.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T23:05:57.659760754Z | 44 | PC: 13182 | Get time 0x13182: cmp byte ptr [0x106], 0 0x13187: je 0x1318e 0x13189: cmp dh, 0xf 0x1318c: jg 0x13197 0x1318e: cmp dl, 0 0x13191: je 0x1317e 0x13193: mov byte ptr [0x106], dl 0x13197: mov byte ptr [0x833], 0 0x1319c: mov byte ptr [0x834], 4 0x131a1: mov byte ptr [0x83d], 0 0x131a6: mov cx, 0x27 0x131a9: mov dx, 0x131 0x131ac: mov ah, 0x4e 0x131ae: int 0x21 0x131b0: cmp ax, 0x12 0x131b3: je 0x131b8 0x131b5: call 0x131da 0x131b8: mov cx, 0x27 0x131bb: mov dx, 0x137 0x131be: mov ah, 0x4e |
2018-12-17T23:05:57.662606447Z | 78 | PC: 131b0 | Find first file |
2018-12-17T23:05:57.666484964Z | 78 | PC: 131c2 | Find first file |
2018-12-17T23:05:57.670263844Z | 67 | PC: 131fb | Get or set file attributes |
2018-12-17T23:05:57.684495976Z | 61 | PC: 13201 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T23:05:57.691002745Z | 63 | PC: 13210 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:05:57.697368159Z | 62 | PC: 13244 | Close file |
2018-12-17T23:05:57.703258129Z | 61 | PC: 1324d | Open file (Filename = 'SLEEP.COM') |
2018-12-17T23:05:57.710390627Z | 64 | PC: 12a5a | Write file or device (Write 2276 bytes on handle 5) |
2018-12-17T23:05:57.718987951Z | 87 | PC: 13275 | Get or set file date and time |
2018-12-17T23:05:57.720307943Z | 62 | PC: 1327d | Close file |
2018-12-17T23:05:57.727843216Z | 67 | PC: 1328a | Get or set file attributes |
2018-12-17T23:05:57.732374403Z | 79 | PC: 13234 | Find next file |
2018-12-17T23:05:57.735633191Z | 67 | PC: 131fb | Get or set file attributes |
2018-12-17T23:05:57.745860589Z | 61 | PC: 13201 | Open file (Filename = 'PRINT.COM') |
2018-12-17T23:05:57.75283715Z | 63 | PC: 13210 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:05:57.759105883Z | 62 | PC: 13244 | Close file |
2018-12-17T23:05:57.761553638Z | 61 | PC: 1324d | Open file (Filename = 'PRINT.COM') |
2018-12-17T23:05:57.769131864Z | 64 | PC: 12a5a | Write file or device (Write 2276 bytes on handle 5) |
2018-12-17T23:05:57.778072774Z | 87 | PC: 13275 | Get or set file date and time |
2018-12-17T23:05:57.780173088Z | 62 | PC: 1327d | Close file |
2018-12-17T23:05:57.787732645Z | 67 | PC: 1328a | Get or set file attributes |
2018-12-17T23:05:57.79267299Z | 79 | PC: 13234 | Find next file |
2018-12-17T23:05:57.795973935Z | 67 | PC: 131fb | Get or set file attributes |
2018-12-17T23:05:57.80566442Z | 61 | PC: 13201 | Open file (Filename = 'HELLO.COM') |
2018-12-17T23:05:57.812090774Z | 63 | PC: 13210 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:05:57.818756415Z | 62 | PC: 13244 | Close file |
2018-12-17T23:05:57.820516036Z | 61 | PC: 1324d | Open file (Filename = 'HELLO.COM') |
2018-12-17T23:05:57.828050058Z | 64 | PC: 12a5a | Write file or device (Write 2276 bytes on handle 5) |
2018-12-17T23:05:57.837691393Z | 87 | PC: 13275 | Get or set file date and time |
2018-12-17T23:05:57.839341963Z | 62 | PC: 1327d | Close file |
2018-12-17T23:05:57.847207939Z | 67 | PC: 1328a | Get or set file attributes |
2018-12-17T23:05:57.85209023Z | 79 | PC: 13234 | Find next file |
2018-12-17T23:05:57.854954689Z | 67 | PC: 131fb | Get or set file attributes |
2018-12-17T23:05:57.867215415Z | 61 | PC: 13201 | Open file (Filename = 'PHANG.COM') |
2018-12-17T23:05:57.873914296Z | 63 | PC: 13210 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:05:57.880081795Z | 62 | PC: 13244 | Close file |
2018-12-17T23:05:57.881703133Z | 61 | PC: 1324d | Open file (Filename = 'PHANG.COM') |
2018-12-17T23:05:57.889479231Z | 64 | PC: 12a5a | Write file or device (Write 2276 bytes on handle 5) |
2018-12-17T23:05:57.898087551Z | 87 | PC: 13275 | Get or set file date and time |
2018-12-17T23:05:57.899389711Z | 62 | PC: 1327d | Close file |
2018-12-17T23:05:57.907559575Z | 67 | PC: 1328a | Get or set file attributes |
2018-12-17T23:05:57.912076033Z | 9 | PC: 13318 | Display string (String= ' Program too big to fit in memory ') |
2018-12-17T23:05:57.915930183Z | 76 | PC: 1331c | Terminate with return code (Return code = '36') |