Sample viewer

vx.netlux.org/Virus.DOS.Omega.440

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:22:35.380773746Z 26 PC: 18d2f | Set disk transfer address
2018-12-17T22:22:35.382365884Z 78 PC: 18e0e | Find first file
2018-12-17T22:22:35.388625671Z 61 PC: 18e28 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:22:35.39645623Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.399148674Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.405102633Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.40621701Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.408427328Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.40968885Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.411406702Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:35.426483938Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:35.427777108Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.437206111Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:35.438753162Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.446105951Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.449513737Z 61 PC: 18e28 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:22:35.4556908Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.45706695Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.458754233Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.460056858Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.466452452Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.467615438Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.470024347Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:35.47306669Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:35.474773064Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.477231834Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:35.479058341Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.486393037Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.489162695Z 61 PC: 18e28 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:22:35.495873243Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.497095007Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.498570209Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.500201439Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.50636197Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.507555776Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.510445138Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:35.51858292Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:35.519825617Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.526536981Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:35.527883574Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.535278613Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.538303332Z 61 PC: 18e28 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:22:35.544513532Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.545716837Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.547762553Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.549007659Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.554998367Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.557328313Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.560187701Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:35.562630776Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:35.564351045Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.566821501Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:35.568238574Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.576359015Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.578907119Z 61 PC: 18e28 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:22:35.585873008Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.588280191Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.590205345Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.591775332Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.598890443Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.600802373Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.603648268Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:35.60721419Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:35.609184365Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.611976702Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:35.613838192Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.621603346Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.624195852Z 61 PC: 18e28 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:22:35.63146491Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.633784512Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.64459035Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.646229449Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.649204302Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.65050128Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.653810812Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:35.661746053Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:35.662942572Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.669678412Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:35.673360353Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.681358753Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.68382786Z 61 PC: 18e28 | Open file (Filename = 'PAH.COM')
2018-12-17T22:22:35.690871408Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.692076089Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.693561147Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.696170748Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.705912129Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.707270812Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.710434207Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:35.712903776Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:35.714612242Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.717585796Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:35.718884076Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.726590339Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.729603946Z 61 PC: 18e28 | Open file (Filename = 'TEST.COM')
2018-12-17T22:22:35.735947711Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.737241335Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.74425212Z 62 PC: 18e58 | Close file
2018-12-17T22:22:35.745914322Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:35.748257255Z 78 PC: 18db8 | Find first file
2018-12-17T22:22:35.755208338Z 78 PC: 18e0e | Find first file
2018-12-17T22:22:35.76304331Z 61 PC: 18e28 | Open file (Filename = 'C:\COMMAND.COM')
2018-12-17T22:22:35.769072794Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:35.771292296Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:35.774789724Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:35.776395781Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:35.779752403Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:35.782301931Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:35.786271674Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:36.118567508Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:36.120654376Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.123580885Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:36.126109665Z 62 PC: 18e58 | Close file
2018-12-17T22:22:36.133117412Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:36.137597742Z 78 PC: 18db8 | Find first file
2018-12-17T22:22:36.143904219Z 78 PC: 18e0e | Find first file
2018-12-17T22:22:36.153333681Z 61 PC: 18e28 | Open file (Filename = 'C:\DOS\EDIT.COM')
2018-12-17T22:22:36.160374244Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:36.162317848Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:36.16888108Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:36.170551315Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:36.173320982Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:36.176857838Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.179917392Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:36.186524798Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:36.189260319Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.195188065Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:36.196991025Z 62 PC: 18e58 | Close file
2018-12-17T22:22:36.204675603Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:36.208030547Z 61 PC: 18e28 | Open file (Filename = 'C:\DOS\FORMAT.COM')
2018-12-17T22:22:36.215093104Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:36.217943555Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:36.224064244Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:36.225704316Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:36.232508827Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:36.234177941Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.23756675Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:36.245703189Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:36.247333754Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.250328617Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:36.253006889Z 62 PC: 18e58 | Close file
2018-12-17T22:22:36.259675795Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:36.262954603Z 61 PC: 18e28 | Open file (Filename = 'C:\DOS\KEYB.COM')
2018-12-17T22:22:36.270503167Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:36.272163029Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:36.278234658Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:36.280853474Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:36.286533235Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:36.288144661Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.2923828Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:36.298881006Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:36.300469072Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.304470975Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:36.306191242Z 62 PC: 18e58 | Close file
2018-12-17T22:22:36.312767987Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:36.320905299Z 61 PC: 18e28 | Open file (Filename = 'C:\DOS\SYS.COM')
2018-12-17T22:22:36.327963985Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:36.329588333Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:36.336927738Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:36.338541078Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:36.344122555Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:36.346753029Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.353032802Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:36.359249775Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:36.361092878Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.363064356Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:36.364847707Z 62 PC: 18e58 | Close file
