Sample viewer

vx.netlux.org/Virus.DOS.Vesna.1614.a

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:09:50.133070194Z 48 PC: 12a81 | Get DOS version
2018-12-17T23:09:50.135460867Z 47 PC: 12a95 | Get disk transfer address
2018-12-17T23:09:50.139257613Z 26 PC: 12aa2 | Set disk transfer address
2018-12-17T23:09:50.140506951Z 78 PC: 12b67 | Find first file
2018-12-17T23:09:50.149734493Z 78 PC: 12b67 | Find first file
2018-12-17T23:09:50.156985169Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:50.158861195Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:50.165443866Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:50.184018595Z 61 PC: 12bb0 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:09:50.192133085Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:50.194125069Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.197398251Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.207468486Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:50.215402276Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.21751147Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:50.219490159Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:50.223115843Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:50.225208275Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:50.229227519Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:50.231243037Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:50.236615223Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:50.238909335Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:50.242151849Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:50.252293017Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:50.254500867Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:50.268323545Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:50.279768904Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:50.283955974Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:50.285378187Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:50.291406466Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:50.302771735Z 61 PC: 12bb0 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:09:50.312129602Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:50.313929374Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.318322772Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.332218938Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:50.339767174Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.342728108Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:50.344429115Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:50.347191606Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:50.348825557Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:50.352528186Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:50.354313732Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:50.357455446Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:50.360515998Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:50.364074646Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:50.37400563Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:50.376793129Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:50.385763067Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:50.39652927Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:50.400692034Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:50.403237197Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:50.409911561Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:50.420664118Z 61 PC: 12bb0 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:09:50.429645668Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:50.431480676Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.433381599Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.436034956Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:50.443068133Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.444961282Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:50.4475889Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:50.450183325Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:50.451599768Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:50.454812055Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:50.45616127Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:50.45843309Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:50.459914855Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:50.463317039Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:50.472425477Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:50.474478365Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:50.484411713Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:50.497460737Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:50.500630344Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:50.503202187Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:50.509788916Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:50.520319066Z 61 PC: 12bb0 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:09:50.528335382Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:50.530464033Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.532323186Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.5341078Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:50.542552711Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.544422506Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:50.54626563Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:50.550306884Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:50.552130662Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:50.555271996Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:50.558169601Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:50.561259899Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:50.562992084Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:50.566733947Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:50.865296535Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:50.867306603Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:50.875639663Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:50.894398819Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:50.898670226Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:50.900548957Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:50.908484841Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:50.919372724Z 61 PC: 12bb0 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:09:50.926467928Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:50.929899458Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.931705632Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.934048855Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:50.942545584Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:50.94427285Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:50.945930516Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:50.9485934Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:50.950600923Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:50.953706089Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:50.955306336Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:50.959846399Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:50.967306469Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:50.970316846Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:50.981283857Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:50.982700921Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:50.989203602Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:50.997961341Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:51.00038738Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:51.001591402Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:51.006564419Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:51.015506344Z 