Sample viewer

vx.netlux.org/Virus.DOS.Flower.883

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:21:55.271967501Z 42 PC: 16f8a | Get date 0x16f8a: cmp dx, 0xb0b
0x16f8e: je 0x16f9a
0x16f90: cmp byte ptr [2], 0xae
0x16f95: jge 0x16f9a
0x16f97: jmp 0x1712c
0x16f9a: push ds
0x16f9b: mov ds, word ptr [0x3a5]
0x16f9f: xor si, si
0x16fa1: mov ax, word ptr [si + 0x2c]
0x16fa4: mov ds, ax
0x16fa6: pop es
0x16fa7: mov di, 0x4eb
0x16faa: lodsb al, byte ptr [si]
0x16fab: cmp al, 0
0x16fad: jne 0x16faa
0x16faf: lodsb al, byte ptr [si]
0x16fb0: cmp al, 0
0x16fb2: jne 0x16faa
0x16fb4: add si, 2
0x16fb7: lodsb al, byte ptr [si]
2018-12-17T22:21:55.285775934Z 53 PC: 17132 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.287971029Z 37 PC: 17142 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.289389658Z 47 PC: 17146 | Get disk transfer address
2018-12-17T22:21:55.291372418Z 71 PC: 1715a | Get current directory
2018-12-17T22:21:55.294596614Z 26 PC: 1700b | Set disk transfer address
2018-12-17T22:21:55.295880043Z 78 PC: 17015 | Find first file
2018-12-17T22:21:55.304761373Z 67 PC: 16fde | Get or set file attributes
2018-12-17T22:21:55.319802613Z 61 PC: 16fe3 | Open file (Filename = 'TEST.EXE')
2018-12-17T22:21:55.326331528Z 63 PC: 17065 | Read file or device (Read 28 bytes on handle 5)
2018-12-17T22:21:55.333508256Z 66 PC: 170d4 | Move file pointer
2018-12-17T22:21:55.334800701Z 64 PC: 170de | Write file or device (Write 883 bytes on handle 5)
2018-12-17T22:21:55.342996587Z 66 PC: 170fc | Move file pointer
2018-12-17T22:21:55.344751348Z 64 PC: 17106 | Write file or device (Write 28 bytes on handle 5)
2018-12-17T22:21:55.347878403Z 87 PC: 16ff3 | Get or set file date and time
2018-12-17T22:21:55.350289894Z 62 PC: 16ff7 | Close file
2018-12-17T22:21:55.358498338Z 67 PC: 17003 | Get or set file attributes
2018-12-17T22:21:55.365016805Z 79 PC: 1711e | Find next file
2018-12-17T22:21:55.374790483Z 26 PC: 17164 | Set disk transfer address
2018-12-17T22:21:55.375970436Z 78 PC: 1716e | Find first file
2018-12-17T22:21:55.382597783Z 59 PC: 171a6 | Change current directory
2018-12-17T22:21:55.386839424Z 37 PC: 171c2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.388340656Z 26 PC: 171d0 | Set disk transfer address
2018-12-17T22:21:55.390565066Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:55.392417474Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:55.393882003Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:55.39696394Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:55.398615334Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:55.400079769Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.40317975Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:55.404719272Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:55.406235403Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:55.40850119Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:55.410271865Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:55.411731762Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:55.413415717Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:55.415098022Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:55.416317106Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:55.417773499Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:55.419997115Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:55.421545169Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:55.423070814Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:55.425552995Z 37 PC: 15f47 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:55.427848936Z 37 PC: 15f4f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:55.43082416Z 37 PC: 15f57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.434340307Z 37 PC: 15f5f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:55.435942162Z 68 PC: 164df | I/O control for devices (Set for = '')
2018-12-17T22:21:55.437401659Z 48 PC: 15aa0 | Get DOS version
2018-12-17T22:21:55.439472089Z 48 PC: 151fd | Get DOS version
2018-12-17T22:21:55.440515136Z 82 PC: 151f4 | Get DOS internal pointers (SYSVARS)
2018-12-17T22:21:55.44272016Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:55.445055041Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:55.446182387Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:55.447372392Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:55.449997566Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:55.451641479Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:55.453250446Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:55.457286615Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:55.459642735Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:55.461148248Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:55.463834199Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.465361954Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.466800358Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:55.469473246Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:55.471000441Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:55.472406883Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:55.474998312Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:55.476302188Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:55.477674394Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:55.480059816Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:55.481462351Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:55.482848074Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:55.48448027Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:55.486348886Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:55.487692638Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:55.489125197Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:55.491501414Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:55.492907086Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:55.494299654Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:55.496574024Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:55.497971579Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:55.499388369Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:55.501579705Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:55.502998466Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:55.504380311Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:55.506661034Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:55.507872279Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:55.509282333Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:55.511863299Z 119 PC: 1594d | UNKNOWN!