2018-12-17T22:22:36.372439103Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:36.378615616Z 79 PC: 18def | Find next file
2018-12-17T22:22:36.381599157Z 78 PC: 18e0e | Find first file
2018-12-17T22:22:36.392454387Z 61 PC: 18e28 | Open file (Filename = 'C:\WINDOWS\WIN.COM')
2018-12-17T22:22:36.399459083Z 66 PC: 18e37 | Move file pointer
2018-12-17T22:22:36.401141372Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:22:36.408273006Z 66 PC: 18e6c | Move file pointer
2018-12-17T22:22:36.409863415Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:22:36.415387255Z 66 PC: 18e87 | Move file pointer
2018-12-17T22:22:36.418095317Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.424431173Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-17T22:22:36.430906722Z 66 PC: 18ead | Move file pointer
2018-12-17T22:22:36.433608341Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:22:36.436650278Z 87 PC: 18ecd | Get or set file date and time
2018-12-17T22:22:36.441970167Z 62 PC: 18e58 | Close file
2018-12-17T22:22:36.449603547Z 79 PC: 18e5c | Find next file
2018-12-17T22:22:36.45746532Z 79 PC: 18def | Find next file
2018-12-17T22:22:36.460191049Z 42 PC: 18d52 | Get date 0x18d52: cmp al, 5
0x18d54: jne 0x18d60
0x18d56: cmp dl, 0xd
0x18d59: jne 0x18d60
0x18d5b: call 0x18d83
0x18d5e: int 0x20
0x18d60: mov ah, 0x1a
0x18d62: mov dx, 0x80
0x18d65: int 0x21
0x18d67: lea si, word ptr [bp - 0x1b8]
0x18d6b: mov di, 0x100
0x18d6e: cld
0x18d6f: movsw word ptr es:[di], word ptr [si]
0x18d70: movsb byte ptr es:[di], byte ptr [si]
0x18d71: push cs
0x18d72: pop es
0x18d73: push cs
0x18d74: pop ds
0x18d75: pop ax
0x18d76: mov di, 0x100
2018-12-17T22:22:36.463498628Z 26 PC: 18d67 | Set disk transfer address
2018-12-17T22:22:36.464865177Z 48 PC: 13777 | Get DOS version
2018-12-17T22:22:36.466261885Z 9 PC: 13783 | Display string (String= 'Incorrect DOS version ')

{"DateBased":true,"Day":4,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3960,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:32.751663022Z 26 PC: 18d2f | Set disk transfer address
2018-12-25T11:50:32.753820293Z 78 PC: 18e0e | Find first file
2018-12-25T11:50:32.760119923Z 61 PC: 18e28 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:50:32.766815953Z 66 PC: 18e37 | Move file pointer
2018-12-25T11:50:32.769009402Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-25T11:50:32.77541155Z 66 PC: 18e6c | Move file pointer
2018-12-25T11:50:32.776757457Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:50:32.780331504Z 66 PC: 18e87 | Move file pointer
2018-12-25T11:50:32.781739934Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:32.784444746Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-25T11:50:32.798457088Z 66 PC: 18ead | Move file pointer
2018-12-25T11:50:32.800172184Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:32.804376529Z 87 PC: 18ecd | Get or set file date and time
2018-12-25T11:50:32.806049246Z 62 PC: 18e58 | Close file
2018-12-25T11:50:32.811297743Z 79 PC: 18e5c | Find next file
2018-12-25T11:50:32.813071871Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:32.819273449Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:32.820246132Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:32.821347364Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:32.822770797Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:32.827020902Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:32.828318353Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:32.831388891Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:32.833859605Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:32.834982385Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:32.838316202Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:32.83969788Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:32.846862627Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:32.84981474Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:32.856090616Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:32.85748722Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:32.8601978Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:32.861438123Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:32.867561169Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:32.869303897Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:32.871987074Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:32.879706449Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:32.881341289Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:32.887582319Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:32.888867573Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:32.896828082Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:32.899520972Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:32.9057881Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:32.907632068Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:32.909066796Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:32.910010858Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:32.916643081Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:32.917929003Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:32.920414336Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:32.923769426Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:32.92498662Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:32.928130081Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:32.930788771Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:32.93781154Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:32.940451361Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:32.947098052Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:32.948672726Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:32.950271239Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:32.952585092Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:32.958835578Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:32.960133847Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:32.962803503Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:32.966123028Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:32.967376442Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:32.97001831Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:32.971742133Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:32.978838156Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:32.981394154Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:32.988055718Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:32.989258231Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:32.999051333Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.000297704Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.00264878Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.01830081Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.020825755Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.028748605Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.032951163Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.039749277Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.041069107Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.049285145Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.052125344Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.058373333Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.059771845Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.061526206Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.062782488Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.070076563Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.071489004Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.073948342Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.076573648Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.07887493Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.081390778Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.082742954Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.089942801Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.092356649Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.098572646Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.100927617Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.107771263Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.10937244Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.112957272Z 78 PC: 18db8 | Find first file
2018-12-25T11:50:33.11845257Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.123699946Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.129974522Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.1312325Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.133938632Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.136689941Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.139550305Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.140786259Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.145559267Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.473037582Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.47408772Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.476708825Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.478367155Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.484639938Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.487478169Z 78 PC: 18db8 | Find first file (See above)
2018-12-25T11:50:33.492716658Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.501302819Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.508488573Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.509846188Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.515370295Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.517177354Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.519515319Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.520935071Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.523175555Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.52771471Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.528599873Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.53421849Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.535547066Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.542477096Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.546198761Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.55309916Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.554871853Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.561041122Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.562458864Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.568046777Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.569701002Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.572671455Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.579488464Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.58071008Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.583333396Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.585196584Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.591