Sample viewer

vx.netlux.org/Virus.DOS.Vesna.1614.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:26:34.105960833Z 48 PC: 12a7f | Get DOS version
2018-12-17T22:26:34.112097818Z 47 PC: 12a93 | Get disk transfer address
2018-12-17T22:26:34.114676046Z 26 PC: 12aa0 | Set disk transfer address
2018-12-17T22:26:34.118891094Z 78 PC: 12b65 | Find first file
2018-12-17T22:26:34.126424332Z 78 PC: 12b65 | Find first file
2018-12-17T22:26:34.144969Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.14762402Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.154354334Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.172601853Z 61 PC: 12bae | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:26:34.182033711Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.184692728Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.187701166Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.190876808Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.199599059Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.201976093Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.205356435Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.20843359Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.209999428Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.213841398Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.218188816Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.224514072Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.227256387Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.232144788Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.246884574Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.258107282Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:34.281811955Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:34.293027411Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:34.296547948Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.298986202Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.305323268Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.32088138Z 61 PC: 12bae | Open file (Filename = 'PRINT.COM')
2018-12-17T22:26:34.329595829Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.331636771Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.333482238Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.336398614Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.344360989Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.34644738Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.348748434Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.362632837Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.364312741Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.367499568Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.369904765Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.373269043Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.37518054Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.378911551Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.389218422Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.390913916Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:34.400689822Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:34.411736155Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:34.414953091Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.416972119Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.423951883Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.431563918Z 61 PC: 12bae | Open file (Filename = 'HELLO.COM')
2018-12-17T22:26:34.437178874Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.438607593Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.439951327Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.441423674Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.446196707Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.447518054Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.448783112Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.451237852Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.452412051Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.454535871Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.456146243Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.458056095Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.459196825Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.461719042Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.468157378Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.469427704Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:34.475527349Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:34.482244808Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:34.484361089Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.486119114Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.490082086Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.496527309Z 61 PC: 12bae | Open file (Filename = 'PHANG.COM')
2018-12-17T22:26:34.504305399Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.506129394Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.507708196Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.509345647Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.516646399Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.518349529Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.519921405Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.522923625Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.524662137Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.527598763Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.5298283Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.532776383Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.534255285Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.538612803Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.548732934Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.550334917Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:34.558857589Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:34.570028294Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:34.572965305Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.575156386Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.582213997Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.593332514Z 61 PC: 12bae | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:26:34.60773196Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.610002329Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.612009175Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.613809093Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.621386806Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.623010321Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.624567948Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.628873042Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.630445358Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.633444014Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.635525412Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.638562577Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.640155038Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.644618Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.65540269Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.657514459Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:34.667088139Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:34.678773104Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:34.682365088Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.684376086Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.691314269Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.702537329Z 