2018-12-17T22:21:55.513272613Z 64 PC: 165e2 | Write file or device (Write 48 bytes on handle 1)
2018-12-17T22:21:55.518332228Z 64 PC: 165e2 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:21:55.523760502Z 64 PC: 165e2 | Write file or device (Write 47 bytes on handle 1)
2018-12-17T22:21:55.528604679Z 64 PC: 165e2 | Write file or device (Write 6 bytes on handle 1)
2018-12-17T22:21:55.531894341Z 64 PC: 165e2 | Write file or device (Write 10 bytes on handle 1)
2018-12-17T22:21:55.53768189Z 64 PC: 165e2 | Write file or device (Write 81 bytes on handle 1)
2018-12-17T22:21:55.544488209Z 64 PC: 165e2 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:21:55.548635678Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.553922106Z 64 PC: 165e2 | Write file or device (Write 39 bytes on handle 1)
2018-12-17T22:21:55.557465705Z 64 PC: 165e2 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:21:55.563792006Z 64 PC: 165e2 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:21:55.568484883Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.574244985Z 64 PC: 165e2 | Write file or device (Write 39 bytes on handle 1)
2018-12-17T22:21:55.577643264Z 64 PC: 165e2 | Write file or device (Write 1 bytes on handle 1)
2018-12-17T22:21:55.581786558Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.585218058Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.588695691Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.593155757Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.596692896Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.600066518Z 64 PC: 165e2 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:21:55.60717739Z 64 PC: 165e2 | Write file or device (Write 4 bytes on handle 1)
2018-12-17T22:21:55.610595051Z 64 PC: 165e2 | Write file or device (Write 3 bytes on handle 1)
2018-12-17T22:21:55.616895076Z 64 PC: 165e2 | Write file or device (Write 39 bytes on handle 1)
2018-12-17T22:21:55.621029481Z 64 PC: 165e2 | Write file or device (Write 2 bytes on handle 1)
2018-12-17T22:21:55.62693278Z 64 PC: 165e2 | Write file or device (Write 28 bytes on handle 1)
2018-12-17T22:21:55.633029605Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:55.635132635Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:55.636358985Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:55.637473839Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:55.639367383Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:55.640627275Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:55.641979228Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:55.644168825Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:55.6459094Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:55.647337849Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:55.649450289Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.651238426Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.652637773Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:55.654277473Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:55.65645894Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:55.657899885Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:55.659598696Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:55.661820476Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:55.663971976Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:55.665427581Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:55.667547274Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:55.668664691Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:55.669735516Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:55.671875221Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:55.672940767Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:55.674040615Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:55.676211436Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:55.677383083Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:55.678451836Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:55.680525405Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:55.681652896Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:55.682789803Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:55.684769816Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:55.686140525Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:55.687533661Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:55.689981029Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:55.691377807Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:55.69278729Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:55.695288379Z 64 PC: 165e2 | Write file or device (Write 0 bytes on handle 1)
2018-12-17T22:21:55.697606415Z 37 PC: 16046 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:21:55.699013702Z 37 PC: 16046 | Set interrupt vector (Interrupt = '2' AKA 'Character output')
2018-12-17T22:21:55.701720778Z 37 PC: 16046 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive')
2018-12-17T22:21:55.703402511Z 37 PC: 16046 | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:21:55.70478401Z 37 PC: 16046 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:21:55.707475454Z 37 PC: 16046 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:21:55.709200125Z 37 PC: 16046 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer')
2018-12-17T22:21:55.711299768Z 37 PC: 16046 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector')
2018-12-17T22:21:55.71345317Z 37 PC: 16046 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space')
2018-12-17T22:21:55.715118055Z 37 PC: 16046 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character')
2018-12-17T22:21:55.716505959Z 37 PC: 16046 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info')
2018-12-17T22:21:55.71863703Z 37 PC: 16046 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory')
2018-12-17T22:21:55.720316662Z 37 PC: 16046 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory')
2018-12-17T22:21:55.721638902Z 37 PC: 16046 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory')
2018-12-17T22:21:55.723784512Z 37 PC: 16046 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file')
2018-12-17T22:21:55.7254865Z 37 PC: 16046 | Set interrupt vector (Interrupt = '61' AKA 'Open file')
2018-12-17T22:21:55.726880057Z 37 PC: 16046 | Set interrupt vector (Interrupt = '62' AKA 'Close file')
2018-12-17T22:21:55.729048739Z 37 PC: 16046 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-17T22:21:55.730548559Z 37 PC: 16046 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!')
