Sample viewer

vx.netlux.org/Virus.DOS.Kode4.399

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:08:19.798416085Z 78 PC: 12aa3 | Find first file
2018-12-17T23:08:19.804874084Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:19.811774704Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:19.847427027Z 61 PC: 12ac3 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:08:19.855360388Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:19.858599246Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:19.860386025Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:19.867217886Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:19.869684091Z 66 PC: 12b17 | Move file pointer
2018-12-17T23:08:19.871271285Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:19.874127343Z 66 PC: 12b2c | Move file pointer
2018-12-17T23:08:19.878206179Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-17T23:08:19.893760175Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:19.895837219Z 62 PC: 12b7c | Close file
2018-12-17T23:08:19.904447844Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:19.90890968Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:19.915747212Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:19.926049606Z 61 PC: 12ac3 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:08:19.934457109Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:19.93633528Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:19.938206036Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:19.946414525Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:19.948207425Z 66 PC: 12b17 | Move file pointer
2018-12-17T23:08:19.949877804Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:19.953371972Z 66 PC: 12b2c | Move file pointer
2018-12-17T23:08:19.955032643Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-17T23:08:19.957885385Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:19.960161674Z 62 PC: 12b7c | Close file
2018-12-17T23:08:19.968181248Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:19.971293127Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:19.978087879Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:19.988953011Z 61 PC: 12ac3 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:08:19.996105254Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:19.998109472Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:20.000238052Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:20.007668469Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:20.009548943Z 66 PC: 12b17 | Move file pointer
2018-12-17T23:08:20.011848045Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:20.015042188Z 66 PC: 12b2c | Move file pointer
2018-12-17T23:08:20.017035866Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-17T23:08:20.020982033Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:20.022562774Z 62 PC: 12b7c | Close file
2018-12-17T23:08:20.030497839Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:20.034130988Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:20.040291387Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:20.050871924Z 61 PC: 12ac3 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:08:20.059817849Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:20.061711939Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:20.063252385Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:20.070845988Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:20.072494386Z 66 PC: 12b17 | Move file pointer
2018-12-17T23:08:20.074021506Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:20.076822612Z 66 PC: 12b2c | Move file pointer
2018-12-17T23:08:20.079409414Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-17T23:08:20.082636058Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:20.084614387Z 62 PC: 12b7c | Close file
2018-12-17T23:08:20.093339557Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:20.09639492Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:20.102748252Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:20.114025648Z 61 PC: 12ac3 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:08:20.121049831Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:20.123242803Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:20.125770254Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:20.132486177Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:20.134052562Z 66 PC: 12b17 | Move file pointer
2018-12-17T23:08:20.136200659Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:20.139208402Z 66 PC: 12b2c | Move file pointer
2018-12-17T23:08:20.140692773Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-17T23:08:20.143714151Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:20.145443361Z 62 PC: 12b7c | Close file
2018-12-17T23:08:20.152990547Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:20.155786252Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:20.163166154Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:20.173758904Z 61 PC: 12ac3 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:08:20.180994324Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:20.183706121Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:20.185421485Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:20.193028022Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:20.195769686Z 66 PC: 12b17 | Move file pointer
2018-12-17T23:08:20.197611267Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:20.200734367Z 66 PC: 12b2c | Move file pointer
2018-12-17T23:08:20.203322442Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-17T23:08:20.216652056Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:20.218834428Z 62 PC: 12b7c | Close file
2018-12-17T23:08:20.227444913Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:20.231100754Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:20.237519309Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:20.248140713Z 61 PC: 12ac3 | Open file (Filename = 'PAH.COM')
2018-12-17T23:08:20.256438098Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:20.25825842Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:20.260938087Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:20.26838816Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:20.270168627Z 66 PC: 12b17 | Move file pointer
2018-12-17T23:08:20.27199552Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:08:20.276089986Z 66 PC: 12b2c | Move file pointer
2018-12-17T23:08:20.27795385Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-17T23:08:20.281166678Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:20.284033537Z 62 PC: 12b7c | Close file
2018-12-17T23:08:20.292261132Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:20.295067236Z 67 PC: 12ab1 | Get or set file attributes
2018-12-17T23:08:20.301858962Z 67 PC: 12abb | Get or set file attributes
2018-12-17T23:08:20.312808152Z 61 PC: 12ac3 | Open file (Filename = 'TEST.COM')
2018-12-17T23:08:20.320139943Z 87 PC: 12ad0 | Get or set file date and time
2018-12-17T23:08:20.32233576Z 66 PC: 12adb | Move file pointer
2018-12-17T23:08:20.32515516Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:08:20.332871213Z 66 PC: 12af0 | Move file pointer
2018-12-17T23:08:20.334944991Z 87 PC: 12b78 | Get or set file date and time
2018-12-17T23:08:20.338202073Z 62 PC: 12b7c | Close file
2018-12-17T23:08:20.346215565Z 79 PC: 12b80 | Find next file
2018-12-17T23:08:20.349275026Z 42 PC: 12b89 | Get date 0x12b89: cmp cx, 0x7c8
0x12b8d: jl 0x12b9e
0x12b8f: cmp dx, 0x90a
0x12b93: jl 0x12b9e
0x12b95: mov ah, 9
0x12b97: mov dx, 0x26a
0x12b9a: add dx, si
0x12b9c: int 0x21
0x12b9e: mov bp, 0x100
0x12ba1: jmp bp
0x12ba3: add byte ptr [bp + si], ch
0x12ba5: arpl word ptr cs:[bx + 0x6d], bp
0x12ba9: add byte ptr [bx + si], ah
0x12bab: sub ax, 0x2b3d
