Sample viewer

vx.netlux.org/Virus.DOS.Ahav.383

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:55:57.551491341Z 53 PC: 142a9 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.553274093Z 37 PC: 142c0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.555943053Z 26 PC: 142d3 | Set disk transfer address
2018-12-17T22:55:57.557583578Z 78 PC: 142de | Find first file
2018-12-17T22:55:57.5643811Z 61 PC: 142e9 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:57.573337343Z 63 PC: 142f5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.582307251Z 62 PC: 14323 | Close file
2018-12-17T22:55:57.586249344Z 67 PC: 1432f | Get or set file attributes
2018-12-17T22:55:57.604779962Z 61 PC: 14338 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:57.61300571Z 44 PC: 1433d | Get time 0x1433d: mov word ptr [bp + 0x22f], dx
0x14341: call 0x143b1
0x14344: mov ax, 0x5700
0x14347: mov dx, word ptr [bp + 0x12b]
0x1434b: mov cx, word ptr [bp + 0x129]
0x1434f: inc ax
0x14350: int 0x21
0x14352: mov ah, 0x3e
0x14354: int 0x21
0x14356: mov ax, 0x4300
0x14359: lea dx, word ptr [bp + 0x29d]
0x1435d: xor cx, cx
0x1435f: inc ax
0x14360: mov cl, byte ptr [bp + 0x128]
0x14364: int 0x21
0x14366: jmp 0x14371
0x14368: mov ah, 0x3e
0x1436a: int 0x21
0x1436c: mov ah, 0x4f
0x1436e: jmp 0x142dc
2018-12-17T22:55:57.618193396Z 66 PC: 143bd | Move file pointer
2018-12-17T22:55:57.620319955Z 64 PC: 143cf | Write file or device (Write 383 bytes on handle 5)
2018-12-17T22:55:57.630038411Z 66 PC: 143d8 | Move file pointer
2018-12-17T22:55:57.631961197Z 64 PC: 143e3 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:57.639554886Z 87 PC: 14352 | Get or set file date and time
2018-12-17T22:55:57.644284571Z 62 PC: 14356 | Close file
2018-12-17T22:55:57.653335211Z 67 PC: 14366 | Get or set file attributes
2018-12-17T22:55:57.664324876Z 26 PC: 14378 | Set disk transfer address
2018-12-17T22:55:57.66673021Z 37 PC: 14389 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.670438834Z 53 PC: 13fcc | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.672192061Z 37 PC: 13fe3 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.674271321Z 26 PC: 13ff6 | Set disk transfer address
2018-12-17T22:55:57.676163068Z 78 PC: 14001 | Find first file
2018-12-17T22:55:57.683067563Z 61 PC: 1400c | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:57.690839808Z 63 PC: 14018 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.694337747Z 62 PC: 1408f | Close file
2018-12-17T22:55:57.696442214Z 79 PC: 14001 | Find next file
2018-12-17T22:55:57.699434461Z 61 PC: 1400c | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:57.707810062Z 63 PC: 14018 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.715132261Z 62 PC: 14046 | Close file
2018-12-17T22:55:57.717005684Z 67 PC: 14052 | Get or set file attributes
2018-12-17T22:55:57.735367684Z 61 PC: 1405b | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:57.746876577Z 44 PC: 14060 | Get time 0x14060: mov word ptr [bp + 0x22f], dx
0x14064: call 0x140d4
0x14067: mov ax, 0x5700
0x1406a: mov dx, word ptr [bp + 0x12b]
0x1406e: mov cx, word ptr [bp + 0x129]
0x14072: inc ax
0x14073: int 0x21
0x14075: mov ah, 0x3e
0x14077: int 0x21
0x14079: mov ax, 0x4300
0x1407c: lea dx, word ptr [bp + 0x29d]
0x14080: xor cx, cx
0x14082: inc ax
0x14083: mov cl, byte ptr [bp + 0x128]
0x14087: int 0x21
0x14089: jmp 0x14094
0x1408b: mov ah, 0x3e
0x1408d: int 0x21
0x1408f: mov ah, 0x4f
0x14091: jmp 0x13fff
2018-12-17T22:55:57.750115748Z 66 PC: 140e0 | Move file pointer
2018-12-17T22:55:57.754915895Z 64 PC: 140f2 | Write file or device (Write 383 bytes on handle 5)
2018-12-17T22:55:57.758835486Z 66 PC: 140fb | Move file pointer
2018-12-17T22:55:57.761166499Z 64 PC: 14106 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:57.764951688Z 87 PC: 14075 | Get or set file date and time
2018-12-17T22:55:57.766920801Z 62 PC: 14079 | Close file
2018-12-17T22:55:57.775329653Z 67 PC: 14089 | Get or set file attributes
2018-12-17T22:55:57.786967869Z 26 PC: 1409b | Set disk transfer address
2018-12-17T22:55:57.78829761Z 37 PC: 140ac | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.792237569Z 53 PC: 13d17 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.794417829Z 37 PC: 13d2e | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.79588607Z 26 PC: 13d41 | Set disk transfer address