2018-12-17T22:21:55.731981762Z 76 PC: 16085 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3835,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:17.305021419Z 42 PC: 16f8a | Get date 0x16f8a: cmp dx, 0xb0b
0x16f8e: je 0x16f9a
0x16f90: cmp byte ptr [2], 0xae
0x16f95: jge 0x16f9a
0x16f97: jmp 0x1712c
0x16f9a: push ds
0x16f9b: mov ds, word ptr [0x3a5]
0x16f9f: xor si, si
0x16fa1: mov ax, word ptr [si + 0x2c]
0x16fa4: mov ds, ax
0x16fa6: pop es
0x16fa7: mov di, 0x4eb
0x16faa: lodsb al, byte ptr [si]
0x16fab: cmp al, 0
0x16fad: jne 0x16faa
0x16faf: lodsb al, byte ptr [si]
0x16fb0: cmp al, 0
0x16fb2: jne 0x16faa
0x16fb4: add si, 2
0x16fb7: lodsb al, byte ptr [si]
2018-12-25T11:50:17.307951697Z 53 PC: 17132 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:17.310001948Z 37 PC: 17142 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:17.311417869Z 47 PC: 17146 | Get disk transfer address
2018-12-25T11:50:17.313047734Z 71 PC: 1715a | Get current directory
2018-12-25T11:50:17.317567935Z 26 PC: 1700b | Set disk transfer address
2018-12-25T11:50:17.31896377Z 78 PC: 17015 | Find first file
2018-12-25T11:50:17.325967686Z 67 PC: 16fde | Get or set file attributes
2018-12-25T11:50:17.344850302Z 61 PC: 16fe3 | Open file (Filename = 'TEST.EXE')
2018-12-25T11:50:17.356459663Z 63 PC: 17065 | Read file or device (Read 28 bytes on handle 5)
2018-12-25T11:50:17.362923924Z 66 PC: 170d4 | Move file pointer
2018-12-25T11:50:17.365220197Z 64 PC: 170de | Write file or device (Write 883 bytes on handle 5)
2018-12-25T11:50:17.373905456Z 66 PC: 170fc | Move file pointer
2018-12-25T11:50:17.375478442Z 64 PC: 17106 | Write file or device (Write 28 bytes on handle 5)
2018-12-25T11:50:17.379606032Z 87 PC: 16ff3 | Get or set file date and time
2018-12-25T11:50:17.38122206Z 62 PC: 16ff7 | Close file
2018-12-25T11:50:17.38898213Z 67 PC: 17003 | Get or set file attributes
2018-12-25T11:50:17.393891363Z 79 PC: 1711e | Find next file
2018-12-25T11:50:17.396815851Z 26 PC: 17164 | Set disk transfer address
2018-12-25T11:50:17.398001992Z 78 PC: 1716e | Find first file
2018-12-25T11:50:17.403878378Z 59 PC: 171a6 | Change current directory
2018-12-25T11:50:17.407756183Z 37 PC: 171c2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:17.408906335Z 26 PC: 171d0 | Set disk transfer address
2018-12-25T11:50:17.410272424Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.412086797Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.413167224Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.414254973Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.416215236Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.417592145Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.419007492Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.421127383Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.422316179Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.423442131Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.426309296Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.427449864Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.428508982Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.431852994Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.433222593Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.434504498Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.436765748Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.438150528Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.439508945Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.441701091Z 37 PC: 15f47 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.443674768Z 37 PC: 15f4f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:50:17.445591203Z 37 PC: 15f57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:17.447507743Z 37 PC: 15f5f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-25T11:50:17.450846697Z 68 PC: 164df | I/O control for devices (Set for = '')
2018-12-25T11:50:17.453071991Z 48 PC: 15aa0 | Get DOS version
2018-12-25T11:50:17.457911979Z 48 PC: 151fd | Get DOS version
2018-12-25T11:50:17.460123028Z 82 PC: 151f4 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:50:17.46222Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.463327191Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.46527414Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.466434719Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.467482018Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.468738797Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.470440102Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.471475489Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.472480652Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.475088157Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.476232818Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.477541112Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.479550949Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.48062742Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.481637791Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.483752586Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.484776427Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.485820533Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.487724497Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.488790753Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.489799333Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.491624021Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.492759351Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.493799986Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.495544859Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.496585646Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.497535837Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.499387894Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.50069184Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.501927699Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.505472589Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.506770578Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.507989547Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.51000684Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.511269931Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.512505318Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.514766647Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.51584494Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.517096243Z 119 PC: 1594d | UNKNOWN!
2018-12-25T11:50:17.519159826Z 64 PC: 165e2 | Write file or device (Write 48 bytes on handle 1)