0x12bae: and byte ptr [bp + di + 0x6f], cl
0x12bb1: xor al, 0x20
0x12bb5: sub di, word ptr [di]
0x12bb7: sub ax, 0x202c
0x12bba: push sp
0x12bbb: push 0x2065
2018-12-17T23:08:20.353475441Z 9 PC: 12b9e | Display string (String= ' -=+ Kode4 +=-, The one and ONLY!')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":16153,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:45:29.439505437Z 78 PC: 12aa3 | Find first file
2018-12-25T12:45:29.446144912Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:45:29.452808455Z 67 PC: 12abb | Get or set file attributes
2018-12-25T12:45:29.469994731Z 61 PC: 12ac3 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:45:29.477082977Z 87 PC: 12ad0 | Get or set file date and time
2018-12-25T12:45:29.478613959Z 66 PC: 12adb | Move file pointer
2018-12-25T12:45:29.479846957Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:45:29.486696128Z 66 PC: 12af0 | Move file pointer
2018-12-25T12:45:29.488170007Z 66 PC: 12b17 | Move file pointer
2018-12-25T12:45:29.489544648Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:45:29.492187698Z 66 PC: 12b2c | Move file pointer
2018-12-25T12:45:29.494157638Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-25T12:45:29.500800932Z 87 PC: 12b78 | Get or set file date and time
2018-12-25T12:45:29.502083131Z 62 PC: 12b7c | Close file
2018-12-25T12:45:29.508800531Z 79 PC: 12b80 | Find next file
2018-12-25T12:45:29.511115338Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.515489214Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.523737567Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.527893775Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.52885058Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.530073668Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.534126588Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.535125076Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:29.536456984Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:29.539227777Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:29.540489827Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:29.543259996Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.544978232Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.552706272Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.555281961Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.559049827Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.56527648Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.572403798Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.57381076Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.574739038Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.578774621Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.58008671Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:29.581052353Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:29.582738922Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:29.584116823Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:29.586355079Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.587367907Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.59268644Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.594404478Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.597907828Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.604731056Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.60902603Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.61006241Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.611394276Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.615504154Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.616514866Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:29.617789269Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:29.619728501Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:29.620873648Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:29.622870839Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.624178418Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.629036017Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.630730825Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.637546567Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.645469938Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.652931864Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.654363681Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.655300525Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.659170871Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.660704003Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:29.661996202Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:29.66462565Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:29.66648971Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:29.669365926Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.670733384Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.678867307Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.681621283Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.687771264Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.698766842Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.706037912Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.707404441Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.708968539Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.713062996Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.714061141Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:29.715832328Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:29.718023581Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:29.719317164Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:29.728209625Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.729736676Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.737652089Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.740775837Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.74443992Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.750791045Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.755267689Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.756265613Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.757196203Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.761613427Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.762624947Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:29.763571263Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:29.765607771Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:29.766619832Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:29.76841764Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.769799895Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.774632486Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.776337297Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.783591168Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.789833809Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.793954673Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.795244436Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.796245229Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.800186273Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.801542276Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.802593372Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.807007835Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.808892276Z 42 PC: 12b89 | Get date 0x12b89: cmp cx, 0x7c8
0x12b8d: jl 0x12b9e
0x12b8f: cmp dx, 0x90a
0x12b93: jl 0x12b9e
0x12b95: mov ah, 9
0x12b97: mov dx, 0x26a
0x12b9a: add dx, si
0x12b9c: int 0x21
0x12b9e: mov bp, 0x100
0x12ba1: jmp bp
0x12ba3: add byte ptr [bp + si], ch
0x12ba5: arpl word ptr cs:[bx + 0x6d], bp
0x12ba9: add byte ptr [bx + si], ah
0x12bab: sub ax, 0x2b3d
0x12bae: and byte ptr [bp + di + 0x6f], cl
