Sample viewer

vx.netlux.org/Virus.DOS.Fart.3794

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:11:58.361937608Z 24 PC: 1397a | Reserved
2018-12-17T22:11:58.363069831Z 11 PC: 1397e | Get input status
2018-12-17T22:11:58.407113233Z 254 PC: 12ab2 | UNKNOWN!
2018-12-17T22:11:58.409016195Z 82 PC: 12ae7 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:11:58.410261406Z 82 PC: 9eaa8 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:11:58.411393445Z 53 PC: 9eac0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:11:58.41416863Z 25 PC: 9ebf0 | Get default drive
2018-12-17T22:11:58.418150504Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:11:58.419508662Z 72 PC: 12174 | Allocate memory
2018-12-17T22:11:58.421383575Z 72 PC: 1218d | Allocate memory
2018-12-17T22:11:58.423637462Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:11:58.424674849Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:11:58.425750878Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:11:58.436585391Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.439946248Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.442055926Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.444329125Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.445923999Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.448329434Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.451261541Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.453133806Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.454975352Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.458007439Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.460091914Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.46217871Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.46506349Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.46707935Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.468920986Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.472491886Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.474312723Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.47633397Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.478880282Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.480626964Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.482001594Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.483803887Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.487130956Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.488655037Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.496644134Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.498524868Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.501156224Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.503169039Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.505329306Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.507756575Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.510915889Z 67 PC: 9ed97 | Get or set file attributes
2018-12-17T22:11:58.524492921Z 67 PC: 9ed97 | Get or set file attributes
2018-12-17T22:11:58.877062144Z 61 PC: 9ed97 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:11:58.883594547Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.885872589Z 67 PC: 9ed97 | Get or set file attributes
2018-12-17T22:11:58.890161846Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:11:58.89688664Z 66 PC: 12372 | Move file pointer
2018-12-17T22:11:58.89971228Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-17T22:11:58.913958881Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:11:58.916963834Z 62 PC: 9ed97 | Close file
2018-12-17T22:11:58.921383918Z 99 PC: 993f7 | Get DBCS lead byte table pointer
2018-12-17T22:11:58.922808944Z 56 PC: 93c19 | Get or set country info
2018-12-17T22:11:58.924748049Z 64 PC: 99668 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:11:58.929656724Z 25 PC: 93c82 | Get default drive
2018-12-17T22:11:58.931730924Z 71 PC: 95efd | Get current directory
2018-12-17T22:11:58.935944691Z 64 PC: 99668 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:11:58.940651316Z 2 PC: 95ed2 | Character output (Char = '3e')
2018-12-17T22:11:58.942939219Z 93 PC: 93d40 | File sharing functions
2018-12-17T22:11:58.9445644Z 93 PC: 93d47 | File sharing functions
2018-12-17T22:11:58.946786293Z 10 PC: 93d59 | Buffered keyboard input
2018-12-17T22:12:13.358500835Z 0 PC: 0 | Program terminate
2018-12-17T22:12:14.711786544Z 0 PC: 0 | Program terminate
2018-12-17T22:12:14.814110038Z 64 PC: 99668 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:12:14.8195938Z 41 PC: 93dce | Parse filename
2018-12-17T22:12:14.821953176Z 41 PC: 93e4f | Parse filename
2018-12-17T22:12:14.823497769Z 41 PC: 93e6c | Parse filename
2018-12-17T22:12:14.826919175Z 26 PC: 97317 | Set disk transfer address
2018-12-17T22:12:14.829546983Z 71 PC: 97513 | Get current directory
2018-12-17T22:12:14.838339461Z 78 PC: 9751e | Find first file
2018-12-17T22:12:14.850917539Z 71 PC: 9738c | Get current directory
2018-12-17T22:12:14.854497181Z 73 PC: 96a29 | Release memory
2018-12-17T22:12:14.856001153Z 67 PC: 9ed97 | Get or set file attributes
2018-12-17T22:12:14.862082964Z 67 PC: 9ed97 | Get or set file attributes
2018-12-17T22:12:14.877661056Z 61 PC: 9ed97 | Open file (Filename = '��:�?�8�D�4�D�6�D�')
2018-12-17T22:12:14.88648442Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:14.887800278Z 63 PC: 9ed97 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:12:14.896125989Z 66 PC: 9ed97 | Move file pointer
2018-12-17T22:12:14.899661098Z 66 PC: 9ed97 | Move file pointer
