Sample viewer

vx.netlux.org/Virus.DOS.HoChiMinh

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:03:38.515770184Z 206 PC: 12ab2 | UNKNOWN!
2018-12-17T23:03:38.51681064Z 53 PC: 12aee | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:38.518283069Z 44 PC: 12b28 | Get time 0x12b28: mov byte ptr [0x20], ch
0x12b2c: mov ax, 0x2521
0x12b2f: mov dx, 0xd2
0x12b32: int 0x21
0x12b34: mov byte ptr [0x22], 0
0x12b39: mov byte ptr [0x21], 0
0x12b3e: jmp 0x12ab7
0x12b41: jmp 0x12b9c
0x12b43: nop
0x12b44: dec ax
0x12b45: insb byte ptr es:[di], dx
0x12b47: sub ax, 0xba0d
0x12b4a: fimul dword ptr [bp + si]
0x12b4c: cmp ax, 5
0x12b4f: je 0x12b6c
0x12b51: mov dx, 0x2ebf
0x12b54: cmp byte ptr [0x22], 0xff
0x12b59: jne 0x12b5e
0x12b5b: jmp 0x12ccb
0x12b5e: cmp ah, 0xce
2018-12-17T23:03:38.51990104Z 37 PC: 12b34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:03:38.521062663Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.523446388Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.525174922Z 9 PC: 12aa2 | Display string (String= 'Hello - This is a 100 COM test file, 1993 ')
2018-12-17T23:03:38.529179365Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.531763663Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.533480383Z 77 PC: 11fe0 | Get program return code
2018-12-17T23:03:38.534649674Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.537625077Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.539458081Z 72 PC: 12174 | Allocate memory
2018-12-17T23:03:38.540892509Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.543179756Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.545013166Z 72 PC: 1218d | Allocate memory
2018-12-17T23:03:38.547208904Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.549398937Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.551298142Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T23:03:38.552185442Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.553830188Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.555986036Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:03:38.557104773Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.558795913Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.561318093Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:03:38.562504042Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.564216012Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.567795072Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.571176036Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.574420846Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.58617953Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.58850965Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.591330574Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.5955316Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.59786685Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.600722217Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.60386807Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.607071533Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.610018133Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.612972011Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.616325549Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.619222322Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.622126753Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.62648912Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.628423534Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.631148336Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.63378919Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.636451353Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.639877403Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.643140239Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.646277225Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.648064882Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.649510568Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.651731902Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.653472562Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.654882272Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.657503944Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.659431533Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.660904146Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.663718641Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.665752809Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.667476518Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.66984995Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.671942093Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.673642796Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.676552531Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.678600936Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.680049109Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.681953677Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.683985738Z 62 PC: 122ab | Close file
2018-12-17T23:03:38.686267372Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.687995729Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.690322311Z 99 PC: 99dd7 | Get DBCS lead byte table pointer
2018-12-17T23:03:38.691564303Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.693507442Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.696280915Z 56 PC: 945f9 | Get or set country info
2018-12-17T23:03:38.697963861Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.699968805Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.702339565Z 64 PC: 9a048 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T23:03:38.706782325Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.709535177Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.71295857Z 25 PC: 94662 | Get default drive
2018-12-17T23:03:38.715496705Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.718267846Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.721470241Z 71 PC: 968dd | Get current directory
2018-12-17T23:03:38.74392894Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.746349884Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.757372288Z 64 PC: 9a048 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T23:03:38.761596364Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.764069914Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.766993723Z 2 PC: 968b2 | Character output (Char = '3e')
2018-12-17T23:03:38.775817408Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.779930613Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.784792494Z 93 PC: 94720 | File sharing functions
2018-12-17T23:03:38.787248868Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.790063487Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.79354931Z 93 PC: 94727 | File sharing functions
2018-12-17T23:03:38.79608475Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-17T23:03:38.798792775Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-17T23:03:38.802295737Z 10 PC: 94739 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14610,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:07.283512016Z 206 PC: 12ab2 | UNKNOWN!