2018-12-17T22:55:57.797123637Z 78 PC: 13d4c | Find first file
2018-12-17T22:55:57.804076422Z 61 PC: 13d57 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:57.813355482Z 63 PC: 13d63 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.816381051Z 62 PC: 13dda | Close file
2018-12-17T22:55:57.81855Z 79 PC: 13d4c | Find next file
2018-12-17T22:55:57.823454673Z 61 PC: 13d57 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:57.830644794Z 63 PC: 13d63 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.8336152Z 62 PC: 13dda | Close file
2018-12-17T22:55:57.836288788Z 79 PC: 13d4c | Find next file
2018-12-17T22:55:57.839250067Z 61 PC: 13d57 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:57.846210686Z 63 PC: 13d63 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.854069295Z 62 PC: 13d91 | Close file
2018-12-17T22:55:57.857610113Z 67 PC: 13d9d | Get or set file attributes
2018-12-17T22:55:57.868413589Z 61 PC: 13da6 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:57.875885721Z 44 PC: 13dab | Get time 0x13dab: mov word ptr [bp + 0x22f], dx
0x13daf: call 0x13e1f
0x13db2: mov ax, 0x5700
0x13db5: mov dx, word ptr [bp + 0x12b]
0x13db9: mov cx, word ptr [bp + 0x129]
0x13dbd: inc ax
0x13dbe: int 0x21
0x13dc0: mov ah, 0x3e
0x13dc2: int 0x21
0x13dc4: mov ax, 0x4300
0x13dc7: lea dx, word ptr [bp + 0x29d]
0x13dcb: xor cx, cx
0x13dcd: inc ax
0x13dce: mov cl, byte ptr [bp + 0x128]
0x13dd2: int 0x21
0x13dd4: jmp 0x13ddf
0x13dd6: mov ah, 0x3e
0x13dd8: int 0x21
0x13dda: mov ah, 0x4f
0x13ddc: jmp 0x13d4a
2018-12-17T22:55:57.878526247Z 66 PC: 13e2b | Move file pointer
2018-12-17T22:55:57.880084186Z 64 PC: 13e3d | Write file or device (Write 383 bytes on handle 5)
2018-12-17T22:55:57.883186069Z 66 PC: 13e46 | Move file pointer
2018-12-17T22:55:57.885789976Z 64 PC: 13e51 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:57.888681023Z 87 PC: 13dc0 | Get or set file date and time
2018-12-17T22:55:57.890302362Z 62 PC: 13dc4 | Close file
2018-12-17T22:55:57.89922991Z 67 PC: 13dd4 | Get or set file attributes
2018-12-17T22:55:57.909685431Z 26 PC: 13de6 | Set disk transfer address
2018-12-17T22:55:57.910890498Z 37 PC: 13df7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.917528851Z 53 PC: 13a86 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.919469671Z 37 PC: 13a9d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:57.921345549Z 26 PC: 13ab0 | Set disk transfer address
2018-12-17T22:55:57.923088386Z 78 PC: 13abb | Find first file
2018-12-17T22:55:57.931212333Z 61 PC: 13ac6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:57.938996191Z 63 PC: 13ad2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.942353505Z 62 PC: 13b49 | Close file
2018-12-17T22:55:57.945943766Z 79 PC: 13abb | Find next file
2018-12-17T22:55:57.950165886Z 61 PC: 13ac6 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:57.957700865Z 63 PC: 13ad2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.961944236Z 62 PC: 13b49 | Close file
2018-12-17T22:55:57.964857193Z 79 PC: 13abb | Find next file
2018-12-17T22:55:57.968311619Z 61 PC: 13ac6 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:57.977129993Z 63 PC: 13ad2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:57.980562858Z 62 PC: 13b49 | Close file
2018-12-17T22:55:57.982891998Z 79 PC: 13abb | Find next file
2018-12-17T22:55:57.986100131Z 61 PC: 13ac6 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:57.994204602Z 63 PC: 13ad2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.001332556Z 62 PC: 13b00 | Close file
2018-12-17T22:55:58.003532162Z 67 PC: 13b0c | Get or set file attributes
2018-12-17T22:55:58.015576963Z 61 PC: 13b15 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:58.023632612Z 44 PC: 13b1a | Get time 0x13b1a: mov word ptr [bp + 0x22f], dx
0x13b1e: call 0x13b8e
0x13b21: mov ax, 0x5700
0x13b24: mov dx, word ptr [bp + 0x12b]
0x13b28: mov cx, word ptr [bp + 0x129]
0x13b2c: inc ax
0x13b2d: int 0x21
0x13b2f: mov ah, 0x3e
0x13b31: int 0x21
0x13b33: mov ax, 0x4300
0x13b36: lea dx, word ptr [bp + 0x29d]
0x13b3a: xor cx, cx
0x13b3c: inc ax