2018-12-17T22:12:14.903624525Z 64 PC: 9ed97 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:12:14.917762862Z 64 PC: 9ed97 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:12:14.926448333Z 64 PC: 9ed97 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:12:14.935712574Z 64 PC: 9ed97 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:12:14.944190204Z 64 PC: 9ed97 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:12:14.952491166Z 64 PC: 9ed97 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:12:14.961588901Z 64 PC: 9ed97 | Write file or device (Write 512 bytes on handle 5)
2018-12-17T22:12:14.97010209Z 64 PC: 9ed97 | Write file or device (Write 210 bytes on handle 5)
2018-12-17T22:12:14.974331844Z 64 PC: 9ed97 | Write file or device (Write 51 bytes on handle 5)
2018-12-17T22:12:14.977292523Z 66 PC: 9ed97 | Move file pointer
2018-12-17T22:12:14.979089065Z 64 PC: 9ed97 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:12:14.985950674Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:14.987578788Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:14.999727769Z 67 PC: 9ed97 | Get or set file attributes
2018-12-17T22:12:15.056035008Z 75 PC: 11821 | Execute program
2018-12-17T22:12:15.070889685Z 48 PC: 13935 | Get DOS version
2018-12-17T22:12:15.132490037Z 42 PC: 12a74 | Get date 0x12a74: cmp al, 1
0x12a76: jne 0x12a85
0x12a78: cmp dl, 9
0x12a7b: ja 0x12a85
0x12a7d: and dl, 1
0x12a80: je 0x12a85
0x12a82: jmp 0x12c63
0x12a85: jmp 0x12b2b
0x12a88: int 0x12
0x12a8a: mov cl, 6
0x12a8c: shl ax, cl
0x12a8e: dec ax
0x12a8f: mov es, ax
0x12a91: cmp word ptr es:[8], 0x4353
0x12a98: je 0x12aa2
0x12a9a: mov ah, 0x52
0x12a9c: int 0x21
0x12a9e: mov ax, word ptr es:[bx - 2]
0x12aa2: mov es, ax
0x12aa4: cmp byte ptr es:[0], 0x5a
2018-12-17T22:12:15.135009699Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-17T22:12:15.137479322Z 98 PC: 9ed97 | Get current PSP
2018-12-17T22:12:15.138849409Z 61 PC: 9ed97 | Open file (Filename = 'A:\PRINT.COM')
2018-12-17T22:12:15.143589369Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.145539386Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.148768757Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-17T22:12:15.152307507Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:12:15.153747138Z 72 PC: 12174 | Allocate memory
2018-12-17T22:12:15.156775008Z 72 PC: 1218d | Allocate memory
2018-12-17T22:12:15.159219942Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:12:15.160686484Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:12:15.162677231Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:12:15.164027475Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.165900877Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.168608382Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.170554671Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.172332425Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.175204334Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.177894517Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.179949078Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.182322999Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.184189557Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.186060017Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.188715718Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.190573437Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.192644457Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.195570243Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.197523865Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.199208979Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.201539998Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.203337246Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.205053506Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.207752637Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.209780225Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.211464999Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.214640275Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.216338351Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.218113593Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.220005519Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.222457315Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.224106001Z 87 PC: 9ed97 | Get or set file date and time
2018-12-17T22:12:15.225883114Z 62 PC: 9ed97 | Close file
2018-12-17T22:12:15.229570476Z 99 PC: 993f7 | Get DBCS lead byte table pointer
2018-12-17T22:12:15.230790734Z 56 PC: 93c19 | Get or set country info
2018-12-17T22:12:15.232536331Z 64 PC: 99668 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:12:15.237654226Z 25 PC: 93c82 | Get default drive
2018-12-17T22:12:15.23931696Z 71 PC: 95efd | Get current directory
2018-12-17T22:12:15.243214977Z 64 PC: 99668 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:12:15.247393142Z 2 PC: 95ed2 | Character output (Char = '3e')
2018-12-17T22:12:15.250015207Z 93 PC: 93d40 | File sharing functions
2018-12-17T22:12:15.252085281Z 93 PC: 93d47 | File sharing functions
2018-12-17T22:12:15.257891363Z 10 PC: 93d59 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":9,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2451,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:52.12042204Z 24 PC: 1397a | Reserved
2018-12-25T11:45:52.126480927Z 11 PC: 1397e | Get input status
2018-12-25T11:45:52.170685188Z 254 PC: 12ab2 | UNKNOWN!
