.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:59:39.608979813Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:59:39.610549328Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:59:39.611722817Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:59:39.613086246Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:59:39.615073262Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:59:39.616419898Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:59:39.617553439Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:59:39.620196422Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:59:39.621093032Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:59:39.621979392Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:59:39.623406558Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:59:39.624273481Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:59:39.62515562Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:59:39.626191877Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:59:39.627499007Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:59:39.628432534Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:59:39.62931319Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:59:39.630927408Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:59:39.631957262Z | 53 | PC: 13f0a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:59:39.633278272Z | 37 | PC: 13f1f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:59:39.635097331Z | 37 | PC: 13f27 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:59:39.636271967Z | 37 | PC: 13f2f | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:59:39.637147878Z | 37 | PC: 13f37 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:59:39.639350672Z | 68 | PC: 14bdc | I/O control for devices (Set for = '�') |
2018-12-17T22:59:39.641147243Z | 44 | PC: 14d13 | Get time 0x14d13: mov word ptr [0x8a], cx 0x14d17: mov word ptr [0x8c], dx 0x14d1b: retf 0x14d1c: call 0x14d63 0x14d1f: jb 0x14d30 0x14d21: mov cx, word ptr es:[di + 4] 0x14d25: cmp cx, 1 0x14d28: je 0x14d30 0x14d2a: xor bx, bx 0x14d2c: push cs 0x14d2d: call 0x248a4 0x14d30: retf 4 0x14d33: call 0x14d63 0x14d36: jb 0x14d4b 0x14d38: mov ax, cx 0x14d3a: mov dx, bx 0x14d3c: mov cx, word ptr es:[di + 4] 0x14d40: cmp cx, 1 0x14d43: je 0x14d4b 0x14d45: xor bx, bx |
2018-12-17T22:59:39.643535548Z | 48 | PC: 147f2 | Get DOS version |
2018-12-17T22:59:39.646309888Z | 67 | PC: 13cdf | Get or set file attributes |
2018-12-17T22:59:39.649823881Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T22:59:39.665012315Z | 61 | PC: 14630 | Open file (Filename = 'A:\TEST.EXE') |
2018-12-17T22:59:39.672079185Z | 63 | PC: 14703 | Read file or device (Read 8 bytes on handle 5) |
2018-12-17T22:59:39.674807282Z | 66 | PC: 14762 | Move file pointer |
2018-12-17T22:59:39.676155773Z | 63 | PC: 14703 | Read file or device (Read 1 bytes on handle 5) |
2018-12-17T22:59:39.683478467Z | 63 | PC: 14703 | Read file or device (Read 6810 bytes on handle 5) |
2018-12-17T22:59:39.691136629Z | 60 | PC: 14630 | Create or truncate file |
2018-12-17T22:59:39.701975543Z | 63 | PC: 14703 | Read file or device (Read 10000 bytes on handle 5) |
2018-12-17T22:59:39.704529418Z | 66 | PC: 14d7d | Move file pointer |
2018-12-17T22:59:39.705945305Z | 66 | PC: 14d8b | Move file pointer |
2018-12-17T22:59:39.707299088Z | 66 | PC: 14d99 | Move file pointer |
2018-12-17T22:59:39.710525523Z | 62 | PC: 14680 | Close file |
2018-12-17T22:59:39.712340434Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T22:59:39.722508862Z | 62 | PC: 14680 | Close file |
2018-12-17T22:59:39.725244237Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:59:39.72648427Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:59:39.727836411Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:59:39.729712317Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:59:39.730749568Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:59:39.731771344Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:59:39.733231371Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:59:39.734299848Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:59:39.735210892Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:59:39.737836721Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:59:39.738931622Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:59:39.740027467Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:59:39.742073747Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:59:39.743342305Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:59:39.744524689Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:59:39.746795459Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:59:39.748168667Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:59:39.749642115Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:59:39.751258902Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:59:39.75298915Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:59:39.754027254Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:59:39.755092173Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:59:39.756492936Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:59:39.757682086Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:59:39.758809796Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:59:39.760027854Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:59:39.761183513Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:59:39.762257602Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:59:39.764169482Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:59:39.765705326Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:59:39.767169679Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:59:39.769666254Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:59:39.771137005Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:59:39.772645672Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:59:39.774964817Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:59:39.776185001Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:59:39.777418043Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:59:39.779752381Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:59:39.781330619Z | 41 | PC: 13e35 | Parse filename |
2018-12-17T22:59:39.782925298Z | 41 | PC: 13e43 | Parse filename |
2018-12-17T22:59:39.785058281Z | 75 | PC: 13e4e | Execute program |