2018-12-25T12:41:07.28427763Z 53 PC: 12aee | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:07.286062754Z 44 PC: 12b28 | Get time 0x12b28: mov byte ptr [0x20], ch
0x12b2c: mov ax, 0x2521
0x12b2f: mov dx, 0xd2
0x12b32: int 0x21
0x12b34: mov byte ptr [0x22], 0
0x12b39: mov byte ptr [0x21], 0
0x12b3e: jmp 0x12ab7
0x12b41: jmp 0x12b9c
0x12b43: nop
0x12b44: dec ax
0x12b45: insb byte ptr es:[di], dx
0x12b47: sub ax, 0xba0d
0x12b4a: fimul dword ptr [bp + si]
0x12b4c: cmp ax, 5
0x12b4f: je 0x12b6c
0x12b51: mov dx, 0x2ebf
0x12b54: cmp byte ptr [0x22], 0xff
0x12b59: jne 0x12b5e
0x12b5b: jmp 0x12ccb
0x12b5e: cmp ah, 0xce
2018-12-25T12:41:07.288058183Z 37 PC: 12b34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:07.289217238Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-25T12:41:07.291836144Z 9 PC: 12aa2 | Display string (String= 'Hello - This is a 100 COM test file, 1993 ')
2018-12-25T12:41:07.299523369Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.301574176Z 77 PC: 11fe0 | Get program return code
2018-12-25T12:41:07.303280876Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.306333265Z 72 PC: 12174 | Allocate memory
2018-12-25T12:41:07.308522861Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.312173445Z 72 PC: 1218d | Allocate memory
2018-12-25T12:41:07.314385065Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.316907876Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:41:07.318716118Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.333034634Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:41:07.334128497Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.335983622Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:41:07.337475354Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.339959719Z 62 PC: 122ab | Close file
2018-12-25T12:41:07.343033412Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.348307554Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.350918405Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.353482972Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.367420553Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.37089779Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.378347953Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.382267917Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.384107217Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.386507854Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.389401441Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.391796751Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.393438878Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.39662075Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.398254662Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.400391729Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.403100242Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.405327805Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.406923621Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.409936173Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.411537038Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.413742769Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.416059808Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.418549789Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.420526553Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.423354686Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.424905314Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.427042895Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:07.43087814Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.432972962Z 99 PC: 99dd7 | Get DBCS lead byte table pointer
2018-12-25T12:41:07.434257492Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.436931913Z 56 PC: 945f9 | Get or set country info
2018-12-25T12:41:07.43905401Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.44137994Z 64 PC: 9a048 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:41:07.446396569Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.448508831Z 25 PC: 94662 | Get default drive
2018-12-25T12:41:07.450228675Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.452870096Z 71 PC: 968dd | Get current directory
2018-12-25T12:41:07.457406325Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.45988283Z 64 PC: 9a048 | Write file or device (See above)
2018-12-25T12:41:07.46431387Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.467149108Z 2 PC: 968b2 | Character output (Char = '3e')
2018-12-25T12:41:07.469870886Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.47255323Z 93 PC: 94720 | File sharing functions
2018-12-25T12:41:07.474247237Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.476680075Z 93 PC: 94727 | File sharing functions
2018-12-25T12:41:07.479543925Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.482076617Z 10 PC: 94739 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14610,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:07.966964415Z 206 PC: 12ab2 | UNKNOWN!
