Sample viewer

vx.netlux.org/Virus.DOS.Flue.1179

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:09.766546171Z 71 PC: 12a7f | Get current directory
2018-12-17T22:56:09.770004535Z 47 PC: 12a83 | Get disk transfer address
2018-12-17T22:56:09.772211186Z 53 PC: 12a8a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:09.773551263Z 37 PC: 12a9f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:09.774580384Z 26 PC: 12ab3 | Set disk transfer address
2018-12-17T22:56:09.776147058Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:09.77865613Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add byte ptr [bx + si], al
0x12d91: add bl, ch
0x12d93: adc byte ptr [bx + si - 0x217], dl
2018-12-17T22:56:09.781174137Z 78 PC: 12aff | Find first file
2018-12-17T22:56:09.787982424Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:09.814254784Z 61 PC: 12b23 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:09.821657986Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:09.828802636Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:09.831741202Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:09.833689345Z 62 PC: 12add | Close file
2018-12-17T22:56:09.844251542Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:09.858108169Z 79 PC: 12aff | Find next file
2018-12-17T22:56:09.861226728Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:09.872370189Z 61 PC: 12b23 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:56:09.88078249Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:09.887976767Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:09.889933847Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:09.892224408Z 62 PC: 12add | Close file
2018-12-17T22:56:09.900979616Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:09.914715656Z 79 PC: 12aff | Find next file
2018-12-17T22:56:09.917416484Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:09.928362425Z 61 PC: 12b23 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:56:09.93542977Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:09.942457033Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:09.944803436Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:09.946575156Z 62 PC: 12add | Close file
2018-12-17T22:56:09.954595564Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:09.965935088Z 79 PC: 12aff | Find next file
2018-12-17T22:56:09.968849143Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:09.983219851Z 61 PC: 12b23 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:56:09.991214965Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:09.998667418Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:10.000393061Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:10.002911242Z 62 PC: 12add | Close file
2018-12-17T22:56:10.010850456Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:10.021581342Z 79 PC: 12aff | Find next file
2018-12-17T22:56:10.024932615Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:10.035594106Z 61 PC: 12b23 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:56:10.043542286Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:10.051864126Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:10.053531178Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:10.055220999Z 62 PC: 12add | Close file
2018-12-17T22:56:10.062895704Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:10.074634528Z 79 PC: 12aff | Find next file
2018-12-17T22:56:10.077937037Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:10.089105297Z 61 PC: 12b23 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:56:10.09736833Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:10.105358201Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:10.107579683Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.110988803Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x800
0x12d92: fninit
0x12d94: mov ah, 0xe9
0x12d96: add dword ptr [bp + si], bp
2018-12-17T22:56:10.113478157Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.116075192Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x800
0x12d92: fninit
0x12d94: mov ah, 0xe9
0x12d96: add dword ptr [bp + si], bp
2018-12-17T22:56:10.119323821Z 64 PC: 12b7b | Write file or device (Write 846 bytes on handle 5)
2018-12-17T22:56:10.129148189Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:10.131042445Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.134532687Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x800
0x12d92: fninit
0x12d94: mov ah, 0xe9
0x12d96: inc ax
