Sample viewer

vx.netlux.org/Virus.DOS.Noiembrie.610

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:01:18.124758868Z 78 PC: 12a6e | Find first file
2018-12-17T23:01:18.131214621Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.14866742Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:01:18.154987403Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.161674524Z 66 PC: 12af6 | Move file pointer
2018-12-17T23:01:18.163776968Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.166401549Z 66 PC: 12b1e | Move file pointer
2018-12-17T23:01:18.167670066Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-17T23:01:18.16968491Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-17T23:01:18.174685183Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-17T23:01:18.182658425Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.197856391Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.199326137Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.207176844Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.217099496Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.219710216Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.229824654Z 61 PC: 12a9e | Open file (Filename = 'PRINT.COM')
2018-12-17T23:01:18.237029767Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.243174415Z 66 PC: 12af6 | Move file pointer
2018-12-17T23:01:18.244615839Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.248007635Z 66 PC: 12b1e | Move file pointer
2018-12-17T23:01:18.249621101Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-17T23:01:18.25215414Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-17T23:01:18.260340336Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-17T23:01:18.262904282Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.265419122Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.267370643Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.275098587Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.284832478Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.288681562Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.298323437Z 61 PC: 12a9e | Open file (Filename = 'HELLO.COM')
2018-12-17T23:01:18.304895064Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.311790186Z 66 PC: 12af6 | Move file pointer
2018-12-17T23:01:18.313116243Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.315590361Z 66 PC: 12b1e | Move file pointer
2018-12-17T23:01:18.317479305Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-17T23:01:18.320009752Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-17T23:01:18.328031966Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-17T23:01:18.331762932Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.33462172Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.336029835Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.344398174Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.353928187Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.356529257Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.367275022Z 61 PC: 12a9e | Open file (Filename = 'PHANG.COM')
2018-12-17T23:01:18.373625614Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.379640858Z 66 PC: 12af6 | Move file pointer
2018-12-17T23:01:18.381186879Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.383596187Z 66 PC: 12b1e | Move file pointer
2018-12-17T23:01:18.385221948Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-17T23:01:18.387774657Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-17T23:01:18.395576338Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-17T23:01:18.39802461Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.401393708Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.403007908Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.410269225Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.419499305Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.422361923Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.432372575Z 61 PC: 12a9e | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:01:18.438668497Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.446016401Z 66 PC: 12af6 | Move file pointer
2018-12-17T23:01:18.447290609Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.449787681Z 66 PC: 12b1e | Move file pointer
2018-12-17T23:01:18.451983949Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-17T23:01:18.454702998Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-17T23:01:18.462480283Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-17T23:01:18.466835058Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.470099094Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.471838695Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.480208652Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.489859572Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.492675584Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.502742857Z 61 PC: 12a9e | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:01:18.509709674Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.515933693Z 66 PC: 12af6 | Move file pointer
2018-12-17T23:01:18.517431525Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.520691391Z 66 PC: 12b1e | Move file pointer
2018-12-17T23:01:18.522159265Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-17T23:01:18.530816161Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-17T23:01:18.539196094Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-17T23:01:18.54190838Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.544590501Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.546746544Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.553995858Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.56368284Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.567676228Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.577414877Z 61 PC: 12a9e | Open file (Filename = 'PAH.COM')
2018-12-17T23:01:18.583916365Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.590986803Z 66 PC: 12af6 | Move file pointer
2018-12-17T23:01:18.592631505Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.595555211Z 66 PC: 12b1e | Move file pointer
2018-12-17T23:01:18.597831697Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-17T23:01:18.601501641Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-17T23:01:18.609544611Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-17T23:01:18.61352479Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:01:18.616472955Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.618282289Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.626978754Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.636800137Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.639807302Z 67 PC: 12a91 | Get or set file attributes
2018-12-17T23:01:18.650376566Z 61 PC: 12a9e | Open file (Filename = 'TEST.COM')
2018-12-17T23:01:18.656805011Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:01:18.659295449Z 87 PC: 12ba6 | Get or set file date and time
2018-12-17T23:01:18.661502441Z 62 PC: 12baf | Close file
2018-12-17T23:01:18.670895295Z 67 PC: 12bc1 | Get or set file attributes
2018-12-17T23:01:18.684038349Z 79 PC: 12bcd | Find next file
2018-12-17T23:01:18.686713881Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-17T23:01:18.688695909Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":2,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:11.04260663Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:11.047261633Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:11.35348455Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:11.365050055Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:11.372677717Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:11.374325465Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.377040451Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:11.378722928Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:11.381773075Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:11.390089499Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:11.393113031Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.396918331Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:11.398886599Z 62 PC: 12baf | Close file
2018-12-25T12:39:11.406439384Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:11.417366691Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:11.420212696Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.429902488Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.437178715Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.443502227Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.44548726Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.449720508Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.451317028Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.454098159Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.462786076Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.465411362Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.468164216Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.470603018Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.478261671Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.488430309Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.491819552Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.501759769Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.508455412Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.515398175Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.517077257Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.519615164Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.521153454Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.523883734Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.531383403Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.533911707Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.536909437Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.538262947Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.545376339Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.55528275Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.558068036Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.567597549Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.574702424Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.581211428Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.582666528Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.585737785Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.587070871Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.589561754Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.597655407Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.599626853Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.602126306Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.604019706Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.611489481Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.621283106Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.624464254Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.634146081Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.64169833Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.648998719Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.650579821Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.653359225Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.655588867Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.658213216Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.666270456Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.669644275Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.672166494Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.673573726Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.681350586Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.691358424Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.694022459Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.703998158Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.712264111Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.719151954Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.720530562Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.723527617Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.724790285Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.730064986Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.737080716Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.738959737Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.740798151Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.742739975Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.747913483Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.754519586Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.757396209Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.764400162Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.768788079Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.773423045Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.774909116Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.777102972Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.778890868Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.781159553Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.790744531Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.793776209Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.796221678Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.797492585Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.805076785Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.814510305Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.816899211Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.827873144Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.834531409Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.840767244Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.842853731Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.849996559Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.859510515Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.862760896Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:11.864733946Z 9 PC: 12bfb | Display string (String= 'Sunday error 262 at 7053:0122')
2018-12-25T12:39:11.866866177Z 76 PC: 12c00 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":9,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:11.335023919Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:11.34176438Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:11.36460405Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:11.378115162Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:11.392546377Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:11.393983854Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.396494158Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:11.397863608Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:11.400781951Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:11.408708865Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:11.411494288Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.414935365Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:11.417325544Z 62 PC: 12baf | Close file
2018-12-25T12:39:11.425024707Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:11.435978449Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:11.438690109Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.44820448Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.456806792Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.463297638Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.464894127Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.470610444Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.472192774Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.474988377Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.483608079Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.486261864Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.488844362Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.490731559Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.498348141Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.508262059Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.511503006Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.520128484Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.526586993Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.532723343Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.53456552Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.537282492Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.53890254Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.542066987Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.549725128Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.552417484Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.555411231Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.556858682Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.564308794Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.574444742Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.576897721Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.586184735Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.592920399Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.60492268Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.606213969Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.609526423Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.611062022Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.613717066Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.621986566Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.624984018Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.627959445Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.629975779Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.637914573Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.647417724Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.650961714Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.66033728Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.667159458Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.674427886Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.676055976Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.678842324Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.68119008Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.683799131Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.692149468Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.697143819Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.700461412Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.70181254Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.710263336Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.719972835Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.72274616Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.732921036Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.743668371Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.749812377Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.75170027Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.754212419Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.755919561Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.765222Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.773199629Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.775847834Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.779782677Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.781147166Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.791750483Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.801424111Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.803794797Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.813115769Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.820128445Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.826223612Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.827411778Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.829905021Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.831182814Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.833464531Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.838982845Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.842730505Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.845405635Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.846862481Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.854207683Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.864019154Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.867018995Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.877490044Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.884004221Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.890102886Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.891802678Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.901555025Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.911061383Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.914792714Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:11.917100692Z 9 PC: 12bfb | Display string (String= '9 Noiembrie 1979 - Ziua Lui Cosmin NoNov - HCA Romania September 1996')
2018-12-25T12:39:11.920257149Z 76 PC: 12c00 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:11.33557533Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:11.342350731Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:11.364755368Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:11.371438255Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:11.377708658Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:11.379897664Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.382468727Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:11.383814547Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:11.387469439Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:11.395739972Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:11.398292778Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.401756511Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:11.403190123Z 62 PC: 12baf | Close file