2018-12-25T11:50:17.526387446Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.53131247Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.53556362Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.540877623Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.545485041Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.552310027Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.555772844Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.561046712Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.565549054Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.572213177Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.575317714Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.579705797Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.583448615Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.587076793Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.592465567Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.602490243Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.605749067Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.609716238Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.613921679Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.619661961Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.623742065Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.629247826Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.632582899Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.638373902Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.64542697Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.646844334Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.647878961Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.64978484Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.650934628Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.652002461Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.654656458Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.655739455Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.657495935Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.66030366Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.662115403Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.66350332Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.665760583Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.667169641Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.66849236Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.670038833Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.67220599Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.673219012Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.674468869Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.676677913Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.677995599Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.679348945Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.681629055Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.683036997Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.684037088Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.685732888Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.686761654Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.687804738Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.689228261Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.691035728Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.692327577Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.693916723Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.69495123Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.696007172Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.697864611Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.699014115Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.700060791Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.702004691Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.70327581Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.704932494Z 37 PC: 16046 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.706986888Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.708441518Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.709776069Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.71143842Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.712497097Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.713816041Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.715901738Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.71718045Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.718643999Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.720790607Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.72208869Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.723559563Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.724945528Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.725949199Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.727144112Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.728674008Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.729689682Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.730900591Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.732653571Z 76 PC: 16085 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":11,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3835,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:17.307660605Z 42 PC: 16f8a | Get date 0x16f8a: cmp dx, 0xb0b
0x16f8e: je 0x16f9a
0x16f90: cmp byte ptr [2], 0xae
0x16f95: jge 0x16f9a
0x16f97: jmp 0x1712c
0x16f9a: push ds
0x16f9b: mov ds, word ptr [0x3a5]
0x16f9f: xor si, si
0x16fa1: mov ax, word ptr [si + 0x2c]
0x16fa4: mov ds, ax
0x16fa6: pop es
0x16fa7: mov di, 0x4eb
0x16faa: lodsb al, byte ptr [si]
0x16fab: cmp al, 0
0x16fad: jne 0x16faa
0x16faf: lodsb al, byte ptr [si]
0x16fb0: cmp al, 0
0x16fb2: jne 0x16faa
0x16fb4: add si, 2
0x16fb7: lodsb al, byte ptr [si]
2018-12-25T11:50:17.310921507Z 67 PC: 16fde | Get or set file attributes
2018-12-25T11:50:17.32749425Z 61 PC: 16fe3 | Open file (Filename = 'A:\TEST.EXE')
2018-12-25T11:50:17.334377215Z 64 PC: 16fce | Write file or device (Write 194 bytes on handle 5)
2018-12-25T11:50:17.344554813Z 87 PC: 16ff3 | Get or set file date and time
2018-12-25T11:50:17.346380505Z 62 PC: 16ff7 | Close file
2018-12-25T11:50:17.353666167Z 67 PC: 17003 | Get or set file attributes
2018-12-25T11:50:17.358638697Z 37 PC: 171c2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:17.360438176Z 26 PC: 171d0 | Set disk transfer address
2018-12-25T11:50:17.361600742Z 53 PC: 15f32 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.362765834Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.365529242Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.368156422Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.369376494Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.37190668Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.373539793Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.375382722Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.377258655Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.378435738Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.379662588Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.381257864Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.382312036Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.383695782Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.38627957Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.387377294Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.388474596Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.390713181Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.39227445Z 53 PC: 15f32 | Get interrupt vector (See above)
2018-12-25T11:50:17.39383852Z 37 PC: 15f47 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.396488703Z 37 PC: 15f4f | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:50:17.397880111Z 37 PC: 15f57 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:50:17.399217Z 37 PC: 15f5f | Set interrupt vector (Interrupt = '63' AKA 'Read file or device')
2018-12-25T11:50:17.401608842Z 68 PC: 164df | I/O control for devices (Set for = '')
2018-12-25T11:50:17.403132086Z 48 PC: 15aa0 | Get DOS version
2018-12-25T11:50:17.405670572Z 48 PC: 151fd | Get DOS version
2018-12-25T11:50:17.408551843Z 82 PC: 151f4 | Get DOS internal pointers (SYSVARS)
