Time Syscall Op Syscall Name
2018-12-17T22:06:15.816217097Z 25 PC: 12a74 | Get default drive
2018-12-17T22:06:15.817731028Z 14 PC: 12a7b | Set default drive (Drive = 'C')
2018-12-17T22:06:15.819414155Z 71 PC: 12a85 | Get current directory
2018-12-17T22:06:15.821746162Z 78 PC: 12a8c | Find first file
2018-12-17T22:06:15.827331711Z 78 PC: 12a95 | Find first file
2018-12-17T22:06:15.833226447Z 67 PC: 12a9f | Get or set file attributes
2018-12-17T22:06:15.838189961Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:06:16.870589783Z 61 PC: 12aaf | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:06:16.87726116Z 87 PC: 12ab7 | Get or set file date and time
2018-12-17T22:06:16.878730224Z 64 PC: 12a53 | Write file or device (Write 666 bytes on handle 5)
2018-12-17T22:06:16.886173799Z 87 PC: 12ac9 | Get or set file date and time
2018-12-17T22:06:16.887671125Z 62 PC: 12acd | Close file
2018-12-17T22:06:16.894423286Z 67 PC: 12ad6 | Get or set file attributes
2018-12-17T22:06:16.903084028Z 79 PC: 12a95 | Find next file
2018-12-17T22:06:16.90634258Z 59 PC: 12ae1 | Change current directory
2018-12-17T22:06:16.909697933Z 44 PC: 12ae7 | Get time 0x12ae7: cmp dl, 0x32
0x12aea: ja 0x12b0e
0x12aec: jmp 0x12aef
0x12aef: mov ah, 9
0x12af1: mov dx, 0x32a
0x12af4: int 0x21
0x12af6: mov ah, 0x2c
0x12af8: int 0x21
0x12afa: cmp dl, 0xa
0x12afd: ja 0x12b0e
0x12aff: jmp 0x12b02
0x12b02: cli
0x12b03: mov ah, 2
0x12b05: cdq
0x12b06: mov cx, 0x100
0x12b09: int 0x26
0x12b0b: jmp 0x12b0e
0x12b0e: pop dx
0x12b0f: mov ah, 0xe
0x12b11: int 0x21
2018-12-17T22:06:16.911618235Z 14 PC: 12b13 | Set default drive (Drive = 'A')
2018-12-17T22:06:16.91355133Z 59 PC: 12b1b | Change current directory
2018-12-17T22:06:16.9153963Z 76 PC: 12b1f | Terminate with return code (Return code = '3')