Sample viewer




Time Syscall Op Syscall Name
2018-12-17T23:08:42.996978631Z 42 PC: 12ac1 | Get date 0x12ac1: dec dl
0x12ac3: jne 0x12acc
0x12ac5: dec al
0x12ac7: jne 0x12acc
0x12ac9: cli
0x12aca: jmp 0x12aca
0x12acc: push es
0x12acd: mov dx, es
0x12acf: mov ax, 0x3521
0x12ad2: int 0x21
0x12ad4: push es
0x12ad5: pop ds
0x12ad6: mov si, bx
0x12ad8: mov ax, ds
0x12ada: sub dx, ax
0x12adc: mov cx, 0x1000
0x12adf: cmp dx, 0x100
0x12ae3: jge 0x12aec
0x12ae5: mov ax, 0x10
0x12ae8: mul dx
2018-12-17T23:08:42.999684286Z 53 PC: 12ad4 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T23:08:43.002807837Z 26 PC: 12b29 | Set disk transfer address
2018-12-17T23:08:43.004561753Z 67 PC: 12e3f | Get or set file attributes
2018-12-17T23:08:43.010642302Z 67 PC: 12e4c | Get or set file attributes
2018-12-17T23:08:43.355604031Z 61 PC: 12e51 | Open file (Filename = '')
2018-12-17T23:08:43.363102374Z 66 PC: 12e29 | Move file pointer
2018-12-17T23:08:43.367000872Z 63 PC: 12e31 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:08:43.37456537Z 87 PC: 12c66 | Get or set file date and time
2018-12-17T23:08:43.376776315Z 66 PC: 12e1f | Move file pointer
2018-12-17T23:08:43.378742891Z 63 PC: 12e31 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T23:08:43.384355761Z 66 PC: 12e29 | Move file pointer
2018-12-17T23:08:43.386427986Z 66 PC: 12e1f | Move file pointer
2018-12-17T23:08:43.388426512Z 64 PC: 12e39 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:08:43.391921491Z 66 PC: 12e29 | Move file pointer
2018-12-17T23:08:43.394793359Z 64 PC: 12e39 | Write file or device (Write 1045 bytes on handle 5)
2018-12-17T23:08:43.406448385Z 66 PC: 12e29 | Move file pointer
2018-12-17T23:08:43.408503949Z 64 PC: 12e39 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T23:08:43.412910251Z 87 PC: 12e61 | Get or set file date and time
2018-12-17T23:08:43.415028662Z 62 PC: 12e65 | Close file
2018-12-17T23:08:43.426415814Z 67 PC: 12e75 | Get or set file attributes
2018-12-17T23:08:43.438214511Z 26 PC: 12ba5 | Set disk transfer address
2018-12-17T23:08:43.440475711Z 9 PC: 12aa2 | Display string (String= 'Hello - This is a 100 COM test file, 1993 ')