Sample viewer

vx.netlux.org/Virus.DOS.Bomj.904

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:25.346476437Z 254 PC: 13f1e | UNKNOWN!
2018-12-17T22:19:25.348951264Z 74 PC: 13f2d | Reallocate memory
2018-12-17T22:19:25.351074791Z 74 PC: 13f34 | Reallocate memory
2018-12-17T22:19:25.352904587Z 72 PC: 13f3b | Allocate memory
2018-12-17T22:19:25.356008783Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.358415004Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.361043547Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-17T22:19:25.368561868Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.370770086Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.372899877Z 76 PC: 12a61 | Terminate with return code (Return code = '0')
2018-12-17T22:19:25.395894288Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.398517232Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.401153079Z 77 PC: 11fe0 | Get program return code
2018-12-17T22:19:25.403156995Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.405684765Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.407948974Z 72 PC: 12174 | Allocate memory
2018-12-17T22:19:25.409786209Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.412200651Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.414434283Z 72 PC: 1218d | Allocate memory
2018-12-17T22:19:25.416686651Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.419915755Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.422376941Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-17T22:19:25.426431451Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.430186369Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.432748899Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:19:25.443349801Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.446993049Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.450624967Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:19:25.452044567Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.457509919Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.460567298Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.462572297Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.465552742Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.468171065Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.470236948Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.473130197Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.476362962Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.479024266Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.481121822Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.484533987Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.486472372Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.488953177Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.491972515Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.493795623Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.496230293Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.49958212Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.501131785Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.503196225Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.505935409Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.507382168Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.509400551Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.512372772Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.514261679Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.51656564Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.519176094Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.521770805Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.524209549Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.526665942Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.528828079Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.530928093Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.533012374Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.534856002Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.537571375Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.539694665Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.541816824Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.54395854Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.546338957Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.54865314Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.550935885Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.553299734Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.555798308Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.558083551Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.560425266Z 62 PC: 122ab | Close file
2018-12-17T22:19:25.563919141Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.565929939Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.568063376Z 99 PC: 9a227 | Get DBCS lead byte table pointer
2018-12-17T22:19:25.570470783Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.572444533Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.574539783Z 56 PC: 94a49 | Get or set country info
2018-12-17T22:19:25.577360826Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.579379582Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.581466479Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:19:25.586539399Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.588788917Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.591012786Z 25 PC: 94ab2 | Get default drive
2018-12-17T22:19:25.593028834Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.595149211Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.597228589Z 71 PC: 96d2d | Get current directory
2018-12-17T22:19:25.601906919Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.604140352Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.606462544Z 64 PC: 9a498 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:19:25.610721773Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.612807296Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.615547273Z 2 PC: 96d02 | Character output (Char = '3e')
2018-12-17T22:19:25.618792601Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.620798613Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.622862997Z 93 PC: 94b70 | File sharing functions
2018-12-17T22:19:25.625388807Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.627451313Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.629575832Z 93 PC: 94b77 | File sharing functions
2018-12-17T22:19:25.632727863Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-17T22:19:25.634741923Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-17T22:19:25.636929354Z 10 PC: 94b89 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":3345,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:00.746276877Z 254 PC: 13f1e | UNKNOWN!
