Sample viewer

vx.netlux.org/Virus.DOS.Trianon.1141

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:12:58.759574655Z 71 PC: 17c23 | Get current directory
2018-12-17T23:12:58.764176388Z 26 PC: 17c2a | Set disk transfer address
2018-12-17T23:12:58.76621994Z 78 PC: 17c34 | Find first file
2018-12-17T23:12:58.773375395Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:12:58.785423658Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:00.214052429Z 61 PC: 17c50 | Open file (Filename = 'SLEEP.COM')
2018-12-17T23:13:00.22740218Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:00.230708367Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:00.238183812Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:00.240600055Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-17T23:13:00.374272309Z 66 PC: 17ca0 | Move file pointer
2018-12-17T23:13:00.377454242Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:13:00.384896425Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:00.386900182Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:00.414888847Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:00.43454205Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:00.437761063Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:13:00.445921827Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:00.47258052Z 61 PC: 17c50 | Open file (Filename = 'PRINT.COM')
2018-12-17T23:13:00.481032202Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:00.487135678Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:00.498907662Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:00.501107077Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-17T23:13:00.53441836Z 66 PC: 17ca0 | Move file pointer
2018-12-17T23:13:00.53755094Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:13:00.547975701Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:00.554675327Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:00.590123378Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:00.623209888Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:00.62650316Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:13:00.634352949Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:00.658890406Z 61 PC: 17c50 | Open file (Filename = 'HELLO.COM')
2018-12-17T23:13:00.671048956Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:00.674203377Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:00.681468106Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:00.683704712Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-17T23:13:00.707446682Z 66 PC: 17ca0 | Move file pointer
2018-12-17T23:13:00.709848759Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:13:00.717529791Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:00.720259102Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:00.753282504Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:00.787918578Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:00.790910012Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:13:00.795997928Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:00.818759386Z 61 PC: 17c50 | Open file (Filename = 'PHANG.COM')
2018-12-17T23:13:00.826578377Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:00.829549193Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:00.839080253Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:00.841267716Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-17T23:13:00.870584088Z 66 PC: 17ca0 | Move file pointer
2018-12-17T23:13:00.872644982Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:13:00.880806528Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:00.883572128Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:00.93112068Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:00.962379113Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:00.96704715Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:13:00.973618054Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:00.993762441Z 61 PC: 17c50 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T23:13:01.006542921Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:01.009750111Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:01.017452112Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:01.027965019Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-17T23:13:01.067784448Z 66 PC: 17ca0 | Move file pointer
2018-12-17T23:13:01.07041275Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:13:01.078163884Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:01.080958097Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:01.112385338Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:01.175563206Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:01.180137607Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:13:01.188735183Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:01.265461966Z 61 PC: 17c50 | Open file (Filename = 'MANDEL.COM')
2018-12-17T23:13:01.274191339Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:01.277166232Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:01.286016613Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:01.289352034Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-17T23:13:01.403864964Z 66 PC: 17ca0 | Move file pointer
2018-12-17T23:13:01.406273032Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:13:01.413806577Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:01.416624405Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:01.521234505Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:01.614846726Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:01.619382565Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:13:01.626022209Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:01.642046047Z 61 PC: 17c50 | Open file (Filename = 'PAH.COM')
2018-12-17T23:13:01.650368956Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:01.653638453Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:01.661007218Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:01.663454379Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-17T23:13:01.676057206Z 66 PC: 17ca0 | Move file pointer
2018-12-17T23:13:01.678498416Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-17T23:13:01.688846402Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:01.691689839Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:01.702638775Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:01.714433131Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:01.71885803Z 67 PC: 17c42 | Get or set file attributes
2018-12-17T23:13:01.725991984Z 67 PC: 17c4b | Get or set file attributes
2018-12-17T23:13:01.737002396Z 61 PC: 17c50 | Open file (Filename = 'TEST.COM')
2018-12-17T23:13:01.749821389Z 87 PC: 17c57 | Get or set file date and time
2018-12-17T23:13:01.753849592Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-17T23:13:01.7613422Z 66 PC: 17c75 | Move file pointer
2018-12-17T23:13:01.763408986Z 87 PC: 17cb3 | Get or set file date and time
2018-12-17T23:13:01.766700886Z 62 PC: 17cb7 | Close file
2018-12-17T23:13:01.774508335Z 67 PC: 17cbe | Get or set file attributes
2018-12-17T23:13:01.785485756Z 79 PC: 17cc3 | Find next file
2018-12-17T23:13:01.807197288Z 59 PC: 17cd0 | Change current directory
2018-12-17T23:13:01.811752843Z 59 PC: 17cdd | Change current directory
2018-12-17T23:13:01.814170619Z 42 PC: 17ce3 | Get date 0x17ce3: cmp dx, 0x805
0x17ce7: je 0x17cf2
0x17ce9: cmp al, 5
0x17ceb: jne 0x17cfb
0x17ced: cmp dl, 0xd
0x17cf0: jne 0x17cfb
0x17cf2: mov dx, bx
0x17cf4: add dx, 0x40
0x17cf7: mov ah, 9
0x17cf9: int 0x21
0x17cfb: popaw
0x17cfc: pop es
0x17cfd: pop ds
0x17cfe: pop ss
0x17cff: jmp si
0x17d01: mov cx, 0x350
0x17d04: mov al, byte ptr [si]
0x17d06: inc al
0x17d08: mov byte ptr [si], al
0x17d0a: inc si
2018-12-17T23:13:01.822885214Z 48 PC: 18097 | Get DOS version