61 PC: 12bb0 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:09:51.025244475Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:51.026621844Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.028801691Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.030139145Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:51.035835199Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.037815591Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:51.039223226Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:51.041628166Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:51.04363111Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:51.045953986Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:51.047835522Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:51.056462906Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:51.058594663Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:51.062299305Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:51.075229526Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:51.076952093Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:51.086492503Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:51.103683621Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:51.106704819Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:51.108355131Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:51.115401243Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:51.126574512Z 61 PC: 12bb0 | Open file (Filename = 'PAH.COM')
2018-12-17T23:09:51.133744397Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:51.136671517Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.13846641Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.140587587Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:51.147381706Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.149557044Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:51.151516697Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:51.154751857Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:51.157346343Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:51.160651124Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:51.163271128Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:51.167202997Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:51.16910419Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:51.172480656Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:51.18318884Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:51.186063323Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:51.194626205Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:51.206067838Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:51.209097642Z 47 PC: 12b6f | Get disk transfer address
2018-12-17T23:09:51.210595487Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:51.217626982Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:51.228051193Z 61 PC: 12bb0 | Open file (Filename = 'TEST.COM')
2018-12-17T23:09:51.23553105Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:51.238284034Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.240022512Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.241588434Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:51.249992909Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.251718262Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:51.254121238Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:51.257937109Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:51.259829897Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:51.262991689Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:51.265801089Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:51.273549381Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:51.276442337Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:51.280546831Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:51.291100626Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:51.293084434Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:51.302688443Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:51.314115599Z 79 PC: 12b67 | Find next file
2018-12-17T23:09:51.316983539Z 78 PC: 12b67 | Find first file
2018-12-17T23:09:51.323112948Z 26 PC: 12abe | Set disk transfer address
2018-12-17T23:09:51.325134758Z 78 PC: 1306b | Find first file
2018-12-17T23:09:51.330300286Z 47 PC: 13073 | Get disk transfer address
2018-12-17T23:09:51.331694206Z 67 PC: 12ba0 | Get or set file attributes
2018-12-17T23:09:51.336446337Z 67 PC: 12bab | Get or set file attributes
2018-12-17T23:09:51.672473093Z 61 PC: 12bb0 | Open file (Filename = 'c:\COMMAND.COM')
2018-12-17T23:09:51.677592243Z 87 PC: 12bba | Get or set file date and time
2018-12-17T23:09:51.680822996Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.682753864Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.684887805Z 63 PC: 12cb4 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T23:09:51.689755333Z 66 PC: 12c8f | Move file pointer
2018-12-17T23:09:51.691662306Z 66 PC: 12dcc | Move file pointer
2018-12-17T23:09:51.693497425Z 63 PC: 12dd8 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T23:09:51.697084978Z 66 PC: 12e2f | Move file pointer
2018-12-17T23:09:51.698725872Z 64 PC: 12e3b | Write file or device (Write 11 bytes on handle 5)
2018-12-17T23:09:51.701865843Z 66 PC: 12e5c | Move file pointer
2018-12-17T23:09:51.704714076Z 64 PC: 12e68 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T23:09:51.708455066Z 66 PC: 12e8c | Move file pointer
2018-12-17T23:09:51.710507012Z 44 PC: 13016 | Get time 0x13016: xor cx, dx
0x13018: xor ch, cl
0x1301a: mov byte ptr [0x10b], ch
0x1301e: popaw
0x1301f: ret
0x13020: xor byte ptr [bp + si], bl
0x13022: das
0x13023: dec si
0x13024: dec di
0x13025: add byte ptr [bp + di + 1], al
0x13028: inc bx
0x13029: add bh, byte ptr [di]
0x1302b: add byte ptr [bx + 1], dl
0x1302e: push di
0x1302f: inc dx
0x13031: add bh, bh
0x13033: add byte ptr [bx], bh
0x13035: push ds
0x13036: sub al, 0x19
0x13038: xchg ax, si
2018-12-17T23:09:51.714846397Z 64 PC: 12a75 | Write file or device (Write 1614 bytes on handle 5)
2018-12-17T23:09:51.727520888Z 87 PC: 12bf0 | Get or set file date and time
2018-12-17T23:09:51.729391433Z 62 PC: 12bf6 | Close file
2018-12-17T23:09:51.736245474Z 67 PC: 12c00 | Get or set file attributes
2018-12-17T23:09:51.7440651Z 79 PC: 1306b | Find next file
2018-12-17T23:09:51.747125502Z 78 PC: 1306b | Find first file
2018-12-17T23:09:51.753923127Z 78 PC: 1306b | Find first file
2018-12-17T23:09:51.760360125Z 44 PC: 12b04 | Get time 0x12b04: xor dx, dx
0x12b06: cmp ch, cl
0x12b08: je 0x12b0d
0x12b0a: jmp 0x12b5a
0x12b0c: nop
0x12b0d: cmp ch, 7
0x12b10: jne 0x12b15
0x12b12: mov dx, 0x180
0x12b15: cmp ch, 9
0x12b18: jne 0x12b1d
0x12b1a: mov dx, 0x239
0x12b1d: cmp ch, 0xb
0x12b20: jne 0x12b25
0x12b22: mov dx, 0x284
0x12b25: cmp ch, 0xd
0x12b28: jne 0x12b2d
0x12b2a: mov dx, 0x2c2
0x12b2d: cmp ch, 0xf
0x12b30: jne 0x12b35
0x12b32: mov dx, 0x335