2018-12-25T11:49:00.747511055Z 74 PC: 13f2d | Reallocate memory
2018-12-25T11:49:00.749640386Z 74 PC: 13f34 | Reallocate memory
2018-12-25T11:49:00.750874465Z 72 PC: 13f3b | Allocate memory
2018-12-25T11:49:00.754062346Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-25T11:49:00.756051673Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-25T11:49:00.758299469Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-25T11:49:00.764419902Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.766381088Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.768604048Z 76 PC: 12a61 | Terminate with return code (Return code = '0')
2018-12-25T11:49:00.771916868Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.773863597Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.776138859Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:49:00.777692994Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.779797249Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.78215377Z 72 PC: 12174 | Allocate memory
2018-12-25T11:49:00.784289921Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.786474362Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.788822869Z 72 PC: 1218d | Allocate memory
2018-12-25T11:49:00.79182387Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.793780028Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.796360711Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:49:00.798091001Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.800077205Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.802326824Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:49:00.80382792Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.806154997Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.808539152Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:49:00.809824229Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.812007722Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.81431023Z 62 PC: 122ab | Close file
2018-12-25T11:49:00.817396371Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.819480069Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.821819042Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.826071787Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.828069331Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.830328385Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.832153447Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.834306483Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.836616704Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.838158587Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.840632708Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.84322171Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.845257654Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.847120442Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.849368911Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.851070497Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.85297278Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.855594518Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.857179902Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.859179416Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.861453752Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.863620303Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.865610525Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.867938616Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.869691349Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.871647994Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.873849716Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.875646798Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.877602641Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.88112701Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.882995345Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.884899084Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.887114299Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.889004986Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.890956294Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.893161749Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.894882498Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.897622588Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.900102493Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.901938848Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.904009108Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.906213666Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.908991364Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.911064133Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.913314006Z 99 PC: 9a227 | Get DBCS lead byte table pointer
2018-12-25T11:49:00.914674903Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.916841125Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.919383232Z 56 PC: 94a49 | Get or set country info
2018-12-25T11:49:00.921421883Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.923483316Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.925705069Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:49:00.930266746Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.932400297Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.934730437Z 25 PC: 94ab2 | Get default drive
2018-12-25T11:49:00.936419965Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.939459008Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.941710235Z 71 PC: 96d2d | Get current directory
2018-12-25T11:49:00.945186874Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.947174518Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.949376193Z 64 PC: 9a498 | Write file or device (See above)
2018-12-25T11:49:00.952334633Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.954595673Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.956694919Z 2 PC: 96d02 | Character output (Char = '3e')
2018-12-25T11:49:00.958567529Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.960656259Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.962772927Z 93 PC: 94b70 | File sharing functions
2018-12-25T11:49:00.964131607Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.96608431Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.968815428Z 93 PC: 94b77 | File sharing functions
2018-12-25T11:49:00.97023041Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.97233045Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.974593576Z 10 PC: 94b89 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":3345,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:00.815686906Z 254 PC: 13f1e | UNKNOWN!
2018-12-25T11:49:00.817488262Z 74 PC: 13f2d | Reallocate memory
2018-12-25T11:49:00.819014324Z 74 PC: 13f34 | Reallocate memory
2018-12-25T11:49:00.820268613Z 72 PC: 13f3b | Allocate memory
2018-12-25T11:49:00.82239725Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-25T11:49:00.824368281Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-25T11:49:00.826629445Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-25T11:49:00.846560915Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.848537089Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.850826327Z 76 PC: 12a61 | Terminate with return code (Return code = '0')
2018-12-25T11:49:00.854416624Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.856377245Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.85875983Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:49:00.865642885Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.874654589Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.877036361Z 72 PC: 12174 | Allocate memory
2018-12-25T11:49:00.879083544Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.881467214Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.884040312Z 72 PC: 1218d | Allocate memory
2018-12-25T11:49:00.886402579Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.8885565Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.890871043Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:49:00.892138111Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.894867743Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.897285747Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:49:00.898848252Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.900894411Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.903237357Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:49:00.905353466Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.90805071Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.910470632Z 62 PC: 122ab | Close file
2018-12-25T11:49:00.912049828Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.916099088Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.918493956Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.920073924Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.922748038Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.925106974Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.926806677Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.929086203Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.932120872Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.933633911Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.935814612Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.938111636Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.939753052Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.942335562Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.944750828Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.946337204Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.94868936Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.95098522Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.952423829Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.967060836Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.969511948Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.971216335Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.97348915Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.975814131Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.977168165Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.979480392Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.981843683Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.983234025Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.985665103Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.987985243Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.990120061Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.992333732Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:00.99482067Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:00.996328378Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:00.998733518Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.001501342Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.003330244Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.005745261Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.00817054Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.009583344Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.012044752Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.01440333Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.017079219Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.019287324Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.022268641Z 99 PC: 9a227 | Get DBCS lead byte table pointer
2018-12-25T11:49:01.023451231Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.025610973Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.027920422Z 56 PC: 94a49 | Get or set country info
2018-12-25T11:49:01.029682495Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.036171854Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.038524712Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:49:01.042771249Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.045462335Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.048239088Z 25 PC: 94ab2 | Get default drive
2018-12-25T11:49:01.049893592Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.052592133Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.055322835Z 71 PC: 96d2d | Get current directory
2018-12-25T11:49:01.059639206Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.062497214Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.065244636Z 64 PC: 9a498 | Write file or device (See above)
2018-12-25T11:49:01.068741077Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.072054489Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.075019327Z 2 PC: 96d02 | Character output (Char = '3e')
2018-12-25T11:49:01.076626571Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.078654651Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.080311725Z 93 PC: 94b70 | File sharing functions
2018-12-25T11:49:01.081495591Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.083744929Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.085590097Z 93 PC: 94b77 | File sharing functions
2018-12-25T11:49:01.086901744Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.08871805Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.090485665Z 10 PC: 94b89 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":6,"Min":0,"Second":0,"TimeBased":true,"OriginalID":3345,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:01.0464771Z 254 PC: 13f1e | UNKNOWN!