605663Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.595350768Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.603488197Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.604886429Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.610536284Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.612198152Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.617533034Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.618757932Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.621925498Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.627988552Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.629243793Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.631964577Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.633237339Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.63936284Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.645319817Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.651998251Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.653069593Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.659387938Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.660819346Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.667252768Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.668563638Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.684282263Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.691095094Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.69273737Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.69549164Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.697575628Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.704522975Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.710293068Z 79 PC: 18def | Find next file
2018-12-25T11:50:33.714129236Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.723163135Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.730555954Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.732349011Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.738248659Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.739456858Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.750695541Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.752615583Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.758811375Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.960691195Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.96245737Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.965208588Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.96700496Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.349448575Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.354173315Z 79 PC: 18def | Find next file (See above)
2018-12-25T11:50:34.356702284Z 42 PC: 18d52 | Get date 0x18d52: cmp al, 5
0x18d54: jne 0x18d60
0x18d56: cmp dl, 0xd
0x18d59: jne 0x18d60
0x18d5b: call 0x18d83
0x18d5e: int 0x20
0x18d60: mov ah, 0x1a
0x18d62: mov dx, 0x80
0x18d65: int 0x21
0x18d67: lea si, word ptr [bp - 0x1b8]
0x18d6b: mov di, 0x100
0x18d6e: cld
0x18d6f: movsw word ptr es:[di], word ptr [si]
0x18d70: movsb byte ptr es:[di], byte ptr [si]
0x18d71: push cs
0x18d72: pop es
0x18d73: push cs
0x18d74: pop ds
0x18d75: pop ax
0x18d76: mov di, 0x100
2018-12-25T11:50:34.358149976Z 26 PC: 18d67 | Set disk transfer address
2018-12-25T11:50:34.359224331Z 48 PC: 13777 | Get DOS version
2018-12-25T11:50:34.360635035Z 9 PC: 13783 | Display string (String= 'Incorrect DOS version ')

{"DateBased":true,"Day":13,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3960,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:32.827712615Z 26 PC: 18d2f | Set disk transfer address
2018-12-25T11:50:32.829401225Z 78 PC: 18e0e | Find first file
2018-12-25T11:50:32.833787347Z 61 PC: 18e28 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:50:32.837987573Z 66 PC: 18e37 | Move file pointer
2018-12-25T11:50:32.839524979Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-25T11:50:32.843809471Z 66 PC: 18e6c | Move file pointer
2018-12-25T11:50:32.844941054Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:50:32.847124351Z 66 PC: 18e87 | Move file pointer
2018-12-25T11:50:32.848223533Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:32.850079893Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-25T11:50:32.861706546Z 66 PC: 18ead | Move file pointer
2018-12-25T11:50:32.864070063Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:32.871459768Z 87 PC: 18ecd | Get or set file date and time
2018-12-25T11:50:32.873060282Z 62 PC: 18e58 | Close file
2018-12-25T11:50:32.881568357Z 79 PC: 18e5c | Find next file
2018-12-25T11:50:32.884600175Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:32.891819594Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:32.894324157Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:32.895862083Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:32.8973779Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:32.904813751Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:32.906215051Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:32.908866179Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:32.912009524Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:32.920456416Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:32.932340787Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:32.935058421Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:32.9433176Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:32.946289125Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:32.954023753Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:32.95562153Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:32.957397404Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:32.95931654Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:32.966463485Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:32.967878515Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:32.970786489Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:32.979836409Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:32.981217771Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:32.98831109Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:32.991331624Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.000275167Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.003190881Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.010898692Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.012357334Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.014575521Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.017050219Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.024093176Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.025565707Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.029088272Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.032664554Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.034465388Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.038471691Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.040173404Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.048286834Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.051961515Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.059027328Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.060076283Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.061382531Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.063096152Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.069950049Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.071618916Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.074840284Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.07772655Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.079252576Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.082326409Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.08402351Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.091883318Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.095520796Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.103091228Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.104956967Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.112193198Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.113406185Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.115935451Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.117514894Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.120379429Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.130176854Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.13172151Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.138913798Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.140464527Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.149288769Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.152160645Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.159283395Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.161233602Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.162930998Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.164194151Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.171709258Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.172869394Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.174801319Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.177647829Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.178762077Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.180719985Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.182231866Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.187832772Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.189736177Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.194956578Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.196623503Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.204085903Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.206375521Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.209360351Z 78 PC: 18db8 | Find first file
2018-12-25T11:50:33.215670172Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.222257989Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.228882944Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.230294368Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.233829452Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.235274361Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.238085556Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.239900645Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.243470462Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.606662298Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.609067317Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.612199889Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.614741275Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.623681664Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.626764821Z 78 PC: 18db8 | Find first file (See above)
