Sample viewer

vx.netlux.org/Virus.DOS.IronMaiden

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:04.040174338Z 26 PC: 12abd | Set disk transfer address
2018-12-17T22:57:04.041644902Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:04.042745207Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:04.043756649Z 25 PC: 12af4 | Get default drive
2018-12-17T22:57:04.045351147Z 78 PC: 12b11 | Find first file
2018-12-17T22:57:04.051060972Z 67 PC: 12b2d | Get or set file attributes
2018-12-17T22:57:04.05638662Z 67 PC: 12b38 | Get or set file attributes
2018-12-17T22:57:04.235225815Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:57:04.242003847Z 87 PC: 12b5a | Get or set file date and time
2018-12-17T22:57:04.243232429Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:04.249754893Z 66 PC: 12b88 | Move file pointer
2018-12-17T22:57:04.251171184Z 66 PC: 12ba4 | Move file pointer
2018-12-17T22:57:04.252411681Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:57:04.254760209Z 66 PC: 12bd1 | Move file pointer
2018-12-17T22:57:04.256937633Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-17T22:57:04.265148036Z 66 PC: 12bff | Move file pointer
2018-12-17T22:57:04.266431154Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:57:04.274235179Z 87 PC: 12c36 | Get or set file date and time
2018-12-17T22:57:04.275780639Z 62 PC: 12c3a | Close file
2018-12-17T22:57:04.281028332Z 67 PC: 12c48 | Get or set file attributes
2018-12-17T22:57:04.28886447Z 79 PC: 12b1c | Find next file
2018-12-17T22:57:04.290735343Z 67 PC: 12b2d | Get or set file attributes
2018-12-17T22:57:04.294414198Z 67 PC: 12b38 | Get or set file attributes
2018-12-17T22:57:04.314576884Z 61 PC: 12b46 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:57:04.322158304Z 87 PC: 12b5a | Get or set file date and time
2018-12-17T22:57:04.323212437Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:04.328232557Z 66 PC: 12b88 | Move file pointer
2018-12-17T22:57:04.329554391Z 66 PC: 12ba4 | Move file pointer
2018-12-17T22:57:04.330775289Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:57:04.333743245Z 66 PC: 12bd1 | Move file pointer
2018-12-17T22:57:04.335102084Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-17T22:57:04.343243446Z 66 PC: 12bff | Move file pointer
2018-12-17T22:57:04.345659704Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:57:04.352809486Z 87 PC: 12c36 | Get or set file date and time
2018-12-17T22:57:04.35452061Z 62 PC: 12c3a | Close file
2018-12-17T22:57:04.36264472Z 67 PC: 12c48 | Get or set file attributes
2018-12-17T22:57:04.372118126Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-17T22:57:04.373230164Z 78 PC: 12b11 | Find first file
2018-12-17T22:57:04.379137806Z 67 PC: 12b2d | Get or set file attributes
2018-12-17T22:57:04.384114522Z 67 PC: 12b38 | Get or set file attributes
2018-12-17T22:57:05.408093075Z 61 PC: 12b46 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:57:05.414880607Z 87 PC: 12b5a | Get or set file date and time
2018-12-17T22:57:05.416195821Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:57:05.418661499Z 66 PC: 12b88 | Move file pointer
2018-12-17T22:57:05.421090141Z 87 PC: 12c36 | Get or set file date and time
2018-12-17T22:57:05.422487751Z 62 PC: 12c3a | Close file
2018-12-17T22:57:05.600271999Z 67 PC: 12c48 | Get or set file attributes
2018-12-17T22:57:05.781072285Z 79 PC: 12b1c | Find next file
2018-12-17T22:57:05.783789212Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-17T22:57:05.785288849Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-17T22:57:05.787330488Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:05.789091367Z 26 PC: 12cd8 | Set disk transfer address
2018-12-17T22:57:05.790121151Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":8,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:55.1106878Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:55.112186574Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.113508811Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.114818814Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:55.120320002Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:55.126694358Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:55.131395973Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:55.1709954Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:55.178520358Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:55.180240828Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:55.186844452Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:55.18925169Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:55.198834306Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:55.201702048Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:55.205201987Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:55.214307656Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:55.216010107Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:55.223748908Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:55.225737917Z 62 PC: 12c3a | Close file
2018-12-25T12:32:55.233688222Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:55.244236294Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:55.247385601Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.274749434Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:55.301726518Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:55.308150484Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:55.310668148Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:55.317061071Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:55.318995938Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:55.320628395Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:55.323144768Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:55.32544823Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:55.333646947Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:55.335304325Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:55.342424619Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:55.344190285Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:55.354390862Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:55.377232312Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:55.378757645Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:55.384483309Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.390714528Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:55.720853484Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:55.727324966Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:55.729886022Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:55.733285686Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:55.735044846Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:55.737070535Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:55.744847862Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:55.902485613Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:55.905970689Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:55.907934278Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:55.909892717Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.911284115Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:55.913106889Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":16,"Month":8,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:55.22066457Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:55.223110598Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.224916247Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.226358228Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:55.227965294Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:55.235123772Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:55.241422567Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:55.256932414Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:55.270159813Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:55.271539764Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:55.278376017Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:55.280761563Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:55.282301478Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:55.294648697Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:55.296982649Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:55.306090726Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:55.30747628Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:55.314921153Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:55.316780311Z 62 PC: 12c3a | Close file