2018-12-17T22:59:39.79356356Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:59:39.794963201Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:59:39.796932986Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:59:39.798088492Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:59:39.799146509Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:59:39.803213187Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:59:39.804497961Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:59:39.805610948Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:59:39.808746799Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:59:39.810214162Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:59:39.811919169Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:59:39.813776311Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:59:39.815137426Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:59:39.816447955Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:59:39.818601933Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:59:39.819824056Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:59:39.820999004Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:59:39.82284013Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:59:39.824600732Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:59:39.825720732Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:59:39.82749179Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:59:39.829068362Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:59:39.830620966Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:59:39.833034137Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:59:39.834508966Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:59:39.835821423Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:59:39.838417549Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:59:39.839530118Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:59:39.840567366Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:59:39.841815098Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:59:39.843278464Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:59:39.844529354Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:59:39.845955229Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:59:39.847643013Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:59:39.848563821Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:59:39.849433768Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:59:39.850963158Z | 53 | PC: 13e7e | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:59:39.852218062Z | 37 | PC: 13e87 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:59:39.853609994Z | 65 | PC: 14779 | Delete file (Filename = 'Victim.Exe') |
2018-12-17T22:59:39.880212074Z | 26 | PC: 13d7d | Set disk transfer address |
2018-12-17T22:59:39.881355286Z | 78 | PC: 13d89 | Find first file |
2018-12-17T22:59:39.887485418Z | 86 | PC: 147bd | Rename file |
2018-12-17T22:59:39.902366205Z | 60 | PC: 14630 | Create or truncate file |
2018-12-17T22:59:39.913936075Z | 67 | PC: 13cdf | Get or set file attributes |
2018-12-17T22:59:39.920140558Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T22:59:39.930321586Z | 61 | PC: 14630 | Open file (Filename = 'Victim.Exe') |
2018-12-17T22:59:39.936843457Z | 64 | PC: 14703 | Write file or device (Write 7091 bytes on handle 5) |
2018-12-17T22:59:39.945278516Z | 64 | PC: 14703 | Write file or device (Write 1 bytes on handle 5) |
2018-12-17T22:59:39.949383362Z | 64 | PC: 14703 | Write file or device (Write 6810 bytes on handle 5) |
2018-12-17T22:59:39.958817643Z | 63 | PC: 14703 | Read file or device (Read 10000 bytes on handle 6) |
2018-12-17T22:59:39.967349476Z | 64 | PC: 14703 | Write file or device (Write 10000 bytes on handle 5) |
2018-12-17T22:59:39.97562751Z | 66 | PC: 14d7d | Move file pointer |
2018-12-17T22:59:39.976684303Z | 66 | PC: 14d8b | Move file pointer |
2018-12-17T22:59:39.977732978Z | 66 | PC: 14d99 | Move file pointer |
2018-12-17T22:59:39.979450785Z | 63 | PC: 14703 | Read file or device (Read 10000 bytes on handle 6) |
2018-12-17T22:59:39.983911408Z | 64 | PC: 14703 | Write file or device (Write 3029 bytes on handle 5) |
2018-12-17T22:59:39.98957652Z | 66 | PC: 14d7d | Move file pointer |
2018-12-17T22:59:39.991357925Z | 66 | PC: 14d8b | Move file pointer |
2018-12-17T22:59:39.992324061Z | 66 | PC: 14d99 | Move file pointer |
2018-12-17T22:59:39.993646314Z | 87 | PC: 13d4d | Get or set file date and time |
2018-12-17T22:59:39.995252589Z | 62 | PC: 14680 | Close file |
2018-12-17T22:59:39.996508209Z | 67 | PC: 13d06 | Get or set file attributes |
2018-12-17T22:59:40.003356675Z | 62 | PC: 14680 | Close file |
2018-12-17T22:59:40.008382022Z | 65 | PC: 14779 | Delete file (Filename = 'Victim.Exe') |
2018-12-17T22:59:40.015795113Z | 26 | PC: 13da1 | Set disk transfer address |
2018-12-17T22:59:40.016635039Z | 79 | PC: 13da6 | Find next file |
2018-12-17T22:59:40.019011939Z | 26 | PC: 13da1 | Set disk transfer address |
2018-12-17T22:59:40.019859427Z | 79 | PC: 13da6 | Find next file |
2018-12-17T22:59:40.022017724Z | 64 | PC: 1458b | Write file or device (Write 0 bytes on handle 1) |
2018-12-17T22:59:40.02360782Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:59:40.024478336Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:59:40.025942664Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:59:40.026849342Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:59:40.027713725Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:59:40.029099947Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:59:40.029972403Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:59:40.030848354Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:59:40.032292444Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:59:40.033168618Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:59:40.0340358Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:59:40.035439715Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:59:40.03685814Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:59:40.037722662Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:59:40.039168393Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:59:40.040268227Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:59:40.041276012Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:59:40.042789317Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:59:40.043692206Z | 37 | PC: 14061 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:59:40.044603942Z | 76 | PC: 140a0 | Terminate with return code (Return code = '0') |