2018-12-25T12:39:11.410740953Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:11.421292488Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:11.42412484Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.433726907Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.44127856Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.450065273Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.451423411Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.454087716Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.455795739Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.459344429Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.46718776Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.470366786Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.472953147Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.474440636Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.482347087Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.49214949Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.494842764Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.506102152Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.513640269Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.522871425Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.524816442Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.527468279Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.528901741Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.532353966Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.540245258Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.54282673Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.546512414Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.548181539Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.556778274Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.563191214Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.565693806Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.5752416Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.581863109Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.588918742Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.590185211Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.59305379Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.5950943Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.597807847Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.605813052Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.608790107Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.611297794Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.612882994Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.620743905Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.630267394Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.632963826Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.643145654Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.649837172Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.656756349Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.659398397Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.662264278Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.663994456Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.667799124Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.676151825Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.679237259Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.682681513Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.684486518Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.692204316Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.703177691Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.70572565Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.715414843Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.72307604Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.729243884Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.730904379Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.734487774Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.736394595Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.744133569Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.752791554Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.755594902Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.758080711Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.760143564Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.76733143Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.776871514Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.779732249Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.79341982Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.799775408Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.806364796Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.807597974Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.809961436Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.811625463Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.814064377Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.821576195Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.824675595Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.827393985Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.829070166Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.837401815Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.847590737Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.850277184Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.861026829Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.868164724Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.870669832Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.872582211Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.879385745Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.888870875Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.892043978Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:11.894140505Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":6,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:11.330569873Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:11.337983814Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:11.354177744Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:11.36738061Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:11.374730799Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:11.377159728Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.380102761Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:11.381746701Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:11.385788344Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:11.391547095Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:11.394932424Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:11.397940268Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:11.399235552Z 62 PC: 12baf | Close file
2018-12-25T12:39:11.404403255Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:11.418449236Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:11.421466Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.430288354Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.438337996Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.446673368Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.453099816Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.456642424Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.458257328Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.461476841Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.470700555Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.476564369Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.479467069Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.481072421Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.490104242Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.500972047Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.503820192Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.515334865Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.522860207Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.530408951Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.533387641Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.53767717Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.539871821Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.544384295Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.553311674Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.555415778Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.557722275Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.559330427Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.564665884Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.571277924Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.573596062Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.580875143Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.587549918Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.594580896Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.596106617Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.598953815Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.601396427Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.604285529Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.612783987Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.616735696Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.619664543Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.621063288Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.629067105Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.639967222Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.649911644Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.661271665Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.668592765Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.675482879Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.678466144Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.681325591Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.682796104Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.686435082Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.695175277Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.69813213Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.701010938Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.717833858Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.727293676Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.738660048Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.742216889Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.752981797Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.760349916Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.767757781Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.76923085Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.772234502Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.774924101Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.783778964Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.793222814Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.79765063Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.800990499Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.803001569Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.812626733Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.824011334Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.826876358Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.838466242Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.844176742Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.849109476Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:11.850461877Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:11.854860118Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:11.856229039Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:11.858560725Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:11.868827488Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:11.872005357Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:11.874828194Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.877100515Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.885590478Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.896320804Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.900177203Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:11.911236332Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:11.919468692Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:11.926975167Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:11.929045776Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:11.937292462Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:11.948764054Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:11.95267983Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:11.955485831Z 9 PC: 12bfb | Display string (String= 'Sunday error 262 at 7053:0122')
