Sample viewer

vx.netlux.org/Virus.DOS.Angel.1000.b

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:30:19.630565122Z 26 PC: 12a6d | Set disk transfer address
2018-12-17T22:30:19.631973652Z 78 PC: 12a79 | Find first file
2018-12-17T22:30:19.636375797Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.642384516Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.657560055Z 61 PC: 12aeb | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:30:19.666675802Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:19.667981164Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.669361389Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:19.674330355Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.675648167Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:19.677506669Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.679292674Z 64 PC: 12c0c | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:30:19.685357533Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.691464922Z 63 PC: 12c0c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:19.700809701Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.702557683Z 64 PC: 12c0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:19.705925285Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.70833559Z 64 PC: 12c0c | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:19.710654485Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.711943303Z 64 PC: 12c0c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:30:19.714419606Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:19.715806704Z 62 PC: 12c0c | Close file
2018-12-17T22:30:19.721520303Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.728485623Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:19.731896227Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.748611219Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.759800194Z 61 PC: 12aeb | Open file (Filename = 'PRINT.COM')
2018-12-17T22:30:19.767895448Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:19.769886433Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.77190825Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:19.78051286Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.782630237Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:19.785925134Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.788714901Z 64 PC: 12c0c | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:30:19.798331124Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.800353836Z 63 PC: 12c0c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:19.808854213Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.811116179Z 64 PC: 12c0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:19.814414168Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.816959295Z 64 PC: 12c0c | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:19.821201245Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.823279147Z 64 PC: 12c0c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:30:19.830431766Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:19.832544637Z 62 PC: 12c0c | Close file
2018-12-17T22:30:19.841437814Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.853187702Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:19.857784671Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.865983615Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.878058342Z 61 PC: 12aeb | Open file (Filename = 'HELLO.COM')
2018-12-17T22:30:19.887392532Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:19.889774204Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.892413121Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:19.901692673Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.903598584Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:19.906678029Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.909558116Z 64 PC: 12c0c | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:30:19.919328496Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.921205871Z 63 PC: 12c0c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:19.930044825Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.93206549Z 64 PC: 12c0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:19.935413016Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.937878004Z 64 PC: 12c0c | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:19.941654476Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:19.943747606Z 64 PC: 12c0c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:30:19.947175573Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:19.950619483Z 62 PC: 12c0c | Close file
2018-12-17T22:30:19.959936892Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.971822047Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:19.976225997Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.982826228Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:19.993811112Z 61 PC: 12aeb | Open file (Filename = 'PHANG.COM')
2018-12-17T22:30:20.002335924Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.004365449Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.006462163Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:20.014289697Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.016347826Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:20.019341825Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.021640308Z 64 PC: 12c0c | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:30:20.032105799Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.033914669Z 63 PC: 12c0c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:20.041023731Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.04292708Z 64 PC: 12c0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:20.046194978Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.049113785Z 64 PC: 12c0c | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:20.053362421Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.054977906Z 64 PC: 12c0c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:30:20.058187209Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.061179533Z 62 PC: 12c0c | Close file
2018-12-17T22:30:20.070431463Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.081739738Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:20.086041383Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.092992357Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.104738937Z 61 PC: 12aeb | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:30:20.112660225Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.11531537Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.117405117Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:20.124977394Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.128111102Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:20.131355531Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.133339898Z 64 PC: 12c0c | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:30:20.144244256Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.146740913Z 63 PC: 12c0c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:20.154263608Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.157176727Z 64 PC: 12c0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:20.160899115Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.162905414Z 64 PC: 12c0c | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:20.166482067Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.169304606Z 64 PC: 12c0c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:30:20.173439395Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.175529452Z 62 PC: 12c0c | Close file
2018-12-17T22:30:20.185421486Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.196902259Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:20.200274864Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.207836355Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.219353929Z 61 PC: 12aeb | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:30:20.227248536Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.23008789Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.232400911Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:20.240382959Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.242602143Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:20.246653348Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.248631663Z 64 PC: 12c0c | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:30:20.258625289Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.261708629Z 63 PC: 12c0c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:20.269212994Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.271233821Z 64 PC: 12c0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:20.280353289Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.282693544Z 64 PC: 12c0c | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:20.286198297Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.288964982Z 64 PC: 12c0c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:30:20.292688041Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.294780733Z 62 PC: 12c0c | Close file
2018-12-17T22:30:20.304857391Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.31691072Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:20.320295249Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.327224647Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.343377827Z 61 PC: 12aeb | Open file (Filename = 'PAH.COM')
2018-12-17T22:30:20.351293802Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.353393558Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.355886368Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:20.363459244Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.36540758Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:20.369037563Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.370954553Z 64 PC: 12c0c | Write file or device (Write 1000 bytes on handle 5)
2018-12-17T22:30:20.381543118Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.384961124Z 63 PC: 12c0c | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:30:20.392712823Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.395010151Z 64 PC: 12c0c | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:30:20.399691328Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.401898292Z 64 PC: 12c0c | Write file or device (Write 1 bytes on handle 5)
2018-12-17T22:30:20.405371861Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.40859666Z 64 PC: 12c0c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:30:20.412697874Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.415134249Z 62 PC: 12c0c | Close file
2018-12-17T22:30:20.425191822Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.436926491Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:20.440692877Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.449807571Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.46167635Z 61 PC: 12aeb | Open file (Filename = 'TEST.COM')
2018-12-17T22:30:20.469917653Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.473501977Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.475938144Z 63 PC: 12c0c | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:30:20.48421007Z 66 PC: 12c0c | Move file pointer
2018-12-17T22:30:20.486624073Z 63 PC: 12c0c | Read file or device (Read 10 bytes on handle 5)
2018-12-17T22:30:20.496134395Z 87 PC: 12c0c | Get or set file date and time
2018-12-17T22:30:20.498822903Z 62 PC: 12c0c | Close file