2018-12-25T11:45:52.171622193Z 82 PC: 12ae7 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:52.173773058Z 82 PC: 9eaa8 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:52.174861044Z 53 PC: 9eac0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:52.176201509Z 25 PC: 9ebf0 | Get default drive
2018-12-25T11:45:52.181112593Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:45:52.182269831Z 72 PC: 12174 | Allocate memory
2018-12-25T11:45:52.183920392Z 72 PC: 1218d | Allocate memory
2018-12-25T11:45:52.186486311Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:45:52.187989528Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:45:52.189181797Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:45:52.19189981Z 87 PC: 9ed97 | Get or set file date and time
2018-12-25T11:45:52.193631956Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.195230387Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.197114979Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.199284986Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.201364572Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.202965111Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.205133693Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.206934983Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.208820374Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.211322463Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.213079834Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.215416093Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.226047923Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.227909691Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.229916189Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.23273988Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.235036724Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.236952143Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.239815194Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.241817253Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.244038163Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.246619318Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.248376612Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.249951367Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.252344665Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.253902218Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.255595379Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.257493914Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.259273274Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.262586061Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:52.270890968Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.32402403Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:45:53.33130941Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.33327715Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.337889424Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-25T11:45:53.343822702Z 66 PC: 12372 | Move file pointer
2018-12-25T11:45:53.345125291Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-25T11:45:53.410723336Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.412911627Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.416433689Z 99 PC: 993f7 | Get DBCS lead byte table pointer
2018-12-25T11:45:53.418176487Z 56 PC: 93c19 | Get or set country info
2018-12-25T11:45:53.421023607Z 64 PC: 99668 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:45:53.425305563Z 25 PC: 93c82 | Get default drive
2018-12-25T11:45:53.427735511Z 71 PC: 95efd | Get current directory
2018-12-25T11:45:53.431530047Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:45:53.43458695Z 2 PC: 95ed2 | Character output (Char = '3e')
2018-12-25T11:45:53.437281725Z 93 PC: 93d40 | File sharing functions
2018-12-25T11:45:53.439199621Z 93 PC: 93d47 | File sharing functions
2018-12-25T11:45:53.440997093Z 10 PC: 93d59 | Buffered keyboard input
2018-12-25T11:46:07.114400956Z 0 PC: 0 | Program terminate
2018-12-25T11:46:08.468781289Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:46:08.571281435Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:08.5772203Z 41 PC: 93dce | Parse filename
2018-12-25T11:46:08.585923935Z 41 PC: 93e4f | Parse filename
2018-12-25T11:46:08.587590378Z 41 PC: 93e6c | Parse filename
2018-12-25T11:46:08.589758782Z 26 PC: 97317 | Set disk transfer address
2018-12-25T11:46:08.591479858Z 71 PC: 97513 | Get current directory
2018-12-25T11:46:08.599882348Z 78 PC: 9751e | Find first file
2018-12-25T11:46:08.608951487Z 71 PC: 9738c | Get current directory
2018-12-25T11:46:08.61187075Z 73 PC: 96a29 | Release memory
2018-12-25T11:46:08.614109867Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:08.620146656Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.391969495Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:46:09.400162099Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.40190761Z 63 PC: 9ed97 | Read file or device (See above)
2018-12-25T11:46:09.408617296Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.4114554Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.41379558Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.422118686Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.431665303Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.446007378Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.451711891Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.458466444Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.464551671Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.473879085Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.476987466Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.479194392Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.480308508Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.485218473Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.486385947Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.491678238Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.520559105Z 75 PC: 11821 | Execute program
2018-12-25T11:46:09.530643505Z 25 PC: 13931 | Get default drive
2018-12-25T11:46:09.540051639Z 98 PC: 13935 | Get current PSP
2018-12-25T11:46:09.602698697Z 42 PC: 12a74 | Get date 0x12a74: cmp al, 1
0x12a76: jne 0x12a85
0x12a78: cmp dl, 9
0x12a7b: ja 0x12a85
0x12a7d: and dl, 1
0x12a80: je 0x12a85
0x12a82: jmp 0x12c63
0x12a85: jmp 0x12b2b
0x12a88: int 0x12
0x12a8a: mov cl, 6
0x12a8c: shl ax, cl
0x12a8e: dec ax
0x12a8f: mov es, ax
0x12a91: cmp word ptr es:[8], 0x4353
0x12a98: je 0x12aa2
0x12a9a: mov ah, 0x52
0x12a9c: int 0x21
0x12a9e: mov ax, word ptr es:[bx - 2]
0x12aa2: mov es, ax
0x12aa4: cmp byte ptr es:[0], 0x5a

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2451,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:52.351427878Z 24 PC: 1397a | Reserved
2018-12-25T11:45:52.352816668Z 11 PC: 1397e | Get input status
2018-12-25T11:45:52.396112397Z 254 PC: 12ab2 | UNKNOWN!