2018-12-25T12:41:07.96788036Z 53 PC: 12aee | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:07.969844212Z 44 PC: 12b28 | Get time 0x12b28: mov byte ptr [0x20], ch
0x12b2c: mov ax, 0x2521
0x12b2f: mov dx, 0xd2
0x12b32: int 0x21
0x12b34: mov byte ptr [0x22], 0
0x12b39: mov byte ptr [0x21], 0
0x12b3e: jmp 0x12ab7
0x12b41: jmp 0x12b9c
0x12b43: nop
0x12b44: dec ax
0x12b45: insb byte ptr es:[di], dx
0x12b47: sub ax, 0xba0d
0x12b4a: fimul dword ptr [bp + si]
0x12b4c: cmp ax, 5
0x12b4f: je 0x12b6c
0x12b51: mov dx, 0x2ebf
0x12b54: cmp byte ptr [0x22], 0xff
0x12b59: jne 0x12b5e
0x12b5b: jmp 0x12ccb
0x12b5e: cmp ah, 0xce
2018-12-25T12:41:07.972647639Z 37 PC: 12b34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:07.974524791Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-25T12:41:07.977764829Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-25T12:41:07.980590032Z 9 PC: 12aa2 | Display string (String= 'Hello - This is a 100 COM test file, 1993 ')
2018-12-25T12:41:07.989078722Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:07.992668132Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:07.9954404Z 77 PC: 11fe0 | Get program return code
2018-12-25T12:41:07.997190566Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.000401261Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.002755891Z 72 PC: 12174 | Allocate memory
2018-12-25T12:41:08.00471739Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.007341712Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.009934691Z 72 PC: 1218d | Allocate memory
2018-12-25T12:41:08.013212301Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.015728267Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.01888086Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:41:08.020256513Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.022567215Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.0256087Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:41:08.027015421Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.029553519Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.032381505Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:41:08.03515016Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.037781345Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.040842763Z 62 PC: 122ab | Close file
2018-12-25T12:41:08.042775327Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.045316782Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.048854372Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.051107441Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.054029551Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.05751194Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.059469556Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.06855154Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.072404537Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.074086131Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.076457145Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.078787699Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.080722683Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.083149776Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.085450968Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.087486021Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.090178338Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.093388071Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.095955206Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.098455642Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.100749683Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.102877709Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.113342126Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.115828234Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.118202864Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.120783931Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.123265967Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.125198817Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.127931383Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.13031739Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.133007528Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.136261131Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.138562085Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.140175313Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.144009911Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.146349608Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.147989624Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.150988029Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.153179959Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.154936668Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.157431188Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.160100716Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.163483523Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.166667263Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.168999067Z 99 PC: 99dd7 | Get DBCS lead byte table pointer
2018-12-25T12:41:08.170423352Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.173251134Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.175615238Z 56 PC: 945f9 | Get or set country info
2018-12-25T12:41:08.178695237Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.181297185Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.183875056Z 64 PC: 9a048 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:41:08.188819106Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.190908274Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.194258687Z 25 PC: 94662 | Get default drive
2018-12-25T12:41:08.196011837Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.198313702Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.201258153Z 71 PC: 968dd | Get current directory
2018-12-25T12:41:08.205699488Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.208282845Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.210887571Z 64 PC: 9a048 | Write file or device (See above)
2018-12-25T12:41:08.214473606Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.216864984Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.219524565Z 2 PC: 968b2 | Character output (Char = '3e')
2018-12-25T12:41:08.22196807Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.224333017Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.22797909Z 93 PC: 94720 | File sharing functions
2018-12-25T12:41:08.230044738Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.232573504Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.235538441Z 93 PC: 94727 | File sharing functions
2018-12-25T12:41:08.237968616Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.240488226Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.243648526Z 10 PC: 94739 | Buffered keyboard input

{"DateBased":true,"Day":2,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14610,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:08.441656315Z 206 PC: 12ab2 | UNKNOWN!
