.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:10:04.119623361Z | 44 | PC: 1314e | Get time 0x1314e: cmp byte ptr [0x103], 0 0x13153: je 0x1315a 0x13155: cmp dh, 0xf 0x13158: jg 0x13163 0x1315a: cmp dl, 0 0x1315d: je 0x1314a 0x1315f: mov byte ptr [0x103], dl 0x13163: mov byte ptr [0x7ff], 0 0x13168: mov byte ptr [0x800], 4 0x1316d: mov byte ptr [0x809], 0 0x13172: mov cx, 0x27 0x13175: mov dx, 0x115 0x13178: mov ah, 0x4e 0x1317a: int 0x21 0x1317c: cmp ax, 0x12 0x1317f: je 0x13184 0x13181: call 0x131a6 0x13184: mov cx, 0x27 0x13187: mov dx, 0x11b 0x1318a: mov ah, 0x4e |
2018-12-17T22:10:04.122785473Z | 78 | PC: 1317c | Find first file |
2018-12-17T22:10:04.128512172Z | 78 | PC: 1318e | Find first file |
2018-12-17T22:10:04.135538064Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:10:04.156107887Z | 61 | PC: 131cd | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:10:04.163199342Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:10:04.16716075Z | 62 | PC: 13210 | Close file |
2018-12-17T22:10:04.169300173Z | 61 | PC: 13219 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:10:04.174046286Z | 64 | PC: 12a54 | Write file or device (Write 562 bytes on handle 5) |
2018-12-17T22:10:04.185598385Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:10:04.187688976Z | 62 | PC: 13249 | Close file |
2018-12-17T22:10:04.216060845Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:10:04.22164818Z | 79 | PC: 13200 | Find next file |
2018-12-17T22:10:04.2256439Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:10:04.236711875Z | 61 | PC: 131cd | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:10:04.243838065Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:10:04.255482148Z | 62 | PC: 13210 | Close file |
2018-12-17T22:10:04.258959957Z | 61 | PC: 13219 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:10:04.271564195Z | 64 | PC: 12a54 | Write file or device (Write 562 bytes on handle 5) |
2018-12-17T22:10:04.279896377Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:10:04.282431213Z | 62 | PC: 13249 | Close file |
2018-12-17T22:10:04.290579568Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:10:04.295322921Z | 79 | PC: 13200 | Find next file |
2018-12-17T22:10:04.300207646Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:10:04.310048058Z | 61 | PC: 131cd | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:10:04.316865135Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:10:04.324752987Z | 62 | PC: 13210 | Close file |
2018-12-17T22:10:04.326902181Z | 61 | PC: 13219 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:10:04.333430248Z | 64 | PC: 12a54 | Write file or device (Write 562 bytes on handle 5) |
2018-12-17T22:10:04.342814311Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:10:04.344591522Z | 62 | PC: 13249 | Close file |
2018-12-17T22:10:04.352829146Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:10:04.358457949Z | 79 | PC: 13200 | Find next file |
2018-12-17T22:10:04.361090925Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:10:04.370632734Z | 61 | PC: 131cd | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:10:04.377882888Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:10:04.384609879Z | 62 | PC: 13210 | Close file |
2018-12-17T22:10:04.386497479Z | 61 | PC: 13219 | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:10:04.393886064Z | 64 | PC: 12a54 | Write file or device (Write 562 bytes on handle 5) |
2018-12-17T22:10:04.401732408Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:10:04.403373555Z | 62 | PC: 13249 | Close file |
2018-12-17T22:10:04.411233964Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:10:04.42129303Z | 9 | PC: 132d4 | Display string (String= ' Error #2307 - Too big to fit in memory') |
2018-12-17T22:10:04.425365055Z | 76 | PC: 132d8 | Terminate with return code (Return code = '36') |