Sample viewer

vx.netlux.org/Virus.DOS.HWF.937

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:33.265522984Z 53 PC: 13c40 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:33.268003128Z 37 PC: 13c4d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:33.269877246Z 26 PC: 13c5b | Set disk transfer address
2018-12-17T22:56:33.272416349Z 71 PC: 13c64 | Get current directory
2018-12-17T22:56:33.275495611Z 53 PC: 13c6b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:56:33.2766914Z 37 PC: 13c74 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T22:56:33.277879728Z 25 PC: 13c85 | Get default drive
2018-12-17T22:56:33.278885455Z 14 PC: 13c92 | Set default drive (Drive = 'C')
2018-12-17T22:56:33.280266512Z 78 PC: 13d78 | Find first file
2018-12-17T22:56:33.285325231Z 78 PC: 13d78 | Find first file
2018-12-17T22:56:33.290387282Z 78 PC: 13d78 | Find first file
2018-12-17T22:56:33.295978835Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:33.301023101Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:33.642366493Z 61 PC: 13d95 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:56:33.649516139Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:33.651239547Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:33.654067361Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:33.656996098Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:33.658691512Z 62 PC: 13f06 | Close file
2018-12-17T22:56:33.665251107Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:33.674729791Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:33.677470701Z 14 PC: 13cac | Set default drive (Drive = 'A')
2018-12-17T22:56:33.67898828Z 78 PC: 13d78 | Find first file
2018-12-17T22:56:33.686205734Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:33.691956106Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:33.707291885Z 61 PC: 13d95 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:56:33.725562091Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:33.72760031Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:33.730523565Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:33.733234935Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:33.735758871Z 62 PC: 13f06 | Close file
2018-12-17T22:56:33.74285402Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:33.759064969Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:33.761950706Z 78 PC: 13d78 | Find first file
2018-12-17T22:56:33.7676673Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:33.773522616Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:33.783664869Z 61 PC: 13d95 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:33.790246689Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:33.791869197Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:33.799744094Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:33.801375769Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:33.803037964Z 62 PC: 13f06 | Close file
2018-12-17T22:56:33.813710752Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:33.823794006Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:33.826433813Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:33.832651248Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:33.842031562Z 61 PC: 13d95 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:56:33.848412446Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:33.852396055Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:33.858459122Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:33.859855792Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:33.862561615Z 62 PC: 13f06 | Close file
2018-12-17T22:56:33.871676933Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:33.883804019Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:33.887567882Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:33.892996772Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:33.902297652Z 61 PC: 13d95 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:56:33.909193289Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:33.911019756Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:33.917484793Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:33.920167672Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:33.921836963Z 62 PC: 13f06 | Close file
2018-12-17T22:56:33.928768326Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:33.942397667Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:33.945138665Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:33.956024983Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:33.969676887Z 61 PC: 13d95 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:56:33.976273939Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:33.977751579Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:33.984724405Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:33.986394805Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:33.987787611Z 62 PC: 13f06 | Close file
2018-12-17T22:56:33.994745313Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:34.004414156Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:34.00711599Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:34.017881547Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:34.027489455Z 61 PC: 13d95 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:56:34.034016543Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:34.035791044Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:34.042226119Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:34.043870418Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:34.045901593Z 62 PC: 13f06 | Close file
2018-12-17T22:56:34.052635298Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:34.062143907Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:34.064748347Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:34.075587876Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:34.088167168Z 61 PC: 13d95 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:56:34.094796408Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:34.097640162Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:34.103980287Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:34.105627378Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:34.108488169Z 62 PC: 13f06 | Close file
2018-12-17T22:56:34.115524705Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:34.125217689Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:34.129050692Z 67 PC: 13d82 | Get or set file attributes
2018-12-17T22:56:34.135220163Z 67 PC: 13d8d | Get or set file attributes