2018-12-25T12:41:08.442938901Z 53 PC: 12aee | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:08.444094018Z 44 PC: 12b28 | Get time 0x12b28: mov byte ptr [0x20], ch
0x12b2c: mov ax, 0x2521
0x12b2f: mov dx, 0xd2
0x12b32: int 0x21
0x12b34: mov byte ptr [0x22], 0
0x12b39: mov byte ptr [0x21], 0
0x12b3e: jmp 0x12ab7
0x12b41: jmp 0x12b9c
0x12b43: nop
0x12b44: dec ax
0x12b45: insb byte ptr es:[di], dx
0x12b47: sub ax, 0xba0d
0x12b4a: fimul dword ptr [bp + si]
0x12b4c: cmp ax, 5
0x12b4f: je 0x12b6c
0x12b51: mov dx, 0x2ebf
0x12b54: cmp byte ptr [0x22], 0xff
0x12b59: jne 0x12b5e
0x12b5b: jmp 0x12ccb
0x12b5e: cmp ah, 0xce
2018-12-25T12:41:08.445802251Z 37 PC: 12b34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:08.447399942Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-25T12:41:08.449832134Z 9 PC: 12aa2 | Display string (String= 'Hello - This is a 100 COM test file, 1993 ')
2018-12-25T12:41:08.457939414Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.460543075Z 77 PC: 11fe0 | Get program return code
2018-12-25T12:41:08.462136761Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.46556555Z 72 PC: 12174 | Allocate memory
2018-12-25T12:41:08.467931075Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.471075889Z 72 PC: 1218d | Allocate memory
2018-12-25T12:41:08.473827466Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.476502005Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:41:08.478563534Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.481038544Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:41:08.483389736Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.497016589Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:41:08.498468835Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.50081004Z 62 PC: 122ab | Close file
2018-12-25T12:41:08.50319152Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.506064654Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.508225898Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.511715924Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.513926148Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.51702233Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.519743185Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.522543577Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.524767092Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.527972896Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.530500505Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.533890658Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.535576499Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.538561409Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.540146116Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.542433135Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.544336961Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.546832506Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.548525101Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.551594699Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.552887384Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.554872387Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.556426477Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.558205452Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.559369801Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.561797661Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.563509357Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.565992549Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.569727442Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.572356802Z 99 PC: 99dd7 | Get DBCS lead byte table pointer
2018-12-25T12:41:08.573735983Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.57611051Z 56 PC: 945f9 | Get or set country info
2018-12-25T12:41:08.578405333Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.580887733Z 64 PC: 9a048 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:41:08.585985291Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.588621352Z 25 PC: 94662 | Get default drive
2018-12-25T12:41:08.590267785Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.59331133Z 71 PC: 968dd | Get current directory
2018-12-25T12:41:08.598738139Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.601304931Z 64 PC: 9a048 | Write file or device (See above)
2018-12-25T12:41:08.605095177Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.60919387Z 2 PC: 968b2 | Character output (Char = '3e')
2018-12-25T12:41:08.611770155Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.61481913Z 93 PC: 94720 | File sharing functions
2018-12-25T12:41:08.618850255Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.622017492Z 93 PC: 94727 | File sharing functions
2018-12-25T12:41:08.62440029Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.627969839Z 10 PC: 94739 | Buffered keyboard input

{"DateBased":true,"Day":15,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14610,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:08.480323982Z 206 PC: 12ab2 | UNKNOWN!
2018-12-25T12:41:08.48117424Z 53 PC: 12aee | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:08.482951857Z 44 PC: 12b28 | Get time 0x12b28: mov byte ptr [0x20], ch
0x12b2c: mov ax, 0x2521
0x12b2f: mov dx, 0xd2
0x12b32: int 0x21
0x12b34: mov byte ptr [0x22], 0
0x12b39: mov byte ptr [0x21], 0
0x12b3e: jmp 0x12ab7
0x12b41: jmp 0x12b9c
0x12b43: nop
0x12b44: dec ax
0x12b45: insb byte ptr es:[di], dx
0x12b47: sub ax, 0xba0d
0x12b4a: fimul dword ptr [bp + si]
0x12b4c: cmp ax, 5
0x12b4f: je 0x12b6c
0x12b51: mov dx, 0x2ebf
0x12b54: cmp byte ptr [0x22], 0xff
0x12b59: jne 0x12b5e
0x12b5b: jmp 0x12ccb
0x12b5e: cmp ah, 0xce
2018-12-25T12:41:08.485327618Z 37 PC: 12b34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:08.48780623Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-25T12:41:08.490990147Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-25T12:41:08.493541813Z 9 PC: 12aa2 | Display string (String= 'Hello - This is a 100 COM test file, 1993 ')
2018-12-25T12:41:08.50184394Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.504740063Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.5076947Z 77 PC: 11fe0 | Get program return code
2018-12-25T12:41:08.509126223Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.512027981Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.514662628Z 72 PC: 12174 | Allocate memory
2018-12-25T12:41:08.516569037Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.51957901Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.522209517Z 72 PC: 1218d | Allocate memory