0x13b3d: mov cl, byte ptr [bp + 0x128]
0x13b41: int 0x21
0x13b43: jmp 0x13b4e
0x13b45: mov ah, 0x3e
0x13b47: int 0x21
0x13b49: mov ah, 0x4f
0x13b4b: jmp 0x13ab9
2018-12-17T22:55:58.026367064Z 66 PC: 13b9a | Move file pointer
2018-12-17T22:55:58.028740828Z 64 PC: 13bac | Write file or device (Write 383 bytes on handle 5)
2018-12-17T22:55:58.032547516Z 66 PC: 13bb5 | Move file pointer
2018-12-17T22:55:58.034324668Z 64 PC: 13bc0 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:58.03822364Z 87 PC: 13b2f | Get or set file date and time
2018-12-17T22:55:58.039922836Z 62 PC: 13b33 | Close file
2018-12-17T22:55:58.048170976Z 67 PC: 13b43 | Get or set file attributes
2018-12-17T22:55:58.059602043Z 26 PC: 13b55 | Set disk transfer address
2018-12-17T22:55:58.061547541Z 37 PC: 13b66 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.066057292Z 53 PC: 13812 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.067415796Z 37 PC: 13829 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.069346447Z 26 PC: 1383c | Set disk transfer address
2018-12-17T22:55:58.070639068Z 78 PC: 13847 | Find first file
2018-12-17T22:55:58.077115417Z 61 PC: 13852 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:58.085623596Z 63 PC: 1385e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.089520034Z 62 PC: 138d5 | Close file
2018-12-17T22:55:58.09156505Z 79 PC: 13847 | Find next file
2018-12-17T22:55:58.095406413Z 61 PC: 13852 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:58.103242439Z 63 PC: 1385e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.106486299Z 62 PC: 138d5 | Close file
2018-12-17T22:55:58.110923834Z 79 PC: 13847 | Find next file
2018-12-17T22:55:58.114282039Z 61 PC: 13852 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:58.121644254Z 63 PC: 1385e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.124990857Z 62 PC: 138d5 | Close file
2018-12-17T22:55:58.130078224Z 79 PC: 13847 | Find next file
2018-12-17T22:55:58.132964462Z 61 PC: 13852 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:58.139914952Z 63 PC: 1385e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.144187036Z 62 PC: 138d5 | Close file
2018-12-17T22:55:58.146723886Z 79 PC: 13847 | Find next file
2018-12-17T22:55:58.150178292Z 61 PC: 13852 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:58.159112293Z 63 PC: 1385e | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.167037856Z 62 PC: 1388c | Close file
2018-12-17T22:55:58.169525174Z 67 PC: 13898 | Get or set file attributes
2018-12-17T22:55:58.181333349Z 61 PC: 138a1 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:58.189227825Z 44 PC: 138a6 | Get time 0x138a6: mov word ptr [bp + 0x22f], dx
0x138aa: call 0x1391a
0x138ad: mov ax, 0x5700
0x138b0: mov dx, word ptr [bp + 0x12b]
0x138b4: mov cx, word ptr [bp + 0x129]
0x138b8: inc ax
0x138b9: int 0x21
0x138bb: mov ah, 0x3e
0x138bd: int 0x21
0x138bf: mov ax, 0x4300
0x138c2: lea dx, word ptr [bp + 0x29d]
0x138c6: xor cx, cx
0x138c8: inc ax
0x138c9: mov cl, byte ptr [bp + 0x128]
0x138cd: int 0x21
0x138cf: jmp 0x138da
0x138d1: mov ah, 0x3e
0x138d3: int 0x21
0x138d5: mov ah, 0x4f
0x138d7: jmp 0x13845
2018-12-17T22:55:58.19217642Z 66 PC: 13926 | Move file pointer
2018-12-17T22:55:58.194561605Z 64 PC: 13938 | Write file or device (Write 383 bytes on handle 5)
2018-12-17T22:55:58.198255963Z 66 PC: 13941 | Move file pointer
2018-12-17T22:55:58.199886439Z 64 PC: 1394c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:58.204460791Z 87 PC: 138bb | Get or set file date and time
2018-12-17T22:55:58.206351917Z 62 PC: 138bf | Close file
2018-12-17T22:55:58.214678736Z 67 PC: 138cf | Get or set file attributes
2018-12-17T22:55:58.225957636Z 26 PC: 138e1 | Set disk transfer address
2018-12-17T22:55:58.227932851Z 37 PC: 138f2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.232257673Z 53 PC: 135b5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.234100769Z 37 PC: 135cc | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.236338056Z 26 PC: 135df | Set disk transfer address
2018-12-17T22:55:58.237771251Z 78 PC: 135ea | Find first file
2018-12-17T22:55:58.244936576Z 61 PC: 135f5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:58.252556646Z 63 PC: 13601 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.255316656Z 62 PC: 13678 | Close file
