Sample viewer

vx.netlux.org/Virus.DOS.HLLP.5074

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:01:37.544928978Z 53 PC: 132fa | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:37.558940347Z 53 PC: 132fa | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:37.560079371Z 53 PC: 132fa | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:37.561052809Z 53 PC: 132fa | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:37.563091782Z 53 PC: 132fa | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:37.563966708Z 53 PC: 132fa | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:37.564991937Z 53 PC: 132fa | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:37.567901324Z 53 PC: 132fa | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:37.568970848Z 53 PC: 132fa | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:37.575109948Z 53 PC: 132fa | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:37.576844361Z 53 PC: 132fa | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:37.577855253Z 53 PC: 132fa | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:37.579100403Z 53 PC: 132fa | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:37.581195294Z 53 PC: 132fa | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:37.58274067Z 53 PC: 132fa | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:37.584204473Z 53 PC: 132fa | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:37.587017901Z 53 PC: 132fa | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:37.588769132Z 53 PC: 132fa | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:37.590120601Z 53 PC: 132fa | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:37.591879326Z 37 PC: 1330f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:37.594194496Z 37 PC: 13317 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:37.595734178Z 37 PC: 1331f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:37.597027722Z 37 PC: 13327 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:37.610888516Z 68 PC: 14081 | I/O control for devices (Set for = '\')
2018-12-17T22:01:37.612666756Z 44 PC: 141b8 | Get time 0x141b8: mov word ptr [0x3e], cx
0x141bc: mov word ptr [0x40], dx
0x141c0: retf
0x141c1: call 0x14208
0x141c4: jb 0x141d5
0x141c6: mov cx, word ptr es:[di + 4]
0x141ca: cmp cx, 1
0x141cd: je 0x141d5
0x141cf: xor bx, bx
0x141d1: push cs
0x141d2: call 0x23d44
0x141d5: retf 4
0x141d8: call 0x14208
0x141db: jb 0x141f0
0x141dd: mov ax, cx
0x141df: mov dx, bx
0x141e1: mov cx, word ptr es:[di + 4]
0x141e5: cmp cx, 1
0x141e8: je 0x141f0
0x141ea: xor bx, bx
2018-12-17T22:01:37.615114171Z 25 PC: 13c39 | Get default drive
2018-12-17T22:01:37.617348368Z 71 PC: 13c4c | Get current directory
2018-12-17T22:01:37.621736411Z 42 PC: 12d8b | Get date 0x12d8b: mov byte ptr [0xff], dh
0x12d8f: cmp byte ptr [0xff], 2
0x12d94: jne 0x12dee
0x12d96: cmp byte ptr [0x201], 0x43
0x12d9b: jb 0x12dad
0x12d9d: mov al, byte ptr [0x201]
0x12da0: xor ah, ah
0x12da2: add ax, 0x7f
0x12da5: sub ax, 0x42
0x12da8: mov byte ptr [0xff], al
0x12dab: jmp 0x12db8
0x12dad: mov al, byte ptr [0x201]
0x12db0: xor ah, ah
0x12db2: sub ax, 0x41
0x12db5: mov byte ptr [0xff], al
0x12db8: mov dl, byte ptr [0xff]
0x12dbc: mov dh, 0
0x12dbe: mov ch, 0
0x12dc0: mov cl, 1
0x12dc2: mov al, 1
2018-12-17T22:01:37.624373532Z 26 PC: 130fd | Set disk transfer address
2018-12-17T22:01:37.625636158Z 78 PC: 13109 | Find first file
2018-12-17T22:01:37.629373158Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.630354514Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.632356514Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.633652705Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.63597648Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.637661906Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.640131453Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.641384871Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.644025849Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.644904753Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.646771977Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.64862552Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.650506045Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.651346151Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.653722765Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.654646322Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.656548246Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.658824381Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.661956146Z 26 PC: 130fd | Set disk transfer address
2018-12-17T22:01:37.662980332Z 78 PC: 13109 | Find first file
2018-12-17T22:01:37.669945066Z 67 PC: 1305f | Get or set file attributes
2018-12-17T22:01:37.675998363Z 67 PC: 13086 | Get or set file attributes
2018-12-17T22:01:37.691523036Z 61 PC: 139ea | Open file (Filename = 'TEST.EXE')
2018-12-17T22:01:37.698595702Z 66 PC: 14222 | Move file pointer
2018-12-17T22:01:37.699789806Z 66 PC: 14230 | Move file pointer
2018-12-17T22:01:37.701127154Z 66 PC: 1423e | Move file pointer