2018-12-25T12:39:11.958423929Z 76 PC: 12c00 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:12.164544173Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:12.172252631Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:12.187994148Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:12.195433716Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:12.202852647Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:12.204606768Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.207469302Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:12.209066133Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:12.212250658Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:12.221112123Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:12.224194245Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.227350214Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:12.22890022Z 62 PC: 12baf | Close file
2018-12-25T12:39:12.237829001Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:12.249747957Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:12.252708592Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.26334832Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.271133404Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.278106323Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.279526084Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.29710842Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.298665815Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.301527695Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.317799113Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.321912998Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.324771482Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.326792558Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.335411862Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.346295993Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.352547212Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.36349707Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.370844492Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.378053838Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.380243316Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.383643077Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.385704326Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.390244147Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.399548937Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.403120835Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.4069309Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.408589274Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.417325564Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.428776792Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.431701583Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.442418462Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.464320038Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.46953996Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.470752318Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.473626786Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.475017924Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.477101582Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.482975889Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.484920903Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.486738408Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.488360086Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.494418536Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.500852951Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.502813671Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.51487505Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.519419611Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.523627039Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.533487495Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.536368735Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.537966283Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.541502984Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.551063871Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.554165687Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.557659565Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.559278037Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.567709794Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.579499177Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.582361016Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.592994205Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.602244316Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.609093127Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.610674322Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.615291502Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.617034474Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.626063085Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.635535223Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.638958932Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.641949985Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.643824908Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.653359952Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.665606545Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.66896002Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.685762952Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.692824149Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.699639885Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.703134174Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.7061289Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.70775423Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.711692193Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.720252645Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.723136353Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.727481136Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.729200837Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.737495773Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.748980223Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.753018271Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.763626134Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.771469862Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.774208988Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.775691251Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.798241155Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.809191706Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.812905639Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:12.816093223Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":9,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:12.345503526Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:12.349550485Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:12.362084266Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:12.373265772Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:12.37998615Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:12.381257858Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.384138905Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:12.387153682Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:12.389992024Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:12.397653144Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:12.410163981Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.413874027Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:12.415688883Z 62 PC: 12baf | Close file
2018-12-25T12:39:12.42334552Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:12.433271124Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:12.436122395Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.446050281Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.45456963Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.460635191Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.461824359Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.465646819Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.467069789Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.469539817Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.479425787Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.481920094Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.484385092Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.494375655Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.503011835Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.51254375Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.51598184Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.525470542Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.531916332Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.54257763Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.543597268Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.545221372Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.54655172Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.548269977Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.553107943Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.555624427Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.557295793Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.558283266Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.563558226Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.569877059Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.571748199Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.578437103Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