2018-12-17T22:55:58.257230866Z 79 PC: 135ea | Find next file
2018-12-17T22:55:58.261676405Z 61 PC: 135f5 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:58.269073947Z 63 PC: 13601 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.272409319Z 62 PC: 13678 | Close file
2018-12-17T22:55:58.275849097Z 79 PC: 135ea | Find next file
2018-12-17T22:55:58.279334181Z 61 PC: 135f5 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:58.286773381Z 63 PC: 13601 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.290794492Z 62 PC: 13678 | Close file
2018-12-17T22:55:58.295429839Z 79 PC: 135ea | Find next file
2018-12-17T22:55:58.299289187Z 61 PC: 135f5 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:58.307359974Z 63 PC: 13601 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.310408958Z 62 PC: 13678 | Close file
2018-12-17T22:55:58.312444175Z 79 PC: 135ea | Find next file
2018-12-17T22:55:58.317811598Z 61 PC: 135f5 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:58.325360594Z 63 PC: 13601 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.328670689Z 62 PC: 13678 | Close file
2018-12-17T22:55:58.332040747Z 79 PC: 135ea | Find next file
2018-12-17T22:55:58.335497527Z 61 PC: 135f5 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:55:58.343563014Z 63 PC: 13601 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.353455477Z 62 PC: 1362f | Close file
2018-12-17T22:55:58.355917948Z 67 PC: 1363b | Get or set file attributes
2018-12-17T22:55:58.367512021Z 61 PC: 13644 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:55:58.376308673Z 44 PC: 13649 | Get time 0x13649: mov word ptr [bp + 0x22f], dx
0x1364d: call 0x136bd
0x13650: mov ax, 0x5700
0x13653: mov dx, word ptr [bp + 0x12b]
0x13657: mov cx, word ptr [bp + 0x129]
0x1365b: inc ax
0x1365c: int 0x21
0x1365e: mov ah, 0x3e
0x13660: int 0x21
0x13662: mov ax, 0x4300
0x13665: lea dx, word ptr [bp + 0x29d]
0x13669: xor cx, cx
0x1366b: inc ax
0x1366c: mov cl, byte ptr [bp + 0x128]
0x13670: int 0x21
0x13672: jmp 0x1367d
0x13674: mov ah, 0x3e
0x13676: int 0x21
0x13678: mov ah, 0x4f
0x1367a: jmp 0x135e8
2018-12-17T22:55:58.379773669Z 66 PC: 136c9 | Move file pointer
2018-12-17T22:55:58.381532045Z 64 PC: 136db | Write file or device (Write 383 bytes on handle 5)
2018-12-17T22:55:58.391713332Z 66 PC: 136e4 | Move file pointer
2018-12-17T22:55:58.393883332Z 64 PC: 136ef | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:58.401531836Z 87 PC: 1365e | Get or set file date and time
2018-12-17T22:55:58.404507231Z 62 PC: 13662 | Close file
2018-12-17T22:55:58.413192793Z 67 PC: 13672 | Get or set file attributes
2018-12-17T22:55:58.424207457Z 26 PC: 13684 | Set disk transfer address
2018-12-17T22:55:58.425712858Z 37 PC: 13695 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.430547289Z 53 PC: 13364 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.432203404Z 37 PC: 1337b | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.433791139Z 26 PC: 1338e | Set disk transfer address
2018-12-17T22:55:58.436552041Z 78 PC: 13399 | Find first file
2018-12-17T22:55:58.443263832Z 61 PC: 133a4 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:58.450590801Z 63 PC: 133b0 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.454211389Z 62 PC: 13427 | Close file
2018-12-17T22:55:58.456417238Z 79 PC: 13399 | Find next file
2018-12-17T22:55:58.460481791Z 61 PC: 133a4 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:58.468525127Z 63 PC: 133b0 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.471798743Z 62 PC: 13427 | Close file
2018-12-17T22:55:58.473772986Z 79 PC: 13399 | Find next file
2018-12-17T22:55:58.47756154Z 61 PC: 133a4 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:58.485709432Z 63 PC: 133b0 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.488499088Z 62 PC: 13427 | Close file
2018-12-17T22:55:58.491218462Z 79 PC: 13399 | Find next file
2018-12-17T22:55:58.494107705Z 61 PC: 133a4 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:58.501559779Z 63 PC: 133b0 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.504981273Z 62 PC: 13427 | Close file