2018-12-17T22:30:20.507120835Z 67 PC: 12c24 | Get or set file attributes
2018-12-17T22:30:20.519973666Z 79 PC: 12a8b | Find next file
2018-12-17T22:30:20.523107952Z 26 PC: 12a97 | Set disk transfer address
2018-12-17T22:30:20.524861814Z 42 PC: 12c29 | Get date 0x12c29: cmp dx, 0xb1d
0x12c2d: jne 0x12c39
0x12c2f: mov ah, 9
0x12c31: lea dx, word ptr [bx + 0x1ea]
0x12c35: int 0x21
0x12c37: cli
0x12c38: hlt
0x12c39: ret
0x12c3a: or ax, 0x480a
0x12c3d: popaw
0x12c3e: jo 0x12cb0
0x12c40: jns 0x12c62
0x12c42: bound bp, dword ptr [bx + di + 0x72]
0x12c45: je 0x12caf
0x12c47: popaw
0x12c49: jns 0x12c6b
0x12c4b: je 0x12cbc
0x12c4d: and byte ptr [di + 0x65], ch
0x12c50: and byte ptr [bx + di], ah
0x12c52: or ax, 0x70a
2018-12-17T22:30:20.528141928Z 76 PC: 12a50 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5419,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:30.493646743Z 26 PC: 12a6d | Set disk transfer address
2018-12-25T11:54:30.495195302Z 78 PC: 12a79 | Find first file
2018-12-25T11:54:30.499087952Z 67 PC: 12c24 | Get or set file attributes
2018-12-25T11:54:30.502804046Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.54354884Z 61 PC: 12aeb | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:30.54790481Z 87 PC: 12c0c | Get or set file date and time
2018-12-25T11:54:30.548934025Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.550338657Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.554734014Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.555837824Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.5578434Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.559388562Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.564965094Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.566231267Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.572985254Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.574729268Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.577566157Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.579013231Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.582279409Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.583678732Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.586253394Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.58818025Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.593521919Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.600006125Z 79 PC: 12a8b | Find next file
2018-12-25T11:54:30.602217097Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.605888562Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.614130595Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:30.621464969Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.622946844Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.62424158Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.631192808Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.632835528Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.63547902Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.636759202Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.64590588Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.647130921Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.653883939Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.655696122Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.657742583Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.659002555Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.661885922Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.663412408Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.666420909Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.66966757Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.679436627Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.690279374Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:30.693672589Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.69986673Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.710492038Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:30.718250181Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.720367736Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.722466082Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.730462576Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.732057362Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.734710576Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.73641782Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.74686838Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.74956399Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.75791883Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.760642812Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.764264208Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.766798275Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.772173979Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.773911805Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.77735977Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.78001072Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.786962715Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.797576572Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:30.80096261Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.807281162Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.818562789Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:30.826760197Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.828390211Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.829961209Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.83784742Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.840068015Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.842983099Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.844661013Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.861469637Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.865610836Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.875154227Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.87809529Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.88126254Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.882966762Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.888983252Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.890912346Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.894449186Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.897510943Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.90711528Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.9195424Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:30.922686935Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.929208762Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.94278775Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:30.95141517Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.954661972Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.956567229Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.964161621Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.967367024Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.970423254Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.972268669Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.983215813Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.984988409Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.992078765Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.994366373Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.996738248Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.998654863Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.004539023Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.006539694Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.009770672Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.011552771Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.021002074Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.031802029Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.034679991Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.041733182Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.052925647Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.060791646Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.063777923Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.065994001Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.073452663Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.075893011Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.079097023Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.080959717Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.091726622Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.093846034Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.101310292Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.103879758Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.110276307Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.111757936Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.115588744Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.117247817Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.120220132Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.122127796Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.13241771Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.145350815Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.149462926Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.156539181Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.168995699Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.178661519Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.180789239Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.182804063Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.191183195Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.193862281Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.196826538Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.198645522Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.208521197Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.210110492Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.217454313Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.220692744Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.223672581Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.225263004Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.228917647Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.23081687Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.234057925Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.236860964Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.247571163Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.258692346Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.263204595Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.269499092Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.284104321Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.2940355Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.295988033Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.297946672Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.306046271Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.308004125Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.317271233Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.324608813Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.331022817Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.342036118Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.3462503Z 26 PC: 12a97 | Set disk transfer address