2018-12-25T12:41:08.524639782Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.526908878Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.529536342Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:41:08.53070725Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.532988661Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.536009453Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:41:08.538122691Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.540861327Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.544550211Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:41:08.546013122Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.548360398Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.551354176Z 62 PC: 122ab | Close file
2018-12-25T12:41:08.55316809Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.555692592Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.560652415Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.563749469Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.565472208Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.567380584Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.581453577Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.584343095Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.587330795Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.590583512Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.59341863Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.596215052Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.599251409Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.60299101Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.605816757Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.608712504Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.611015754Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.613832432Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.615630671Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.617597174Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.620056115Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.621768893Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.624277015Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.626805476Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.628552645Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.631680924Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.634218145Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.636068352Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.639340471Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.642316678Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.644567665Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.647641035Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.650687872Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.652923628Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.662255877Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.665951167Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.667830761Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.672330237Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.675001841Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.677179054Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.680253465Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.683028868Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.686480143Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.689436394Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.692151979Z 99 PC: 99dd7 | Get DBCS lead byte table pointer
2018-12-25T12:41:08.693701918Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.696084117Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.699213218Z 56 PC: 945f9 | Get or set country info
2018-12-25T12:41:08.701315207Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.70375125Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.706801533Z 64 PC: 9a048 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:41:08.711768832Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.714098972Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.716964988Z 25 PC: 94662 | Get default drive
2018-12-25T12:41:08.718834505Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.721184704Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.724010776Z 71 PC: 968dd | Get current directory
2018-12-25T12:41:08.72833113Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.73065544Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.733612063Z 64 PC: 9a048 | Write file or device (See above)
2018-12-25T12:41:08.737126061Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.739992992Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.74246351Z 2 PC: 968b2 | Character output (Char = '3e')
2018-12-25T12:41:08.745235042Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.747616929Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.749990144Z 93 PC: 94720 | File sharing functions
2018-12-25T12:41:08.752084695Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.754500322Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.756802992Z 93 PC: 94727 | File sharing functions
2018-12-25T12:41:08.76065431Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.7630823Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.765484776Z 10 PC: 94739 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1991,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14610,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:08.769541722Z 206 PC: 12ab2 | UNKNOWN!
2018-12-25T12:41:08.770930756Z 53 PC: 12aee | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:08.772001373Z 44 PC: 12b28 | Get time 0x12b28: mov byte ptr [0x20], ch
0x12b2c: mov ax, 0x2521
0x12b2f: mov dx, 0xd2
0x12b32: int 0x21
0x12b34: mov byte ptr [0x22], 0
0x12b39: mov byte ptr [0x21], 0
0x12b3e: jmp 0x12ab7
0x12b41: jmp 0x12b9c
0x12b43: nop
0x12b44: dec ax
0x12b45: insb byte ptr es:[di], dx
0x12b47: sub ax, 0xba0d
0x12b4a: fimul dword ptr [bp + si]
0x12b4c: cmp ax, 5
0x12b4f: je 0x12b6c
0x12b51: mov dx, 0x2ebf
0x12b54: cmp byte ptr [0x22], 0xff
0x12b59: jne 0x12b5e
0x12b5b: jmp 0x12ccb
0x12b5e: cmp ah, 0xce
2018-12-25T12:41:08.773894075Z 37 PC: 12b34 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T12:41:08.775516826Z 42 PC: 9f653 | Get date 0x9f653: cmp cx, 0x7c6
0x9f657: ja 0x9f668
0x9f659: cmp dh, 0xb
0x9f65c: jb 0x9f68f
0x9f65e: cmp dl, 1
0x9f661: je 0x9f668
0x9f663: cmp dl, 0xf
0x9f666: jne 0x9f68f
0x9f668: cmp byte ptr cs:[0x21], 0xff
0x9f66e: je 0x9f68f
0x9f670: mov ah, 0x2c
0x9f672: int 0x21
0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