2018-12-17T22:56:10.137417436Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.139801758Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x800
0x12d92: fninit
0x12d94: mov ah, 0xe9
0x12d96: inc ax
2018-12-17T22:56:10.142430705Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.146017441Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x800
0x12d92: fninit
0x12d94: mov ah, 0xe9
0x12d96: inc ax
2018-12-17T22:56:10.148823358Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.15165741Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x800
0x12d92: fninit
0x12d94: mov ah, 0xe9
0x12d96: inc ax
2018-12-17T22:56:10.155740905Z 64 PC: 12f05 | Write file or device (Write 1179 bytes on handle 5)
2018-12-17T22:56:10.166044739Z 66 PC: 12cba | Move file pointer
2018-12-17T22:56:10.16831095Z 64 PC: 12cc5 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:10.178773609Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:10.18139439Z 62 PC: 12add | Close file
2018-12-17T22:56:10.192451184Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:10.205589843Z 79 PC: 12aff | Find next file
2018-12-17T22:56:10.20938997Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:10.221557137Z 61 PC: 12b23 | Open file (Filename = 'PAH.COM')
2018-12-17T22:56:10.230384151Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:10.238778467Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:10.240418417Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:10.242359564Z 62 PC: 12add | Close file
2018-12-17T22:56:10.251005206Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:10.26193212Z 79 PC: 12aff | Find next file
2018-12-17T22:56:10.264822219Z 67 PC: 12b1e | Get or set file attributes
2018-12-17T22:56:10.276695039Z 61 PC: 12b23 | Open file (Filename = 'TEST.COM')
2018-12-17T22:56:10.285209052Z 63 PC: 12b41 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:56:10.292774543Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:10.295862245Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.299271514Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x700
0x12d92: in al, 0x40
0x12d94: xchg cl, ch
0x12d96: stosw word ptr es:[di], ax
2018-12-17T22:56:10.302262526Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.306760015Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x700
0x12d92: in al, 0x40
0x12d94: xchg cl, ch
0x12d96: stosw word ptr es:[di], ax
2018-12-17T22:56:10.31001595Z 64 PC: 12b7b | Write file or device (Write 332 bytes on handle 5)
2018-12-17T22:56:10.318104126Z 66 PC: 12d50 | Move file pointer
2018-12-17T22:56:10.320023192Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.322795133Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x700
0x12d92: in al, 0x40
0x12d94: xchg cl, ch
0x12d96: test word ptr [di], 0x2e2a
2018-12-17T22:56:10.325415442Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.32821968Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x700
0x12d92: in al, 0x40
0x12d94: xchg cl, ch
0x12d96: test word ptr [di], 0x2e2a
2018-12-17T22:56:10.331561742Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.334032378Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x700
0x12d92: in al, 0x40
0x12d94: xchg cl, ch
0x12d96: test word ptr [di], 0x2e2a
2018-12-17T22:56:10.336681342Z 44 PC: 12d6e | Get time 0x12d6e: xchg dl, ch
0x12d70: nop
0x12d71: mov ah, 0x2c
0x12d73: int 0x21
0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
2018-12-17T22:56:10.341263908Z 44 PC: 12d75 | Get time 0x12d75: xchg dl, cl
0x12d77: in al, 0x40
0x12d79: xchg al, ah
0x12d7b: in al, 0x40
0x12d7d: xor ax, cx
0x12d7f: ret
0x12d80: mov cx, 9
0x12d83: pop ax
0x12d84: loop 0x12d83
0x12d86: pop bp
0x12d87: pop ds
0x12d88: pop es
0x12d89: pop dx
0x12d8a: pop ds
0x12d8b: popf
0x12d8c: jmp 0x12cf1
0x12d8f: add ax, 0x700
0x12d92: in al, 0x40
0x12d94: xchg cl, ch
0x12d96: test word ptr [di], 0x2e2a
2018-12-17T22:56:10.345844096Z 64 PC: 12f05 | Write file or device (Write 1179 bytes on handle 5)
2018-12-17T22:56:10.355994897Z 66 PC: 12cba | Move file pointer
2018-12-17T22:56:10.358600356Z 64 PC: 12cc5 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:10.36368739Z 87 PC: 12ad9 | Get or set file date and time
2018-12-17T22:56:10.36577796Z 62 PC: 12add | Close file
2018-12-17T22:56:10.375532426Z 67 PC: 12aed | Get or set file attributes
2018-12-17T22:56:10.387572147Z 79 PC: 12aff | Find next file
2018-12-17T22:56:10.390677645Z 59 PC: 12b0e | Change current directory
2018-12-17T22:56:10.396144906Z 37 PC: 12eff | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:10.398566871Z 26 PC: 12f05 | Set disk transfer address
2018-12-17T22:56:10.400184599Z 59 PC: 12f0f | Change current directory