61 PC: 12bae | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:26:34.710613677Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.712707814Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.714734842Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.716894244Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.724324341Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.725966961Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.727547331Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.731086638Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.732656511Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.735759721Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.738692581Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.748934135Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.750271682Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.754073306Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.76442166Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.766035006Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:34.775184864Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:34.786317323Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:34.789520337Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.792309296Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.798744276Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.810189439Z 61 PC: 12bae | Open file (Filename = 'PAH.COM')
2018-12-17T22:26:34.818656445Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.820682853Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.822526374Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.825235839Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.832466723Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.834147079Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.83676313Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.839722696Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.841532666Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.844935768Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.847683629Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.850941045Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.853114613Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.857902263Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.865182867Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.866843446Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:34.876180445Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:34.888164541Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:34.908369369Z 47 PC: 12b6d | Get disk transfer address
2018-12-17T22:26:34.91036032Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:34.91690834Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:34.928767022Z 61 PC: 12bae | Open file (Filename = 'TEST.COM')
2018-12-17T22:26:34.9375489Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:34.939443276Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.941326038Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.943920886Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:34.951471226Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:34.953348336Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:34.956008658Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:34.959414501Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:34.961240757Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:34.965187546Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:34.967349755Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:34.975114795Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:34.977698Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:34.981439192Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:34.993190679Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:34.994970079Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:35.000700736Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:35.007265888Z 79 PC: 12b65 | Find next file
2018-12-17T22:26:35.009583352Z 78 PC: 12b65 | Find first file
2018-12-17T22:26:35.013733561Z 26 PC: 12abc | Set disk transfer address
2018-12-17T22:26:35.014939545Z 78 PC: 13069 | Find first file
2018-12-17T22:26:35.022318711Z 47 PC: 13071 | Get disk transfer address
2018-12-17T22:26:35.023661725Z 67 PC: 12b9e | Get or set file attributes
2018-12-17T22:26:35.029422833Z 67 PC: 12ba9 | Get or set file attributes
2018-12-17T22:26:35.372442783Z 61 PC: 12bae | Open file (Filename = 'c:\COMMAND.COM')
2018-12-17T22:26:35.380452284Z 87 PC: 12bb8 | Get or set file date and time
2018-12-17T22:26:35.382661587Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:35.384982431Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:35.387265832Z 63 PC: 12cb2 | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:26:35.3906105Z 66 PC: 12c8d | Move file pointer
2018-12-17T22:26:35.392904901Z 66 PC: 12dca | Move file pointer
2018-12-17T22:26:35.394633806Z 63 PC: 12dd6 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:26:35.39753062Z 66 PC: 12e2d | Move file pointer
2018-12-17T22:26:35.399171934Z 64 PC: 12e39 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:26:35.402743688Z 66 PC: 12e5a | Move file pointer
2018-12-17T22:26:35.404204013Z 64 PC: 12e66 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:26:35.407857545Z 66 PC: 12e8a | Move file pointer
2018-12-17T22:26:35.409517201Z 44 PC: 13014 | Get time 0x13014: xor cx, dx
0x13016: xor ch, cl
0x13018: mov byte ptr [0x10b], ch
0x1301c: popaw
0x1301d: ret
0x1301e: xor byte ptr [bp + si], bl
0x13020: das
0x13021: dec si
0x13022: dec di
0x13023: add byte ptr [bp + di + 1], al
0x13026: inc bx
0x13027: add bh, byte ptr [di]
0x13029: add byte ptr [bx + 1], dl
0x1302c: push di
0x1302d: inc dx
0x1302f: add bh, bh
0x13031: add byte ptr [bx], bh
0x13033: push ds
0x13034: sub al, 0x19
0x13036: xchg ax, si
2018-12-17T22:26:35.412679847Z 64 PC: 12a73 | Write file or device (Write 1612 bytes on handle 5)
2018-12-17T22:26:35.425508094Z 87 PC: 12bee | Get or set file date and time
2018-12-17T22:26:35.427477699Z 62 PC: 12bf4 | Close file
2018-12-17T22:26:35.436167188Z 67 PC: 12bfe | Get or set file attributes
2018-12-17T22:26:35.446735047Z 79 PC: 13069 | Find next file
2018-12-17T22:26:35.45039528Z 78 PC: 13069 | Find first file
2018-12-17T22:26:35.456662881Z 78 PC: 13069 | Find first file
2018-12-17T22:26:35.46312637Z 44 PC: 12b02 | Get time 0x12b02: xor dx, dx
0x12b04: cmp ch, cl
0x12b06: je 0x12b0b
0x12b08: jmp 0x12b58
0x12b0b: cmp ch, 7
0x12b0e: jne 0x12b13
0x12b10: mov dx, 0x17e
0x12b13: cmp ch, 9
0x12b16: jne 0x12b1b
0x12b18: mov dx, 0x237
0x12b1b: cmp ch, 0xb
0x12b1e: jne 0x12b23
0x12b20: mov dx, 0x282
0x12b23: cmp ch, 0xd
0x12b26: jne 0x12b2b
0x12b28: mov dx, 0x2c0
0x12b2b: cmp ch, 0xf
0x12b2e: jne 0x12b33
0x12b30: mov dx, 0x333
0x12b33: cmp ch, 0x11