2018-12-17T23:13:01.824703163Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T23:13:01.826817568Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T23:13:01.829428508Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17694,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:23.390989834Z 71 PC: 17c23 | Get current directory
2018-12-25T12:56:23.394348234Z 26 PC: 17c2a | Set disk transfer address
2018-12-25T12:56:23.395440398Z 78 PC: 17c34 | Find first file
2018-12-25T12:56:23.401131046Z 67 PC: 17c42 | Get or set file attributes
2018-12-25T12:56:23.408146079Z 67 PC: 17c4b | Get or set file attributes
2018-12-25T12:56:23.425538516Z 61 PC: 17c50 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:56:23.433842778Z 87 PC: 17c57 | Get or set file date and time
2018-12-25T12:56:23.435656858Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:56:23.439746864Z 66 PC: 17c75 | Move file pointer
2018-12-25T12:56:23.440917957Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-25T12:56:23.449928368Z 66 PC: 17ca0 | Move file pointer
2018-12-25T12:56:23.451198725Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:56:23.456884756Z 87 PC: 17cb3 | Get or set file date and time
2018-12-25T12:56:23.459188874Z 62 PC: 17cb7 | Close file
2018-12-25T12:56:23.466974626Z 67 PC: 17cbe | Get or set file attributes
2018-12-25T12:56:23.476688761Z 79 PC: 17cc3 | Find next file
2018-12-25T12:56:23.479100226Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.484602908Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.493885324Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.50503446Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.506513205Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.512515834Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.514341022Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.525126704Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.526067287Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.530480683Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.531907275Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.54088284Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.547250987Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.549182169Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.552910989Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.558912963Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.567706817Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.569483969Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.575583433Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.577573678Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.58691545Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.588128825Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.594450333Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.595703138Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.603307257Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.613265068Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.616144961Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.621957083Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.632454658Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.643893856Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.645687966Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.652592162Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.653838675Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.660049551Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.662662241Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.669139931Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.670697008Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.679519595Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.689225736Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.69171992Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.697992588Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.707812585Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.719772745Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.721987287Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.728355986Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.730037725Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.739339173Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.740763372Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.747253572Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.74998737Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.757606335Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.767002638Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.770074636Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.775569006Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.785383074Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.792349323Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.79364141Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.799985642Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.801942161Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.810555495Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.816670344Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.824119747Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.825570785Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.833138174Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.843670217Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.847554185Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.853065391Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.862848497Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.87057695Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.871968681Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.878332416Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.8801362Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.888949881Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.890382907Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.897144705Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.898577719Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.90599087Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.915874436Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.918502938Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.924035471Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.933869027Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.940569266Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.942258236Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.948846421Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.950389029Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.952085277Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.959494397Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.972043165Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.97502176Z 59 PC: 17cd0 | Change current directory
2018-12-25T12:56:23.979087483Z 59 PC: 17cdd | Change current directory
2018-12-25T12:56:23.980736955Z 42 PC: 17ce3 | Get date 0x17ce3: cmp dx, 0x805
0x17ce7: je 0x17cf2
0x17ce9: cmp al, 5
0x17ceb: jne 0x17cfb
0x17ced: cmp dl, 0xd
0x17cf0: jne 0x17cfb
0x17cf2: mov dx, bx
0x17cf4: add dx, 0x40
0x17cf7: mov ah, 9
0x17cf9: int 0x21
0x17cfb: popaw
0x17cfc: pop es
0x17cfd: pop ds
0x17cfe: pop ss
0x17cff: jmp si
0x17d01: mov cx, 0x350
0x17d04: mov al, byte ptr [si]
0x17d06: inc al
0x17d08: mov byte ptr [si], al
0x17d0a: inc si
2018-12-25T12:56:23.988045505Z 48 PC: 18097 | Get DOS version
2018-12-25T12:56:23.990183467Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-25T12:56:23.991278007Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:56:23.992357697Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":4,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17694,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:23.447999166Z 71 PC: 17c23 | Get current directory
