Sample viewer

vx.netlux.org/Virus.DOS.HLLC.12880

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:04.769311744Z 53 PC: 1477a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:04.776625816Z 53 PC: 1477a | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:04.77762845Z 53 PC: 1477a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:04.778644389Z 53 PC: 1477a | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:04.780079801Z 53 PC: 1477a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:04.781090119Z 53 PC: 1477a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:04.782048395Z 53 PC: 1477a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:04.783364108Z 53 PC: 1477a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:04.784346975Z 53 PC: 1477a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:04.785293922Z 53 PC: 1477a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:04.786586117Z 53 PC: 1477a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:04.787526761Z 53 PC: 1477a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:04.788457111Z 53 PC: 1477a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:04.790050462Z 53 PC: 1477a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:04.791000822Z 53 PC: 1477a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:04.791927693Z 53 PC: 1477a | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:04.793300932Z 53 PC: 1477a | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:04.79430983Z 53 PC: 1477a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:04.795278859Z 53 PC: 1477a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:04.797260171Z 37 PC: 1478f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:04.798156428Z 37 PC: 14797 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:04.799014891Z 37 PC: 1479f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:04.800318584Z 37 PC: 147a7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:04.801654367Z 68 PC: 154d7 | I/O control for devices (Set for = '')
2018-12-17T22:57:04.881340624Z 37 PC: 13f01 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:04.88322319Z 48 PC: 15002 | Get DOS version
2018-12-17T22:57:04.884746152Z 53 PC: 144f2 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:04.88578933Z 37 PC: 1450e | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:04.886964579Z 25 PC: 1508f | Get default drive
2018-12-17T22:57:04.888073404Z 71 PC: 150a2 | Get current directory
2018-12-17T22:57:04.890928724Z 14 PC: 150e8 | Set default drive (Drive = 'C')
2018-12-17T22:57:04.892104715Z 25 PC: 150ec | Get default drive
2018-12-17T22:57:04.893212183Z 59 PC: 15156 | Change current directory
2018-12-17T22:57:04.896539815Z 26 PC: 144b6 | Set disk transfer address
2018-12-17T22:57:04.897626126Z 78 PC: 14487 | Find first file
2018-12-17T22:57:04.902761588Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.90362204Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.905950399Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.907207042Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.909701695Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.910704242Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.912994Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.913696281Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.916101474Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.917296401Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.919530781Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.920498921Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.923165839Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.924104648Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.926514281Z 44 PC: 1560e | Get time 0x1560e: mov word ptr [0xca], cx
0x15612: mov word ptr [0xcc], dx
0x15616: retf
0x15617: call 0x1565e
0x1561a: jb 0x1562b
0x1561c: mov cx, word ptr es:[di + 4]
0x15620: cmp cx, 1
0x15623: je 0x1562b
0x15625: xor bx, bx
0x15627: push cs
0x15628: call 0x2519a
0x1562b: retf 4
0x1562e: call 0x1565e
0x15631: jb 0x15646
0x15633: mov ax, cx
0x15635: mov dx, bx
0x15637: mov cx, word ptr es:[di + 4]
0x1563b: cmp cx, 1
0x1563e: je 0x15646
0x15640: xor bx, bx
2018-12-17T22:57:04.92882467Z 59 PC: 15156 | Change current directory
2018-12-17T22:57:04.936967421Z 26 PC: 144b6 | Set disk transfer address
2018-12-17T22:57:04.938231432Z 78 PC: 14487 | Find first file
2018-12-17T22:57:04.947308063Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.948701724Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.952290404Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.953509417Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.956546025Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.957669219Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.960902368Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.962187828Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.968956048Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.970316513Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.976618307Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.977934027Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.981560386Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.982470568Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.985437441Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.986419159Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.989384759Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.990272448Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.993374876Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.994272771Z 79 PC: 144dd | Find next file
