Sample viewer

vx.netlux.org/Virus.DOS.IVP.Messenger.449

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:56:59.395262466Z 26 PC: 12b69 | Set disk transfer address
2018-12-17T22:56:59.397612928Z 53 PC: 12a68 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:59.398739166Z 37 PC: 12a7a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:56:59.39978537Z 71 PC: 12a86 | Get current directory
2018-12-17T22:56:59.403148075Z 78 PC: 12ac1 | Find first file
2018-12-17T22:56:59.409287019Z 61 PC: 12b72 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:59.416064228Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:59.423142686Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.424934884Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.441694071Z 61 PC: 12b72 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:56:59.453309727Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:59.460225386Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.461677435Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.463999581Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 5)
2018-12-17T22:56:59.472434258Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.473626762Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.478498434Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.489549545Z 79 PC: 12ac1 | Find next file
2018-12-17T22:56:59.491840493Z 61 PC: 12b72 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:56:59.495847502Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:59.50072558Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.503386917Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.514484645Z 61 PC: 12b72 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:56:59.528603228Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:59.536805696Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.538187545Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.542497896Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 5)
2018-12-17T22:56:59.545917659Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.548040627Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.556411597Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.573805116Z 79 PC: 12ac1 | Find next file
2018-12-17T22:56:59.576859287Z 61 PC: 12b72 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:56:59.584463481Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:59.591269061Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.593080951Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.603303982Z 61 PC: 12b72 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:56:59.609987329Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:59.612672881Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.614019999Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.617301993Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 5)
2018-12-17T22:56:59.625825138Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.62731867Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.638807505Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.64972056Z 79 PC: 12ac1 | Find next file
2018-12-17T22:56:59.652578811Z 61 PC: 12b72 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:56:59.659957886Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:59.666331691Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.668497959Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.679895622Z 61 PC: 12b72 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:56:59.687258201Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:56:59.690424165Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.692368896Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.696043531Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 5)
2018-12-17T22:56:59.698873783Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.70034124Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.70899254Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.723970017Z 79 PC: 12ac1 | Find next file
2018-12-17T22:56:59.727312188Z 61 PC: 12b72 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:56:59.734878723Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:56:59.741734807Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.743809234Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.749009269Z 61 PC: 12b72 | Open file (Filename = 'PRINTA~1.COM�')
2018-12-17T22:56:59.754863874Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:56:59.757807861Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.760009119Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.762363042Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 2)
2018-12-17T22:56:59.770819942Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.773184878Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.775409805Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.77999235Z 79 PC: 12ac1 | Find next file
2018-12-17T22:56:59.783934238Z 61 PC: 12b72 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:56:59.790367646Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 2)
2018-12-17T22:56:59.796980497Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.799351207Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.816486659Z 61 PC: 12b72 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:56:59.823295799Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:56:59.830231536Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.832899246Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.835669381Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 2)
2018-12-17T22:56:59.844091362Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.846279012Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.854605031Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.865277625Z 79 PC: 12ac1 | Find next file
2018-12-17T22:56:59.86898842Z 61 PC: 12b72 | Open file (Filename = 'PAH.COM')
2018-12-17T22:56:59.876508621Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 2)
2018-12-17T22:56:59.882762176Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.884899408Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.895037198Z 61 PC: 12b72 | Open file (Filename = 'PAH.COM')
2018-12-17T22:56:59.901942811Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:56:59.905970249Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.907648417Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.910331726Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 2)
2018-12-17T22:56:59.91427655Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.915820247Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.92442892Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.935029585Z 79 PC: 12ac1 | Find next file
2018-12-17T22:56:59.938294964Z 61 PC: 12b72 | Open file (Filename = 'TEST.COM')
2018-12-17T22:56:59.944497701Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 2)
2018-12-17T22:56:59.951307327Z 62 PC: 12ae0 | Close file
2018-12-17T22:56:59.95307139Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:56:59.96272Z 61 PC: 12b72 | Open file (Filename = 'TEST.COM')
2018-12-17T22:56:59.970027322Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:56:59.972692945Z 66 PC: 12b64 | Move file pointer
2018-12-17T22:56:59.973994112Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-17T22:56:59.976467431Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 2)
2018-12-17T22:56:59.985715347Z 87 PC: 12b4d | Get or set file date and time
2018-12-17T22:56:59.987170995Z 62 PC: 12b51 | Close file
2018-12-17T22:56:59.994843077Z 67 PC: 12b7d | Get or set file attributes
2018-12-17T22:57:00.005871126Z 79 PC: 12ac1 | Find next file
2018-12-17T22:57:00.00868836Z 59 PC: 12a95 | Change current directory
2018-12-17T22:57:00.012760082Z 9 PC: 12a9f | Display string (String= 'Distruction Messenger From Hell [IVP] ')
