Sample viewer




Time Syscall Op Syscall Name
2018-12-17T22:12:43.324165985Z 48 PC: 12a99 | Get DOS version
2018-12-17T22:12:43.326334694Z 26 PC: 12aa7 | Set disk transfer address
2018-12-17T22:12:43.328273611Z 78 PC: 12ab1 | Find first file
2018-12-17T22:12:43.335261251Z 67 PC: 12abe | Get or set file attributes
2018-12-17T22:12:43.341419702Z 67 PC: 12ac6 | Get or set file attributes
2018-12-17T22:12:43.361001233Z 61 PC: 12acb | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:12:43.36789476Z 87 PC: 12ad1 | Get or set file date and time
2018-12-17T22:12:43.369273157Z 63 PC: 12ade | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:12:43.376320197Z 66 PC: 12b04 | Move file pointer
2018-12-17T22:12:43.378067969Z 66 PC: 12ba3 | Move file pointer
2018-12-17T22:12:43.379813538Z 63 PC: 12bad | Read file or device (Read 52 bytes on handle 5)
2018-12-17T22:12:43.383012971Z 66 PC: 12b04 | Move file pointer
2018-12-17T22:12:43.384353308Z 44 PC: 12bfa | Get time 0x12bfa: cmp dl, 0
0x12bfd: jne 0x12c01
0x12bff: jmp 0x12bf6
0x12c01: mov byte ptr cs:[bp + 0x118], dl
0x12c06: lea si, word ptr [bp + 0x104]
0x12c0a: mov di, 0xfb00
0x12c0d: mov cx, 0x18
0x12c10: rep movsb byte ptr es:[di], byte ptr [si]
0x12c12: lea si, word ptr [bp + 0x11c]
0x12c16: mov cx, 0x284
0x12c19: lodsb al, byte ptr [si]
0x12c1a: xor al, dl
0x12c1c: stosb byte ptr es:[di], al
0x12c1d: loop 0x12c19
0x12c1f: mov ah, 0x40
0x12c21: mov dx, 0xfb00
0x12c24: mov cx, 0x29c
0x12c27: int 0x21
0x12c29: mov ax, 0x4200
0x12c2c: call 0x22afe
2018-12-17T22:12:43.386581543Z 64 PC: 12c29 | Write file or device (Write 668 bytes on handle 5)
2018-12-17T22:12:43.397026782Z 66 PC: 12b04 | Move file pointer
2018-12-17T22:12:43.400585049Z 64 PC: 12c3a | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:12:43.420208728Z 87 PC: 12c89 | Get or set file date and time
2018-12-17T22:12:43.43757285Z 62 PC: 12c8d | Close file
2018-12-17T22:12:43.445778744Z 67 PC: 12c96 | Get or set file attributes
2018-12-17T22:12:43.454005323Z 26 PC: 12c44 | Set disk transfer address