2018-12-17T22:01:37.702814007Z 66 PC: 13b1c | Move file pointer
2018-12-17T22:01:37.704518617Z 63 PC: 13a7c | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:01:37.708954757Z 67 PC: 13086 | Get or set file attributes
2018-12-17T22:01:37.715985956Z 62 PC: 13a3a | Close file
2018-12-17T22:01:37.717940857Z 26 PC: 13121 | Set disk transfer address
2018-12-17T22:01:37.718794337Z 79 PC: 13126 | Find next file
2018-12-17T22:01:37.721398444Z 48 PC: 13bac | Get DOS version
2018-12-17T22:01:37.72288164Z 61 PC: 139ea | Open file (Filename = 'A:\TEST.EXE')
2018-12-17T22:01:37.727155252Z 60 PC: 139ea | Create or truncate file
2018-12-17T22:01:37.73796839Z 60 PC: 139ea | Create or truncate file
2018-12-17T22:01:37.749449543Z 63 PC: 13abd | Read file or device (Read 5074 bytes on handle 5)
2018-12-17T22:01:37.756653441Z 64 PC: 13abd | Write file or device (Write 5074 bytes on handle 6)
2018-12-17T22:01:37.765620311Z 63 PC: 13abd | Read file or device (Read 5074 bytes on handle 5)
2018-12-17T22:01:37.77318364Z 64 PC: 13abd | Write file or device (Write 5074 bytes on handle 7)
2018-12-17T22:01:37.781940664Z 63 PC: 13abd | Read file or device (Read 5074 bytes on handle 5)
2018-12-17T22:01:37.786117305Z 64 PC: 13abd | Write file or device (Write 46 bytes on handle 7)
2018-12-17T22:01:37.789044382Z 63 PC: 13abd | Read file or device (Read 5074 bytes on handle 5)
2018-12-17T22:01:37.790864255Z 62 PC: 13a3a | Close file
2018-12-17T22:01:37.792511713Z 62 PC: 13a3a | Close file
2018-12-17T22:01:37.800785306Z 62 PC: 13a3a | Close file
2018-12-17T22:01:37.807987153Z 65 PC: 13b33 | Delete file (Filename = '~')
2018-12-17T22:01:37.819146675Z 53 PC: 1326c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:37.821500962Z 37 PC: 13275 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:37.822770265Z 53 PC: 1326c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:37.824454216Z 37 PC: 13275 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:37.832345491Z 53 PC: 1326c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:37.833403128Z 37 PC: 13275 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:37.834347087Z 53 PC: 1326c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:37.835971274Z 37 PC: 13275 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:37.836998764Z 53 PC: 1326c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:37.838089784Z 37 PC: 13275 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:37.840015168Z 53 PC: 1326c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:37.841098664Z 37 PC: 13275 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:37.842150609Z 53 PC: 1326c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:37.8439143Z 37 PC: 13275 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:37.844884524Z 53 PC: 1326c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:37.84591274Z 37 PC: 13275 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:37.84758258Z 53 PC: 1326c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:37.848952773Z 37 PC: 13275 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:37.850210863Z 53 PC: 1326c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:37.852026628Z 37 PC: 13275 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:37.853042796Z 53 PC: 1326c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:37.854055492Z 37 PC: 13275 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:37.857295617Z 53 PC: 1326c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:37.858296043Z 37 PC: 13275 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:37.859236966Z 53 PC: 1326c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:37.860904702Z 37 PC: 13275 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:37.861898718Z 53 PC: 1326c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:37.862898577Z 37 PC: 13275 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:37.864715987Z 53 PC: 1326c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:37.865828047Z 37 PC: 13275 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:37.866774451Z 53 PC: 1326c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:37.868645808Z 37 PC: 13275 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:37.869793461Z 53 PC: 1326c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:37.871042081Z 37 PC: 13275 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:37.873136603Z 53 PC: 1326c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:37.874403354Z 37 PC: 13275 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:37.875641287Z 53 PC: 1326c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:37.878088618Z 37 PC: 13275 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:37.880191043Z 41 PC: 13223 | Parse filename
2018-12-17T22:01:37.881941357Z 41 PC: 13231 | Parse filename
2018-12-17T22:01:37.883787508Z 75 PC: 1323c | Execute program
2018-12-17T22:01:37.898430167Z 9 PC: 24edc | Display string (String= 'ЪрюрмJWUWФ€€€€€€€€€€€€€€€„')
2018-12-17T22:01:37.903826725Z 76 PC: 24ee1 | Terminate with return code (Return code = '0')