2018-12-25T11:45:52.398116766Z 82 PC: 12ae7 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:52.399964036Z 82 PC: 9eaa8 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:52.401075786Z 53 PC: 9eac0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:52.402356223Z 25 PC: 9ebf0 | Get default drive
2018-12-25T11:45:52.406522949Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:45:52.407693768Z 72 PC: 12174 | Allocate memory
2018-12-25T11:45:52.40937242Z 72 PC: 1218d | Allocate memory
2018-12-25T11:45:52.417398627Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:45:52.418522324Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:45:52.419594341Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:45:52.425536406Z 87 PC: 9ed97 | Get or set file date and time
2018-12-25T11:45:52.42744948Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.429045364Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.431406873Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.433210713Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.435026215Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.437482256Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.439279278Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.440844451Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.442500439Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.444442278Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.446186917Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.447769059Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.44990297Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.451554069Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.453272917Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.455797177Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.457839927Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.459782069Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.462191704Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.463881923Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.466295418Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.47305566Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.474802698Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.476330809Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.478306975Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.47990124Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.481553823Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.483843342Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.485504222Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.488095928Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:52.493486621Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.323948965Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:45:53.33035876Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.332432064Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.336644822Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-25T11:45:53.342495643Z 66 PC: 12372 | Move file pointer
2018-12-25T11:45:53.344404242Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-25T11:45:53.406977872Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.410410406Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.41543592Z 99 PC: 993f7 | Get DBCS lead byte table pointer
2018-12-25T11:45:53.416751568Z 56 PC: 93c19 | Get or set country info
2018-12-25T11:45:53.418544109Z 64 PC: 99668 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:45:53.426847878Z 25 PC: 93c82 | Get default drive
2018-12-25T11:45:53.428422714Z 71 PC: 95efd | Get current directory
2018-12-25T11:45:53.43220544Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:45:53.435713154Z 2 PC: 95ed2 | Character output (Char = '3e')
2018-12-25T11:45:53.437827954Z 93 PC: 93d40 | File sharing functions
2018-12-25T11:45:53.439477766Z 93 PC: 93d47 | File sharing functions
2018-12-25T11:45:53.441794986Z 10 PC: 93d59 | Buffered keyboard input
2018-12-25T11:46:07.339629072Z 0 PC: 0 | Program terminate
2018-12-25T11:46:08.693156763Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:46:08.79529986Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:08.801466749Z 41 PC: 93dce | Parse filename
2018-12-25T11:46:08.803646346Z 41 PC: 93e4f | Parse filename
2018-12-25T11:46:08.804982704Z 41 PC: 93e6c | Parse filename
2018-12-25T11:46:08.808021038Z 26 PC: 97317 | Set disk transfer address
2018-12-25T11:46:08.809974785Z 71 PC: 97513 | Get current directory
2018-12-25T11:46:08.81739762Z 78 PC: 9751e | Find first file
2018-12-25T11:46:08.828211587Z 71 PC: 9738c | Get current directory
2018-12-25T11:46:08.831571434Z 73 PC: 96a29 | Release memory
2018-12-25T11:46:08.832945594Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:08.838262182Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.394281607Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:46:09.407089352Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.409566921Z 63 PC: 9ed97 | Read file or device (See above)