2018-12-17T22:56:34.147437116Z 61 PC: 13d95 | Open file (Filename = 'PAH.COM')
2018-12-17T22:56:34.15482771Z 87 PC: 13d9a | Get or set file date and time
2018-12-17T22:56:34.156528121Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:34.162890248Z 66 PC: 13dad | Move file pointer
2018-12-17T22:56:34.165202992Z 87 PC: 13f03 | Get or set file date and time
2018-12-17T22:56:34.167209114Z 62 PC: 13f06 | Close file
2018-12-17T22:56:34.174701985Z 67 PC: 13f0a | Get or set file attributes
2018-12-17T22:56:34.185057954Z 79 PC: 13d78 | Find next file
2018-12-17T22:56:34.187806194Z 59 PC: 13cd4 | Change current directory
2018-12-17T22:56:34.191714439Z 59 PC: 13ce2 | Change current directory
2018-12-17T22:56:34.200810301Z 37 PC: 13ce8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:34.202078147Z 26 PC: 13cf0 | Set disk transfer address
2018-12-17T22:56:34.203077215Z 42 PC: 13cf3 | Get date 0x13cf3: cmp cx, 0x7cb
0x13cf7: jb 0x13d15
0x13cf9: and dx, 0xf0f
0x13cfd: add dl, 8
0x13d00: cmp dh, dl
0x13d02: jne 0x13d15
0x13d04: cmp al, 3
0x13d06: ja 0x13d15
0x13d08: xor ax, ax
0x13d0a: int 0x10
0x13d0c: mov ah, 9
0x13d0e: lea dx, word ptr [bp + 0x26d]
0x13d12: int3
0x13d13: cli
0x13d14: hlt
0x13d15: cmp word ptr cs:[bp + 0x52a], -4
0x13d1b: je 0x13d45
0x13d1d: mov di, 0x100
0x13d20: lea si, word ptr [bp + 0x29f]
0x13d24: movsw word ptr es:[di], word ptr [si]
2018-12-17T22:56:34.205969708Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12262,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:21.285921325Z 53 PC: 13c40 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:21.288310629Z 37 PC: 13c4d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:21.289655876Z 26 PC: 13c5b | Set disk transfer address
2018-12-25T12:32:21.290985957Z 71 PC: 13c64 | Get current directory
2018-12-25T12:32:21.29471336Z 53 PC: 13c6b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:32:21.295991828Z 37 PC: 13c74 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T12:32:21.297113207Z 25 PC: 13c85 | Get default drive
2018-12-25T12:32:21.305568701Z 14 PC: 13c92 | Set default drive (Drive = 'C')
2018-12-25T12:32:21.306981825Z 78 PC: 13d78 | Find first file
2018-12-25T12:32:21.312798731Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:21.318330981Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:21.323817452Z 67 PC: 13d82 | Get or set file attributes
2018-12-25T12:32:21.329894094Z 67 PC: 13d8d | Get or set file attributes
2018-12-25T12:32:21.671187907Z 61 PC: 13d95 | Open file (Filename = 'COMMAND.COM')
2018-12-25T12:32:21.677312263Z 87 PC: 13d9a | Get or set file date and time
2018-12-25T12:32:21.679011782Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:32:21.681782939Z 66 PC: 13dad | Move file pointer
2018-12-25T12:32:21.691210666Z 87 PC: 13f03 | Get or set file date and time
2018-12-25T12:32:21.692969608Z 62 PC: 13f06 | Close file
2018-12-25T12:32:21.699940919Z 67 PC: 13f0a | Get or set file attributes
2018-12-25T12:32:21.709602255Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:21.711874157Z 14 PC: 13cac | Set default drive (Drive = 'A')
2018-12-25T12:32:21.712977978Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:21.719514247Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:21.725604817Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:21.741164387Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:21.748310401Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:21.749767692Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:21.752307583Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:21.754538628Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:21.756037542Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:21.762711914Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:21.773032873Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:21.775500436Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:21.779201841Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:21.783322858Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:21.789913551Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:21.796527695Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:21.798700322Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:21.805002693Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:21.806615954Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:21.808990875Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:21.816724996Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:21.828017117Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:21.831884145Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:21.837928049Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:21.847514198Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:21.854397321Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:21.856388282Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:21.86248962Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:21.864337394Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:21.866446718Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:21.871317586Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:21.877683184Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:21.880088356Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:21.883789186Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:21.8927195Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:21.900062805Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:21.901135198Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:21.907066337Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:21.909625893Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:21.911377719Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:21.91852204Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:21.934740385Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:21.945961413Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:21.963340855Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:21.974314507Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:21.992396604Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:21.994189632Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.001647437Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.003416543Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.00586786Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.017941547Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.028515113Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.0311358Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.037524735Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.048234987Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.055116353Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:22.057528731Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.063835715Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.065422402Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.067817582Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.075655765Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.088393887Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.09256729Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.098602358Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.108295018Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.11565263Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:22.117966225Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.124651364Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.125969386Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.127993849Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.391608487Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.427996579Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.432086587Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.43765291Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.447284364Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.451939454Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:22.452961765Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.457923399Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.4595975Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.460673073Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.466966066Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.480792624Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.482463526Z 59 PC: 13cd4 | Change current directory
2018-12-25T12:32:22.485056637Z 59 PC: 13ce2 | Change current directory
2018-12-25T12:32:22.49100376Z 37 PC: 13ce8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:22.491861833Z 26 PC: 13cf0 | Set disk transfer address
2018-12-25T12:32:22.492687644Z 42 PC: 13cf3 | Get date 0x13cf3: cmp cx, 0x7cb
0x13cf7: jb 0x13d15
0x13cf9: and dx, 0xf0f
0x13cfd: add dl, 8
0x13d00: cmp dh, dl
0x13d02: jne 0x13d15
0x13d04: cmp al, 3
0x13d06: ja 0x13d15
0x13d08: xor ax, ax
0x13d0a: int 0x10
0x13d0c: mov ah, 9
0x13d0e: lea dx, word ptr [bp + 0x26d]
0x13d12: int3
0x13d13: cli
0x13d14: hlt
0x13d15: cmp word ptr cs:[bp + 0x52a], -4
0x13d1b: je 0x13d45
0x13d1d: mov di, 0x100
0x13d20: lea si, word ptr [bp + 0x29f]
0x13d24: movsw word ptr es:[di], word ptr [si]
2018-12-25T12:32:22.494804103Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1995,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12262,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:21.334816164Z 53 PC: 13c40 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:21.336475706Z 37 PC: 13c4d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:21.337778724Z 26 PC: 13c5b | Set disk transfer address
2018-12-25T12:32:21.338832633Z 71 PC: 13c64 | Get current directory
2018-12-25T12:32:21.342358966Z 53 PC: 13c6b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:32:21.343565745Z 37 PC: 13c74 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T12:32:21.344691533Z 25 PC: 13c85 | Get default drive
2018-12-25T12:32:21.346090948Z 14 PC: 13c92 | Set default drive (Drive = 'C')
2018-12-25T12:32:21.347342676Z 78 PC: 13d78 | Find first file
2018-12-25T12:32:21.350891359Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:21.354390048Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:21.360374988Z 67 PC: 13d82 | Get or set file attributes
2018-12-25T12:32:21.365987126Z 67 PC: 13d8d | Get or set file attributes
2018-12-25T12:32:23.465531294Z 61 PC: 13d95 | Open file (Filename = 'COMMAND.COM')
2018-12-25T12:32:23.474572179Z 87 PC: 13d9a | Get or set file date and time
2018-12-25T12:32:23.47605742Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:32:23.478963226Z 66 PC: 13dad | Move file pointer
2018-12-25T12:32:23.481083493Z 87 PC: 13f03 | Get or set file date and time
2018-12-25T12:32:23.482998115Z 62 PC: 13f06 | Close file
2018-12-25T12:32:23.509954803Z 67 PC: 13f0a | Get or set file attributes
2018-12-25T12:32:23.52173197Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.524578777Z 14 PC: 13cac | Set default drive (Drive = 'A')
2018-12-25T12:32:23.526019334Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:23.533685286Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.539910773Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.557467252Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.565679776Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.567605709Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.570372145Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.571870686Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.577594783Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.585843956Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.597087558Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.60063889Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:23.607487016Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.613735605Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.625452234Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.638912562Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.640786945Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.648987101Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.650902533Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.652852558Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.661554633Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.672962485Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.676194333Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.682952107Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.694152477Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.701267026Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.702776923Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.711021548Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.713014786Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.715096996Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.72491747Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.735686395Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.738939501Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.746716471Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.758071554Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