0x12bb1: xor al, 0x20
0x12bb5: sub di, word ptr [di]
0x12bb7: sub ax, 0x202c
0x12bba: push sp
0x12bbb: push 0x2065

{"DateBased":true,"Day":1,"Month":1,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":16153,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:45:29.873174699Z 78 PC: 12aa3 | Find first file
2018-12-25T12:45:29.878675501Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:45:29.883507323Z 67 PC: 12abb | Get or set file attributes
2018-12-25T12:45:29.899514047Z 61 PC: 12ac3 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:45:29.908902887Z 87 PC: 12ad0 | Get or set file date and time
2018-12-25T12:45:29.910084194Z 66 PC: 12adb | Move file pointer
2018-12-25T12:45:29.911189919Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:45:29.916609648Z 66 PC: 12af0 | Move file pointer
2018-12-25T12:45:29.917724513Z 66 PC: 12b17 | Move file pointer
2018-12-25T12:45:29.918761276Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:45:29.920866463Z 66 PC: 12b2c | Move file pointer
2018-12-25T12:45:29.922237051Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-25T12:45:29.928134222Z 87 PC: 12b78 | Get or set file date and time
2018-12-25T12:45:29.929415652Z 62 PC: 12b7c | Close file
2018-12-25T12:45:29.935501024Z 79 PC: 12b80 | Find next file
2018-12-25T12:45:29.938283469Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:29.94427601Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:29.955036826Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:29.962309667Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:29.963522534Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:29.965307945Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:29.972378221Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:29.973711883Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:29.975586857Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:29.979747064Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:29.981490604Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:29.985156814Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:29.987306489Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:29.993708098Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:29.997788295Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:30.005566694Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:30.016262982Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:30.024061362Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:30.025542299Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:30.026947386Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:30.033954552Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:30.035696829Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:30.036962019Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:30.039628108Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:30.041116042Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:30.044696799Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:30.046057208Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:30.053932956Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:30.056688864Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:30.062626245Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:30.073401213Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:30.080566401Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:30.08191094Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:30.083654734Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:30.090512443Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:30.09153717Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:30.092876148Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:30.094657836Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:30.095678334Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:30.09777317Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:30.098866158Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:30.103744438Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:30.106452388Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:30.112822803Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:30.122647022Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:30.127008243Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:30.128386787Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:30.129369044Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:30.133377026Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:30.13462733Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:30.1357019Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:30.137561326Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:30.139173453Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:30.141942816Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:30.143256794Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:30.14910327Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:30.15178681Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:30.157590797Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:30.167632378Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:30.176312732Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:30.17725271Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:30.178685609Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:30.183395727Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:30.184398156Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:30.185695384Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:30.18740793Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:30.188413918Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:30.19398052Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:30.19500464Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:30.199903537Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:30.202074524Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:30.205754686Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:30.21194711Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:30.219602531Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:30.220994672Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:30.222207186Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:30.229285212Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:30.230687473Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:30.23188024Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:30.234801301Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:30.236243025Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:30.239741564Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:30.241190961Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:30.249241907Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:30.251767132Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:30.258089856Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:30.264299689Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:30.268410848Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:30.26977963Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:30.270812964Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:30.274814385Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:30.276145331Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:30.277229064Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:30.281757456Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:30.283750035Z 42 PC: 12b89 | Get date 0x12b89: cmp cx, 0x7c8
0x12b8d: jl 0x12b9e
0x12b8f: cmp dx, 0x90a
0x12b93: jl 0x12b9e
0x12b95: mov ah, 9
0x12b97: mov dx, 0x26a
0x12b9a: add dx, si
0x12b9c: int 0x21
0x12b9e: mov bp, 0x100
0x12ba1: jmp bp
0x12ba3: add byte ptr [bp + si], ch
0x12ba5: arpl word ptr cs:[bx + 0x6d], bp