2018-12-17T22:57:04.997252693Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:04.998230642Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.00121632Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.002110651Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.005443722Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.00621171Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.009065455Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.012784643Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.015787475Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.016705168Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.023578311Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.024586457Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.027547372Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.028515605Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.031501116Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.032376511Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.035414969Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.036337769Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.039454979Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.040817906Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.043842227Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.044787566Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.048205821Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.049476074Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.052936156Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.054562017Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.0607712Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.061802237Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.06508892Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.066443643Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.069559754Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.071679437Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.075096215Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.076644764Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.080257698Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.081189545Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.084350719Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.085686086Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.092769096Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.093680436Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.100802319Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.10174068Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.107737055Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.111347982Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.11780245Z 26 PC: 144b6 | Set disk transfer address
2018-12-17T22:57:05.118825113Z 78 PC: 14487 | Find first file
2018-12-17T22:57:05.12574475Z 61 PC: 14e40 | Open file (Filename = 'SETUP.EXE')
2018-12-17T22:57:05.132182308Z 66 PC: 15678 | Move file pointer
2018-12-17T22:57:05.13346502Z 66 PC: 15686 | Move file pointer
2018-12-17T22:57:05.136080201Z 66 PC: 15694 | Move file pointer
2018-12-17T22:57:05.13752143Z 62 PC: 14e90 | Close file
2018-12-17T22:57:05.139242069Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.140606144Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.14389773Z 61 PC: 14e40 | Open file (Filename = 'SETUP.HLP')
2018-12-17T22:57:05.150352082Z 66 PC: 15678 | Move file pointer
2018-12-17T22:57:05.15218264Z 66 PC: 15686 | Move file pointer
2018-12-17T22:57:05.15352127Z 66 PC: 15694 | Move file pointer
2018-12-17T22:57:05.154966468Z 62 PC: 14e90 | Close file
2018-12-17T22:57:05.157000374Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.158068202Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.161503049Z 61 PC: 14e40 | Open file (Filename = 'SETUP.TXT')
2018-12-17T22:57:05.168913388Z 66 PC: 15678 | Move file pointer
2018-12-17T22:57:05.170122832Z 66 PC: 15686 | Move file pointer
2018-12-17T22:57:05.171863853Z 66 PC: 15694 | Move file pointer
2018-12-17T22:57:05.173180719Z 62 PC: 14e90 | Close file
2018-12-17T22:57:05.174811562Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.176473716Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.17967686Z 26 PC: 144b6 | Set disk transfer address
2018-12-17T22:57:05.180623121Z 78 PC: 14487 | Find first file
2018-12-17T22:57:05.187903302Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.18914038Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.192374211Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.193799213Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.196826136Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.197730667Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.201208308Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.202190682Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.20518369Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.206404994Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.209967326Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.210947818Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.214328293Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.215518868Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.218523518Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.220177221Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.22341524Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.224527811Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.228366194Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.229255444Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.232322725Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.234039369Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.236954525Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.239092166Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.242165248Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.24304019Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.246369369Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.247601181Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.250611346Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.251851056Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.254851584Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.255881899Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.259142067Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.259991709Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.26284701Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.26399407Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.266862005Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.267697819Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.271101399Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.271981324Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.274896561Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.276233779Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.279104748Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.279959738Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.289748546Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.290662048Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.293858123Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.29488747Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.297781001Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.299085973Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.302001962Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.302880867Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.306241759Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.307139711Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.310068551Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.311389653Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.314352326Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.315243506Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.319699737Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.320580807Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.323594646Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.324749609Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.327746388Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.328517206Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.332413696Z 26 PC: 144b6 | Set disk transfer address
2018-12-17T22:57:05.333306442Z 78 PC: 14487 | Find first file
2018-12-17T22:57:05.339174917Z 61 PC: 14e40 | Open file (Filename = 'SETUP.EXE')
2018-12-17T22:57:05.345598356Z 66 PC: 15678 | Move file pointer
2018-12-17T22:57:05.346736687Z 66 PC: 15686 | Move file pointer
2018-12-17T22:57:05.348065085Z 66 PC: 15694 | Move file pointer
2018-12-17T22:57:05.349707711Z 62 PC: 14e90 | Close file
2018-12-17T22:57:05.351615583Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.353119911Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.356174638Z 61 PC: 14e40 | Open file (Filename = 'SETUP.HLP')
2018-12-17T22:57:05.362443763Z 66 PC: 15678 | Move file pointer
2018-12-17T22:57:05.364092177Z 66 PC: 15686 | Move file pointer
2018-12-17T22:57:05.365309194Z 66 PC: 15694 | Move file pointer
2018-12-17T22:57:05.366569922Z 62 PC: 14e90 | Close file
2018-12-17T22:57:05.368610352Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.369500013Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.372756849Z 61 PC: 14e40 | Open file (Filename = 'SETUP.TXT')
2018-12-17T22:57:05.380090917Z 66 PC: 15678 | Move file pointer
2018-12-17T22:57:05.381522361Z 66 PC: 15686 | Move file pointer
2018-12-17T22:57:05.382723377Z 66 PC: 15694 | Move file pointer
2018-12-17T22:57:05.384948902Z 62 PC: 14e90 | Close file
2018-12-17T22:57:05.387303211Z 26 PC: 144d8 | Set disk transfer address
2018-12-17T22:57:05.388213093Z 79 PC: 144dd | Find next file
2018-12-17T22:57:05.393036531Z 44 PC: 1560e | Get time 0x1560e: mov word ptr [0xca], cx
0x15612: mov word ptr [0xcc], dx
0x15616: retf
0x15617: call 0x1565e
0x1561a: jb 0x1562b
0x1561c: mov cx, word ptr es:[di + 4]
0x15620: cmp cx, 1
0x15623: je 0x1562b
0x15625: xor bx, bx
0x15627: push cs
0x15628: call 0x2519a
0x1562b: retf 4
0x1562e: call 0x1565e
0x15631: jb 0x15646
0x15633: mov ax, cx
0x15635: mov dx, bx
0x15637: mov cx, word ptr es:[di + 4]
0x1563b: cmp cx, 1
0x1563e: je 0x15646
0x15640: xor bx, bx
2018-12-17T22:57:05.395451708Z 86 PC: 14fcd | Rename file
2018-12-17T22:57:06.06077995Z 61 PC: 14e40 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:57:06.068093864Z 66 PC: 15678 | Move file pointer
2018-12-17T22:57:06.069332985Z 66 PC: 15686 | Move file pointer
2018-12-17T22:57:06.07074213Z 66 PC: 15694 | Move file pointer
2018-12-17T22:57:06.073141554Z 63 PC: 14f13 | Read file or device (Read 12880 bytes on handle 5)
2018-12-17T22:57:06.081189306Z 60 PC: 14e40 | Create or truncate file
2018-12-17T22:57:06.091902855Z 64 PC: 14f13 | Write file or device (Write 12880 bytes on handle 6)
2018-12-17T22:57:06.106851894Z 62 PC: 14e90 | Close file
2018-12-17T22:57:06.118099982Z 14 PC: 150e8 | Set default drive (Drive = 'A')
2018-12-17T22:57:06.119956124Z 25 PC: 150ec | Get default drive
2018-12-17T22:57:06.122359594Z 59 PC: 15156 | Change current directory
2018-12-17T22:57:06.127297967Z 42 PC: 14490 | Get date 0x14490: xor ah, ah
0x14492: les di, ptr [bp + 6]
0x14495: stosw word ptr es:[di], ax
0x14496: mov al, dl
0x14498: les di, ptr [bp + 0xa]
0x1449b: stosw word ptr es:[di], ax
0x1449c: mov al, dh
0x1449e: les di, ptr [bp + 0xe]
0x144a1: stosw word ptr es:[di], ax
0x144a2: xchg ax, cx
0x144a3: les di, ptr [bp + 0x12]
0x144a6: stosw word ptr es:[di], ax
0x144a7: pop bp
0x144a8: retf 0x10
0x144ab: push bp
0x144ac: mov bp, sp
0x144ae: push ds
0x144af: lds dx, ptr [bp + 6]
0x144b2: mov ah, 0x1a
0x144b4: int 0x21
2018-12-17T22:57:06.13043304Z 61 PC: 14e40 | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:57:06.140959377Z 66 PC: 14f72 | Move file pointer
2018-12-17T22:57:06.142408662Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.149683184Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.152494074Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.155174416Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.158544862Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.161416784Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.164010693Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.167295056Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.170213585Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.172990977Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.176466189Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.17996106Z 63 PC: 14ed2 | Read file or device (Read 1 bytes on handle 6)
2018-12-17T22:57:06.182708864Z 62 PC: 14e90 | Close file
