.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T23:12:44.200822786Z | 44 | PC: 12b6e | Get time 0x12b6e: cmp byte ptr [0x103], 0 0x12b73: je 0x12b7a 0x12b75: cmp dh, 0xf 0x12b78: jg 0x12b83 0x12b7a: cmp dl, 0 0x12b7d: je 0x12b6a 0x12b7f: mov byte ptr [0x103], dl 0x12b83: mov byte ptr [0x21f], 0 0x12b88: mov byte ptr [0x220], 4 0x12b8d: mov byte ptr [0x229], 0 0x12b92: mov cx, 0x27 0x12b95: mov dx, 0x115 0x12b98: mov ah, 0x4e 0x12b9a: int 0x21 0x12b9c: cmp ax, 0x12 0x12b9f: je 0x12ba4 0x12ba1: call 0x12bc6 0x12ba4: mov cx, 0x27 0x12ba7: mov dx, 0x11b 0x12baa: mov ah, 0x4e |
2018-12-17T23:12:44.203863221Z | 78 | PC: 12b9c | Find first file |
2018-12-17T23:12:44.209562876Z | 78 | PC: 12bae | Find first file |
2018-12-17T23:12:44.21518296Z | 67 | PC: 12be7 | Get or set file attributes |
2018-12-17T23:12:44.230670931Z | 61 | PC: 12bed | Open file (Filename = 'SLEEP.COM') |
2018-12-17T23:12:44.238026935Z | 63 | PC: 12bfc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:12:44.244529617Z | 62 | PC: 12c30 | Close file |
2018-12-17T23:12:44.246600161Z | 61 | PC: 12c39 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T23:12:44.254727891Z | 64 | PC: 12a54 | Write file or device (Write 625 bytes on handle 5) |
2018-12-17T23:12:44.263394596Z | 87 | PC: 12c61 | Get or set file date and time |
2018-12-17T23:12:44.265409829Z | 62 | PC: 12c69 | Close file |
2018-12-17T23:12:44.277630044Z | 67 | PC: 12c76 | Get or set file attributes |
2018-12-17T23:12:44.286192165Z | 79 | PC: 12c20 | Find next file |
2018-12-17T23:12:44.289395823Z | 67 | PC: 12be7 | Get or set file attributes |
2018-12-17T23:12:44.299882554Z | 61 | PC: 12bed | Open file (Filename = 'PRINT.COM') |
2018-12-17T23:12:44.30659691Z | 63 | PC: 12bfc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:12:44.31289095Z | 62 | PC: 12c30 | Close file |
2018-12-17T23:12:44.31499088Z | 61 | PC: 12c39 | Open file (Filename = 'PRINT.COM') |
2018-12-17T23:12:44.327134563Z | 64 | PC: 12a54 | Write file or device (Write 625 bytes on handle 5) |
2018-12-17T23:12:44.335592155Z | 87 | PC: 12c61 | Get or set file date and time |
2018-12-17T23:12:44.337489806Z | 62 | PC: 12c69 | Close file |
2018-12-17T23:12:44.357783922Z | 67 | PC: 12c76 | Get or set file attributes |
2018-12-17T23:12:44.362614947Z | 79 | PC: 12c20 | Find next file |
2018-12-17T23:12:44.365276186Z | 67 | PC: 12be7 | Get or set file attributes |
2018-12-17T23:12:44.387479728Z | 61 | PC: 12bed | Open file (Filename = 'HELLO.COM') |
2018-12-17T23:12:44.394028035Z | 63 | PC: 12bfc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:12:44.402384665Z | 62 | PC: 12c30 | Close file |
2018-12-17T23:12:44.405615831Z | 61 | PC: 12c39 | Open file (Filename = 'HELLO.COM') |
2018-12-17T23:12:44.412510788Z | 64 | PC: 12a54 | Write file or device (Write 625 bytes on handle 5) |
2018-12-17T23:12:44.424966516Z | 87 | PC: 12c61 | Get or set file date and time |
2018-12-17T23:12:44.427983658Z | 62 | PC: 12c69 | Close file |
2018-12-17T23:12:44.450373055Z | 67 | PC: 12c76 | Get or set file attributes |
2018-12-17T23:12:44.458356748Z | 79 | PC: 12c20 | Find next file |
2018-12-17T23:12:44.472523224Z | 67 | PC: 12be7 | Get or set file attributes |
2018-12-17T23:12:44.482189297Z | 61 | PC: 12bed | Open file (Filename = 'PHANG.COM') |
2018-12-17T23:12:44.48890531Z | 63 | PC: 12bfc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T23:12:44.495830238Z | 62 | PC: 12c30 | Close file |
2018-12-17T23:12:44.497899108Z | 61 | PC: 12c39 | Open file (Filename = 'PHANG.COM') |
2018-12-17T23:12:44.504561331Z | 64 | PC: 12a54 | Write file or device (Write 625 bytes on handle 5) |
2018-12-17T23:12:44.525422646Z | 87 | PC: 12c61 | Get or set file date and time |
2018-12-17T23:12:44.527468436Z | 62 | PC: 12c69 | Close file |
2018-12-17T23:12:44.535244917Z | 67 | PC: 12c76 | Get or set file attributes |
2018-12-17T23:12:44.540856847Z | 9 | PC: 12ca4 | Display string (String= ' Error #2693 - Execution Halted') |
2018-12-17T23:12:44.545362346Z | 76 | PC: 12ca8 | Terminate with return code (Return code = '36') |