Sample viewer

vx.netlux.org/Virus.DOS.Vienna.SPb.641

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:11:03.9952172Z 48 PC: 15169 | Get DOS version
2018-12-17T23:11:03.997324839Z 26 PC: 15177 | Set disk transfer address
2018-12-17T23:11:04.000169441Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-17T23:11:04.002136248Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-17T23:11:04.00475245Z 78 PC: 1518a | Find first file
2018-12-17T23:11:04.011189513Z 67 PC: 151e1 | Get or set file attributes
2018-12-17T23:11:04.027058632Z 61 PC: 151e6 | Open file (Filename = '\SLEEP.COM')
2018-12-17T23:11:04.03370847Z 63 PC: 151f3 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:11:04.038352567Z 66 PC: 15209 | Move file pointer
2018-12-17T23:11:04.039480919Z 64 PC: 15225 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:11:04.042323891Z 66 PC: 1523f | Move file pointer
2018-12-17T23:11:04.044133704Z 64 PC: 1524f | Write file or device (Write 641 bytes on handle 5)
2018-12-17T23:11:04.052441848Z 87 PC: 15264 | Get or set file date and time
2018-12-17T23:11:04.053876769Z 62 PC: 1526a | Close file
2018-12-17T23:11:04.06551135Z 67 PC: 1527b | Get or set file attributes
2018-12-17T23:11:04.070077721Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":5,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:41.462251079Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:41.463803687Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:41.46662129Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:41.924054165Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:41.489765129Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:41.491245546Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:41.493990338Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:41.495939845Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:41.498361588Z 78 PC: 1518a | Find first file
2018-12-25T12:54:41.512833808Z 67 PC: 151e1 | Get or set file attributes
2018-12-25T12:54:41.928379934Z 61 PC: 151e6 | Open file (Filename = '\SLEEP.COM')
2018-12-25T12:54:41.936389113Z 63 PC: 151f3 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:54:41.943852812Z 66 PC: 15209 | Move file pointer
2018-12-25T12:54:41.945468858Z 64 PC: 15225 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:54:41.950052847Z 66 PC: 1523f | Move file pointer
2018-12-25T12:54:41.957363409Z 64 PC: 1524f | Write file or device (Write 641 bytes on handle 5)
2018-12-25T12:54:41.965665374Z 87 PC: 15264 | Get or set file date and time
2018-12-25T12:54:41.967413885Z 62 PC: 1526a | Close file
2018-12-25T12:54:41.975856079Z 67 PC: 1527b | Get or set file attributes
2018-12-25T12:54:41.981190643Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:41.498727834Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:41.500892758Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:41.504334886Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:41.508606883Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:41.511318248Z 78 PC: 1518a | Find first file
2018-12-25T12:54:41.518285909Z 67 PC: 151e1 | Get or set file attributes
2018-12-25T12:54:41.543638929Z 61 PC: 151e6 | Open file (Filename = '\SLEEP.COM')
2018-12-25T12:54:41.551401381Z 63 PC: 151f3 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:54:41.565875863Z 66 PC: 15209 | Move file pointer
2018-12-25T12:54:41.567498392Z 64 PC: 15225 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:54:41.570452648Z 66 PC: 1523f | Move file pointer
2018-12-25T12:54:41.572626275Z 64 PC: 1524f | Write file or device (Write 641 bytes on handle 5)
2018-12-25T12:54:41.596485192Z 87 PC: 15264 | Get or set file date and time
2018-12-25T12:54:41.598091713Z 62 PC: 1526a | Close file
2018-12-25T12:54:41.607521397Z 67 PC: 1527b | Get or set file attributes
2018-12-25T12:54:41.614711312Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":25,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:41.736479491Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:41.737974268Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:41.748433326Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:41.756494644Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:42.105721559Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:41.837796899Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:41.839104899Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:41.841759205Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:41.843711754Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:41.846008683Z 78 PC: 1518a | Find first file
2018-12-25T12:54:41.851689583Z 67 PC: 151e1 | Get or set file attributes
2018-12-25T12:54:41.92450487Z 61 PC: 151e6 | Open file (Filename = '\SLEEP.COM')
2018-12-25T12:54:41.931622022Z 63 PC: 151f3 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:54:41.938165857Z 66 PC: 15209 | Move file pointer
2018-12-25T12:54:41.939917656Z 64 PC: 15225 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:54:41.942963961Z 66 PC: 1523f | Move file pointer
2018-12-25T12:54:41.9443409Z 64 PC: 1524f | Write file or device (Write 641 bytes on handle 5)
2018-12-25T12:54:41.952943767Z 87 PC: 15264 | Get or set file date and time
2018-12-25T12:54:41.95529881Z 62 PC: 1526a | Close file
2018-12-25T12:54:41.962927701Z 67 PC: 1527b | Get or set file attributes
2018-12-25T12:54:41.967554454Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":27,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:42.217135415Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:42.218631692Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:42.221351482Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:42.223273449Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:43.005893299Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":25,"Month":3,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:42.347400631Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:42.348754753Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:42.351467327Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:42.353381596Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:43.006008333Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":20,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:44.380821313Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:44.38250701Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:44.385346359Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:44.387275347Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:45.262303599Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":23,"Month":9,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:44.533755867Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:44.535130321Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:44.538224849Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:44.540431972Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:45.262225097Z 26 PC: 15212 | Set disk transfer address

{"DateBased":true,"Day":6,"Month":10,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17066,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:54:44.624169776Z 48 PC: 15169 | Get DOS version
2018-12-25T12:54:44.62637024Z 26 PC: 15177 | Set disk transfer address
2018-12-25T12:54:44.62918951Z 42 PC: 152a5 | Get date 0x152a5: cmp dh, 8
0x152a8: jne 0x152e3
0x152aa: cmp dl, 5
0x152ad: jb 0x152e3
0x152af: push es
0x152b0: mov bx, 0xb900
0x152b3: mov es, bx
0x152b5: xor bx, bx
0x152b7: mov cx, 1
0x152ba: mov dx, 0x80
0x152bd: mov ax, 0x201
0x152c0: int 0x13
0x152c2: jae 0x152c7
0x152c4: jmp 0x1517c
0x152c7: mov bx, 0xb900
0x152ca: mov es, bx
0x152cc: mov al, 0
0x152ce: mov byte ptr es:[0x1d2], al
0x152d2: xor bx, bx
0x152d4: mov cx, 1
2018-12-25T12:54:44.630912129Z 42 PC: 152e7 | Get date 0x152e7: cmp dx, 0x319
0x152eb: je 0x1530d
0x152ed: cmp dx, 0xa06
0x152f1: je 0x1530d
0x152f3: cmp dx, 0x11b
0x152f7: je 0x1530d
0x152f9: cmp dx, 0xb19
0x152fd: je 0x1530d
0x152ff: cmp dx, 0x514
0x15303: je 0x1530d
0x15305: cmp dx, 0x917
0x15309: je 0x1530d
0x1530b: jmp 0x152c4
0x1530d: push es
0x1530e: mov bx, 0xb800
0x15311: mov es, bx
0x15313: mov bx, 0x1000
0x15316: mov ax, 0x201
0x15319: mov cx, 1
0x1531c: mov dx, 0x80
2018-12-25T12:54:44.964342033Z 26 PC: 15212 | Set disk transfer address