.765848222Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.768092114Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.775284017Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.776696042Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.779198388Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.78685944Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.797356976Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.800718717Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.806743463Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.81738609Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.825762491Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.82741717Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.8344071Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.836099766Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.83813726Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.845943715Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.856740159Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.860863263Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.867141223Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.878314328Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.891840881Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.895640834Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.902698412Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.905527939Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.907535234Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.915462857Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.932475247Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.935501513Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.942079185Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.954772154Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.962524972Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.964498763Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.972315119Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.974042208Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.975727472Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.983448818Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.995180213Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.998537699Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:24.005295791Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:24.0200656Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:24.027418046Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:24.028825223Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:24.03670922Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:24.038150636Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:24.039515562Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:24.048368524Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:24.059518448Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:24.062786826Z 59 PC: 13cd4 | Change current directory
2018-12-25T12:32:24.067730989Z 59 PC: 13ce2 | Change current directory
2018-12-25T12:32:24.078327925Z 37 PC: 13ce8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:24.079341207Z 26 PC: 13cf0 | Set disk transfer address
2018-12-25T12:32:24.08045334Z 42 PC: 13cf3 | Get date 0x13cf3: cmp cx, 0x7cb
0x13cf7: jb 0x13d15
0x13cf9: and dx, 0xf0f
0x13cfd: add dl, 8
0x13d00: cmp dh, dl
0x13d02: jne 0x13d15
0x13d04: cmp al, 3
0x13d06: ja 0x13d15
0x13d08: xor ax, ax
0x13d0a: int 0x10
0x13d0c: mov ah, 9
0x13d0e: lea dx, word ptr [bp + 0x26d]
0x13d12: int3
0x13d13: cli
0x13d14: hlt
0x13d15: cmp word ptr cs:[bp + 0x52a], -4
0x13d1b: je 0x13d45
0x13d1d: mov di, 0x100
0x13d20: lea si, word ptr [bp + 0x29f]
0x13d24: movsw word ptr es:[di], word ptr [si]
2018-12-25T12:32:24.083931328Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":16,"Month":8,"Year":1995,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12262,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:22.009469459Z 53 PC: 13c40 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:22.01164623Z 37 PC: 13c4d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:22.012838576Z 26 PC: 13c5b | Set disk transfer address
2018-12-25T12:32:22.014064062Z 71 PC: 13c64 | Get current directory
2018-12-25T12:32:22.017678597Z 53 PC: 13c6b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:32:22.01886082Z 37 PC: 13c74 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T12:32:22.019784491Z 25 PC: 13c85 | Get default drive
2018-12-25T12:32:22.020888945Z 14 PC: 13c92 | Set default drive (Drive = 'C')
2018-12-25T12:32:22.02376949Z 78 PC: 13d78 | Find first file
2018-12-25T12:32:22.029534199Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:22.035158112Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:22.040870577Z 67 PC: 13d82 | Get or set file attributes
2018-12-25T12:32:22.046369924Z 67 PC: 13d8d | Get or set file attributes
2018-12-25T12:32:23.511316362Z 61 PC: 13d95 | Open file (Filename = 'COMMAND.COM')
2018-12-25T12:32:23.519241314Z 87 PC: 13d9a | Get or set file date and time
2018-12-25T12:32:23.522136162Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:32:23.525212593Z 66 PC: 13dad | Move file pointer
2018-12-25T12:32:23.527234486Z 87 PC: 13f03 | Get or set file date and time
2018-12-25T12:32:23.52955838Z 62 PC: 13f06 | Close file
2018-12-25T12:32:23.536719414Z 67 PC: 13f0a | Get or set file attributes
2018-12-25T12:32:23.547412852Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.550342912Z 14 PC: 13cac | Set default drive (Drive = 'A')
2018-12-25T12:32:23.552623572Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:23.559809353Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.566936152Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.585171231Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.593518925Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.595433609Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.59825297Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.600470159Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.602439998Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.610586069Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.621974666Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.624742514Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:23.631322746Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.637556954Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.649086994Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.656464525Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.657971167Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.665621711Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.667517634Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.67003144Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.681688551Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.693063455Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.695855567Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.702752757Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.713764079Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.72162566Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.724067669Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.731440203Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.733144369Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.735153441Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.743544687Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.757728563Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.760860914Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.767757714Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.778624133Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.786375354Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.789019535Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.796460483Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.798353176Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.804694249Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.812844229Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.826866078Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.830617485Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.837336525Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.848379231Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.855778974Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.857330802Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.876391084Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.87819735Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.880426798Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.890289067Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.901207675Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.905764899Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.912098549Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.922709249Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.930789658Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.932790727Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.939734286Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.941860656Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.944147672Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.955306658Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.967839277Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.970744403Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.976994113Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.988412084Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.997073455Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.999031288Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:24.006618068Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:24.008520375Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:24.010114448Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:24.021361603Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:24.033014047Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:24.036443643Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:24.043358604Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:24.054445597Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:24.061965972Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:24.063562731Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:24.071862414Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:24.073490369Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:24.074966033Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:24.084476118Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:24.095655316Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:24.098832816Z 59 PC: 13cd4 | Change current directory
2018-12-25T12:32:24.104015457Z 59 PC: 13ce2 | Change current directory
2018-12-25T12:32:24.108968324Z 37 PC: 13ce8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:24.111006884Z 26 PC: 13cf0 | Set disk transfer address
2018-12-25T12:32:24.112454255Z 42 PC: 13cf3 | Get date 0x13cf3: cmp cx, 0x7cb
0x13cf7: jb 0x13d15
0x13cf9: and dx, 0xf0f
0x13cfd: add dl, 8
0x13d00: cmp dh, dl
0x13d02: jne 0x13d15
0x13d04: cmp al, 3
0x13d06: ja 0x13d15
0x13d08: xor ax, ax
0x13d0a: int 0x10
0x13d0c: mov ah, 9
0x13d0e: lea dx, word ptr [bp + 0x26d]
0x13d12: int3
0x13d13: cli
0x13d14: hlt
0x13d15: cmp word ptr cs:[bp + 0x52a], -4
0x13d1b: je 0x13d45
0x13d1d: mov di, 0x100
0x13d20: lea si, word ptr [bp + 0x29f]
0x13d24: movsw word ptr es:[di], word ptr [si]
2018-12-25T12:32:24.125128469Z 9 PC: 13d13 | Display string (Could not find end pointer)

{"DateBased":true,"Day":1,"Month":9,"Year":1995,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12262,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:22.059611104Z 53 PC: 13c40 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:22.061827024Z 37 PC: 13c4d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:22.063453196Z 26 PC: 13c5b | Set disk transfer address
2018-12-25T12:32:22.064891743Z 71 PC: 13c64 | Get current directory
2018-12-25T12:32:22.069348959Z 53 PC: 13c6b | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:32:22.070887594Z 37 PC: 13c74 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T12:32:22.07237883Z 25 PC: 13c85 | Get default drive
2018-12-25T12:32:22.074548768Z 14 PC: 13c92 | Set default drive (Drive = 'C')
2018-12-25T12:32:22.076187743Z 78 PC: 13d78 | Find first file
2018-12-25T12:32:22.085509023Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:22.091582688Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:22.097171294Z 67 PC: 13d82 | Get or set file attributes
2018-12-25T12:32:22.10259069Z 67 PC: 13d8d | Get or set file attributes
2018-12-25T12:32:22.429354815Z 61 PC: 13d95 | Open file (Filename = 'COMMAND.COM')
2018-12-25T12:32:22.436903586Z 87 PC: 13d9a | Get or set file date and time
2018-12-25T12:32:22.438376551Z 63 PC: 13da6 | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:32:22.442132943Z 66 PC: 13dad | Move file pointer
2018-12-25T12:32:22.443654028Z 87 PC: 13f03 | Get or set file date and time