2018-12-25T12:56:23.451827177Z 26 PC: 17c2a | Set disk transfer address
2018-12-25T12:56:23.452830032Z 78 PC: 17c34 | Find first file
2018-12-25T12:56:23.458894109Z 67 PC: 17c42 | Get or set file attributes
2018-12-25T12:56:23.469934086Z 67 PC: 17c4b | Get or set file attributes
2018-12-25T12:56:23.489111021Z 61 PC: 17c50 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:56:23.495632258Z 87 PC: 17c57 | Get or set file date and time
2018-12-25T12:56:23.497499947Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:56:23.504108017Z 66 PC: 17c75 | Move file pointer
2018-12-25T12:56:23.505713442Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-25T12:56:23.51463945Z 66 PC: 17ca0 | Move file pointer
2018-12-25T12:56:23.516589171Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:56:23.52129845Z 87 PC: 17cb3 | Get or set file date and time
2018-12-25T12:56:23.522304469Z 62 PC: 17cb7 | Close file
2018-12-25T12:56:23.530880131Z 67 PC: 17cbe | Get or set file attributes
2018-12-25T12:56:23.541309013Z 79 PC: 17cc3 | Find next file
2018-12-25T12:56:23.544422992Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.551100565Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.563648231Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.570619285Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.572745253Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.579028543Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.581072367Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.589974024Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.591028891Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.597341559Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.599240535Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.606791769Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.616330621Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.623293813Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.629121036Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.638894808Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.646272356Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.647749803Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.668714869Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.671533289Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.679792327Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.680911506Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.685553497Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.686741428Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.692343205Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.699144603Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.701447566Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.705158834Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.714035849Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.720471944Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.722283453Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.728238776Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.729949255Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.738661321Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.740803026Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.747108046Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.748465034Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.756447298Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.766413392Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.76905422Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.775509042Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.785968497Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.792173715Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.794046089Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.800089804Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.801594353Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.811073688Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.812317473Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.818762174Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.821049713Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.829003243Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.838423352Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.841597269Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.847171841Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.856964307Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.864328493Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.865650061Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.871611885Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.874619368Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.883480114Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.884980333Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.893277359Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.895035783Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.902713693Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.913267355Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.915193533Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.920835803Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.930638109Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.941904398Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.943287275Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.949589592Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.951473436Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.960683823Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.962178043Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.968755286Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.970407388Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.978244529Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.988262793Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.990782825Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.994862968Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:24.004535261Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:24.015715513Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:24.018136208Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:24.024832691Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:24.026118793Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.028218957Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.035655458Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.045518671Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.048120925Z 59 PC: 17cd0 | Change current directory
2018-12-25T12:56:24.052330552Z 59 PC: 17cdd | Change current directory
2018-12-25T12:56:24.053953427Z 42 PC: 17ce3 | Get date 0x17ce3: cmp dx, 0x805
0x17ce7: je 0x17cf2
0x17ce9: cmp al, 5
0x17ceb: jne 0x17cfb
0x17ced: cmp dl, 0xd
0x17cf0: jne 0x17cfb
0x17cf2: mov dx, bx
0x17cf4: add dx, 0x40
0x17cf7: mov ah, 9
0x17cf9: int 0x21
0x17cfb: popaw
0x17cfc: pop es
0x17cfd: pop ds
0x17cfe: pop ss
0x17cff: jmp si
0x17d01: mov cx, 0x350
0x17d04: mov al, byte ptr [si]
0x17d06: inc al
0x17d08: mov byte ptr [si], al
0x17d0a: inc si
2018-12-25T12:56:24.061474246Z 48 PC: 18097 | Get DOS version
2018-12-25T12:56:24.063047542Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-25T12:56:24.064125579Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:56:24.065337064Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":13,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17694,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:23.496296471Z 71 PC: 17c23 | Get current directory
2018-12-25T12:56:23.499796286Z 26 PC: 17c2a | Set disk transfer address