2018-12-25T11:50:33.632711223Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.642983031Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.65060696Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.652028996Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.658462855Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.660086484Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.662725103Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.664700374Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.667827285Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.67477047Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.676538008Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.683605103Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.685047114Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.692505988Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.695771476Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.703310621Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.705107018Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.711515272Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.712860728Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.719271915Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.720776737Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.724208752Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.731166594Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.732799057Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.735664111Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.737772455Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.745919862Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.749186781Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.754216508Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.755510627Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.761745767Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.76348456Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.769449201Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.770651166Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.774617268Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.781450563Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.782654827Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.786178593Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.788348653Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.796163171Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.802846295Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.811820848Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.813571091Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.820275319Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.822062735Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.828572177Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.830359603Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.84690484Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.851711728Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.853194537Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.855862055Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.85696415Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.861431992Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.865837486Z 79 PC: 18def | Find next file
2018-12-25T11:50:33.867724393Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.874099974Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.879023196Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.880251852Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.88430541Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.885661468Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.889153948Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.890316167Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.894817075Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.901914978Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.903718515Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.905794021Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.906900355Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.911564859Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.91647785Z 79 PC: 18def | Find next file (See above)
2018-12-25T11:50:33.91822066Z 42 PC: 18d52 | Get date 0x18d52: cmp al, 5
0x18d54: jne 0x18d60
0x18d56: cmp dl, 0xd
0x18d59: jne 0x18d60
0x18d5b: call 0x18d83
0x18d5e: int 0x20
0x18d60: mov ah, 0x1a
0x18d62: mov dx, 0x80
0x18d65: int 0x21
0x18d67: lea si, word ptr [bp - 0x1b8]
0x18d6b: mov di, 0x100
0x18d6e: cld
0x18d6f: movsw word ptr es:[di], word ptr [si]
0x18d70: movsb byte ptr es:[di], byte ptr [si]
0x18d71: push cs
0x18d72: pop es
0x18d73: push cs
0x18d74: pop ds
0x18d75: pop ax
0x18d76: mov di, 0x100
2018-12-25T11:50:33.920198633Z 2 PC: 18d89 | Character output (Char = 'ea')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3960,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:33.05706883Z 26 PC: 18d2f | Set disk transfer address
2018-12-25T11:50:33.058077426Z 78 PC: 18e0e | Find first file
2018-12-25T11:50:33.063828105Z 61 PC: 18e28 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:50:33.072210091Z 66 PC: 18e37 | Move file pointer
2018-12-25T11:50:33.073555907Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-25T11:50:33.079679266Z 66 PC: 18e6c | Move file pointer
2018-12-25T11:50:33.081028748Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:50:33.086881848Z 66 PC: 18e87 | Move file pointer
2018-12-25T11:50:33.08816131Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:33.090888211Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-25T11:50:33.105169054Z 66 PC: 18ead | Move file pointer
2018-12-25T11:50:33.106546588Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:33.113042244Z 87 PC: 18ecd | Get or set file date and time
2018-12-25T11:50:33.11488199Z 62 PC: 18e58 | Close file
2018-12-25T11:50:33.122559855Z 79 PC: 18e5c | Find next file
2018-12-25T11:50:33.125664344Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.133079611Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.134148998Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.135620883Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.136969709Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.143717944Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.144875066Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.14743701Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.150045015Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.151521467Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.154680172Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.156469396Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.435927252Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.438836567Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.445125061Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.44667346Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.448834329Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.450197029Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.456420617Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.458223246Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.460718802Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.475012221Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.477218649Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.483867223Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.485270004Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.492703727Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.495224138Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.501547642Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.503458379Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.504961731Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.5062554Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.513753198Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.514964838Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.517681115Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.520676488Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.522224854Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.525059246Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.527247038Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.534465045Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.537209507Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.544745503Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.546710391Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.548319991Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.550128314Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.556583989Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.557915963Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.561235866Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.564055395Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.565576054Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.569243982Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.570666208Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.57758382Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.581173453Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.587457127Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.588749675Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.595654068Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.59693756Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.599256485Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.601669076Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.604410968Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.61266012Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.61507606Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.62307293Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.624522386Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.632646512Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.63521609Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.641429014Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.643292533Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.644838368Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.646003445Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.652565588Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.654011162Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.656565244Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.659581845Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.660785536Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.663074578Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.665142769Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.672261722Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.674074052Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.67835656Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.679664437Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.686104754Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.688128268Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.690424208Z 78 PC: 18db8 | Find first file