2018-12-25T11:50:17.411188667Z 53 PC: 15e41 | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.412725701Z 37 PC: 15e4a | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.415202399Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.416728302Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.418123149Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.420840579Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.422305794Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.423684705Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.42523173Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.427194328Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.428629437Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.430230629Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.43213411Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.433350791Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.434510193Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.436662511Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.438150228Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.439561134Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.44224126Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.443716781Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.445109003Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.447081972Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.448482296Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.449896556Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.452576719Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.453963878Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.455353028Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.457227098Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.458679374Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.460295689Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.466088455Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.467471876Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.468773267Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.470543952Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.47170285Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.472559262Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.474331915Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.47542682Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.476444453Z 119 PC: 1594d | UNKNOWN!
2018-12-25T11:50:17.478436573Z 64 PC: 165e2 | Write file or device (Write 48 bytes on handle 1)
2018-12-25T11:50:17.484859136Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.489253981Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.493640047Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.498245375Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.50592931Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.514607955Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.516946428Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.521137102Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.525911388Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.53000141Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.53222214Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.537084312Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.541099918Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.544423424Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.552497837Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.555983879Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.559344968Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.562957854Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.569395507Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.57277582Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.577007535Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.580676165Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.586916209Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.592548378Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.594249842Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.595285425Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.596389792Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.59806085Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.599072716Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.600087806Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.602286271Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.603631636Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.60505853Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.606437693Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.607296354Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.608146784Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.609883565Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.610895141Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.61228138Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.613877692Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.614831186Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.615992117Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.617484063Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.618438927Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.619343654Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.620959386Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.622043778Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.623008831Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.62477472Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.62555527Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.626639259Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.628461183Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.629505078Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.630660844Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.632486805Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.634124421Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.635038417Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.636455987Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.637500582Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.63856745Z 53 PC: 15e41 | Get interrupt vector (See above)
2018-12-25T11:50:17.640106436Z 37 PC: 15e4a | Set interrupt vector (See above)
2018-12-25T11:50:17.641506628Z 64 PC: 165e2 | Write file or device (See above)
2018-12-25T11:50:17.64626848Z 37 PC: 16046 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T11:50:17.647562892Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.648455552Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.649754769Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.65130069Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.652345533Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.65374952Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.654676666Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.655494485Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.656918407Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.65795057Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.658829789Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.660420877Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.661528484Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.662492621Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.663891438Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.664819648Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.665620333Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.666969441Z 37 PC: 16046 | Set interrupt vector (See above)
2018-12-25T11:50:17.667943426Z 76 PC: 16085 | Terminate with return code (Return code = '0')