2018-12-25T11:49:01.047587434Z 74 PC: 13f2d | Reallocate memory
2018-12-25T11:49:01.049080388Z 74 PC: 13f34 | Reallocate memory
2018-12-25T11:49:01.050282426Z 72 PC: 13f3b | Allocate memory
2018-12-25T11:49:01.057113646Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-25T11:49:01.05998065Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-25T11:49:01.06270095Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-25T11:49:01.06711955Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.068664996Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.070168419Z 76 PC: 12a61 | Terminate with return code (Return code = '0')
2018-12-25T11:49:01.072861152Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.074938279Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.076886643Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:49:01.079040039Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.081516435Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.083855579Z 72 PC: 12174 | Allocate memory
2018-12-25T11:49:01.086142728Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.08765861Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.089755875Z 72 PC: 1218d | Allocate memory
2018-12-25T11:49:01.092659077Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.094681269Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.096678452Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:49:01.098948246Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.101265764Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.103257646Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:49:01.104775187Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.106846267Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.108873391Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:49:01.110688884Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.112908499Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.115047699Z 62 PC: 122ab | Close file
2018-12-25T11:49:01.116776508Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.118320098Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.12034164Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.122202518Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.12443534Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.127252096Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.129348352Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.131362277Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.13336812Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.135201894Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.137183609Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.13921984Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.141018641Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.143079674Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.145186499Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.147102298Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.148616019Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.149978271Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.151380614Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.15275793Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.154094573Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.155569208Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.157019163Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.158485935Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.159975891Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.161449617Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.163205167Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.165871435Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.167354271Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.169006309Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.170362967Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.179321514Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.180953786Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.182192714Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.183885356Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.185275935Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.186329829Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.188257862Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.190100875Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.191227383Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.193097975Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.194478736Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.196410662Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.19863373Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.200194497Z 99 PC: 9a227 | Get DBCS lead byte table pointer
2018-12-25T11:49:01.201465626Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.203789888Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.205288234Z 56 PC: 94a49 | Get or set country info
2018-12-25T11:49:01.207068891Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.208954006Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.210432064Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:49:01.213140841Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.214722562Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.216136485Z 25 PC: 94ab2 | Get default drive
2018-12-25T11:49:01.217376116Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.222192267Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.224214596Z 71 PC: 96d2d | Get current directory
2018-12-25T11:49:01.227940734Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.230034428Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.232126831Z 64 PC: 9a498 | Write file or device (See above)
2018-12-25T11:49:01.235146546Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.23734928Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.239345718Z 2 PC: 96d02 | Character output (Char = '3e')
2018-12-25T11:49:01.2413559Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.243526976Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.245572558Z 93 PC: 94b70 | File sharing functions
2018-12-25T11:49:01.247373918Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.250375221Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.2523253Z 93 PC: 94b77 | File sharing functions
2018-12-25T11:49:01.253899077Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.256498358Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.259139478Z 10 PC: 94b89 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":6,"Min":0,"Second":0,"TimeBased":true,"OriginalID":3345,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:49:01.146524245Z 254 PC: 13f1e | UNKNOWN!