2018-12-25T12:32:55.324690214Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:55.33602711Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:55.339107503Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.345068228Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:55.355942155Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:55.36329324Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:55.36481737Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:55.375310755Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:55.377931451Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:55.379642085Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:55.382856815Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:55.385234923Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:55.393202498Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:55.394986298Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:55.407855676Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:55.409787487Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:55.698731561Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:55.726759874Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:55.728505585Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:55.734227398Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.740449717Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.076846722Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.083042244Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.084991191Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.088882797Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.090554301Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.092298476Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.100285031Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.109534475Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:56.112373343Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:56.115067571Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:56.117697185Z 44 PC: 12c92 | Get time 0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
0x12ca3: pop dx
0x12ca4: shr dx, 1
0x12ca6: mov cx, 0xb
0x12ca9: mov al, 2
0x12cab: int 0x26
0x12cad: popf
0x12cae: pop di
0x12caf: push di
0x12cb0: mov dx, word ptr [di + 0x24e]
0x12cb4: mov ax, word ptr [di + 0x250]
0x12cb8: push ax
0x12cb9: pop ds
2018-12-25T12:32:56.124253871Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.126530545Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:56.128359418Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":17,"Month":8,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:55.357066083Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:55.367618039Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.3725302Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.373649443Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:55.375378331Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:55.381460836Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:55.388051208Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:55.720245531Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:55.72745093Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:55.729064782Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:55.736499209Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:55.738964974Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:55.740549035Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:55.743214106Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:55.745814494Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:55.936568575Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:55.938254926Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:55.946251264Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:55.94802945Z 62 PC: 12c3a | Close file
2018-12-25T12:32:55.999862376Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:56.078055248Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:56.081345101Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:56.087230929Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.098120461Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.105701179Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.107122211Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.113715762Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.116083406Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:56.117429412Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:56.119855642Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:56.122023257Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:56.130118136Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:56.131823622Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:56.13923077Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.140954995Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.148739951Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.169398158Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:56.171708274Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:56.179259908Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:56.184793857Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.518252046Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.524795278Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.527025583Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.532116375Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.534391644Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.537327529Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.544869668Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.554467412Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:56.558506246Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:56.560148185Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:56.562464912Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.563744157Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:56.565389162Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":2000,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:55.445531417Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:55.460217624Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.463005259Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.464939626Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:55.466662063Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:55.474582763Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:55.481316257Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:55.501649983Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:55.5103808Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:55.512523613Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:55.520169165Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:55.523142735Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:55.525239971Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:55.528440756Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:55.530629305Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:55.542393929Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:55.5448421Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:55.552776839Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:55.55505617Z 62 PC: 12c3a | Close file
2018-12-25T12:32:55.563734234Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:55.574703641Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:55.578321898Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.585017597Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:55.596171307Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:55.605340426Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:55.606965107Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:55.614309625Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:55.616928668Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:55.619503624Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:55.623007251Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:55.625630922Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:55.635070053Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:55.637196249Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:55.644966707Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:55.647141156Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:55.656287782Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:55.667717658Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:55.669481036Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:55.675650989Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.681788922Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.358835272Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.366322338Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.368449718Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.372937865Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.374863216Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.376863749Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.384615188Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.394629503Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:56.404828166Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:56.407962013Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:56.410546741Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.411939086Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:56.413289525Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:55.50242354Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:55.503987828Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.505463766Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.507637795Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:55.509305362Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:55.516374641Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:55.522947524Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:55.541160125Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:55.549434415Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:55.551462042Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:55.55695929Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:55.559591013Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:55.560928341Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:55.563635739Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:55.565594107Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:55.575064277Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:55.576990858Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:55.58611687Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:55.587835399Z 62 PC: 12c3a | Close file