2018-12-17T22:57:00.02145244Z 37 PC: 12aa9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:00.022991262Z 59 PC: 12ab3 | Change current directory
2018-12-17T22:57:00.029733314Z 26 PC: 12b69 | Set disk transfer address

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":12410,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:54.034835537Z 26 PC: 12b69 | Set disk transfer address
2018-12-25T12:32:54.036541615Z 53 PC: 12a68 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:54.037728567Z 37 PC: 12a7a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:54.038866488Z 71 PC: 12a86 | Get current directory
2018-12-25T12:32:54.04270033Z 78 PC: 12ac1 | Find first file
2018-12-25T12:32:54.049683Z 61 PC: 12b72 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:54.053916152Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:32:54.058376275Z 62 PC: 12ae0 | Close file
2018-12-25T12:32:54.060629255Z 67 PC: 12b7d | Get or set file attributes
2018-12-25T12:32:54.195579675Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.212116784Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:54.220136354Z 66 PC: 12b64 | Move file pointer
2018-12-25T12:32:54.221748809Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-25T12:32:54.224476148Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 5)
2018-12-25T12:32:54.233795013Z 87 PC: 12b4d | Get or set file date and time
2018-12-25T12:32:54.23531991Z 62 PC: 12b51 | Close file
2018-12-25T12:32:54.262776729Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.27418434Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.277050475Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.284889643Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.292562936Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.294551182Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.305522824Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.314545478Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.317766155Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.319756726Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.323561465Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.326850397Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.328363189Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.337739712Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.349048896Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.351852715Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.359312368Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.36668868Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.36858688Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.379846913Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.387435116Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.390388548Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.392114487Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.395763247Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.405819359Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.407338615Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.417050028Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.427886957Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.430794724Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.440054953Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.447613082Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.450136418Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.462848568Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.470321039Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.47246265Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.473967205Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.476221625Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.478342709Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.479622532Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.48524723Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.494004818Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.496784091Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.505837432Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.51302128Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.515219536Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.521492589Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.526880093Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.530319486Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.532961189Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.535979299Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.551796489Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.554428374Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.557081289Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.560219814Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.563751056Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.573618341Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.588700844Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.591234689Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.604805671Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.612263405Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.615411432Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.618094292Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.620676703Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.626329915Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.628829358Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.637894138Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.645040144Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.649047783Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.657110895Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.664474204Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.666988233Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.680883885Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.685445485Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.690417025Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.69204214Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.693868289Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.696015221Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.69771967Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.702945745Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.709383589Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.712976396Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.720108916Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.726879607Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.729219865Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.743313454Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.751373047Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.760299269Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.762061008Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.764725437Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.775369227Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.777055431Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.785848042Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.797158844Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.801412217Z 59 PC: 12a95 | Change current directory
2018-12-25T12:32:54.805927047Z 9 PC: 12a9f | Display string (String= 'Distruction Messenger From Hell [IVP] ')
2018-12-25T12:32:54.813439091Z 37 PC: 12aa9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:54.81546034Z 59 PC: 12ab3 | Change current directory
2018-12-25T12:32:54.817312284Z 26 PC: 12b69 | Set disk transfer address (See above)

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":12410,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:54.205963892Z 26 PC: 12b69 | Set disk transfer address
