.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T23:04:05.147119067Z | 44 | PC: 12b52 | Get time 0x12b52: cmp byte ptr [0x106], 0 0x12b57: je 0x12b59 0x12b59: cmp dl, 0 0x12b5c: je 0x12b4e 0x12b5e: mov byte ptr [0x106], dl 0x12b62: mov byte ptr [0x107], dh 0x12b66: mov byte ptr [0x203], 0 0x12b6b: mov byte ptr [0x204], 4 0x12b70: mov byte ptr [0x20d], 0 0x12b75: mov cx, 0x27 0x12b78: mov dx, 0x141 0x12b7b: mov ah, 0x4e 0x12b7d: int 0x21 0x12b7f: cmp ax, 0x12 0x12b82: je 0x12b87 0x12b84: call 0x12ba9 0x12b87: mov cx, 0x27 0x12b8a: mov dx, 0x147 0x12b8d: mov ah, 0x4e 0x12b8f: int 0x21 |
2018-12-17T23:04:05.150231085Z | 78 | PC: 12b7f | Find first file |
2018-12-17T23:04:05.155789308Z | 78 | PC: 12b91 | Find first file |
2018-12-17T23:04:05.161332319Z | 67 | PC: 12bca | Get or set file attributes |
2018-12-17T23:04:05.177662329Z | 61 | PC: 12bd0 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T23:04:05.184733961Z | 63 | PC: 12bdf | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:04:05.191189875Z | 62 | PC: 12c13 | Close file |
2018-12-17T23:04:05.193437408Z | 61 | PC: 12c1c | Open file (Filename = 'SLEEP.COM') |
2018-12-17T23:04:05.201000207Z | 64 | PC: 12a5b | Write file or device (Write 571 bytes on handle 5) |
2018-12-17T23:04:05.209253381Z | 87 | PC: 12c44 | Get or set file date and time |
2018-12-17T23:04:05.210993747Z | 62 | PC: 12c4c | Close file |
2018-12-17T23:04:05.219274189Z | 67 | PC: 12c59 | Get or set file attributes |
2018-12-17T23:04:05.223884457Z | 79 | PC: 12c03 | Find next file |
2018-12-17T23:04:05.226425546Z | 67 | PC: 12bca | Get or set file attributes |
2018-12-17T23:04:05.236890943Z | 61 | PC: 12bd0 | Open file (Filename = 'PRINT.COM') |
2018-12-17T23:04:05.243244643Z | 63 | PC: 12bdf | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:04:05.249323604Z | 62 | PC: 12c13 | Close file |
2018-12-17T23:04:05.251818032Z | 61 | PC: 12c1c | Open file (Filename = 'PRINT.COM') |
2018-12-17T23:04:05.258808258Z | 64 | PC: 12a5b | Write file or device (Write 571 bytes on handle 5) |
2018-12-17T23:04:05.267120493Z | 87 | PC: 12c44 | Get or set file date and time |
2018-12-17T23:04:05.269266032Z | 62 | PC: 12c4c | Close file |
2018-12-17T23:04:05.290174559Z | 67 | PC: 12c59 | Get or set file attributes |
2018-12-17T23:04:05.301049477Z | 79 | PC: 12c03 | Find next file |
2018-12-17T23:04:05.308396473Z | 67 | PC: 12bca | Get or set file attributes |
2018-12-17T23:04:05.318561157Z | 61 | PC: 12bd0 | Open file (Filename = 'HELLO.COM') |
2018-12-17T23:04:05.324949711Z | 63 | PC: 12bdf | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:04:05.331384978Z | 62 | PC: 12c13 | Close file |
2018-12-17T23:04:05.333473206Z | 61 | PC: 12c1c | Open file (Filename = 'HELLO.COM') |
2018-12-17T23:04:05.340632555Z | 64 | PC: 12a5b | Write file or device (Write 571 bytes on handle 5) |
2018-12-17T23:04:05.349068929Z | 87 | PC: 12c44 | Get or set file date and time |
2018-12-17T23:04:05.351481752Z | 62 | PC: 12c4c | Close file |
2018-12-17T23:04:05.359317268Z | 67 | PC: 12c59 | Get or set file attributes |
2018-12-17T23:04:05.365025033Z | 79 | PC: 12c03 | Find next file |
2018-12-17T23:04:05.368430926Z | 67 | PC: 12bca | Get or set file attributes |
2018-12-17T23:04:05.378258169Z | 61 | PC: 12bd0 | Open file (Filename = 'PHANG.COM') |
2018-12-17T23:04:05.385164035Z | 63 | PC: 12bdf | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:04:05.39232903Z | 62 | PC: 12c13 | Close file |
2018-12-17T23:04:05.394539757Z | 61 | PC: 12c1c | Open file (Filename = 'PHANG.COM') |
2018-12-17T23:04:05.4015944Z | 64 | PC: 12a5b | Write file or device (Write 571 bytes on handle 5) |
2018-12-17T23:04:05.410611978Z | 87 | PC: 12c44 | Get or set file date and time |
2018-12-17T23:04:05.412254974Z | 62 | PC: 12c4c | Close file |
2018-12-17T23:04:05.419738497Z | 67 | PC: 12c59 | Get or set file attributes |
2018-12-17T23:04:05.425096444Z | 9 | PC: 12c77 | Display string (String= ' Program too big to fit in memory') |
2018-12-17T23:04:05.429784317Z | 76 | PC: 12c7b | Terminate with return code (Return code = '36') |