.585160242Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.591804642Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.594028517Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.596599578Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.598022865Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.601380192Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.609138524Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.612496857Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.615591856Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.616924434Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.624476002Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.635157276Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.639621753Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.649207947Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.655761733Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.662428477Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.664028975Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.667004183Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.671853478Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.674311094Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.68251031Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.685237542Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.687665817Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.689230635Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.697382982Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.706902141Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.709790746Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.720399058Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.727723748Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.735342941Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.737630023Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.740326739Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.741866608Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.750951296Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.759196983Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.761762491Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.765321357Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.766870158Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.774199195Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.785277146Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.787839317Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.796579339Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.803340054Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.809929989Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.811207894Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.81417591Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.815628546Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.818258135Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.827457742Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.830212325Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.849254768Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.851882003Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.859425948Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.869422469Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.873920012Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.8844966Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.891053004Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.898187164Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.89964136Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.907357191Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.918104205Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.920887357Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:12.923445005Z 9 PC: 12bfb | Display string (String= '9 Noiembrie 1979 - Ziua Lui Cosmin NoNov - HCA Romania September 1996')
2018-12-25T12:39:12.929937981Z 76 PC: 12c00 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:12.451369982Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:12.457616276Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:12.473123195Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:12.490454078Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:12.497524305Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:12.499145122Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.501860666Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:12.503752267Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:12.506635217Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:12.514113843Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:12.516719608Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.520138365Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:12.52154985Z 62 PC: 12baf | Close file
2018-12-25T12:39:12.528861983Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:12.53877447Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:12.540554631Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.547522906Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.555319439Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.561641854Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.563044793Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.568072564Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.56971407Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.572558517Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.582605636Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.585408756Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.58812626Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.590193691Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.597943149Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.607531333Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.610802423Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.620164865Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.627171058Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.633771653Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.635103451Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.63751689Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.642487063Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.645278189Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.653578817Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.65727527Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.660569976Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.662312336Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.66994069Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.679925083Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.681738083Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.68828568Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.693067555Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.697605503Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.699116117Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.702352538Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.70393096Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.706415358Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.714991988Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.717869201Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.720579891Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.723021907Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.730609984Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.740405836Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.743887257Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.753450772Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.760623082Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.767355317Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.76865644Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.771170816Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.772674779Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.776494075Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.784157585Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.78674594Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.789690831Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.791034743Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.79857192Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.808673447Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.811338781Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.821128904Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.82956107Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.837234844Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.838876778Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.842468852Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.84415325Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.851891822Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.86129308Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.864352142Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.867333948Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.869854709Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.882906545Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.906595349Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.90994805Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.91955481Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.926058719Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.934622554Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.9361309Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.940411836Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.942653553Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.945253422Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.953187816Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.957457853Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.959789593Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.96147209Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.96915358Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.976997876Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.979136378Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.991452882Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.998947489Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:13.004471638Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:13.006308127Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:13.014279447Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:13.024813048Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:13.027535493Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:13.03067717Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":6,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:12.524891468Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:12.532595498Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:12.547642349Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:12.558726264Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:12.565325797Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:12.566583699Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.569040242Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:12.572110549Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:12.575018594Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:12.582611455Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:12.585589364Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.590689168Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:12.59293617Z 62 PC: 12baf | Close file