2018-12-25T11:50:33.694173947Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.698194367Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.701871467Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.702794265Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.705380288Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.706317722Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.708045662Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.709705518Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.711845858Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.725862986Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.730076518Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.734446381Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.736177162Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.743325558Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.747136347Z 78 PC: 18db8 | Find first file (See above)
2018-12-25T11:50:34.752608702Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:34.762728237Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.770958466Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.77263383Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.779375592Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.781461223Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.784255593Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.787064293Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.790159887Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.796931403Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.799359161Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.806048948Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.807847342Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.815039183Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.818853609Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.825832561Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.828312166Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.834837468Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.836451661Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.843892465Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.845473984Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.847793341Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.853805164Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.855432059Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.858381086Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.861185939Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.872080519Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.879852896Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.887536253Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.888928315Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.894574662Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.896717469Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.902557605Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.904085229Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.907640551Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.914463803Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.915885569Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.919477374Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.921027059Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.927404683Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.933958287Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.940863786Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.942168411Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.948719068Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.95002769Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.955251932Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.957180104Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.963072298Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.972640409Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.974195441Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.976855957Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.978712589Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.985927694Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.992058668Z 79 PC: 18def | Find next file
2018-12-25T11:50:34.995610757Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:35.005233552Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:35.011936663Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:35.013605087Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:35.019417696Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:35.020599982Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:35.026418352Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:35.027673947Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:35.03355177Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:35.19281868Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:35.194091242Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:35.1967305Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:35.198363455Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:35.328412888Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:35.334756355Z 79 PC: 18def | Find next file (See above)
2018-12-25T11:50:35.337725916Z 42 PC: 18d52 | Get date 0x18d52: cmp al, 5
0x18d54: jne 0x18d60
0x18d56: cmp dl, 0xd
0x18d59: jne 0x18d60
0x18d5b: call 0x18d83
0x18d5e: int 0x20
0x18d60: mov ah, 0x1a
0x18d62: mov dx, 0x80
0x18d65: int 0x21
0x18d67: lea si, word ptr [bp - 0x1b8]
0x18d6b: mov di, 0x100
0x18d6e: cld
0x18d6f: movsw word ptr es:[di], word ptr [si]
0x18d70: movsb byte ptr es:[di], byte ptr [si]
0x18d71: push cs
0x18d72: pop es
0x18d73: push cs
0x18d74: pop ds
0x18d75: pop ax
0x18d76: mov di, 0x100
2018-12-25T11:50:35.33972859Z 26 PC: 18d67 | Set disk transfer address
2018-12-25T11:50:35.340704909Z 48 PC: 13777 | Get DOS version
2018-12-25T11:50:35.341930184Z 9 PC: 13783 | Display string (String= 'Incorrect DOS version ')

{"DateBased":true,"Day":13,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3960,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:33.384997983Z 26 PC: 18d2f | Set disk transfer address
2018-12-25T11:50:33.386558349Z 78 PC: 18e0e | Find first file
2018-12-25T11:50:33.392574919Z 61 PC: 18e28 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:50:33.398869992Z 66 PC: 18e37 | Move file pointer
2018-12-25T11:50:33.404122075Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-25T11:50:33.408585663Z 66 PC: 18e6c | Move file pointer
2018-12-25T11:50:33.409453468Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:50:33.411404746Z 66 PC: 18e87 | Move file pointer
2018-12-25T11:50:33.412525065Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:33.414312628Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-25T11:50:33.473415873Z 66 PC: 18ead | Move file pointer
2018-12-25T11:50:33.474704438Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:33.480866448Z 87 PC: 18ecd | Get or set file date and time
2018-12-25T11:50:33.482667236Z 62 PC: 18e58 | Close file
2018-12-25T11:50:33.491154827Z 79 PC: 18e5c | Find next file
2018-12-25T11:50:33.493587611Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.500521115Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.501724041Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.503152876Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.504875145Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.510756703Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.511655266Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.514312663Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.516967782Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.518215475Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.52110072Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.522409312Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.529555382Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.532503196Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.538755551Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.539934505Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.541705265Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.542897851Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.54888915Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.5505409Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.552949282Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.560903581Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.562544085Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.568644259Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.569865743Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.577598255Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.580049547Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.586147504Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.587741518Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.589153996Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.590159105Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.596478155Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.597658722Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.599954485Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.602634866Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.60380047Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.60604264Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.607677579Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.614581214Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.617010216Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.624230208Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.625363515Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.626416326Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.628358385Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.634335669Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.635596147Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.638630045Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.641093706Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.642295854Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.646594743Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.647945677Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.655072305Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.658189049Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.664814417Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.666046973Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.673235715Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.674512066Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.676793068Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.67859937Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.681134978Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.688852593Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.690791069Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.698042043Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.69964701Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.707729395Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.710504109Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.71677569Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.719257533Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.720902125Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.72219866Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.741452503Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.742803942Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.745384902Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:33.748917975Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:33.750221675Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:33.752742709Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:33.75521946Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.931176252Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.933623215Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.94104069Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.943220797Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.949915747Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:33.951803623Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:33.954691096Z 