0x12ba9: add byte ptr [bx + si], ah
0x12bab: sub ax, 0x2b3d
0x12bae: and byte ptr [bp + di + 0x6f], cl
0x12bb1: xor al, 0x20
0x12bb5: sub di, word ptr [di]
0x12bb7: sub ax, 0x202c
0x12bba: push sp
0x12bbb: push 0x2065

{"DateBased":true,"Day":10,"Month":9,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":16153,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:45:31.074293396Z 78 PC: 12aa3 | Find first file
2018-12-25T12:45:31.080580264Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:45:31.085937548Z 67 PC: 12abb | Get or set file attributes
2018-12-25T12:45:31.139491628Z 61 PC: 12ac3 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:45:31.14640613Z 87 PC: 12ad0 | Get or set file date and time
2018-12-25T12:45:31.148442921Z 66 PC: 12adb | Move file pointer
2018-12-25T12:45:31.15030609Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:45:31.157243749Z 66 PC: 12af0 | Move file pointer
2018-12-25T12:45:31.158733038Z 66 PC: 12b17 | Move file pointer
2018-12-25T12:45:31.159984914Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:45:31.162569035Z 66 PC: 12b2c | Move file pointer
2018-12-25T12:45:31.16412893Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-25T12:45:31.172720925Z 87 PC: 12b78 | Get or set file date and time
2018-12-25T12:45:31.174080187Z 62 PC: 12b7c | Close file
2018-12-25T12:45:31.181779473Z 79 PC: 12b80 | Find next file
2018-12-25T12:45:31.184213965Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.189797628Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.200303642Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.207116814Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.208732218Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.214770144Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.220931563Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.222146321Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.223902228Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.226432967Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.22778973Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.231477809Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.232871922Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.240029219Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.243712794Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.249137894Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.258657801Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.265390645Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.266762886Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.268007326Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.275007526Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.276402756Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.277773668Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.28054325Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.282430018Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.284999951Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.286534931Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.295708728Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.298181874Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.303918155Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.313831355Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.320159707Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.321442103Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.322984645Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.329117326Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.330410419Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.332219385Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.335028868Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.336694221Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.339953475Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.341594964Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.349047757Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.351975071Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.357623262Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.367264875Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.379151639Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.380338918Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.381552149Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.387734676Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.388935932Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.390631436Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.393390304Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.394624758Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.397086612Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.398737993Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.405779019Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.408430988Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.41420462Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.423881502Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.430273552Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.432485013Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.433712322Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.440020812Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.442865604Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.444370695Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.447418106Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.449483103Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.460343967Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.46177451Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.469711058Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.472603664Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.478464508Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.488846411Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.495642655Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.497328827Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.499766397Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.506210087Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.507677007Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.510244976Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.513412837Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.514738862Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.518032456Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.519712594Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.52695116Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.530025424Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.535883576Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.545647856Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.552708034Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.554078706Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.555406758Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.562463508Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.563862453Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.56520412Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.574191129Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.576454179Z 42 PC: 12b89 | Get date 0x12b89: cmp cx, 0x7c8
0x12b8d: jl 0x12b9e
0x12b8f: cmp dx, 0x90a
0x12b93: jl 0x12b9e
0x12b95: mov ah, 9
0x12b97: mov dx, 0x26a
0x12b9a: add dx, si
0x12b9c: int 0x21
0x12b9e: mov bp, 0x100
0x12ba1: jmp bp
0x12ba3: add byte ptr [bp + si], ch
0x12ba5: arpl word ptr cs:[bx + 0x6d], bp
0x12ba9: add byte ptr [bx + si], ah
0x12bab: sub ax, 0x2b3d
0x12bae: and byte ptr [bp + di + 0x6f], cl
0x12bb1: xor al, 0x20
0x12bb5: sub di, word ptr [di]
0x12bb7: sub ax, 0x202c