2018-12-25T12:41:08.77749558Z 44 PC: 9f674 | Get time 0x9f674: sub ch, byte ptr cs:[0x20]
0x9f679: cmp ch, 3
0x9f67c: jb 0x9f68f
0x9f67e: call 0x9f6e2
0x9f681: mov ah, 9
0x9f683: int 0x21
0x9f685: xor ah, ah
0x9f687: int 0x16
0x9f689: mov byte ptr cs:[0x21], 0xff
0x9f68f: jmp 0x9f63d
0x9f691: mov di, 0xc6
0x9f694: mov si, 1
0x9f697: mov cx, 0xc
0x9f69a: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f69c: je 0x9f6aa
0x9f69e: mov si, 3
0x9f6a1: mov di, 0x2df
0x9f6a4: mov cx, si
0x9f6a6: repe cmpsb byte ptr [si], byte ptr es:[di]
0x9f6a8: jne 0x9f6ad
2018-12-25T12:41:08.779471806Z 9 PC: 12aa2 | Display string (String= 'Hello - This is a 100 COM test file, 1993 ')
2018-12-25T12:41:08.786781227Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.789247495Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.79172612Z 77 PC: 11fe0 | Get program return code
2018-12-25T12:41:08.794412656Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.796636403Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.799107144Z 72 PC: 12174 | Allocate memory
2018-12-25T12:41:08.801668609Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.803722657Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.805716537Z 72 PC: 1218d | Allocate memory
2018-12-25T12:41:08.808405293Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.810368815Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.812341385Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T12:41:08.813796891Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.815817715Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.817722956Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:41:08.8190929Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.821048562Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.823002028Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:41:08.8316056Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.833649658Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.835891756Z 62 PC: 122ab | Close file
2018-12-25T12:41:08.838987903Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.841632114Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.84304511Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.844123896Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.847173657Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.849549945Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.851371831Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.853054375Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.854472595Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.855606823Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.85738513Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.859042651Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.860454558Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.862478139Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.864394962Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.865734194Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.868417954Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.870421976Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.871822406Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.874471458Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.876437763Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.877851531Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.880974771Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.882908963Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.884335452Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.886991467Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.889353568Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.891137143Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.894354874Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.896453763Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.897845188Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.900362187Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.902411836Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.903826908Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.906115354Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.908066555Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.909363221Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.911578463Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.913503969Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.914875761Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.917046722Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.919474401Z 62 PC: 122ab | Close file (See above)
2018-12-25T12:41:08.92206598Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.9242801Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.926261287Z 99 PC: 99dd7 | Get DBCS lead byte table pointer
2018-12-25T12:41:08.927465012Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.929740242Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.931755171Z 56 PC: 945f9 | Get or set country info
2018-12-25T12:41:08.933372429Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.9356771Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.937728797Z 64 PC: 9a048 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T12:41:08.941867893Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.944769854Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.946712714Z 25 PC: 94662 | Get default drive
2018-12-25T12:41:08.94804176Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.950502126Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.9523693Z 71 PC: 968dd | Get current directory
2018-12-25T12:41:08.95594597Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.958025351Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.959908479Z 64 PC: 9a048 | Write file or device (See above)
2018-12-25T12:41:08.962744674Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.964981717Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.96711569Z 2 PC: 968b2 | Character output (Char = '3e')
2018-12-25T12:41:08.969219181Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.971397116Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.973304071Z 93 PC: 94720 | File sharing functions
2018-12-25T12:41:08.97477186Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.977028597Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.979280933Z 93 PC: 94727 | File sharing functions
2018-12-25T12:41:08.98078549Z 42 PC: 9f653 | Get date (See above)
2018-12-25T12:41:08.983411083Z 44 PC: 9f674 | Get time (See above)
2018-12-25T12:41:08.985333578Z 10 PC: 94739 | Buffered keyboard input