Sample viewer

vx.netlux.org/Virus.DOS.Mordor.1104

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:57:41.771648962Z 250 PC: 12a62 | UNKNOWN!
2018-12-17T22:57:41.778646967Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-17T22:57:41.783130335Z 53 PC: 12bc1 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-17T22:57:42.120717182Z 37 PC: 12da3 | Set interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-17T22:57:42.122375519Z 53 PC: 12da8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:42.125027695Z 74 PC: 12db9 | Reallocate memory
2018-12-17T22:57:42.129522654Z 75 PC: 12e10 | Execute program
2018-12-17T22:57:42.144636015Z 250 PC: 13fd2 | UNKNOWN!
2018-12-17T22:57:42.146244178Z 42 PC: 13fd6 | Get date 0x13fd6: cmp dl, 0x1f
0x13fd9: jne 0x13fec
0x13fdb: cmp dh, 3
0x13fde: jne 0x13fec
0x13fe0: mov ah, 9
0x13fe2: mov dx, 0x13f
0x13fe5: int 0x21
0x13fe7: mov ax, 0x4c00
0x13fea: int 0x21
0x13fec: jmp 0x1412c
0x13fef: or cl, byte ptr [di]
0x13ff1: push si
0x13ff2: imul si, word ptr [bp + si + 0x75], 0x2073
0x13ff7: dec bp
0x13ff8: dec di
0x13ff9: push dx
0x13ffa: inc sp
0x13ffb: dec di
0x13ffc: push dx
0x13ffd: and byte ptr [bp + 0x31], dh
2018-12-17T22:57:42.149714842Z 53 PC: 14131 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-17T22:57:42.152672553Z 76 PC: 13fb5 | Terminate with return code (Return code = '0')
2018-12-17T22:57:42.157000518Z 37 PC: 12e1a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:57:42.159588804Z 49 PC: 12e1f | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:44.668478192Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:44.669767558Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:44.672040714Z 53 PC: 12bc1 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:44.988686284Z 37 PC: 12da3 | Set interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:44.992624241Z 53 PC: 12da8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:44.994339956Z 74 PC: 12db9 | Reallocate memory
2018-12-25T12:35:44.996252824Z 75 PC: 12e10 | Execute program
2018-12-25T12:35:45.011693959Z 250 PC: 13fd2 | UNKNOWN!
2018-12-25T12:35:45.012678226Z 42 PC: 13fd6 | Get date 0x13fd6: cmp dl, 0x1f
0x13fd9: jne 0x13fec
0x13fdb: cmp dh, 3
0x13fde: jne 0x13fec
0x13fe0: mov ah, 9
0x13fe2: mov dx, 0x13f
0x13fe5: int 0x21
0x13fe7: mov ax, 0x4c00
0x13fea: int 0x21
0x13fec: jmp 0x1412c
0x13fef: or cl, byte ptr [di]
0x13ff1: push si
0x13ff2: imul si, word ptr [bp + si + 0x75], 0x2073
0x13ff7: dec bp
0x13ff8: dec di
0x13ff9: push dx
0x13ffa: inc sp
0x13ffb: dec di
0x13ffc: push dx
0x13ffd: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:45.014849986Z 53 PC: 14131 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:45.017849199Z 76 PC: 13fb5 | Terminate with return code (Return code = '0')
2018-12-25T12:35:45.021036576Z 37 PC: 12e1a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:45.022073961Z 49 PC: 12e1f | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":31,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:44.930046579Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:44.931191286Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:44.933528037Z 53 PC: 12bc1 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:45.268672308Z 37 PC: 12da3 | Set interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:45.269886876Z 53 PC: 12da8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:45.271278929Z 74 PC: 12db9 | Reallocate memory
2018-12-25T12:35:45.273009906Z 75 PC: 12e10 | Execute program
2018-12-25T12:35:45.288726741Z 250 PC: 13fd2 | UNKNOWN!