2018-12-17T22:55:58.506921261Z 79 PC: 13399 | Find next file
2018-12-17T22:55:58.509804182Z 61 PC: 133a4 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:58.517573132Z 63 PC: 133b0 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.520368138Z 62 PC: 13427 | Close file
2018-12-17T22:55:58.522297436Z 79 PC: 13399 | Find next file
2018-12-17T22:55:58.525290976Z 61 PC: 133a4 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:55:58.533410214Z 63 PC: 133b0 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.536175103Z 62 PC: 13427 | Close file
2018-12-17T22:55:58.538127635Z 79 PC: 13399 | Find next file
2018-12-17T22:55:58.541572533Z 61 PC: 133a4 | Open file (Filename = 'PAH.COM')
2018-12-17T22:55:58.548535357Z 63 PC: 133b0 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.55587561Z 62 PC: 133de | Close file
2018-12-17T22:55:58.558847228Z 67 PC: 133ea | Get or set file attributes
2018-12-17T22:55:58.569425922Z 61 PC: 133f3 | Open file (Filename = 'PAH.COM')
2018-12-17T22:55:58.576466932Z 44 PC: 133f8 | Get time 0x133f8: mov word ptr [bp + 0x22f], dx
0x133fc: call 0x1346c
0x133ff: mov ax, 0x5700
0x13402: mov dx, word ptr [bp + 0x12b]
0x13406: mov cx, word ptr [bp + 0x129]
0x1340a: inc ax
0x1340b: int 0x21
0x1340d: mov ah, 0x3e
0x1340f: int 0x21
0x13411: mov ax, 0x4300
0x13414: lea dx, word ptr [bp + 0x29d]
0x13418: xor cx, cx
0x1341a: inc ax
0x1341b: mov cl, byte ptr [bp + 0x128]
0x1341f: int 0x21
0x13421: jmp 0x1342c
0x13423: mov ah, 0x3e
0x13425: int 0x21
0x13427: mov ah, 0x4f
0x13429: jmp 0x13397
2018-12-17T22:55:58.58006024Z 66 PC: 13478 | Move file pointer
2018-12-17T22:55:58.581645892Z 64 PC: 1348a | Write file or device (Write 383 bytes on handle 5)
2018-12-17T22:55:58.585136896Z 66 PC: 13493 | Move file pointer
2018-12-17T22:55:58.587668577Z 64 PC: 1349e | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:55:58.590592546Z 87 PC: 1340d | Get or set file date and time
2018-12-17T22:55:58.592299045Z 62 PC: 13411 | Close file
2018-12-17T22:55:58.601793379Z 67 PC: 13421 | Get or set file attributes
2018-12-17T22:55:58.613114969Z 26 PC: 13433 | Set disk transfer address
2018-12-17T22:55:58.615011175Z 37 PC: 13444 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.619442468Z 53 PC: 1311b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.620851438Z 37 PC: 13132 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.622184094Z 26 PC: 13145 | Set disk transfer address
2018-12-17T22:55:58.624503947Z 78 PC: 13150 | Find first file
2018-12-17T22:55:58.631182626Z 61 PC: 1315b | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:58.638621495Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.642603884Z 62 PC: 131de | Close file
2018-12-17T22:55:58.64461765Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.647513496Z 61 PC: 1315b | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:58.654433409Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.657942979Z 62 PC: 131de | Close file
2018-12-17T22:55:58.659897204Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.662800975Z 61 PC: 1315b | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:58.676324807Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.68321321Z 62 PC: 131de | Close file
2018-12-17T22:55:58.685248878Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.689480075Z 61 PC: 1315b | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:58.696654847Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.703868463Z 62 PC: 131de | Close file
2018-12-17T22:55:58.706764408Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.709817249Z 61 PC: 1315b | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:58.717043789Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.72521253Z 62 PC: 131de | Close file
2018-12-17T22:55:58.727103226Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.730765914Z 61 PC: 1315b | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:55:58.739215253Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.746349849Z 62 PC: 131de | Close file
2018-12-17T22:55:58.762666052Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.769719426Z 61 PC: 1315b | Open file (Filename = 'PAH.COM')
2018-12-17T22:55:58.776807906Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.783676853Z 62 PC: 131de | Close file
