.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:28:43.698276805Z | 44 | PC: 12e06 | Get time 0x12e06: cmp byte ptr [0x103], 0 0x12e0b: je 0x12e12 0x12e0d: cmp dh, 0x1e 0x12e10: jg 0x12e1b 0x12e12: cmp dl, 0 0x12e15: je 0x12e02 0x12e17: mov byte ptr [0x103], dl 0x12e1b: mov byte ptr [0x4b7], 0 0x12e20: mov byte ptr [0x4b8], 4 0x12e25: mov byte ptr [0x4c1], 0 0x12e2a: mov cx, 0x27 0x12e2d: mov dx, 0x115 0x12e30: mov ah, 0x4e 0x12e32: int 0x21 0x12e34: cmp ax, 0x12 0x12e37: je 0x12e3c 0x12e39: call 0x12e5e 0x12e3c: mov cx, 0x27 0x12e3f: mov dx, 0x11b 0x12e42: mov ah, 0x4e |
2018-12-17T22:28:43.700975774Z | 78 | PC: 12e34 | Find first file |
2018-12-17T22:28:43.706983147Z | 67 | PC: 12e7f | Get or set file attributes |
2018-12-17T22:28:43.723699349Z | 61 | PC: 12e85 | Open file (Filename = 'TEST.EXE') |
2018-12-17T22:28:43.735405174Z | 63 | PC: 12e94 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:28:43.742001349Z | 62 | PC: 12ec8 | Close file |
2018-12-17T22:28:43.743581767Z | 61 | PC: 12ed1 | Open file (Filename = 'TEST.EXE') |
2018-12-17T22:28:43.750332505Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:28:43.758372293Z | 87 | PC: 12ef9 | Get or set file date and time |
2018-12-17T22:28:43.759821438Z | 62 | PC: 12f01 | Close file |
2018-12-17T22:28:43.76909691Z | 67 | PC: 12f0e | Get or set file attributes |
2018-12-17T22:28:43.777729327Z | 79 | PC: 12eb8 | Find next file |
2018-12-17T22:28:43.7804209Z | 78 | PC: 12e46 | Find first file |
2018-12-17T22:28:43.786807021Z | 67 | PC: 12e7f | Get or set file attributes |
2018-12-17T22:28:43.799793606Z | 61 | PC: 12e85 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:28:43.807169554Z | 63 | PC: 12e94 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:28:43.813516676Z | 62 | PC: 12ec8 | Close file |
2018-12-17T22:28:43.81618142Z | 61 | PC: 12ed1 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:28:43.822893714Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:28:43.831367072Z | 87 | PC: 12ef9 | Get or set file date and time |
2018-12-17T22:28:43.833906227Z | 62 | PC: 12f01 | Close file |
2018-12-17T22:28:43.84151392Z | 67 | PC: 12f0e | Get or set file attributes |
2018-12-17T22:28:43.846070235Z | 79 | PC: 12eb8 | Find next file |
2018-12-17T22:28:43.849202753Z | 67 | PC: 12e7f | Get or set file attributes |
2018-12-17T22:28:43.859019018Z | 61 | PC: 12e85 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:28:43.871036246Z | 63 | PC: 12e94 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:28:43.87850656Z | 62 | PC: 12ec8 | Close file |
2018-12-17T22:28:43.88028962Z | 61 | PC: 12ed1 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:28:43.887673055Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:28:43.89679102Z | 87 | PC: 12ef9 | Get or set file date and time |
2018-12-17T22:28:43.906266412Z | 62 | PC: 12f01 | Close file |
2018-12-17T22:28:43.913935266Z | 67 | PC: 12f0e | Get or set file attributes |
2018-12-17T22:28:43.919372047Z | 79 | PC: 12eb8 | Find next file |
2018-12-17T22:28:43.922416698Z | 67 | PC: 12e7f | Get or set file attributes |
2018-12-17T22:28:43.932263824Z | 61 | PC: 12e85 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:28:43.93999208Z | 63 | PC: 12e94 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:28:43.946801571Z | 62 | PC: 12ec8 | Close file |
2018-12-17T22:28:43.948785276Z | 61 | PC: 12ed1 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:28:43.955694957Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:28:43.9643838Z | 87 | PC: 12ef9 | Get or set file date and time |
2018-12-17T22:28:43.966126289Z | 62 | PC: 12f01 | Close file |
2018-12-17T22:28:43.974174955Z | 67 | PC: 12f0e | Get or set file attributes |
2018-12-17T22:28:43.979809361Z | 9 | PC: 12f6f | Display string (String= ' Error #2307 - Too big to fit in memory') |
2018-12-17T22:28:43.984027759Z | 76 | PC: 12f73 | Terminate with return code (Return code = '36') |