0x12bba: push sp
0x12bbb: push 0x2065
2018-12-25T12:45:31.578476449Z 9 PC: 12b9e | Display string (String= ' -=+ Kode4 +=-, The one and ONLY!')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":16153,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:45:31.431812344Z 78 PC: 12aa3 | Find first file
2018-12-25T12:45:31.438196351Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:45:31.443600009Z 67 PC: 12abb | Get or set file attributes
2018-12-25T12:45:31.46093357Z 61 PC: 12ac3 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:45:31.472375217Z 87 PC: 12ad0 | Get or set file date and time
2018-12-25T12:45:31.47419466Z 66 PC: 12adb | Move file pointer
2018-12-25T12:45:31.475982811Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:45:31.48254293Z 66 PC: 12af0 | Move file pointer
2018-12-25T12:45:31.484314592Z 66 PC: 12b17 | Move file pointer
2018-12-25T12:45:31.485591347Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:45:31.488048738Z 66 PC: 12b2c | Move file pointer
2018-12-25T12:45:31.489871128Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-25T12:45:31.497690983Z 87 PC: 12b78 | Get or set file date and time
2018-12-25T12:45:31.499152317Z 62 PC: 12b7c | Close file
2018-12-25T12:45:31.508103075Z 79 PC: 12b80 | Find next file
2018-12-25T12:45:31.51057166Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.515971558Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.526206344Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.533185165Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.534864158Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.537046628Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.543661571Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.545306249Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.548026417Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.553583927Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.555371936Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.558433979Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.559876584Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.567037429Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.57012289Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.575647854Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.584964636Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.59192114Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.593458481Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.594882671Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.601684763Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.603251738Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.605951495Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.608770607Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.610471901Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.613109833Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.614827368Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.622615886Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.625035824Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.630545599Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.640971872Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.647313612Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.648590226Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.651914372Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.658194109Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.659426241Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.660751373Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.663046761Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.664203334Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.667222938Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.668535712Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.675711861Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.678866001Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.690221628Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.699798972Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.706924771Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.708514038Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.710081541Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.71682214Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.718632536Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.72026526Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.723596923Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.724948847Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.727701131Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.732544363Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.739905367Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.742814793Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.749000596Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.761948314Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.768836843Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.771696823Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.773144669Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.779428486Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.782311885Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.78371737Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.78644035Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.798536731Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.806459036Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.807769981Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.815824958Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.818251598Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.823627019Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.833325265Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.840303845Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.841513002Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.843150631Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.849168919Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.850387037Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:31.851980496Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:31.854453549Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:31.855706324Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:31.858686987Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.860038353Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.86691767Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.869472196Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:31.874700285Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:31.883705064Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:31.890044551Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:31.891215225Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:31.892275772Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:31.899726366Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:31.901209717Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:31.90260897Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:31.910336624Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:31.912650016Z 42 PC: 12b89 | Get date 0x12b89: cmp cx, 0x7c8
0x12b8d: jl 0x12b9e
0x12b8f: cmp dx, 0x90a
0x12b93: jl 0x12b9e
0x12b95: mov ah, 9
0x12b97: mov dx, 0x26a
0x12b9a: add dx, si
0x12b9c: int 0x21
0x12b9e: mov bp, 0x100
0x12ba1: jmp bp
0x12ba3: add byte ptr [bp + si], ch
0x12ba5: arpl word ptr cs:[bx + 0x6d], bp
0x12ba9: add byte ptr [bx + si], ah
0x12bab: sub ax, 0x2b3d
0x12bae: and byte ptr [bp + di + 0x6f], cl
0x12bb1: xor al, 0x20
0x12bb5: sub di, word ptr [di]
0x12bb7: sub ax, 0x202c
0x12bba: push sp
0x12bbb: push 0x2065

