Sample viewer




Time Syscall Op Syscall Name
2018-12-17T22:19:23.73119318Z 74 PC: 12be7 | Reallocate memory
2018-12-17T22:19:23.732890109Z 42 PC: 13051 | Get date 0x13051: pushf
0x13052: push es
0x13053: push ds
0x13054: push cx
0x13055: push di
0x13056: push si
0x13057: push cs
0x13058: pop ds
0x13059: les di, ptr [0x70d]
0x1305d: push di
0x1305e: mov si, 0x764
0x13061: mov cx, 5
0x13064: rep movsb byte ptr es:[di], byte ptr [si]
0x13066: mov ds, cx
0x13068: pop di
0x13069: mov word ptr [0x84], di
0x1306d: mov word ptr [0x86], es
0x13071: pop si
0x13072: pop di
0x13073: pop cx
2018-12-17T22:19:23.73449461Z 67 PC: 12e2c | Get or set file attributes
2018-12-17T22:19:23.738005432Z 67 PC: 12e34 | Get or set file attributes
2018-12-17T22:19:23.754676599Z 61 PC: 12e3e | Open file (Filename = '')
2018-12-17T22:19:23.761148046Z 87 PC: 12e4c | Get or set file date and time
2018-12-17T22:19:23.762415963Z 63 PC: 12e58 | Read file or device (Read 32 bytes on handle 5)
2018-12-17T22:19:23.766262592Z 66 PC: 12e77 | Move file pointer
2018-12-17T22:19:23.767503649Z 63 PC: 12e94 | Read file or device (Read 30 bytes on handle 5)
2018-12-17T22:19:23.770365788Z 87 PC: 1300b | Get or set file date and time
2018-12-17T22:19:23.77209851Z 62 PC: 1300f | Close file
2018-12-17T22:19:23.779432454Z 67 PC: 13017 | Get or set file attributes
2018-12-17T22:19:23.789709081Z 75 PC: 12c7a | Execute program
2018-12-17T22:19:23.799998533Z 76 PC: 13051 | Terminate with return code (Return code = '170')
2018-12-17T22:19:23.802518676Z 77 PC: 13051 | Get program return code
2018-12-17T22:19:23.803615413Z 49 PC: 13051 | Terminate and stay resident (Return code = '170' | Memory size = '124')