2018-12-25T12:56:23.50079459Z 78 PC: 17c34 | Find first file
2018-12-25T12:56:23.506669432Z 67 PC: 17c42 | Get or set file attributes
2018-12-25T12:56:23.520642519Z 67 PC: 17c4b | Get or set file attributes
2018-12-25T12:56:23.541703272Z 61 PC: 17c50 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:56:23.548457943Z 87 PC: 17c57 | Get or set file date and time
2018-12-25T12:56:23.55119347Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:56:23.55795932Z 66 PC: 17c75 | Move file pointer
2018-12-25T12:56:23.559946934Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-25T12:56:23.569272088Z 66 PC: 17ca0 | Move file pointer
2018-12-25T12:56:23.57066265Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:56:23.577232674Z 87 PC: 17cb3 | Get or set file date and time
2018-12-25T12:56:23.579258234Z 62 PC: 17cb7 | Close file
2018-12-25T12:56:23.587103407Z 67 PC: 17cbe | Get or set file attributes
2018-12-25T12:56:23.596607687Z 79 PC: 17cc3 | Find next file
2018-12-25T12:56:23.599514327Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.610894133Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.620439885Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.629114631Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.630483255Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.636711298Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.639318201Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.648510758Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.650085461Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.657346914Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.659137335Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.66674417Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.677127123Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.679750962Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.683784868Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.690937918Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.696161386Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.697797221Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.704758689Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.706664245Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.715458428Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.71740215Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.723927194Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.725467934Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.733353084Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.746050451Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.748734333Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.755742665Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.765844361Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.772674398Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.774570429Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.781125874Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.782898244Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.794309192Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.795931548Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.802170339Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.803670269Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.811708172Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.821729291Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.824604492Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.829280474Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.835981919Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.84066211Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.841908891Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.845966991Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.847252406Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.853738502Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.854934458Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.861317082Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.863082336Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.870663941Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.883431307Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.886314632Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.892111808Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.902533517Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.909521799Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.911053119Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.917541561Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.919950713Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.928794381Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.930246588Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.937026355Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.939176296Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.9468434Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.957558028Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.960258396Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.966142704Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.975906755Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.982178547Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.983465803Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.989862558Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.991619016Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:24.000350432Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:24.0021427Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:24.008606795Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.0099101Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.017489146Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.026992351Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.029465919Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:24.035045358Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:24.044581587Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:24.055585473Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:24.057108531Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:24.063621068Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:24.06490803Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.0665515Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.073801346Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.083596565Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.08613746Z 59 PC: 17cd0 | Change current directory
2018-12-25T12:56:24.090054766Z 59 PC: 17cdd | Change current directory
2018-12-25T12:56:24.092034218Z 42 PC: 17ce3 | Get date 0x17ce3: cmp dx, 0x805
0x17ce7: je 0x17cf2
0x17ce9: cmp al, 5
0x17ceb: jne 0x17cfb
0x17ced: cmp dl, 0xd
0x17cf0: jne 0x17cfb
0x17cf2: mov dx, bx
0x17cf4: add dx, 0x40
0x17cf7: mov ah, 9
0x17cf9: int 0x21
0x17cfb: popaw
0x17cfc: pop es
0x17cfd: pop ds
0x17cfe: pop ss
0x17cff: jmp si
0x17d01: mov cx, 0x350
0x17d04: mov al, byte ptr [si]
0x17d06: inc al
0x17d08: mov byte ptr [si], al
0x17d0a: inc si
2018-12-25T12:56:24.094775242Z 9 PC: 17cfb | Display string (Could not find end pointer)
2018-12-25T12:56:24.132376578Z 48 PC: 18097 | Get DOS version
2018-12-25T12:56:24.13380614Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-25T12:56:24.135589078Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:56:24.136943164Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')

{"DateBased":true,"Day":5,"Month":8,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":17694,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:56:23.753823295Z 71 PC: 17c23 | Get current directory
2018-12-25T12:56:23.757452073Z 26 PC: 17c2a | Set disk transfer address
2018-12-25T12:56:23.758672226Z 78 PC: 17c34 | Find first file