2018-12-25T12:32:55.596516862Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:55.60748314Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:55.610992787Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.617886403Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:55.628740281Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:55.642219341Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:55.644569368Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:55.65172845Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:55.655008761Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:55.656700996Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:55.659550822Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:55.662363725Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:55.671314353Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:55.672945868Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:55.680976791Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:55.682938545Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:55.691773413Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:55.893501881Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:55.895014617Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:55.912648509Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:55.919289539Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.358618563Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.365695107Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.36722213Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.370282994Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.371969277Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.373696145Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.381112841Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.391223516Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:56.39418986Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:56.396336089Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:56.399452013Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.400735612Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:56.402929714Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:55.748796018Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:55.751209022Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.752629288Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:55.754072138Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:55.756426065Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:55.765786511Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:55.772689718Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:56.077561016Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:56.08448189Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:56.086148095Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:56.095582558Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:56.097540642Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:56.099184789Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:56.101867448Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:56.104747067Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:56.113168504Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:56.11481926Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:56.12180348Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:56.123548482Z 62 PC: 12c3a | Close file
2018-12-25T12:32:56.131631899Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:56.141557207Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:56.144317219Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:56.150055029Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.168739346Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.176524944Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.178857466Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.194565738Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.208765399Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:56.210556789Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:56.213900223Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:56.215920626Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:56.411152356Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:56.413957808Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:56.420929534Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.422810863Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.517943082Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.528229113Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:56.529899501Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:56.542524496Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:56.548727138Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.875500512Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.883402202Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.88566717Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.888746526Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.890588297Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.892656573Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.899279052Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.908975795Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:56.911725748Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:56.913109603Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:56.916678974Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.918168203Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:56.919603266Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:56.535407325Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:56.537617889Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.539150309Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.540691028Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:56.543819102Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:56.550919931Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:56.55745222Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:56.593608783Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:56.601621241Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:56.603732393Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:56.61177254Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:56.614525704Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:56.618692648Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:56.621803809Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:56.629155601Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:56.635051692Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:56.636325165Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:56.6413117Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:56.642688122Z 62 PC: 12c3a | Close file
2018-12-25T12:32:56.647921024Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:56.655133434Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:56.657394014Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:56.665301418Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:56.676137861Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:56.681083006Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:56.682318275Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:56.687291471Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:56.689067488Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:56.69082798Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:56.694112503Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:56.696590608Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:56.705278553Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:56.706425328Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:56.71163372Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:56.712948734Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:56.718244733Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:56.725343428Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:56.726781675Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:56.732969037Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:56.739565085Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:57.077928383Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:57.084803701Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:57.087210256Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:57.090112047Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:57.091624795Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:57.093492875Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:57.101028056Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:57.111296865Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:57.114618846Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:57.117692062Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:57.120254062Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.121670804Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:57.123987478Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":8,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:56.920224528Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:56.921503473Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.92245318Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:56.923335988Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:56.924906601Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:56.93077258Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:56.93618222Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:56.951186215Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:56.958244686Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:56.959451136Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:56.965389966Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:56.966922185Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:56.968118486Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:56.970399716Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:56.972551742Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:56.980633829Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:56.981813311Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:56.98982247Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:56.991433978Z 62 PC: 12c3a | Close file