78 PC: 18db8 | Find first file
2018-12-25T11:50:33.958370771Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:33.961960413Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:33.968077554Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:33.969328208Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:33.972218527Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:33.973751347Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:33.976215806Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:33.977636353Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:33.981132793Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.727234707Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.729282543Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.733800909Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.736024893Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.743143121Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.746530102Z 78 PC: 18db8 | Find first file (See above)
2018-12-25T11:50:34.751716454Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:34.760399242Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.76788166Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.769533782Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.775090649Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.777513205Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.780240622Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.781933737Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.785968552Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.792540728Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.794168961Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.801030755Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.802796667Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.810081169Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.8142034Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.821451884Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.823158609Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.830038987Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.831622332Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.837355378Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.839698238Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.8425824Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.84896987Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.850862767Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.853492435Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.854879496Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.862555833Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.865707016Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.874162813Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.876809185Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.882890286Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.88500632Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.891896194Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.893461433Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.896826501Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.904065912Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.90543565Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.908064675Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.909873908Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.916404245Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.922483186Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.92965424Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.930958822Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.938462608Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.939816613Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.945903434Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.948109479Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.954368939Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.960865257Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.963387248Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.966540578Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.968898226Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.976117624Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.982643437Z 79 PC: 18def | Find next file
2018-12-25T11:50:34.985567813Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:34.995783595Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:35.003162285Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:35.004478439Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:35.011754443Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:35.013066607Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:35.018315459Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:35.020200368Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:35.026368378Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:35.301370256Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:35.30307935Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:35.306273964Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:35.3078695Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:35.56860046Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:35.619138176Z 79 PC: 18def | Find next file (See above)
2018-12-25T11:50:35.621229863Z 42 PC: 18d52 | Get date 0x18d52: cmp al, 5
0x18d54: jne 0x18d60
0x18d56: cmp dl, 0xd
0x18d59: jne 0x18d60
0x18d5b: call 0x18d83
0x18d5e: int 0x20
0x18d60: mov ah, 0x1a
0x18d62: mov dx, 0x80
0x18d65: int 0x21
0x18d67: lea si, word ptr [bp - 0x1b8]
0x18d6b: mov di, 0x100
0x18d6e: cld
0x18d6f: movsw word ptr es:[di], word ptr [si]
0x18d70: movsb byte ptr es:[di], byte ptr [si]
0x18d71: push cs
0x18d72: pop es
0x18d73: push cs
0x18d74: pop ds
0x18d75: pop ax
0x18d76: mov di, 0x100
2018-12-25T11:50:35.623444261Z 2 PC: 18d89 | Character output (Char = 'ea')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3960,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:33.817448917Z 26 PC: 18d2f | Set disk transfer address
2018-12-25T11:50:33.818840341Z 78 PC: 18e0e | Find first file
2018-12-25T11:50:33.824790146Z 61 PC: 18e28 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:50:33.831522929Z 66 PC: 18e37 | Move file pointer
2018-12-25T11:50:33.833028889Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-25T11:50:33.839194629Z 66 PC: 18e6c | Move file pointer
2018-12-25T11:50:33.84062049Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:50:33.842848177Z 66 PC: 18e87 | Move file pointer
2018-12-25T11:50:33.844033477Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:33.846918999Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-25T11:50:34.725834961Z 66 PC: 18ead | Move file pointer
2018-12-25T11:50:34.727196911Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:34.731809965Z 87 PC: 18ecd | Get or set file date and time
2018-12-25T11:50:34.732992656Z 62 PC: 18e58 | Close file
2018-12-25T11:50:34.737786319Z 79 PC: 18e5c | Find next file
2018-12-25T11:50:34.739859095Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.744446981Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.745705745Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.747625104Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.7493227Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.755423957Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.757100597Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.759679098Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.762095477Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.763904616Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.766681797Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.768110034Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.775949522Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.778498617Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.782408152Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.78370446Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.785150104Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.786027829Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.791227916Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.792209667Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.793872622Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.799270979Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.801068508Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.807458018Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.809179461Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.821263883Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.823773195Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.830311441Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.832555074Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.83432199Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.83558027Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.842362956Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.843724581Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.846928759Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.849981196Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.851310961Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