2018-12-25T11:46:09.417582727Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.419146639Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.420954447Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.429718463Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.437818227Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.446453849Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.45568728Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.463833759Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.472068191Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.481932549Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.485781818Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.488669686Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.491100614Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.498130296Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.499853003Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.508330921Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.563763808Z 75 PC: 11821 | Execute program
2018-12-25T11:46:09.586023484Z 42 PC: 12a74 | Get date 0x12a74: cmp al, 1
0x12a76: jne 0x12a85
0x12a78: cmp dl, 9
0x12a7b: ja 0x12a85
0x12a7d: and dl, 1
0x12a80: je 0x12a85
0x12a82: jmp 0x12c63
0x12a85: jmp 0x12b2b
0x12a88: int 0x12
0x12a8a: mov cl, 6
0x12a8c: shl ax, cl
0x12a8e: dec ax
0x12a8f: mov es, ax
0x12a91: cmp word ptr es:[8], 0x4353
0x12a98: je 0x12aa2
0x12a9a: mov ah, 0x52
0x12a9c: int 0x21
0x12a9e: mov ax, word ptr es:[bx - 2]
0x12aa2: mov es, ax
0x12aa4: cmp byte ptr es:[0], 0x5a
2018-12-25T11:46:09.588865355Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T11:46:09.594774187Z 98 PC: 9ed97 | Get current PSP (See above)
2018-12-25T11:46:09.595968738Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:46:09.602842576Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.604338623Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.61005188Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-25T11:46:09.613076454Z 77 PC: 11fe0 | Get program return code (See above)
2018-12-25T11:46:09.6149271Z 72 PC: 12174 | Allocate memory (See above)
2018-12-25T11:46:09.616625386Z 72 PC: 1218d | Allocate memory (See above)
2018-12-25T11:46:09.618197333Z 37 PC: 123c4 | Set interrupt vector (See above)
2018-12-25T11:46:09.621064436Z 37 PC: 123cb | Set interrupt vector (See above)
2018-12-25T11:46:09.622159822Z 37 PC: 123d2 | Set interrupt vector (See above)
2018-12-25T11:46:09.623373906Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.62564856Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.627347273Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.62910047Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.632065129Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.633777852Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.635423879Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.638030494Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.639697885Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.641474437Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.643647064Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.645384948Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.647349017Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.656248687Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.657926694Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.659639493Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.661975029Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.664406025Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.666436886Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.669088073Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.67144367Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.674252762Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.676536394Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.679070425Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.681374342Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.684134473Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.686496571Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.687732153Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.689920888Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.692125186Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.695330817Z 99 PC: 993f7 | Get DBCS lead byte table pointer (See above)
2018-12-25T11:46:09.697417693Z 56 PC: 93c19 | Get or set country info (See above)
2018-12-25T11:46:09.69917845Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:09.703391807Z 25 PC: 93c82 | Get default drive (See above)
2018-12-25T11:46:09.705568038Z 71 PC: 95efd | Get current directory (See above)
2018-12-25T11:46:09.709266305Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:09.713545559Z 2 PC: 95ed2 | Character output (See above)
2018-12-25T11:46:09.716214151Z 93 PC: 93d40 | File sharing functions (See above)
2018-12-25T11:46:09.717805434Z 93 PC: 93d47 | File sharing functions (See above)
2018-12-25T11:46:09.719551573Z 10 PC: 93d59 | Buffered keyboard input (See above)

{"DateBased":true,"Day":7,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2451,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:52.682968555Z 24 PC: 1397a | Reserved
2018-12-25T11:45:52.684224642Z 11 PC: 1397e | Get input status
2018-12-25T11:45:52.728131408Z 254 PC: 12ab2 | UNKNOWN!
