC: 12c13 | Get or set file attributes |
2018-12-17T22:55:09.509021209Z | 61 | PC: 12c19 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:55:09.518206476Z | 63 | PC: 12c28 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:55:09.526005335Z | 62 | PC: 12c5c | Close file |
2018-12-17T22:55:09.529073335Z | 61 | PC: 12c65 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:55:09.537599603Z | 64 | PC: 12a5c | Write file or device (Write 666 bytes on handle 5) |
2018-12-17T22:55:09.547409295Z | 87 | PC: 12c8d | Get or set file date and time |
2018-12-17T22:55:09.549680757Z | 62 | PC: 12c95 | Close file |
2018-12-17T22:55:09.558679142Z | 67 | PC: 12ca2 | Get or set file attributes |
2018-12-17T22:55:09.564837796Z | 79 | PC: 12c4c | Find next file |
2018-12-17T22:55:09.568110973Z | 67 | PC: 12c13 | Get or set file attributes |
2018-12-17T22:55:09.579060168Z | 61 | PC: 12c19 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:55:09.588281924Z | 63 | PC: 12c28 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:55:09.595999299Z | 62 | PC: 12c5c | Close file |
2018-12-17T22:55:09.598890167Z | 61 | PC: 12c65 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:55:09.610745005Z | 64 | PC: 12a5c | Write file or device (Write 666 bytes on handle 5) |
2018-12-17T22:55:09.620124608Z | 87 | PC: 12c8d | Get or set file date and time |
2018-12-17T22:55:09.622232803Z | 62 | PC: 12c95 | Close file |
2018-12-17T22:55:09.631856705Z | 67 | PC: 12ca2 | Get or set file attributes |
2018-12-17T22:55:09.636993297Z | 79 | PC: 12c4c | Find next file |
2018-12-17T22:55:09.639965247Z | 67 | PC: 12c13 | Get or set file attributes |
2018-12-17T22:55:09.651726669Z | 61 | PC: 12c19 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:55:09.659533804Z | 63 | PC: 12c28 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:55:09.667218489Z | 62 | PC: 12c5c | Close file |
2018-12-17T22:55:09.669847554Z | 61 | PC: 12c65 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:55:09.678567185Z | 64 | PC: 12a5c | Write file or device (Write 666 bytes on handle 5) |
2018-12-17T22:55:09.688541206Z | 87 | PC: 12c8d | Get or set file date and time |
2018-12-17T22:55:09.690816345Z | 62 | PC: 12c95 | Close file |
2018-12-17T22:55:09.700113412Z | 67 | PC: 12ca2 | Get or set file attributes |
2018-12-17T22:55:09.705551591Z | 79 | PC: 12c4c | Find next file |
2018-12-17T22:55:09.708914045Z | 67 | PC: 12c13 | Get or set file attributes |
2018-12-17T22:55:09.733853495Z | 61 | PC: 12c19 | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:55:09.747547162Z | 63 | PC: 12c28 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:55:09.755286519Z | 62 | PC: 12c5c | Close file |
2018-12-17T22:55:09.758134867Z | 61 | PC: 12c65 | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:55:09.768461792Z | 64 | PC: 12a5c | Write file or device (Write 666 bytes on handle 5) |
2018-12-17T22:55:09.777873605Z | 87 | PC: 12c8d | Get or set file date and time |
2018-12-17T22:55:09.780775342Z | 62 | PC: 12c95 | Close file |
2018-12-17T22:55:09.790250534Z | 67 | PC: 12ca2 | Get or set file attributes |
2018-12-17T22:55:09.795757102Z | 9 | PC: 12cd1 | Display string (String= ' Program too big to fit in memory') |
2018-12-17T22:55:09.800997099Z | 76 | PC: 12cd5 | Terminate with return code (Return code = '36') |