2018-12-17T22:01:37.907050881Z 53 PC: 1326c | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:37.908418967Z 37 PC: 13275 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:37.909455004Z 53 PC: 1326c | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:37.910716026Z 37 PC: 13275 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:37.912506338Z 53 PC: 1326c | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:37.913601977Z 37 PC: 13275 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:37.914659778Z 53 PC: 1326c | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:37.916327352Z 37 PC: 13275 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:37.917374513Z 53 PC: 1326c | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:37.918451172Z 37 PC: 13275 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:37.920295607Z 53 PC: 1326c | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:37.921226797Z 37 PC: 13275 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:37.92215381Z 53 PC: 1326c | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:37.924333386Z 37 PC: 13275 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:37.925625845Z 53 PC: 1326c | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:37.926922288Z 37 PC: 13275 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:37.92918328Z 53 PC: 1326c | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:37.930279327Z 37 PC: 13275 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:37.931321775Z 53 PC: 1326c | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:37.933417651Z 37 PC: 13275 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:37.934462412Z 53 PC: 1326c | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:37.935535913Z 37 PC: 13275 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:37.937706089Z 53 PC: 1326c | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:37.938752411Z 37 PC: 13275 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:37.93979623Z 53 PC: 1326c | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:37.941451832Z 37 PC: 13275 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:37.942803575Z 53 PC: 1326c | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:37.944117598Z 37 PC: 13275 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:37.949063713Z 53 PC: 1326c | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:37.950980335Z 37 PC: 13275 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:37.952002383Z 53 PC: 1326c | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:37.954143513Z 37 PC: 13275 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:37.955420959Z 53 PC: 1326c | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:37.956713556Z 37 PC: 13275 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:37.95832371Z 53 PC: 1326c | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:37.959681787Z 37 PC: 13275 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:37.960915042Z 53 PC: 1326c | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:37.962978696Z 37 PC: 13275 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:37.964341001Z 65 PC: 13b33 | Delete file (Filename = '`ј`0')
2018-12-17T22:01:37.975804661Z 14 PC: 13c92 | Set default drive (Drive = 'A')
2018-12-17T22:01:37.978212671Z 25 PC: 13c96 | Get default drive
2018-12-17T22:01:37.979742012Z 59 PC: 13d00 | Change current directory
2018-12-17T22:01:37.984369076Z 64 PC: 13718 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:01:37.986901883Z 37 PC: 13451 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:01:37.988028383Z 37 PC: 13451 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:01:37.990489463Z 37 PC: 13451 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:01:37.997930374Z 37 PC: 13451 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:01:37.999530507Z 37 PC: 13451 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:01:38.00173867Z 37 PC: 13451 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:01:38.003311172Z 37 PC: 13451 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:01:38.004906192Z 37 PC: 13451 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:01:38.007133368Z 37 PC: 13451 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:01:38.008470541Z 37 PC: 13451 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:01:38.00980682Z 37 PC: 13451 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:01:38.011702248Z 37 PC: 13451 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:01:38.013200383Z 37 PC: 13451 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:01:38.014759571Z 37 PC: 13451 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:01:38.016954202Z 37 PC: 13451 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:01:38.01820736Z 37 PC: 13451 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:01:38.019488494Z 37 PC: 13451 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:01:38.021828632Z 37 PC: 13451 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:01:38.023123088Z 37 PC: 13451 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:01:38.024407901Z 76 PC: 13490 | Terminate with return code (Return code = '0')