2018-12-25T12:35:45.289928954Z 42 PC: 13fd6 | Get date 0x13fd6: cmp dl, 0x1f
0x13fd9: jne 0x13fec
0x13fdb: cmp dh, 3
0x13fde: jne 0x13fec
0x13fe0: mov ah, 9
0x13fe2: mov dx, 0x13f
0x13fe5: int 0x21
0x13fe7: mov ax, 0x4c00
0x13fea: int 0x21
0x13fec: jmp 0x1412c
0x13fef: or cl, byte ptr [di]
0x13ff1: push si
0x13ff2: imul si, word ptr [bp + si + 0x75], 0x2073
0x13ff7: dec bp
0x13ff8: dec di
0x13ff9: push dx
0x13ffa: inc sp
0x13ffb: dec di
0x13ffc: push dx
0x13ffd: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:45.292171099Z 53 PC: 14131 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:45.293851365Z 76 PC: 13fb5 | Terminate with return code (Return code = '0')
2018-12-25T12:35:45.296039996Z 37 PC: 12e1a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:45.296862054Z 49 PC: 12e1f | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":31,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:45.30733779Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:45.309822247Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:45.31264699Z 9 PC: 12a77 | Display string (Could not find end pointer)
2018-12-25T12:35:45.334709088Z 76 PC: 12a7c | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:45.707569707Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:45.708825365Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:45.711006415Z 53 PC: 12bc1 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:46.342162429Z 37 PC: 12da3 | Set interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:46.344815974Z 53 PC: 12da8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:46.345893574Z 74 PC: 12db9 | Reallocate memory
2018-12-25T12:35:46.347219637Z 75 PC: 12e10 | Execute program
2018-12-25T12:35:46.360705201Z 250 PC: 13fd2 | UNKNOWN!
2018-12-25T12:35:46.362030981Z 42 PC: 13fd6 | Get date 0x13fd6: cmp dl, 0x1f
0x13fd9: jne 0x13fec
0x13fdb: cmp dh, 3
0x13fde: jne 0x13fec
0x13fe0: mov ah, 9
0x13fe2: mov dx, 0x13f
0x13fe5: int 0x21
0x13fe7: mov ax, 0x4c00
0x13fea: int 0x21
0x13fec: jmp 0x1412c
0x13fef: or cl, byte ptr [di]
0x13ff1: push si
0x13ff2: imul si, word ptr [bp + si + 0x75], 0x2073
0x13ff7: dec bp
0x13ff8: dec di
0x13ff9: push dx
0x13ffa: inc sp
0x13ffb: dec di
0x13ffc: push dx
0x13ffd: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:46.363995468Z 53 PC: 14131 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:46.366375793Z 76 PC: 13fb5 | Terminate with return code (Return code = '0')
2018-12-25T12:35:46.369401814Z 37 PC: 12e1a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:46.370379849Z 49 PC: 12e1f | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":31,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:45.942957356Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:45.943906064Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:45.945833793Z 53 PC: 12bc1 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:46.34191603Z 37 PC: 12da3 | Set interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:46.343723589Z 53 PC: 12da8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:46.344622938Z 74 PC: 12db9 | Reallocate memory
2018-12-25T12:35:46.346266167Z 75 PC: 12e10 | Execute program
2018-12-25T12:35:46.360080187Z 250 PC: 13fd2 | UNKNOWN!
2018-12-25T12:35:46.360997071Z 42 PC: 13fd6 | Get date 0x13fd6: cmp dl, 0x1f
0x13fd9: jne 0x13fec
0x13fdb: cmp dh, 3
0x13fde: jne 0x13fec
0x13fe0: mov ah, 9
0x13fe2: mov dx, 0x13f
0x13fe5: int 0x21
0x13fe7: mov ax, 0x4c00
0x13fea: int 0x21
0x13fec: jmp 0x1412c
0x13fef: or cl, byte ptr [di]
0x13ff1: push si
0x13ff2: imul si, word ptr [bp + si + 0x75], 0x2073
0x13ff7: dec bp
0x13ff8: dec di
0x13ff9: push dx
0x13ffa: inc sp
0x13ffb: dec di
0x13ffc: push dx
0x13ffd: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:46.363009822Z 53 PC: 14131 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:46.365401994Z 76 PC: 13fb5 | Terminate with return code (Return code = '0')
2018-12-25T12:35:46.368291368Z 37 PC: 12e1a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:46.369560745Z 49 PC: 12e1f | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":31,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:46.960883136Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:46.968549946Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:46.971444919Z 9 PC: 12a77 | Display string (Could not find end pointer)
2018-12-25T12:35:46.994430623Z 76 PC: 12a7c | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:47.207404039Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:47.21219647Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:47.214628322Z 53 PC: 12bc1 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:47.669442661Z 37 PC: 12da3 | Set interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:47.671150923Z 53 PC: 12da8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:47.673414692Z 74 PC: 12db9 | Reallocate memory
2018-12-25T12:35:47.675032017Z 75 PC: 12e10 | Execute program
2018-12-25T12:35:47.690639124Z 250 PC: 13fd2 | UNKNOWN!