2018-12-25T12:39:12.60113253Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:12.61095979Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:12.613626881Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.623236728Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.634121482Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.640917679Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.642160165Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.645197586Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.646586115Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.649103894Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.65775771Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.660589573Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.663112613Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.664959268Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.672445322Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.681961331Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.684986359Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.69446163Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.70146224Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.708541877Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.710060383Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.712669634Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.715428883Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.718230725Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.726469014Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.729915375Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.732944092Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.733994972Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.740848766Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.751107131Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.75360171Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.762935988Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.770939732Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.777303223Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.778586521Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.782000493Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.783411432Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.785938733Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.794476051Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.797236556Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.799808794Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.802168808Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.80954731Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.81907553Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.822726565Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.844440004Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.851060875Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.857692128Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.859453388Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.862421973Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.864413895Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.873814246Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.882132668Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.884885198Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.888180493Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.889548495Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.89711432Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.907581856Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.909983133Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.92071235Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.929027556Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.934391522Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.935755539Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.938498247Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.940620652Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.949123147Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.958214965Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.961462872Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.964336549Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.966790957Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.974750112Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.984522298Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.988236208Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.998141982Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:13.005065799Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:13.012426969Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:13.014161138Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:13.017097985Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:13.019691822Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:13.022819247Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:13.030804073Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:13.034690732Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:13.037996136Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:13.039882709Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:13.04894688Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:13.059214667Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:13.062155989Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:13.072272693Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:13.079749789Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:13.085989499Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:13.087423743Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:13.095366365Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:13.120190218Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:13.12262926Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:13.125587479Z 9 PC: 12bfb | Display string (String= 'Sunday error 262 at 7053:0122')
2018-12-25T12:39:13.12828158Z 76 PC: 12c00 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T13:07:24.919718279Z 78 PC: 12a6e | Find first file
2018-12-25T13:07:24.924722586Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T13:07:24.938109085Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T13:07:24.945607745Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T13:07:24.952840794Z 66 PC: 12af6 | Move file pointer
2018-12-25T13:07:24.954109167Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T13:07:24.956628046Z 66 PC: 12b1e | Move file pointer
2018-12-25T13:07:24.958344536Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T13:07:24.961851189Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T13:07:24.969841962Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T13:07:24.973608636Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T13:07:24.976577418Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T13:07:24.97841881Z 62 PC: 12baf | Close file
2018-12-25T13:07:24.988944113Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T13:07:24.999550051Z 79 PC: 12bcd | Find next file
2018-12-25T13:07:25.002453777Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T13:07:25.009481887Z 61 PC: 12a9e | Open file (See above)
2018-12-25T13:07:25.017301164Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T13:07:25.023152904Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T13:07:25.024506167Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T13:07:25.028971527Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T13:07:25.030322828Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T13:07:25.032577306Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T13:07:25.039096952Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T13:07:25.04106814Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T13:07:25.043342715Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T13:07:25.045397445Z 62 PC: 12baf | Close file (See above)
2018-12-25T13:07:25.053080632Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T13:07:25.062615375Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T13:07:25.065740642Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T13:07:25.075166634Z 61 PC: 12a9e | Open file (See above)
2018-12-25T13:07:25.081641467Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T13:07:25.088504802Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T13:07:25.089857822Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T13:07:25.093067429Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T13:07:25.094864108Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T13:07:25.097680858Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T13:07:25.105551511Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T13:07:25.109118436Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T13:07:25.111748713Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T13:07:25.113115574Z 62 PC: 12baf | Close file (See above)
2018-12-25T13:07:25.121083762Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T13:07:25.131093774Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T13:07:25.133859619Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T13:07:25.143549411Z 61 PC: 12a9e | Open file (See above)
2018-12-25T13:07:25.150194355Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T13:07:25.156243117Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T13:07:25.158402044Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T13:07:25.160883478Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T13:07:25.16235192Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T13:07:25.165568523Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T13:07:25.175607718Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T13:07:25.178359317Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T13:07:25.181448003Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T13:07:25.183122287Z 62 PC: 12baf | Close file (See above)
2018-12-25T13:07:25.191384461Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T13:07:25.20176639Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T13:07:25.204783889Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T13:07:25.214640853Z 61 PC: 12a9e | Open file (See above)