.853092637Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.854570302Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.859571569Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.861322902Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.866121237Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.867077034Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.868194444Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.869632417Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.873618088Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.874915733Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.877786929Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.880244235Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.88137304Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.883967831Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.885354633Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.892560604Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.895104674Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.901322303Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.902752284Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.908717545Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.909847497Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.912105795Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.913336763Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.915807898Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.923661771Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.925695021Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.931915369Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.93368217Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.942378065Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.944992148Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.951964781Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.953943127Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.955783448Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.957406885Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.964058091Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.967195997Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.969741461Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.973021314Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.974636509Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.97717826Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.979361453Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.990576231Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.99345525Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:35.002639663Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:35.006878331Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:35.011774365Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:35.013406413Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:35.015189629Z 78 PC: 18db8 | Find first file
2018-12-25T11:50:35.019042718Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:35.023680803Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:35.027850592Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:35.029124041Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:35.032285029Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:35.033465529Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:35.035900046Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:35.03751775Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:35.040472802Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:36.409570375Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:36.412238721Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:36.41507341Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:36.416562141Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:36.647232565Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:36.650102187Z 78 PC: 18db8 | Find first file (See above)
2018-12-25T11:50:36.655669896Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:36.665311348Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:36.67289806Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:36.675410186Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:36.681406045Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:36.683035855Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:36.685885064Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:36.688567514Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:36.691548163Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:36.967174085Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:36.970062562Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:36.9760602Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:36.977422922Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:36.983539208Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:36.9869932Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:36.99410236Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:36.996592898Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.002303747Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.003518111Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.010297498Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.011550699Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.018435824Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.026402984Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.027733593Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.030466328Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.033583989Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.040471071Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.043872176Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.052116983Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.053799826Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.059866212Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.062503431Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.068208103Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.06986863Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.073917278Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.080367474Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.081689158Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.086063891Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.087731558Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.095283044Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.099727958Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.107130341Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.10836293Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.114656224Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.116036284Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.121663351Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.123580564Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.129496824Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.135913179Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.137347275Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.140096744Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.142775262Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.149193336Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.15564713Z 79 PC: 18def | Find next file
2018-12-25T11:50:37.171200841Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:37.18024449Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.185266818Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.187317281Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.193306672Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.19462679Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.200438678Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.201825629Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.208504511Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.216509287Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.217795937Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.220486948Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.223234429Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.229743174Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.236503803Z 79 PC: 18def | Find next file (See above)
2018-12-25T11:50:37.240343288Z 42 PC: 18d52 | Get date 0x18d52: cmp al, 5
0x18d54: jne 0x18d60
0x18d56: cmp dl, 0xd
0x18d59: jne 0x18d60
0x18d5b: call 0x18d83
0x18d5e: int 0x20
0x18d60: mov ah, 0x1a
0x18d62: mov dx, 0x80
0x18d65: int 0x21
0x18d67: lea si, word ptr [bp - 0x1b8]
0x18d6b: mov di, 0x100
0x18d6e: cld
0x18d6f: movsw word ptr es:[di], word ptr [si]
0x18d70: movsb byte ptr es:[di], byte ptr [si]
0x18d71: push cs
0x18d72: pop es
0x18d73: push cs
0x18d74: pop ds
0x18d75: pop ax
0x18d76: mov di, 0x100
2018-12-25T11:50:37.242389829Z 26 PC: 18d67 | Set disk transfer address
2018-12-25T11:50:37.243776786Z 48 PC: 13777 | Get DOS version
2018-12-25T11:50:37.245481821Z 9 PC: 13783 | Display string (String= 'Incorrect DOS version ')

{"DateBased":true,"Day":4,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":3960,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:50:33.904323928Z 26 PC: 18d2f | Set disk transfer address
2018-12-25T11:50:33.906199203Z 78 PC: 18e0e | Find first file
2018-12-25T11:50:33.912525706Z 61 PC: 18e28 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:50:33.918701095Z 66 PC: 18e37 | Move file pointer
2018-12-25T11:50:33.934661803Z 63 PC: 18e48 | Read file or device (Read 2 bytes on handle 5)
2018-12-25T11:50:33.941060497Z 66 PC: 18e6c | Move file pointer
2018-12-25T11:50:33.942499555Z 63 PC: 18e7a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:50:33.945520398Z 66 PC: 18e87 | Move file pointer
2018-12-25T11:50:33.946774166Z 64 PC: 18e93 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:33.949272426Z 64 PC: 18ea0 | Write file or device (Write 437 bytes on handle 5)
2018-12-25T11:50:34.734198068Z 66 PC: 18ead | Move file pointer
2018-12-25T11:50:34.736096515Z 64 PC: 18ec0 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:50:34.743216638Z 87 PC: 18ecd | Get or set file date and time
2018-12-25T11:50:34.746349106Z 62 PC: 18e58 | Close file
2018-12-25T11:50:34.753923937Z 79 PC: 18e5c | Find next file