2018-12-25T11:45:52.728959549Z 82 PC: 12ae7 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:52.730528526Z 82 PC: 9eaa8 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:52.731701317Z 53 PC: 9eac0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:52.732957112Z 25 PC: 9ebf0 | Get default drive
2018-12-25T11:45:52.738438524Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:45:52.739515528Z 72 PC: 12174 | Allocate memory
2018-12-25T11:45:52.74114137Z 72 PC: 1218d | Allocate memory
2018-12-25T11:45:52.744219875Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:45:52.745303987Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:45:52.746323928Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:45:52.74836239Z 87 PC: 9ed97 | Get or set file date and time
2018-12-25T11:45:52.750043267Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.751631519Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.753271845Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.755042224Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.756764838Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.75880104Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.763202891Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.775833784Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.777789463Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.780671193Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.782800913Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.784773239Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.788472003Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.791172882Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.793321889Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.796064418Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.798603738Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.800793056Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.80316665Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.805169077Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.807006243Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.809382203Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.811202845Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.812969092Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.815324151Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.816963432Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.818677753Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.820686828Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:52.822460981Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:52.825043268Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:52.830346941Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.893673077Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:45:53.901343279Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.904246995Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.909024005Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-25T11:45:53.91639612Z 66 PC: 12372 | Move file pointer
2018-12-25T11:45:53.919026926Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-25T11:45:53.933097303Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.935472721Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.939078314Z 99 PC: 993f7 | Get DBCS lead byte table pointer
2018-12-25T11:45:53.940631756Z 56 PC: 93c19 | Get or set country info
2018-12-25T11:45:53.942687469Z 64 PC: 99668 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:45:53.947542094Z 25 PC: 93c82 | Get default drive
2018-12-25T11:45:53.949563878Z 71 PC: 95efd | Get current directory
2018-12-25T11:45:53.95584226Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:45:53.959201861Z 2 PC: 95ed2 | Character output (Char = '3e')
2018-12-25T11:45:53.961822917Z 93 PC: 93d40 | File sharing functions
2018-12-25T11:45:53.963506602Z 93 PC: 93d47 | File sharing functions
2018-12-25T11:45:53.965380159Z 10 PC: 93d59 | Buffered keyboard input
2018-12-25T11:46:07.681101566Z 0 PC: 0 | Program terminate
2018-12-25T11:46:09.034549584Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:46:09.1367228Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:09.142206893Z 41 PC: 93dce | Parse filename
2018-12-25T11:46:09.144242957Z 41 PC: 93e4f | Parse filename
2018-12-25T11:46:09.147342017Z 41 PC: 93e6c | Parse filename
2018-12-25T11:46:09.150491492Z 26 PC: 97317 | Set disk transfer address
2018-12-25T11:46:09.152345186Z 71 PC: 97513 | Get current directory
2018-12-25T11:46:09.160202011Z 78 PC: 9751e | Find first file
2018-12-25T11:46:09.169366425Z 71 PC: 9738c | Get current directory
2018-12-25T11:46:09.172489205Z 73 PC: 96a29 | Release memory
2018-12-25T11:46:09.175901548Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.183557896Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.393371145Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:46:09.405768023Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.407160375Z 63 PC: 9ed97 | Read file or device (See above)
2018-12-25T11:46:09.413910551Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.416443404Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.418295396Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.426296607Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.43623088Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.444640779Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.452967084Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.46261473Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.4714925Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.480444378Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.485151228Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.487900595Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.489233269Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.496514447Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.498105791Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.506227685Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.565052173Z 75 PC: 11821 | Execute program
2018-12-25T11:46:09.580324783Z 42 PC: 13931 | Get date 0x13931: mov ah, 0xf
0x13933: int 0x10
0x13935: jmp 0x1393a
0x13938: mov byte ptr [0xbb77], al
0x1393b: sbb ax, word ptr [bx + di]
0x1393d: mov bp, 0xed7
0x13940: mov ah, 0x7a
0x13942: int 0xa
0x13944: int 0x74
0x13946: push bx
0x13947: int 8
0x13949: int 0xb
0x1394b: sub byte ptr ds:[bx], ah
0x1394e: inc bx
0x1394f: push es
0x13950: pop es
0x13951: int 0xb
0x13953: dec bp
0x13954: int 0xc
0x13956: int 0x72
2018-12-25T11:46:09.667490414Z 42 PC: 12a74 | Get date 0x12a74: cmp al, 1
0x12a76: jne 0x12a85
0x12a78: cmp dl, 9
0x12a7b: ja 0x12a85
0x12a7d: and dl, 1
0x12a80: je 0x12a85
0x12a82: jmp 0x12c63
0x12a85: jmp 0x12b2b
0x12a88: int 0x12
0x12a8a: mov cl, 6
0x12a8c: shl ax, cl
0x12a8e: dec ax
0x12a8f: mov es, ax
0x12a91: cmp word ptr es:[8], 0x4353
0x12a98: je 0x12aa2
0x12a9a: mov ah, 0x52
0x12a9c: int 0x21
0x12a9e: mov ax, word ptr es:[bx - 2]
0x12aa2: mov es, ax
0x12aa4: cmp byte ptr es:[0], 0x5a

{"DateBased":true,"Day":14,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":2451,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:45:52.982287791Z 24 PC: 1397a | Reserved
2018-12-25T11:45:52.984241033Z 11 PC: 1397e | Get input status
2018-12-25T11:45:53.028483326Z 254 PC: 12ab2 | UNKNOWN!