2018-12-17T22:57:06.185528179Z 37 PC: 1450e | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:06.186640753Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:06.187774257Z 37 PC: 14700 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:06.189914513Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:06.190878042Z 37 PC: 14700 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:06.192003177Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:06.193823884Z 37 PC: 14700 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:06.195159396Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:06.196501919Z 37 PC: 14700 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:06.1984479Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:06.199844627Z 37 PC: 14700 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:06.201149614Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:06.202998201Z 37 PC: 14700 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:06.204305874Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:06.206208716Z 37 PC: 14700 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:06.20751356Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:06.208842867Z 37 PC: 14700 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:06.211000792Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:06.212159072Z 37 PC: 14700 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:06.213193048Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:06.21511061Z 37 PC: 14700 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:06.216407398Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:06.2178041Z 37 PC: 14700 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:06.219494068Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:06.220657477Z 37 PC: 14700 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:06.221961465Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:06.223692111Z 37 PC: 14700 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:06.224986609Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:06.227038779Z 37 PC: 14700 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:06.228225465Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:06.229577662Z 37 PC: 14700 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:06.231634934Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:06.232799215Z 37 PC: 14700 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:06.233859192Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:06.235430836Z 37 PC: 14700 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:06.236466747Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:06.237533682Z 37 PC: 14700 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:06.238718335Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:06.239686168Z 37 PC: 14700 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:06.241503268Z 41 PC: 146ae | Parse filename
2018-12-17T22:57:06.242729794Z 41 PC: 146bc | Parse filename
2018-12-17T22:57:06.243901734Z 75 PC: 146c7 | Execute program
2018-12-17T22:57:06.250699861Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:06.251729172Z 37 PC: 14700 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:06.252770835Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:06.254445271Z 37 PC: 14700 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:06.255491306Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:06.256553132Z 37 PC: 14700 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:06.258145173Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:06.259196446Z 37 PC: 14700 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:06.260217405Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:06.261592908Z 37 PC: 14700 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:06.262622755Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:06.264039764Z 37 PC: 14700 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:06.2652602Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:06.266249749Z 37 PC: 14700 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:06.268040107Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:06.269155888Z 37 PC: 14700 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:06.27018878Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:06.272277602Z 37 PC: 14700 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:06.273499725Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:06.274615805Z 37 PC: 14700 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:06.276642761Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:06.278652832Z 37 PC: 14700 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:06.280082407Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:06.281279933Z 37 PC: 14700 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:06.282382179Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:06.283888691Z 37 PC: 14700 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:06.284946326Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:06.286263913Z 37 PC: 14700 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:06.288292341Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:06.289692453Z 37 PC: 14700 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:06.291038603Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:06.292786334Z 37 PC: 14700 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:06.29399971Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:06.295280324Z 37 PC: 14700 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:06.296689033Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:06.298026685Z 37 PC: 14700 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:06.300115545Z 53 PC: 146f7 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:06.301503262Z 37 PC: 14700 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:06.302817379Z 77 PC: 146e5 | Get program return code
2018-12-17T22:57:06.305187052Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:57:06.306553213Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:57:06.307639685Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:57:06.309423512Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:06.310828036Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:57:06.312073221Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:57:06.313823601Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:57:06.31507611Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:57:06.316308293Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:57:06.318195282Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:57:06.319452464Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:57:06.321274781Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:57:06.322658342Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:57:06.323971812Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:57:06.326234851Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:57:06.327276146Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:57:06.328403201Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:57:06.330593865Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:57:06.331732845Z 37 PC: 148d1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:57:06.332779939Z 76 PC: 14910 | Terminate with return code (Return code = '0')