2018-12-25T11:50:34.75648323Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.763443925Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.765081082Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.767413917Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.769759534Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.776602046Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.777843139Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.78103426Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.783751283Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.784994533Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.788331097Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.789913545Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.797255464Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.802049745Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.808558791Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.810154198Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.812154302Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.814014345Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.818469976Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.820182682Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.823379857Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.833290676Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.842889328Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.851883554Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.853794759Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.863342295Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.866461984Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.873616586Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.875460884Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.877879385Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.879315352Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.885722816Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.887828514Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.890418719Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.89288686Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.894294286Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.8966663Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.898033748Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.905311303Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.90789447Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.914206404Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.915696933Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.917272045Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.919450761Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.934567262Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.936345621Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.939592374Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.94278417Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.944041379Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:34.946461395Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:34.949278733Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:34.957477889Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:34.960258715Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:34.967453403Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:34.968936561Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:34.976061378Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:34.97764867Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:34.979922172Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:34.981192744Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:34.984653507Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:34.992443409Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:34.994912007Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:35.0017781Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:35.003274756Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:35.301388542Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:35.30440799Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:35.310759815Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:35.312004502Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:35.322909736Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:35.324090155Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:35.334536829Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:35.336271166Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:35.338828954Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:35.34137133Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:35.343583653Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:35.345979685Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:35.347268024Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:35.584891826Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:35.587489944Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:35.5943601Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:35.596269388Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:35.618576308Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:35.620113801Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:35.623193656Z 78 PC: 18db8 | Find first file
2018-12-25T11:50:35.62861691Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:35.633865104Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:35.640190382Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:35.641681841Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:35.644474994Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:35.646216403Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:35.648576932Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:35.649767482Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:35.662550906Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:36.967782683Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:36.970218089Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:36.974021062Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:36.975544861Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:36.982413356Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:36.986497351Z 78 PC: 18db8 | Find first file (See above)
2018-12-25T11:50:36.996565172Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:37.005906359Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.014213917Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.015817357Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.021380409Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.024154042Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.027863905Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.030520582Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.034972407Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.042486113Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.043983927Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.052026578Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.053926928Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.060723205Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.064680412Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.0716818Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.073411647Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.080315296Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.082447254Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.088124726Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.090717885Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.094542069Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.101789094Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.104432283Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.107554128Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.109344032Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.116563352Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.119679028Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.126462866Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.128181179Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.134310119Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.135720217Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.141737757Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.143105758Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.146201088Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.153708771Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.155100287Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.157900482Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.159213853Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.166124105Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.17384761Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.180741236Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.182191118Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.188831686Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.190133319Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.195476461Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.197505232Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.216362241Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.222556006Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.224345296Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.226965325Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.22825566Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.238281568Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.244108157Z 79 PC: 18def | Find next file
2018-12-25T11:50:37.246755838Z 78 PC: 18e0e | Find first file (See above)
2018-12-25T11:50:37.257714752Z 61 PC: 18e28 | Open file (See above)
2018-12-25T11:50:37.264267953Z 66 PC: 18e37 | Move file pointer (See above)
2018-12-25T11:50:37.265464348Z 63 PC: 18e48 | Read file or device (See above)
2018-12-25T11:50:37.271700099Z 66 PC: 18e6c | Move file pointer (See above)
2018-12-25T11:50:37.273104319Z 63 PC: 18e7a | Read file or device (See above)
2018-12-25T11:50:37.278367986Z 66 PC: 18e87 | Move file pointer (See above)
2018-12-25T11:50:37.279841692Z 64 PC: 18e93 | Write file or device (See above)
2018-12-25T11:50:37.28570831Z 64 PC: 18ea0 | Write file or device (See above)
2018-12-25T11:50:37.289853983Z 66 PC: 18ead | Move file pointer (See above)
2018-12-25T11:50:37.291334047Z 64 PC: 18ec0 | Write file or device (See above)
2018-12-25T11:50:37.293054352Z 87 PC: 18ecd | Get or set file date and time (See above)
2018-12-25T11:50:37.293923743Z 62 PC: 18e58 | Close file (See above)
2018-12-25T11:50:37.29879165Z 79 PC: 18e5c | Find next file (See above)
2018-12-25T11:50:37.303123025Z 79 PC: 18def | Find next file (See above)
2018-12-25T11:50:37.305247883Z 42 PC: 18d52 | Get date 0x18d52: cmp al, 5
0x18d54: jne 0x18d60
0x18d56: cmp dl, 0xd
0x18d59: jne 0x18d60
0x18d5b: call 0x18d83
0x18d5e: int 0x20
0x18d60: mov ah, 0x1a
0x18d62: mov dx, 0x80
0x18d65: int 0x21
0x18d67: lea si, word ptr [bp - 0x1b8]
0x18d6b: mov di, 0x100
0x18d6e: cld
0x18d6f: movsw word ptr es:[di], word ptr [si]
0x18d70: movsb byte ptr es:[di], byte ptr [si]
0x18d71: push cs
0x18d72: pop es
0x18d73: push cs
0x18d74: pop ds
0x18d75: pop ax
0x18d76: mov di, 0x100
2018-12-25T11:50:37.307412437Z 26 PC: 18d67 | Set disk transfer address
2018-12-25T11:50:37.308267595Z 48 PC: 13777 | Get DOS version
2018-12-25T11:50:37.309377891Z 9 PC: 13783 | Display string (String= 'Incorrect DOS version ')