2018-12-17T22:55:58.787466229Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.790560387Z 61 PC: 1315b | Open file (Filename = 'TEST.COM')
2018-12-17T22:55:58.797588574Z 63 PC: 13167 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.805038954Z 62 PC: 131de | Close file
2018-12-17T22:55:58.806968734Z 79 PC: 13150 | Find next file
2018-12-17T22:55:58.810358308Z 26 PC: 131ea | Set disk transfer address
2018-12-17T22:55:58.812646301Z 37 PC: 131fb | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.815284562Z 53 PC: 12eda | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.816620915Z 37 PC: 12ef1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.818432702Z 26 PC: 12f04 | Set disk transfer address
2018-12-17T22:55:58.819747514Z 78 PC: 12f0f | Find first file
2018-12-17T22:55:58.826052201Z 61 PC: 12f1a | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:58.834129269Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.84123395Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.84371206Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.847447123Z 61 PC: 12f1a | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:58.85457068Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.861566675Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.864607314Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.868053915Z 61 PC: 12f1a | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:58.876197429Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.88285575Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.886100111Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.889372995Z 61 PC: 12f1a | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:58.897992535Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.901034425Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.903317028Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.907356935Z 61 PC: 12f1a | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:58.91458662Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.917624753Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.920537972Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.923649994Z 61 PC: 12f1a | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:55:58.930999274Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.935150872Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.937156163Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.941118073Z 61 PC: 12f1a | Open file (Filename = 'PAH.COM')
2018-12-17T22:55:58.950502561Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.954030785Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.957399259Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.961925452Z 61 PC: 12f1a | Open file (Filename = 'TEST.COM')
2018-12-17T22:55:58.969942668Z 63 PC: 12f26 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:58.97338928Z 62 PC: 12f9d | Close file
2018-12-17T22:55:58.976899651Z 79 PC: 12f0f | Find next file
2018-12-17T22:55:58.981332607Z 26 PC: 12fa9 | Set disk transfer address
2018-12-17T22:55:58.983105621Z 37 PC: 12fba | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.987075436Z 53 PC: 12ca6 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.989360824Z 37 PC: 12cbd | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:58.991266488Z 26 PC: 12cd0 | Set disk transfer address
2018-12-17T22:55:58.993890261Z 78 PC: 12cdb | Find first file
2018-12-17T22:55:59.003531763Z 61 PC: 12ce6 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:59.010525815Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.014425138Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.016768444Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.020062539Z 61 PC: 12ce6 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:59.028182448Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.032103382Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.034445857Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.038862041Z 61 PC: 12ce6 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:59.046003581Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.048892925Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.051833735Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.054842142Z 