2018-12-25T12:32:54.207915242Z 53 PC: 12a68 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:54.210423856Z 37 PC: 12a7a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:54.211604055Z 71 PC: 12a86 | Get current directory
2018-12-25T12:32:54.214880871Z 78 PC: 12ac1 | Find first file
2018-12-25T12:32:54.222510344Z 61 PC: 12b72 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:54.229816191Z 63 PC: 12adc | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:32:54.236945728Z 62 PC: 12ae0 | Close file
2018-12-25T12:32:54.239709947Z 67 PC: 12b7d | Get or set file attributes
2018-12-25T12:32:54.257682948Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.270992633Z 64 PC: 12b26 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:54.279389226Z 66 PC: 12b64 | Move file pointer
2018-12-25T12:32:54.281026555Z 44 PC: 12b31 | Get time 0x12b31: cmp dh, 0
0x12b34: je 0x12b2d
0x12b36: mov byte ptr cs:[bp + 0x2c3], dh
0x12b3b: call 0x12bb7
0x12b3e: mov ax, 0x5701
0x12b41: mov cx, word ptr cs:[bp + 0x336]
0x12b46: mov dx, word ptr cs:[bp + 0x338]
0x12b4b: int 0x21
0x12b4d: mov ah, 0x3e
0x12b4f: int 0x21
0x12b51: xor cx, cx
0x12b53: mov cl, byte ptr cs:[bp + 0x335]
0x12b58: call 0x12b74
0x12b5b: ret
0x12b5c: mov ah, 0x42
0x12b5e: xor cx, cx
0x12b60: xor dx, dx
0x12b62: int 0x21
0x12b64: ret
0x12b65: mov ah, 0x1a
2018-12-25T12:32:54.283998664Z 64 PC: 12c14 | Write file or device (Write 449 bytes on handle 5)
2018-12-25T12:32:54.293184611Z 87 PC: 12b4d | Get or set file date and time
2018-12-25T12:32:54.301648567Z 62 PC: 12b51 | Close file
2018-12-25T12:32:54.310096552Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.320739359Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.324629719Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.3316512Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.338922618Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.34148413Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.352712595Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.360486504Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.365125642Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.373860842Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.376807702Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.381088776Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.383270978Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.391459677Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.403657168Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.406818298Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.414729472Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.422375276Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.425065583Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.436805165Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.444889472Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.449125193Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.455025115Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.460363888Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.470727305Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.472786076Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.482211994Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.494057471Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.497198732Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.504506687Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.512485794Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.515050024Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.527025776Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.536975309Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.541703954Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.548872724Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.554543842Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.558702011Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.560817919Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.570083795Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.590816616Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.594170928Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.601731886Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.610673248Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.613149818Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.617963692Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.622449488Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.624384283Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.625469181Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.627688953Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.633848383Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.635034464Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.636885886Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.639926756Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.641911379Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.647200637Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.654482629Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.65697223Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.668582058Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.676947663Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.684400015Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.686332474Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.690054991Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.699358336Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.701467899Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.710484793Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.721334885Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.723934134Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.731682527Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.739247035Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.741267935Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.753171136Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.76098372Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.764502802Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.766677362Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.770587943Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.774222705Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.776269377Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.78884153Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.800081694Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.803380215Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.812648406Z 63 PC: 12adc | Read file or device (See above)
2018-12-25T12:32:54.819570612Z 62 PC: 12ae0 | Close file (See above)
2018-12-25T12:32:54.821518815Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.833130861Z 61 PC: 12b72 | Open file (See above)
2018-12-25T12:32:54.840615296Z 64 PC: 12b26 | Write file or device (See above)
2018-12-25T12:32:54.843664086Z 66 PC: 12b64 | Move file pointer (See above)
2018-12-25T12:32:54.845880258Z 44 PC: 12b31 | Get time (See above)
2018-12-25T12:32:54.848631217Z 64 PC: 12c14 | Write file or device (See above)
2018-12-25T12:32:54.858829429Z 87 PC: 12b4d | Get or set file date and time (See above)
2018-12-25T12:32:54.860639534Z 62 PC: 12b51 | Close file (See above)
2018-12-25T12:32:54.871242993Z 67 PC: 12b7d | Get or set file attributes (See above)
2018-12-25T12:32:54.882244564Z 79 PC: 12ac1 | Find next file (See above)
2018-12-25T12:32:54.884886825Z 59 PC: 12a95 | Change current directory
2018-12-25T12:32:54.893892993Z 9 PC: 12a9f | Display string (String= 'Distruction Messenger From Hell [IVP] ')
2018-12-25T12:32:54.902614262Z 37 PC: 12aa9 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:54.904488009Z 59 PC: 12ab3 | Change current directory
2018-12-25T12:32:54.907447699Z 26 PC: 12b69 | Set disk transfer address (See above)