.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:26:00.373849785Z | 44 | PC: 12c2d | Get time 0x12c2d: cmp byte ptr [0x106], 0
0x12c32: je 0x12c39 0x12c34: cmp dh, 0xf 0x12c37: jg 0x12c42 0x12c39: cmp dl, 0 0x12c3c: je 0x12c29 0x12c3e: mov byte ptr [0x106], dl 0x12c42: mov byte ptr [0x2de], 0 0x12c47: mov byte ptr [0x2df], 4 0x12c4c: mov byte ptr [0x2e8], 0 0x12c51: mov cx, 0x27 0x12c54: mov dx, 0x132 0x12c57: mov ah, 0x4e 0x12c59: int 0x21 0x12c5b: cmp ax, 0x12 0x12c5e: je 0x12c63 0x12c60: call 0x12c85 0x12c63: mov cx, 0x27 0x12c66: mov dx, 0x138 0x12c69: mov ah, 0x4e |
2018-12-17T22:26:00.376599821Z | 78 | PC: 12c5b | Find first file |
2018-12-17T22:26:00.398358123Z | 67 | PC: 12ca6 | Get or set file attributes |
2018-12-17T22:26:00.414668004Z | 61 | PC: 12cac | Open file (Filename = 'TEST.EXE') |
2018-12-17T22:26:00.424104023Z | 63 | PC: 12cbb | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:26:00.429654283Z | 62 | PC: 12cef | Close file |
2018-12-17T22:26:00.432233386Z | 61 | PC: 12cf8 | Open file (Filename = 'TEST.EXE') |
2018-12-17T22:26:00.446749766Z | 64 | PC: 12a5a | Write file or device (Write 792 bytes on handle 5) |
2018-12-17T22:26:00.456721334Z | 87 | PC: 12d20 | Get or set file date and time |
2018-12-17T22:26:00.45848808Z | 62 | PC: 12d28 | Close file |
2018-12-17T22:26:00.466677526Z | 67 | PC: 12d35 | Get or set file attributes |
2018-12-17T22:26:00.472774533Z | 79 | PC: 12cdf | Find next file |
2018-12-17T22:26:00.475730894Z | 78 | PC: 12c6d | Find first file |
2018-12-17T22:26:00.482524592Z | 67 | PC: 12ca6 | Get or set file attributes |
2018-12-17T22:26:00.682259123Z | 61 | PC: 12cac | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:26:00.699419316Z | 63 | PC: 12cbb | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:26:00.707284303Z | 62 | PC: 12cef | Close file |
2018-12-17T22:26:00.709719107Z | 61 | PC: 12cf8 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:26:00.73200558Z | 64 | PC: 12a5a | Write file or device (Write 792 bytes on handle 5) |
2018-12-17T22:26:00.792027363Z | 87 | PC: 12d20 | Get or set file date and time |
2018-12-17T22:26:00.794143462Z | 62 | PC: 12d28 | Close file |
2018-12-17T22:26:00.806715321Z | 67 | PC: 12d35 | Get or set file attributes |
2018-12-17T22:26:00.817133262Z | 79 | PC: 12cdf | Find next file |
2018-12-17T22:26:00.820576562Z | 67 | PC: 12ca6 | Get or set file attributes |
2018-12-17T22:26:00.833412363Z | 61 | PC: 12cac | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:26:00.841386597Z | 63 | PC: 12cbb | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:26:00.863069765Z | 62 | PC: 12cef | Close file |
2018-12-17T22:26:00.866146747Z | 61 | PC: 12cf8 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:26:00.879103647Z | 64 | PC: 12a5a | Write file or device (Write 792 bytes on handle 5) |
2018-12-17T22:26:00.902687835Z | 87 | PC: 12d20 | Get or set file date and time |
2018-12-17T22:26:00.905138703Z | 62 | PC: 12d28 | Close file |
2018-12-17T22:26:00.915649173Z | 67 | PC: 12d35 | Get or set file attributes |
2018-12-17T22:26:00.921463878Z | 79 | PC: 12cdf | Find next file |
2018-12-17T22:26:00.924939756Z | 67 | PC: 12ca6 | Get or set file attributes |
2018-12-17T22:26:00.936579865Z | 61 | PC: 12cac | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:26:00.944162746Z | 63 | PC: 12cbb | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:26:00.951498186Z | 62 | PC: 12cef | Close file |
2018-12-17T22:26:00.955174287Z | 61 | PC: 12cf8 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:26:00.963607461Z | 64 | PC: 12a5a | Write file or device (Write 792 bytes on handle 5) |
2018-12-17T22:26:00.973656122Z | 87 | PC: 12d20 | Get or set file date and time |
2018-12-17T22:26:00.976195895Z | 62 | PC: 12d28 | Close file |
2018-12-17T22:26:00.985437253Z | 67 | PC: 12d35 | Get or set file attributes |
2018-12-17T22:26:00.991208389Z | 9 | PC: 12d54 | Display string (String= ' Program too big to fit in memory') |
2018-12-17T22:26:00.997082812Z | 76 | PC: 12d58 | Terminate with return code (Return code = '36') |