61 PC: 12ce6 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:59.06192414Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.066087589Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.068160437Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.07133158Z 61 PC: 12ce6 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:59.079383943Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.082728462Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.085234194Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.089953018Z 61 PC: 12ce6 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:55:59.097521841Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.100819352Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.104798616Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.109006579Z 61 PC: 12ce6 | Open file (Filename = 'PAH.COM')
2018-12-17T22:55:59.11636222Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.120324181Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.122542413Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.1256996Z 61 PC: 12ce6 | Open file (Filename = 'TEST.COM')
2018-12-17T22:55:59.134120264Z 63 PC: 12cf2 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.137224342Z 62 PC: 12d69 | Close file
2018-12-17T22:55:59.139452813Z 79 PC: 12cdb | Find next file
2018-12-17T22:55:59.143641048Z 26 PC: 12d75 | Set disk transfer address
2018-12-17T22:55:59.145557502Z 37 PC: 12d86 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:59.148024261Z 53 PC: 12a85 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:59.151059459Z 37 PC: 12a9c | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:55:59.152747433Z 26 PC: 12aaf | Set disk transfer address
2018-12-17T22:55:59.154338205Z 78 PC: 12aba | Find first file
2018-12-17T22:55:59.162210969Z 61 PC: 12ac5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:55:59.169612077Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.172703501Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.176223109Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.179441962Z 61 PC: 12ac5 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:55:59.188103721Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.191642535Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.194170249Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.197651967Z 61 PC: 12ac5 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:55:59.20917219Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.217877941Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.220805046Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.225062041Z 61 PC: 12ac5 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:55:59.233119894Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.237343676Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.242085904Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.245600915Z 61 PC: 12ac5 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:55:59.256894371Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.261105541Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.263401639Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.267819727Z 61 PC: 12ac5 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:55:59.279334581Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.28258859Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.286113879Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.293370034Z 61 PC: 12ac5 | Open file (Filename = 'PAH.COM')
2018-12-17T22:55:59.304911989Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.312555843Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.314760128Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.318819071Z 61 PC: 12ac5 | Open file (Filename = 'TEST.COM')
2018-12-17T22:55:59.330585979Z 63 PC: 12ad1 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:55:59.336369595Z 62 PC: 12b48 | Close file
2018-12-17T22:55:59.338994181Z 79 PC: 12aba | Find next file
2018-12-17T22:55:59.344473384Z 26 PC: 12b54 | Set disk transfer address
2018-12-17T22:55:59.346162651Z 37 PC: 12b65 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')