2018-12-25T12:32:22.445188654Z 62 PC: 13f06 | Close file
2018-12-25T12:32:22.456375568Z 67 PC: 13f0a | Get or set file attributes
2018-12-25T12:32:22.469666561Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.4743185Z 14 PC: 13cac | Set default drive (Drive = 'A')
2018-12-25T12:32:22.476307524Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:22.481611444Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.48757878Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.762772251Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.769710469Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:22.771115221Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.773770679Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.776515814Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.778791923Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.785827337Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.796051967Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.798740231Z 78 PC: 13d78 | Find first file (See above)
2018-12-25T12:32:22.804815118Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.810674647Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.820151991Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.826831051Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:22.829063467Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.835598755Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.837311334Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.839341729Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.848374105Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.861009377Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.864211217Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.869991747Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.879515464Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.888068088Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:22.890315993Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.896567092Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.898990273Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.900833431Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.907833325Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.920480275Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.923336758Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.929484499Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.936125353Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.943065093Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:22.944231929Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:22.949285501Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:22.950463109Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:22.952005847Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:22.960089834Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:22.969699401Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:22.972520104Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:22.978993141Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:22.991450401Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:22.998089983Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.000518155Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.007132067Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.008482238Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.010618711Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.017490492Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.026975154Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.030521858Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.036768756Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.04924481Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.06110497Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.062950994Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.069057502Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.070574229Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.073058284Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.080025083Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.089566857Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.092858364Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.098366677Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.107897097Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.120348853Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.121752104Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.127918513Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.130244872Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.131725524Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.138433846Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.149322486Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.152339565Z 67 PC: 13d82 | Get or set file attributes (See above)
2018-12-25T12:32:23.158767678Z 67 PC: 13d8d | Get or set file attributes (See above)
2018-12-25T12:32:23.169438233Z 61 PC: 13d95 | Open file (See above)
2018-12-25T12:32:23.180917743Z 87 PC: 13d9a | Get or set file date and time (See above)
2018-12-25T12:32:23.182684964Z 63 PC: 13da6 | Read file or device (See above)
2018-12-25T12:32:23.190921643Z 66 PC: 13dad | Move file pointer (See above)
2018-12-25T12:32:23.192579965Z 87 PC: 13f03 | Get or set file date and time (See above)
2018-12-25T12:32:23.194283842Z 62 PC: 13f06 | Close file (See above)
2018-12-25T12:32:23.202802336Z 67 PC: 13f0a | Get or set file attributes (See above)
2018-12-25T12:32:23.212712059Z 79 PC: 13d78 | Find next file (See above)
2018-12-25T12:32:23.215514733Z 59 PC: 13cd4 | Change current directory
2018-12-25T12:32:23.220609689Z 59 PC: 13ce2 | Change current directory
2018-12-25T12:32:23.224847187Z 37 PC: 13ce8 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:23.225983273Z 26 PC: 13cf0 | Set disk transfer address
2018-12-25T12:32:23.227844841Z 42 PC: 13cf3 | Get date 0x13cf3: cmp cx, 0x7cb
0x13cf7: jb 0x13d15
0x13cf9: and dx, 0xf0f
0x13cfd: add dl, 8
0x13d00: cmp dh, dl
0x13d02: jne 0x13d15
0x13d04: cmp al, 3
0x13d06: ja 0x13d15
0x13d08: xor ax, ax
0x13d0a: int 0x10
0x13d0c: mov ah, 9
0x13d0e: lea dx, word ptr [bp + 0x26d]
0x13d12: int3
0x13d13: cli
0x13d14: hlt
0x13d15: cmp word ptr cs:[bp + 0x52a], -4
0x13d1b: je 0x13d45
0x13d1d: mov di, 0x100
0x13d20: lea si, word ptr [bp + 0x29f]
0x13d24: movsw word ptr es:[di], word ptr [si]
2018-12-25T12:32:23.230215524Z 76 PC: 12a45 | Terminate with return code (Return code = '0')