{"DateBased":true,"Day":1,"Month":1,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":16153,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:45:33.213706108Z 78 PC: 12aa3 | Find first file
2018-12-25T12:45:33.220808003Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:45:33.226142759Z 67 PC: 12abb | Get or set file attributes
2018-12-25T12:45:33.241241578Z 61 PC: 12ac3 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:45:33.249269341Z 87 PC: 12ad0 | Get or set file date and time
2018-12-25T12:45:33.250609291Z 66 PC: 12adb | Move file pointer
2018-12-25T12:45:33.252112386Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:45:33.261853998Z 66 PC: 12af0 | Move file pointer
2018-12-25T12:45:33.263543348Z 66 PC: 12b17 | Move file pointer
2018-12-25T12:45:33.264896679Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:45:33.268032183Z 66 PC: 12b2c | Move file pointer
2018-12-25T12:45:33.269325608Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-25T12:45:33.277381513Z 87 PC: 12b78 | Get or set file date and time
2018-12-25T12:45:33.279023916Z 62 PC: 12b7c | Close file
2018-12-25T12:45:33.289649234Z 79 PC: 12b80 | Find next file
2018-12-25T12:45:33.292165199Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.29772522Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.307451191Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.313799435Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.315256183Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.317239454Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.323543451Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.325057759Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.32691234Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.329674999Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.331195983Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.334144195Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.335518869Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.343028863Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.346320099Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.35164976Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.360865179Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.368004048Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.369431455Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.370827483Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.37780584Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.379088786Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.380315563Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.383292575Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.384953518Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.387527993Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.38957716Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.396689428Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.399115006Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.410033345Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.419365377Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.425676427Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.427367402Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.428618762Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.43493225Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.437520598Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.43913955Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.441940169Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.44457393Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.447515494Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.44931569Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.456912938Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.459374618Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.464933694Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.477409155Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.483752823Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.484958986Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.486671497Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.49265277Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.493883387Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.496133395Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.498889145Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.500969182Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.506319212Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.508416088Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.515809287Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.518398825Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.523931474Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.53319907Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.544950774Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.546218017Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.547536328Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.553902348Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.555427348Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.556493795Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.559255719Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.560568942Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.568338536Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.570103546Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.577834247Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.580648841Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.586971375Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.596389742Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.603403938Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.605294818Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.606666721Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.612948663Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.615045512Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.616339379Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.618907063Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.620618159Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.624469395Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.626175478Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.633386601Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.635916018Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.64167156Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.651205266Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.658195133Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.659656909Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.661110974Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.667830031Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.669282338Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.670685083Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.678455867Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.680625769Z 42 PC: 12b89 | Get date 0x12b89: cmp cx, 0x7c8
0x12b8d: jl 0x12b9e
0x12b8f: cmp dx, 0x90a
0x12b93: jl 0x12b9e
0x12b95: mov ah, 9
0x12b97: mov dx, 0x26a
0x12b9a: add dx, si
0x12b9c: int 0x21
0x12b9e: mov bp, 0x100
0x12ba1: jmp bp
0x12ba3: add byte ptr [bp + si], ch
0x12ba5: arpl word ptr cs:[bx + 0x6d], bp
0x12ba9: add byte ptr [bx + si], ah
0x12bab: sub ax, 0x2b3d
0x12bae: and byte ptr [bp + di + 0x6f], cl
0x12bb1: xor al, 0x20
0x12bb5: sub di, word ptr [di]
0x12bb7: sub ax, 0x202c
0x12bba: push sp
0x12bbb: push 0x2065

{"DateBased":true,"Day":10,"Month":9,"Year":1992,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":16153,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:45:33.53071609Z 78 PC: 12aa3 | Find first file