2018-12-25T12:35:47.693303811Z 42 PC: 13fd6 | Get date 0x13fd6: cmp dl, 0x1f
0x13fd9: jne 0x13fec
0x13fdb: cmp dh, 3
0x13fde: jne 0x13fec
0x13fe0: mov ah, 9
0x13fe2: mov dx, 0x13f
0x13fe5: int 0x21
0x13fe7: mov ax, 0x4c00
0x13fea: int 0x21
0x13fec: jmp 0x1412c
0x13fef: or cl, byte ptr [di]
0x13ff1: push si
0x13ff2: imul si, word ptr [bp + si + 0x75], 0x2073
0x13ff7: dec bp
0x13ff8: dec di
0x13ff9: push dx
0x13ffa: inc sp
0x13ffb: dec di
0x13ffc: push dx
0x13ffd: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:47.695669786Z 53 PC: 14131 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:47.698753509Z 76 PC: 13fb5 | Terminate with return code (Return code = '0')
2018-12-25T12:35:47.703008948Z 37 PC: 12e1a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:47.70424879Z 49 PC: 12e1f | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":31,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:47.552245056Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:47.554038264Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:47.556033039Z 53 PC: 12bc1 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:47.875548764Z 37 PC: 12da3 | Set interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:47.87708032Z 53 PC: 12da8 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:47.877990693Z 74 PC: 12db9 | Reallocate memory
2018-12-25T12:35:47.879006711Z 75 PC: 12e10 | Execute program
2018-12-25T12:35:47.888162285Z 250 PC: 13fd2 | UNKNOWN!
2018-12-25T12:35:47.888850476Z 42 PC: 13fd6 | Get date 0x13fd6: cmp dl, 0x1f
0x13fd9: jne 0x13fec
0x13fdb: cmp dh, 3
0x13fde: jne 0x13fec
0x13fe0: mov ah, 9
0x13fe2: mov dx, 0x13f
0x13fe5: int 0x21
0x13fe7: mov ax, 0x4c00
0x13fea: int 0x21
0x13fec: jmp 0x1412c
0x13fef: or cl, byte ptr [di]
0x13ff1: push si
0x13ff2: imul si, word ptr [bp + si + 0x75], 0x2073
0x13ff7: dec bp
0x13ff8: dec di
0x13ff9: push dx
0x13ffa: inc sp
0x13ffb: dec di
0x13ffc: push dx
0x13ffd: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:47.890360892Z 53 PC: 14131 | Get interrupt vector (Interrupt = '218' AKA 'UNKNOWN!')
2018-12-25T12:35:47.89233795Z 76 PC: 13fb5 | Terminate with return code (Return code = '0')
2018-12-25T12:35:47.894345153Z 37 PC: 12e1a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:35:47.895171793Z 49 PC: 12e1f | Terminate and stay resident (Return code = '0' | Memory size = '85')

{"DateBased":true,"Day":31,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":12632,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:35:47.917847841Z 250 PC: 12a62 | UNKNOWN!
2018-12-25T12:35:47.918872011Z 42 PC: 12a66 | Get date 0x12a66: cmp dl, 0x1f
0x12a69: jne 0x12a7c
0x12a6b: cmp dh, 3
0x12a6e: jne 0x12a7c
0x12a70: mov ah, 9
0x12a72: mov dx, 0x13f
0x12a75: int 0x21
0x12a77: mov ax, 0x4c00
0x12a7a: int 0x21
0x12a7c: jmp 0x12bbc
0x12a7f: or cl, byte ptr [di]
0x12a81: push si
0x12a82: imul si, word ptr [bp + si + 0x75], 0x2073
0x12a87: dec bp
0x12a88: dec di
0x12a89: push dx
0x12a8a: inc sp
0x12a8b: dec di
0x12a8c: push dx
0x12a8d: and byte ptr [bp + 0x31], dh
2018-12-25T12:35:47.921689421Z 9 PC: 12a77 | Display string (Could not find end pointer)
2018-12-25T12:35:47.942959878Z 76 PC: 12a7c | Terminate with return code (Return code = '0')