2018-12-25T12:56:23.764742711Z 67 PC: 17c42 | Get or set file attributes
2018-12-25T12:56:23.776772961Z 67 PC: 17c4b | Get or set file attributes
2018-12-25T12:56:23.79448761Z 61 PC: 17c50 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:56:23.801031861Z 87 PC: 17c57 | Get or set file date and time
2018-12-25T12:56:23.80236052Z 63 PC: 17c65 | Read file or device (Read 3 bytes on handle 5)
2018-12-25T12:56:23.808730165Z 66 PC: 17c75 | Move file pointer
2018-12-25T12:56:23.810557383Z 64 PC: 17c96 | Write file or device (Write 1141 bytes on handle 5)
2018-12-25T12:56:23.819413531Z 66 PC: 17ca0 | Move file pointer
2018-12-25T12:56:23.82169595Z 64 PC: 17cac | Write file or device (Write 3 bytes on handle 5)
2018-12-25T12:56:23.828258334Z 87 PC: 17cb3 | Get or set file date and time
2018-12-25T12:56:23.829652693Z 62 PC: 17cb7 | Close file
2018-12-25T12:56:23.837953149Z 67 PC: 17cbe | Get or set file attributes
2018-12-25T12:56:23.848072819Z 79 PC: 17cc3 | Find next file
2018-12-25T12:56:23.8506049Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.856477081Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.866467898Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.872926546Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.875070542Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.881500052Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.883589864Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.893224906Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.894526542Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.900754433Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.911332065Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.919432754Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:23.931571293Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:23.934563424Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:23.93998287Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:23.949600859Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:23.957864583Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:23.959212406Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:23.965337544Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:23.967896039Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:23.976796885Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:23.97844639Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:23.986289766Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:23.987815692Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:23.99551233Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.005930178Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.008765418Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:24.014245786Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:24.024524514Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:24.035736057Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:24.037100822Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:24.044462183Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:24.046460392Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:24.055303109Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:24.056891212Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:24.063704823Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.065735981Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.074269397Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.0840059Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.08649403Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:24.092449154Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:24.101999482Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:24.113477782Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:24.115221054Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:24.12106861Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:24.122579639Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:24.13163148Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:24.132822964Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:24.139275462Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.141520991Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.149385033Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.158932557Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.161623021Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:24.167207044Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:24.177132496Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:24.183964796Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:24.186167149Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:24.192548718Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:24.194566321Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:24.204174298Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:24.205426991Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:24.211863688Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.213446928Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.220995564Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.230843682Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.234467552Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:24.240846406Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:24.25058963Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:24.258166805Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:24.259544505Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:24.266086931Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:24.268620183Z 64 PC: 17c96 | Write file or device (See above)
2018-12-25T12:56:24.277394815Z 66 PC: 17ca0 | Move file pointer (See above)
2018-12-25T12:56:24.27868595Z 64 PC: 17cac | Write file or device (See above)
2018-12-25T12:56:24.286824826Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.288390585Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.296038013Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.307329083Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.309870677Z 67 PC: 17c42 | Get or set file attributes (See above)
2018-12-25T12:56:24.316845109Z 67 PC: 17c4b | Get or set file attributes (See above)
2018-12-25T12:56:24.327776434Z 61 PC: 17c50 | Open file (See above)
2018-12-25T12:56:24.334241667Z 87 PC: 17c57 | Get or set file date and time (See above)
2018-12-25T12:56:24.335707494Z 63 PC: 17c65 | Read file or device (See above)
2018-12-25T12:56:24.342743214Z 66 PC: 17c75 | Move file pointer (See above)
2018-12-25T12:56:24.344113391Z 87 PC: 17cb3 | Get or set file date and time (See above)
2018-12-25T12:56:24.345515187Z 62 PC: 17cb7 | Close file (See above)
2018-12-25T12:56:24.353172653Z 67 PC: 17cbe | Get or set file attributes (See above)
2018-12-25T12:56:24.365262566Z 79 PC: 17cc3 | Find next file (See above)
2018-12-25T12:56:24.367482476Z 59 PC: 17cd0 | Change current directory
2018-12-25T12:56:24.378029181Z 59 PC: 17cdd | Change current directory
2018-12-25T12:56:24.379956892Z 42 PC: 17ce3 | Get date 0x17ce3: cmp dx, 0x805
0x17ce7: je 0x17cf2
0x17ce9: cmp al, 5
0x17ceb: jne 0x17cfb
0x17ced: cmp dl, 0xd
0x17cf0: jne 0x17cfb
0x17cf2: mov dx, bx
0x17cf4: add dx, 0x40
0x17cf7: mov ah, 9
0x17cf9: int 0x21
0x17cfb: popaw
0x17cfc: pop es
0x17cfd: pop ds
0x17cfe: pop ss
0x17cff: jmp si
0x17d01: mov cx, 0x350
0x17d04: mov al, byte ptr [si]
0x17d06: inc al
0x17d08: mov byte ptr [si], al
0x17d0a: inc si
2018-12-25T12:56:24.382366654Z 9 PC: 17cfb | Display string (Could not find end pointer)
2018-12-25T12:56:24.420165441Z 48 PC: 18097 | Get DOS version
2018-12-25T12:56:24.421623083Z 37 PC: 182f6 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-25T12:56:24.422692576Z 37 PC: 1832a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T12:56:24.424566577Z 37 PC: 182c4 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')