2018-12-25T11:45:53.029350784Z 82 PC: 12ae7 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:53.031629001Z 82 PC: 9eaa8 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:45:53.03292097Z 53 PC: 9eac0 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:45:53.034593317Z 25 PC: 9ebf0 | Get default drive
2018-12-25T11:45:53.038997488Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:45:53.040406242Z 72 PC: 12174 | Allocate memory
2018-12-25T11:45:53.042158179Z 72 PC: 1218d | Allocate memory
2018-12-25T11:45:53.044656983Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:45:53.045743413Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:45:53.046805332Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:45:53.048523859Z 87 PC: 9ed97 | Get or set file date and time
2018-12-25T11:45:53.050289414Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.051880843Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.053872159Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.055494457Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.057170842Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.058934036Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.060884924Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.062372908Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.063927212Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.065601452Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.067275404Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.068899302Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.070802635Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.072301303Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.073935554Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.076180377Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.077869829Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.079444529Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.082067137Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.083697605Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.085319041Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.087269482Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.088873966Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.090469981Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.092310287Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.093743438Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.095262734Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.097219152Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.098919586Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.100558326Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.10466614Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.899041486Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:45:53.905691685Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.908437436Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:45:53.911913152Z 61 PC: 12354 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-25T11:45:53.917934836Z 66 PC: 12372 | Move file pointer
2018-12-25T11:45:53.919898649Z 63 PC: 12383 | Read file or device (Read 44693 bytes on handle 5)
2018-12-25T11:45:53.935418837Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:45:53.937823738Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:45:53.942183977Z 99 PC: 993f7 | Get DBCS lead byte table pointer
2018-12-25T11:45:53.943523152Z 56 PC: 93c19 | Get or set country info
2018-12-25T11:45:53.945359059Z 64 PC: 99668 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:45:53.95063908Z 25 PC: 93c82 | Get default drive
2018-12-25T11:45:53.95214991Z 71 PC: 95efd | Get current directory
2018-12-25T11:45:53.956857325Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:45:53.960706092Z 2 PC: 95ed2 | Character output (Char = '3e')
2018-12-25T11:45:53.962528037Z 93 PC: 93d40 | File sharing functions
2018-12-25T11:45:53.964320841Z 93 PC: 93d47 | File sharing functions
2018-12-25T11:45:53.966368005Z 10 PC: 93d59 | Buffered keyboard input
2018-12-25T11:46:07.981070137Z 0 PC: 0 | Program terminate
2018-12-25T11:46:09.334566567Z 0 PC: 0 | Program terminate (See above)
2018-12-25T11:46:09.437232814Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:09.443142803Z 41 PC: 93dce | Parse filename
2018-12-25T11:46:09.445588752Z 41 PC: 93e4f | Parse filename
2018-12-25T11:46:09.447051269Z 41 PC: 93e6c | Parse filename
2018-12-25T11:46:09.450377043Z 26 PC: 97317 | Set disk transfer address
2018-12-25T11:46:09.45289646Z 71 PC: 97513 | Get current directory
2018-12-25T11:46:09.463896384Z 78 PC: 9751e | Find first file
2018-12-25T11:46:09.474056775Z 71 PC: 9738c | Get current directory
2018-12-25T11:46:09.477703117Z 73 PC: 96a29 | Release memory
2018-12-25T11:46:09.479443414Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.485110307Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.502145497Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:46:09.51334564Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.514749876Z 63 PC: 9ed97 | Read file or device (See above)
