Sample viewer




Time Syscall Op Syscall Name
2018-12-17T21:52:29.94889472Z 78 PC: 12b09 | Find first file
2018-12-17T21:52:29.953946086Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:29.966906927Z 61 PC: 12b09 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:52:29.973368332Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:29.975271879Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:29.981780048Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:29.989603299Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:29.990974507Z 62 PC: 12b09 | Close file
2018-12-17T21:52:29.999744907Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.003684193Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:30.011672176Z 61 PC: 12b09 | Open file (Filename = 'PRINT.COM')
2018-12-17T21:52:30.018743473Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.020386704Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:30.024772685Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:30.031519625Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.033130533Z 62 PC: 12b09 | Close file
2018-12-17T21:52:30.04383068Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.055047042Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:30.064913412Z 61 PC: 12b09 | Open file (Filename = 'HELLO.COM')
2018-12-17T21:52:30.071338958Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.087779507Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:30.094634053Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:30.102986712Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.105742425Z 62 PC: 12b09 | Close file
2018-12-17T21:52:30.114052957Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.116882973Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:30.125894759Z 61 PC: 12b09 | Open file (Filename = 'PHANG.COM')
2018-12-17T21:52:30.130940854Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.132562147Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:30.139671826Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:30.147417682Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.148882405Z 62 PC: 12b09 | Close file
2018-12-17T21:52:30.157519782Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.1601476Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:30.16971743Z 61 PC: 12b09 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T21:52:30.189823595Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.191589416Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:30.198499115Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:30.207041989Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.208583586Z 62 PC: 12b09 | Close file
2018-12-17T21:52:30.216223233Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.219121632Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:30.229230946Z 61 PC: 12b09 | Open file (Filename = 'MANDEL.COM')
2018-12-17T21:52:30.235986787Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.24201177Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:30.248426792Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:30.256606881Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.258702609Z 62 PC: 12b09 | Close file
2018-12-17T21:52:30.266277077Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.268996843Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:30.279451658Z 61 PC: 12b09 | Open file (Filename = 'PAH.COM')
2018-12-17T21:52:30.28661495Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.288119557Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:30.294519113Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:30.30229532Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.303656362Z 62 PC: 12b09 | Close file
2018-12-17T21:52:30.3111539Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.31447829Z 67 PC: 12b09 | Get or set file attributes
2018-12-17T21:52:30.324310995Z 61 PC: 12b09 | Open file (Filename = 'TEST.COM')
2018-12-17T21:52:30.330778667Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.335416471Z 64 PC: 12b09 | Write file or device (Write 38 bytes on handle 5)
2018-12-17T21:52:30.341925665Z 64 PC: 12b09 | Write file or device (Write 632 bytes on handle 5)
2018-12-17T21:52:30.35072342Z 87 PC: 12b09 | Get or set file date and time
2018-12-17T21:52:30.352408493Z 62 PC: 12b09 | Close file
2018-12-17T21:52:30.359613074Z 79 PC: 12b09 | Find next file
2018-12-17T21:52:30.362003231Z 59 PC: 12b09 | Change current directory
2018-12-17T21:52:30.366246191Z 42 PC: 12b09 | Get date 0x12b09: ret
0x12b0a: add byte ptr [bp + si], cl
0x12b0c: or ax, 0x6341
0x12b0f: jne 0x12b83
0x12b11: jbe 0x12b34
0x12b14: jbe 0x12b47
0x12b16: cmp byte ptr cs:[bx + si], ah
0x12b19: arpl word ptr [bx + 0x64], bp
0x12b1c: and byte ptr fs:[bp + si + 0x79], ah
0x12b21: and byte ptr [bp + di + 0x69], cl
0x12b24: insb byte ptr es:[di], dx
0x12b25: dec dx
0x12b26: popaw
0x12b27: outsb dx, byte ptr gs:[si]
0x12b2b: and byte ptr [bx + 0x66], ch
0x12b2e: and byte ptr [si + 0x68], dh
0x12b31: and byte ptr gs:[bp + di + 0x6f], al
0x12b35: bound si, dword ptr gs:[bp + si + 0x65]
0x12b3a: popaw
0x12b3b: imul sp, word ptr [di + 0x72], 0x73
2018-12-17T21:52:30.368185346Z 42 PC: 12b09 | Get date 0x12b09: ret
0x12b0a: add byte ptr [bp + si], cl
0x12b0c: or ax, 0x6341
0x12b0f: jne 0x12b83
0x12b11: jbe 0x12b34
0x12b14: jbe 0x12b47
0x12b16: cmp byte ptr cs:[bx + si], ah
0x12b19: arpl word ptr [bx + 0x64], bp
0x12b1c: and byte ptr fs:[bp + si + 0x79], ah
0x12b21: and byte ptr [bp + di + 0x69], cl
0x12b24: insb byte ptr es:[di], dx
0x12b25: dec dx
0x12b26: popaw
0x12b27: outsb dx, byte ptr gs:[si]
0x12b2b: and byte ptr [bx + 0x66], ch
0x12b2e: and byte ptr [si + 0x68], dh
0x12b31: and byte ptr gs:[bp + di + 0x6f], al
0x12b35: bound si, dword ptr gs:[bp + si + 0x65]
0x12b3a: popaw
0x12b3b: imul sp, word ptr [di + 0x72], 0x73