2018-12-25T12:45:33.537221309Z 67 PC: 12ab1 | Get or set file attributes
2018-12-25T12:45:33.542635318Z 67 PC: 12abb | Get or set file attributes
2018-12-25T12:45:33.558778111Z 61 PC: 12ac3 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:45:33.565778714Z 87 PC: 12ad0 | Get or set file date and time
2018-12-25T12:45:33.567089949Z 66 PC: 12adb | Move file pointer
2018-12-25T12:45:33.568286865Z 63 PC: 12ae7 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:45:33.574929822Z 66 PC: 12af0 | Move file pointer
2018-12-25T12:45:33.576727544Z 66 PC: 12b17 | Move file pointer
2018-12-25T12:45:33.578163764Z 64 PC: 12b23 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:45:33.581841942Z 66 PC: 12b2c | Move file pointer
2018-12-25T12:45:33.583578358Z 64 PC: 12b54 | Write file or device (Write 399 bytes on handle 5)
2018-12-25T12:45:33.591757227Z 87 PC: 12b78 | Get or set file date and time
2018-12-25T12:45:33.593533118Z 62 PC: 12b7c | Close file
2018-12-25T12:45:33.601810782Z 79 PC: 12b80 | Find next file
2018-12-25T12:45:33.604285244Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.609691996Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.620617047Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.626993751Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.628242209Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.629793972Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.635945242Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.637200375Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.638982345Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.641509404Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.64285562Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.646027521Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.647606157Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.654910519Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.658310047Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.669299725Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.678949268Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.686594858Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.689046636Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.691537108Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.699843752Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.701213113Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.702500376Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.705803302Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.707180149Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.709719542Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.711643798Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.719290686Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.721823736Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.727728693Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.739844314Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.746145637Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.748733377Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.750058372Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.756092514Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.757888332Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.759289233Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.761828686Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.763683592Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.76622142Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.767549051Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.77503837Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.777461135Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.782783409Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.792600851Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.804396683Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.80564256Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.807288466Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.813324957Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.814640262Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.816438158Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.819029787Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.820365128Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.823643385Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.825164378Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.831985669Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.835096168Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.840674492Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.850107436Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.85690278Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.858144667Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.859364425Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.865892667Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.867263623Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.868566954Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.872597637Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.873907563Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.881628028Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.88348437Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.890737442Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.893096541Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.899144065Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.908364975Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.914770881Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.916596115Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.917803881Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.923769495Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.925487027Z 66 PC: 12b17 | Move file pointer (See above)
2018-12-25T12:45:33.926702618Z 64 PC: 12b23 | Write file or device (See above)
2018-12-25T12:45:33.929046661Z 66 PC: 12b2c | Move file pointer (See above)
2018-12-25T12:45:33.930839585Z 64 PC: 12b54 | Write file or device (See above)
2018-12-25T12:45:33.933330234Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.934630367Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.942467352Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.944165863Z 67 PC: 12ab1 | Get or set file attributes (See above)
2018-12-25T12:45:33.947574895Z 67 PC: 12abb | Get or set file attributes (See above)
2018-12-25T12:45:33.953971228Z 61 PC: 12ac3 | Open file (See above)
2018-12-25T12:45:33.958135169Z 87 PC: 12ad0 | Get or set file date and time (See above)
2018-12-25T12:45:33.959403907Z 66 PC: 12adb | Move file pointer (See above)
2018-12-25T12:45:33.961061277Z 63 PC: 12ae7 | Read file or device (See above)
2018-12-25T12:45:33.967097919Z 66 PC: 12af0 | Move file pointer (See above)
2018-12-25T12:45:33.968299989Z 87 PC: 12b78 | Get or set file date and time (See above)
2018-12-25T12:45:33.970068616Z 62 PC: 12b7c | Close file (See above)
2018-12-25T12:45:33.97694088Z 79 PC: 12b80 | Find next file (See above)
2018-12-25T12:45:33.979154282Z 42 PC: 12b89 | Get date 0x12b89: cmp cx, 0x7c8
0x12b8d: jl 0x12b9e
0x12b8f: cmp dx, 0x90a
0x12b93: jl 0x12b9e
0x12b95: mov ah, 9
0x12b97: mov dx, 0x26a
0x12b9a: add dx, si
0x12b9c: int 0x21
0x12b9e: mov bp, 0x100
0x12ba1: jmp bp
0x12ba3: add byte ptr [bp + si], ch
0x12ba5: arpl word ptr cs:[bx + 0x6d], bp
0x12ba9: add byte ptr [bx + si], ah
0x12bab: sub ax, 0x2b3d
0x12bae: and byte ptr [bp + di + 0x6f], cl
0x12bb1: xor al, 0x20
0x12bb5: sub di, word ptr [di]
0x12bb7: sub ax, 0x202c
0x12bba: push sp
0x12bbb: push 0x2065
2018-12-25T12:45:33.981581332Z 9 PC: 12b9e | Display string (String= ' -=+ Kode4 +=-, The one and ONLY!')