2018-12-25T11:46:09.52126243Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.523582925Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.526056193Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.533962762Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.542586369Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.550690331Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.558643978Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.567177281Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.575385667Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.583272307Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.58852728Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.591190419Z 66 PC: 9ed97 | Move file pointer (See above)
2018-12-25T11:46:09.592514432Z 64 PC: 9ed97 | Write file or device (See above)
2018-12-25T11:46:09.600040146Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.601550616Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.609143617Z 67 PC: 9ed97 | Get or set file attributes (See above)
2018-12-25T11:46:09.664340351Z 75 PC: 11821 | Execute program
2018-12-25T11:46:09.80466285Z 42 PC: 12a74 | Get date 0x12a74: cmp al, 1
0x12a76: jne 0x12a85
0x12a78: cmp dl, 9
0x12a7b: ja 0x12a85
0x12a7d: and dl, 1
0x12a80: je 0x12a85
0x12a82: jmp 0x12c63
0x12a85: jmp 0x12b2b
0x12a88: int 0x12
0x12a8a: mov cl, 6
0x12a8c: shl ax, cl
0x12a8e: dec ax
0x12a8f: mov es, ax
0x12a91: cmp word ptr es:[8], 0x4353
0x12a98: je 0x12aa2
0x12a9a: mov ah, 0x52
0x12a9c: int 0x21
0x12a9e: mov ax, word ptr es:[bx - 2]
0x12aa2: mov es, ax
0x12aa4: cmp byte ptr es:[0], 0x5a
2018-12-25T11:46:09.807072062Z 9 PC: 12a47 | Display string (String= 'Hello, World! ')
2018-12-25T11:46:09.812250617Z 98 PC: 9ed97 | Get current PSP (See above)
2018-12-25T11:46:09.813243228Z 61 PC: 9ed97 | Open file (See above)
2018-12-25T11:46:09.825150634Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.827403313Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.829366995Z 76 PC: 12a4b | Terminate with return code (Return code = '36')
2018-12-25T11:46:09.832436304Z 77 PC: 11fe0 | Get program return code (See above)
2018-12-25T11:46:09.834618375Z 72 PC: 12174 | Allocate memory (See above)
2018-12-25T11:46:09.836384459Z 72 PC: 1218d | Allocate memory (See above)
2018-12-25T11:46:09.838016322Z 37 PC: 123c4 | Set interrupt vector (See above)
2018-12-25T11:46:09.839751731Z 37 PC: 123cb | Set interrupt vector (See above)
2018-12-25T11:46:09.841319829Z 37 PC: 123d2 | Set interrupt vector (See above)
2018-12-25T11:46:09.842612534Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.845817045Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.847707754Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.84949206Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.851479905Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.853821652Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.8555069Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.857946761Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.859903038Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.862079931Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.864118827Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.86618512Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.868081741Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.870371235Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.872349783Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.874283823Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.876288619Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.878593655Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.881429799Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.883859472Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.885875375Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.887748994Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.889738292Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.902959539Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.904652694Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.906983812Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.908938295Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.910820051Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.9127959Z 87 PC: 9ed97 | Get or set file date and time (See above)
2018-12-25T11:46:09.915422244Z 62 PC: 9ed97 | Close file (See above)
2018-12-25T11:46:09.918368423Z 99 PC: 993f7 | Get DBCS lead byte table pointer (See above)
2018-12-25T11:46:09.919666528Z 56 PC: 93c19 | Get or set country info (See above)
2018-12-25T11:46:09.921839344Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:09.926279077Z 25 PC: 93c82 | Get default drive (See above)
2018-12-25T11:46:09.928062287Z 71 PC: 95efd | Get current directory (See above)
2018-12-25T11:46:09.932922701Z 64 PC: 99668 | Write file or device (See above)
2018-12-25T11:46:09.937415785Z 2 PC: 95ed2 | Character output (See above)
2018-12-25T11:46:09.939587872Z 93 PC: 93d40 | File sharing functions (See above)
2018-12-25T11:46:09.941384914Z 93 PC: 93d47 | File sharing functions (See above)
2018-12-25T11:46:09.943069012Z 10 PC: 93d59 | Buffered keyboard input (See above)