2018-12-25T13:07:25.219874786Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T13:07:25.226709807Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T13:07:25.227774274Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T13:07:25.229910127Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T13:07:25.231544179Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T13:07:25.233300463Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T13:07:25.238563018Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T13:07:25.24110771Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T13:07:25.242975134Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T13:07:25.244175661Z 62 PC: 12baf | Close file (See above)
2018-12-25T13:07:25.2494911Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T13:07:25.256792924Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T13:07:25.260467129Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T13:07:25.270356169Z 61 PC: 12a9e | Open file (See above)
2018-12-25T13:07:25.276682926Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T13:07:25.282950832Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T13:07:25.285037304Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T13:07:25.287842708Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T13:07:25.289178174Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T13:07:25.295261086Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T13:07:25.301144597Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T13:07:25.303171287Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T13:07:25.305360833Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T13:07:25.306409602Z 62 PC: 12baf | Close file (See above)
2018-12-25T13:07:25.312304506Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T13:07:25.319963753Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T13:07:25.323218421Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T13:07:25.332208918Z 61 PC: 12a9e | Open file (See above)
2018-12-25T13:07:25.337530801Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T13:07:25.344378064Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T13:07:25.347570807Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T13:07:25.351320784Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T13:07:25.353162088Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T13:07:25.356519568Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T13:07:25.365484776Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T13:07:25.368186868Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T13:07:25.370762026Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T13:07:25.372770341Z 62 PC: 12baf | Close file (See above)
2018-12-25T13:07:25.380107835Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T13:07:25.389790677Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T13:07:25.393579215Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T13:07:25.403197665Z 61 PC: 12a9e | Open file (See above)
2018-12-25T13:07:25.409713988Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T13:07:25.417177107Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T13:07:25.418523612Z 62 PC: 12baf | Close file (See above)
2018-12-25T13:07:25.428176683Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T13:07:25.440222866Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T13:07:25.443072346Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T13:07:25.445470258Z 76 PC: 12a45 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":2,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":13820,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:39:12.567936371Z 78 PC: 12a6e | Find first file
2018-12-25T12:39:12.575230346Z 67 PC: 12a91 | Get or set file attributes
2018-12-25T12:39:12.593055437Z 61 PC: 12a9e | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:39:12.600407119Z 63 PC: 12adb | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:39:12.608242796Z 66 PC: 12af6 | Move file pointer
2018-12-25T12:39:12.613234141Z 64 PC: 12b0c | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.61552215Z 66 PC: 12b1e | Move file pointer
2018-12-25T12:39:12.617086125Z 64 PC: 12b44 | Write file or device (Write 18 bytes on handle 5)
2018-12-25T12:39:12.620100513Z 64 PC: 12b55 | Write file or device (Write 546 bytes on handle 5)
2018-12-25T12:39:12.629001517Z 64 PC: 12b68 | Write file or device (Write 42 bytes on handle 5)
2018-12-25T12:39:12.632896908Z 64 PC: 12b94 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:39:12.636095918Z 87 PC: 12ba6 | Get or set file date and time
2018-12-25T12:39:12.637823847Z 62 PC: 12baf | Close file
2018-12-25T12:39:12.646153235Z 67 PC: 12bc1 | Get or set file attributes
2018-12-25T12:39:12.657675721Z 79 PC: 12bcd | Find next file
2018-12-25T12:39:12.660614791Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.671430496Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.679482432Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.690612112Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.693323434Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.696725142Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.698564108Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.702143016Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.711827587Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.71488536Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.717611673Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.719120854Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.727660776Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.739540247Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.743130962Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.755429077Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.763754225Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.771098258Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.773984926Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.778182635Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.780299936Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.783899711Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.792207204Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.795206952Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.799053473Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.801265772Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.810238259Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.821727322Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.826792493Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.838052435Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.845897639Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.853800218Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.855251818Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.858119141Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.860465926Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.863307975Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.871865396Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.875218172Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.878064403Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.88035554Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.890375216Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.901614944Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.904623449Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.916517515Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:12.924818193Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:12.932277841Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:12.934249393Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:12.938659442Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:12.940693995Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:12.944057139Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:12.954621496Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:12.95781031Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:12.961102882Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:12.964088189Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:12.97328566Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:12.984331939Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:12.987477498Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:12.99879126Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:13.005990303Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:13.012959017Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:13.014939056Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:13.01853368Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:13.019855407Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:13.029070931Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:13.037900033Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:13.040968395Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:13.04463557Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:13.04639828Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:13.054915325Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:13.066261742Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:13.069261949Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:13.080756695Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:13.088818348Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:13.096060579Z 66 PC: 12af6 | Move file pointer (See above)
2018-12-25T12:39:13.097449187Z 64 PC: 12b0c | Write file or device (See above)
2018-12-25T12:39:13.100788579Z 66 PC: 12b1e | Move file pointer (See above)
2018-12-25T12:39:13.103708105Z 64 PC: 12b44 | Write file or device (See above)
2018-12-25T12:39:13.107077362Z 64 PC: 12b55 | Write file or device (See above)
2018-12-25T12:39:13.116298369Z 64 PC: 12b68 | Write file or device (See above)
2018-12-25T12:39:13.120820392Z 64 PC: 12b94 | Write file or device (See above)
2018-12-25T12:39:13.124210035Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:13.126298791Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:13.137754623Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:13.149508315Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:13.152604625Z 67 PC: 12a91 | Get or set file attributes (See above)
2018-12-25T12:39:13.164518193Z 61 PC: 12a9e | Open file (See above)
2018-12-25T12:39:13.172603473Z 63 PC: 12adb | Read file or device (See above)
2018-12-25T12:39:13.176246888Z 87 PC: 12ba6 | Get or set file date and time (See above)
2018-12-25T12:39:13.179676179Z 62 PC: 12baf | Close file (See above)
2018-12-25T12:39:13.184665812Z 67 PC: 12bc1 | Get or set file attributes (See above)
2018-12-25T12:39:13.195883479Z 79 PC: 12bcd | Find next file (See above)
2018-12-25T12:39:13.198982434Z 42 PC: 12bea | Get date 0x12bea: cmp dh, 0xb
0x12bed: jne 0x12c00
0x12bef: cmp dl, 9
0x12bf2: jne 0x12c00
0x12bf4: mov dx, 0x2ce
0x12bf7: mov ah, 9
0x12bf9: int 0x21
0x12bfb: mov ax, 0x4c00
0x12bfe: int 0x21
0x12c00: cmp al, 0
0x12c02: jne 0x12c09
0x12c04: mov dx, 0x315
0x12c07: jmp 0x12bf7
0x12c09: mov bx, 0x100
0x12c0c: jmp bx
0x12c0e: cmp word ptr [bx + si], sp
0x12c10: dec si
0x12c11: outsw dx, word ptr [si]
0x12c12: imul sp, word ptr [di + 0x6d], 0x7262
0x12c17: imul sp, word ptr [di + 0x20], 0x3931
2018-12-25T12:39:13.201845992Z 9 PC: 12bfb | Display string (String= 'Sunday error 262 at 7053:0122')
2018-12-25T12:39:13.204919616Z 76 PC: 12c00 | Terminate with return code (Return code = '0')