2018-12-25T12:32:56.999146768Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:57.022292063Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:57.025166529Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:57.030727306Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:57.04082096Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:57.052777526Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:57.054158709Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:57.062726172Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:57.064148848Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:57.065497769Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:57.068865863Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:57.070257041Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:57.077805835Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:57.079696685Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:57.086187714Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:57.087597491Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:57.095424884Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:57.105586268Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:57.106996514Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:57.112614697Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:57.119285696Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:57.446131031Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:57.452118359Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:57.453976421Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:57.458321581Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:57.462149393Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:57.465124819Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:57.471542333Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:57.479999802Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:57.483285306Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:57.48476728Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:57.487098492Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.489026723Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:57.490375001Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":16,"Month":8,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:57.738174834Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:57.740003839Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.741196607Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.74233785Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:57.74956363Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:57.757862232Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:57.763836919Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:57.780664752Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:57.787542806Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:57.789865179Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:57.802359982Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:57.803882703Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:57.805199932Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:57.807777277Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:57.809981234Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:57.819659908Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:57.823854787Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:57.839838329Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:57.841675822Z 62 PC: 12c3a | Close file
2018-12-25T12:32:57.849694605Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:57.862655298Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:57.86532539Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:57.870973946Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:57.889749264Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:57.910897601Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:57.91574442Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:57.931551595Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:57.943762892Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:57.945177156Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:57.955772435Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:57.957593523Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:57.966900836Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:57.969125602Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:57.975614224Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:57.977104633Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:57.985524342Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:57.995559051Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:57.997152437Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:58.003584679Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:58.009142582Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:58.335883304Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:58.342935705Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:58.345034856Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:58.348675605Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:58.351143408Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:58.366638985Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:58.372927631Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:58.692038621Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:58.695998607Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:58.697557993Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:58.69988476Z 44 PC: 12c92 | Get time 0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
0x12ca3: pop dx
0x12ca4: shr dx, 1
0x12ca6: mov cx, 0xb
0x12ca9: mov al, 2
0x12cab: int 0x26
0x12cad: popf
0x12cae: pop di
0x12caf: push di
0x12cb0: mov dx, word ptr [di + 0x24e]
0x12cb4: mov ax, word ptr [di + 0x250]
0x12cb8: push ax
0x12cb9: pop ds
2018-12-25T12:32:58.709897039Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:58.711360418Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:58.712774884Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":17,"Month":8,"Year":1990,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:57.835565001Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:57.837622048Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.839774494Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.842091355Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:57.843484021Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:57.85090739Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:57.85674338Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:57.875879423Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:57.888650159Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:57.890509344Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:57.896833696Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:57.899819685Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:57.90163669Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:57.904392534Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:57.906570508Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:57.916735569Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:57.918144752Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:57.924652177Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:57.931239305Z 62 PC: 12c3a | Close file