2018-12-25T11:49:01.147921774Z 74 PC: 13f2d | Reallocate memory
2018-12-25T11:49:01.149300433Z 74 PC: 13f34 | Reallocate memory
2018-12-25T11:49:01.150465807Z 72 PC: 13f3b | Allocate memory
2018-12-25T11:49:01.152529989Z 42 PC: 9f8be | Get date 0x9f8be: cmp dx, 0x703
0x9f8c2: jne 0x9f8c7
0x9f8c4: jmp 0x9f966
0x9f8c7: mov ah, 0x2c
0x9f8c9: int 0x60
0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
2018-12-25T11:49:01.154594386Z 44 PC: 9f8cb | Get time 0x9f8cb: cmp ch, 5
0x9f8ce: ja 0x9f943
0x9f8d0: push 0x40
0x9f8d2: pop es
0x9f8d3: mov dh, byte ptr es:[0x17]
0x9f8d8: cmp dh, 0x70
0x9f8db: jne 0x9f8e5
0x9f8dd: mov byte ptr es:[0x17], 0
0x9f8e3: jmp 0x9f8eb
0x9f8e5: mov byte ptr es:[0x17], 0x70
0x9f8eb: mov bh, 0x14
0x9f8ed: xor ax, ax
0x9f8ef: mov al, cl
0x9f8f1: div bh
0x9f8f3: or ah, ah
0x9f8f5: jne 0x9f943
0x9f8f7: push ds
0x9f8f8: pop es
0x9f8f9: mov bx, 0xe7
0x9f8fc: mov ax, 0x1500
2018-12-25T11:49:01.156671517Z 9 PC: 12a5c | Display string (Could not find end pointer)
2018-12-25T11:49:01.163385334Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.166557779Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.168642129Z 76 PC: 12a61 | Terminate with return code (Return code = '0')
2018-12-25T11:49:01.172382862Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.178037781Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.180109304Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:49:01.181452917Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.183722261Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.185775554Z 72 PC: 12174 | Allocate memory
2018-12-25T11:49:01.187324856Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.189839239Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.192177334Z 72 PC: 1218d | Allocate memory
2018-12-25T11:49:01.194625007Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.197451684Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.199684699Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:49:01.200772914Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.203677255Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.206636625Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:49:01.208055223Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.210935386Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.213547628Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:49:01.214668185Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.218074486Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.220376028Z 62 PC: 122ab | Close file
2018-12-25T11:49:01.223030696Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.225980442Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.228184863Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.229658368Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.232267807Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.234450267Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.235998222Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.238282737Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.240463853Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.241818337Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.244401028Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.24687378Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.248292325Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.250475569Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.253016545Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.254851107Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.257439745Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.260782772Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.262196054Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.26482956Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.267695503Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.26902189Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.270900452Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.273371873Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.274899244Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.276965175Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.278992674Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.280285596Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.282113978Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.284949834Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.28643297Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.288516937Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.291124561Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.29289133Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.295200352Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.298177776Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.299592607Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.301945766Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.304084312Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.305433478Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.307311681Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.309398633Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:49:01.311977016Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.313877171Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.316043115Z 99 PC: 9a227 | Get DBCS lead byte table pointer
2018-12-25T11:49:01.317168627Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.318955266Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.32157242Z 56 PC: 94a49 | Get or set country info
2018-12-25T11:49:01.323654837Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.325610298Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.328312601Z 64 PC: 9a498 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:49:01.33261013Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.334458241Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.336999248Z 25 PC: 94ab2 | Get default drive
2018-12-25T11:49:01.339297967Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.341211246Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.34393113Z 71 PC: 96d2d | Get current directory
2018-12-25T11:49:01.347598407Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.349494339Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.363362557Z 64 PC: 9a498 | Write file or device (See above)
2018-12-25T11:49:01.366415034Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.368407406Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.371449132Z 2 PC: 96d02 | Character output (Char = '3e')
2018-12-25T11:49:01.373930583Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.376242576Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.378820869Z 93 PC: 94b70 | File sharing functions
2018-12-25T11:49:01.380359172Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.382259523Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.384585829Z 93 PC: 94b77 | File sharing functions
2018-12-25T11:49:01.386195809Z 42 PC: 9f8be | Get date (See above)
2018-12-25T11:49:01.388104043Z 44 PC: 9f8cb | Get time (See above)
2018-12-25T11:49:01.390638853Z 10 PC: 94b89 | Buffered keyboard input