2018-12-25T12:32:57.939530418Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:57.94933816Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:57.955038293Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:57.970929029Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:57.992506295Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:58.000714262Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:58.002144734Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:58.008931826Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:58.011582257Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:58.02653461Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:58.029307034Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:58.031841374Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:58.297434427Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:58.299177212Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:58.306758163Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:58.30881028Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:58.335075486Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:58.348278335Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:58.350880638Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:58.357363952Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:58.363388465Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:58.692537867Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:58.699040964Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:58.700729333Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:58.704461089Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:58.705935276Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:58.707386Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:58.72088242Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:58.732739627Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:58.735536249Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:58.737607294Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:58.741112408Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:58.742342118Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:58.74680615Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":2000,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:57.8404516Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:57.841763928Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.843088356Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.845751274Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:57.847129366Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:57.854182439Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:57.86142207Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:57.879757259Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:57.887468785Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:57.889528376Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:57.897492829Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:57.899111628Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:57.900768118Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:57.904778225Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:57.907514201Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:57.918183465Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:57.920369695Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:57.928696774Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:57.930546866Z 62 PC: 12c3a | Close file
2018-12-25T12:32:57.940126736Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:57.951754316Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:57.95486074Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:57.962116548Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:57.973048714Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:57.986385393Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:57.988447729Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:57.996018653Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:57.998128585Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:58.000429549Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:58.003754698Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:58.005365538Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:58.014977921Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:58.017086389Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:58.025070958Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:58.02725381Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:58.037702158Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:58.049502746Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:58.05127819Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:58.059735229Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:58.065633363Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:58.411708223Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:58.420160946Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:58.422752546Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:58.426248684Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:58.428594871Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:58.431607373Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:58.438766287Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:58.449085543Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:58.454426483Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:58.456264181Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:58.459088165Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:58.461657586Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:58.463315684Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12432,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:32:57.926724765Z 26 PC: 12abd | Set disk transfer address
2018-12-25T12:32:57.928570334Z 53 PC: 12ac2 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.938424159Z 37 PC: 12ad6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:57.940176142Z 25 PC: 12af4 | Get default drive
2018-12-25T12:32:57.944376584Z 78 PC: 12b11 | Find first file
2018-12-25T12:32:57.95135275Z 67 PC: 12b2d | Get or set file attributes
2018-12-25T12:32:57.957468729Z 67 PC: 12b38 | Get or set file attributes
2018-12-25T12:32:57.972858313Z 61 PC: 12b46 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:32:57.980083563Z 87 PC: 12b5a | Get or set file date and time
2018-12-25T12:32:57.981707441Z 63 PC: 12b6e | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:32:57.98850816Z 66 PC: 12b88 | Move file pointer
2018-12-25T12:32:57.991135972Z 66 PC: 12ba4 | Move file pointer
2018-12-25T12:32:57.992571898Z 63 PC: 12bb0 | Read file or device (Read 11 bytes on handle 5)
2018-12-25T12:32:57.995917514Z 66 PC: 12bd1 | Move file pointer
2018-12-25T12:32:57.998077099Z 64 PC: 12beb | Write file or device (Write 636 bytes on handle 5)
2018-12-25T12:32:58.006486109Z 66 PC: 12bff | Move file pointer
2018-12-25T12:32:58.008042304Z 64 PC: 12c0d | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:32:58.01529938Z 87 PC: 12c36 | Get or set file date and time
2018-12-25T12:32:58.017095521Z 62 PC: 12c3a | Close file
2018-12-25T12:32:58.21650446Z 67 PC: 12c48 | Get or set file attributes
2018-12-25T12:32:58.341568593Z 79 PC: 12b1c | Find next file
2018-12-25T12:32:58.345404841Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:58.352291238Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:58.36466357Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:58.37474743Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:58.376699917Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:58.383848641Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:58.386946184Z 66 PC: 12ba4 | Move file pointer (See above)
2018-12-25T12:32:58.388746157Z 63 PC: 12bb0 | Read file or device (See above)
2018-12-25T12:32:58.391614339Z 66 PC: 12bd1 | Move file pointer (See above)
2018-12-25T12:32:58.395183184Z 64 PC: 12beb | Write file or device (See above)
2018-12-25T12:32:58.68271289Z 66 PC: 12bff | Move file pointer (See above)
2018-12-25T12:32:58.684481178Z 64 PC: 12c0d | Write file or device (See above)
2018-12-25T12:32:58.693946508Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:58.698129256Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:58.710228445Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:58.725603628Z 14 PC: 12c5a | Set default drive (Drive = 'C')
2018-12-25T12:32:58.727074717Z 78 PC: 12b11 | Find first file (See above)
2018-12-25T12:32:58.738924697Z 67 PC: 12b2d | Get or set file attributes (See above)
2018-12-25T12:32:58.747949208Z 67 PC: 12b38 | Get or set file attributes (See above)
2018-12-25T12:32:59.076913144Z 61 PC: 12b46 | Open file (See above)
2018-12-25T12:32:59.083304698Z 87 PC: 12b5a | Get or set file date and time (See above)
2018-12-25T12:32:59.085615334Z 63 PC: 12b6e | Read file or device (See above)
2018-12-25T12:32:59.088598454Z 66 PC: 12b88 | Move file pointer (See above)
2018-12-25T12:32:59.091046245Z 87 PC: 12c36 | Get or set file date and time (See above)
2018-12-25T12:32:59.093592289Z 62 PC: 12c3a | Close file (See above)
2018-12-25T12:32:59.1105078Z 67 PC: 12c48 | Get or set file attributes (See above)
2018-12-25T12:32:59.119432318Z 79 PC: 12b1c | Find next file (See above)
2018-12-25T12:32:59.122628317Z 14 PC: 12c6f | Set default drive (Drive = 'A')
2018-12-25T12:32:59.123870211Z 42 PC: 12c74 | Get date 0x12c74: cmp cx, 0x7c6
0x12c78: jl 0x12cb0
0x12c7a: cmp cx, 0x7d0
0x12c7e: je 0x12cb0
0x12c80: cmp dh, 8
0x12c83: jl 0x12cb0
0x12c85: cmp dl, 0x10
0x12c88: jl 0x12cb0
0x12c8a: cmp al, 4
0x12c8c: jne 0x12cb0
0x12c8e: mov ah, 0x2c
0x12c90: int 0x21
0x12c92: shl dl, 1
0x12c94: shl dl, 1
0x12c96: xor dh, dh
0x12c98: mov cx, 2
0x12c9b: mov al, byte ptr [di + 0x24d]
0x12c9f: push dx
0x12ca0: int 0x26
0x12ca2: popf
2018-12-25T12:32:59.125942337Z 37 PC: 12cbf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:32:59.127031382Z 26 PC: 12cd8 | Set disk transfer address
2018-12-25T12:32:59.128721236Z 9 PC: 12aa2 | Display string (String= 'Hello - Copyright S & S International, 1990 ')