2018-12-25T11:54:31.347788982Z 42 PC: 12c29 | Get date 0x12c29: cmp dx, 0xb1d
0x12c2d: jne 0x12c39
0x12c2f: mov ah, 9
0x12c31: lea dx, word ptr [bx + 0x1ea]
0x12c35: int 0x21
0x12c37: cli
0x12c38: hlt
0x12c39: ret
0x12c3a: or ax, 0x480a
0x12c3d: popaw
0x12c3e: jo 0x12cb0
0x12c40: jns 0x12c62
0x12c42: bound bp, dword ptr [bx + di + 0x72]
0x12c45: je 0x12caf
0x12c47: popaw
0x12c49: jns 0x12c6b
0x12c4b: je 0x12cbc
0x12c4d: and byte ptr [di + 0x65], ch
0x12c50: and byte ptr [bx + di], ah
0x12c52: or ax, 0x70a
2018-12-25T11:54:31.350592391Z 76 PC: 12a50 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":29,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5419,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:30.691513795Z 26 PC: 12a6d | Set disk transfer address
2018-12-25T11:54:30.692809403Z 78 PC: 12a79 | Find first file
2018-12-25T11:54:30.699176196Z 67 PC: 12c24 | Get or set file attributes
2018-12-25T11:54:30.705052321Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.722649007Z 61 PC: 12aeb | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:30.729859859Z 87 PC: 12c0c | Get or set file date and time
2018-12-25T11:54:30.731302219Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.732697836Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.739660443Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.741066736Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.743453684Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.745379208Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.754281426Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.755467026Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.762577321Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.764222427Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.766939555Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.768689038Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.770767639Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.771908376Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.774062797Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.775363989Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.783254158Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.79409798Z 79 PC: 12a8b | Find next file
2018-12-25T11:54:30.797298713Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.803518571Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.814232052Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:30.822185951Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.82367665Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.825277612Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.832894083Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.834411079Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.837213446Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.839203953Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.849125331Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.850668467Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.860070301Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.86200775Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.865129814Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.867953386Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.871127203Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.873140374Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.876646908Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.878561116Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.887311653Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.898521645Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:30.901923928Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.908719293Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.921368229Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:30.929498101Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.931520687Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.93374666Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.941797421Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.943774352Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.946777753Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.95060959Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.960839265Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.962637462Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.970619176Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.971843744Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.973876451Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.975678106Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.978133437Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.980346608Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.984075684Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.986237133Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.995736882Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.007538866Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.01151467Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.018808845Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.030405716Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.038797182Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.040835891Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.042527915Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.05053688Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.052142662Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.054997304Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.057020028Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.066660745Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.068216033Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.075796736Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.077535398Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.080727599Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.083227206Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.086448268Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.088322748Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.092119694Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.093992212Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.103074343Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.115124117Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.119007505Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.125511543Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.137350328Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.144947292Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.146416075Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.14788638Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.155129249Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.156555855Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.16422773Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.166934414Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.176540789Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.178458933Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.186263348Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.188747374Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.192190223Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.195004773Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.198041783Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.199617835Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.203596855Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.20542896Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.21450535Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.226402452Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.229877556Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.236496519Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.248168117Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.257278887Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.259330668Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.262103722Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.270365499Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.272396847Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.275595614Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.278496766Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.288308242Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.290205084Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.299692386Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.301954453Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.310163873Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.313204244Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.316974419Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.319464458Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.323714375Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.326057955Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.335701468Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.348259378Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.351647396Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.358077723Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.649313687Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.657063404Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.659008617Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.660940281Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.668960509Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.670508366Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.67330558Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.676195697Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.685703824Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.687156405Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.695417418Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.697461601Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.700668482Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.703027028Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.7058412Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.707343491Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.710769824Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.712451031Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.720850863Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.731698728Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.734978075Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.742246501Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.754074931Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.761736101Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.763401375Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.76613999Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.770276416Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.771888794Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.77606762Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.778012547Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.785533803Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.796955476Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.799512303Z 26 PC: 12a97 | Set disk transfer address
2018-12-25T11:54:31.800676114Z 42 PC: 12c29 | Get date 0x12c29: cmp dx, 0xb1d
0x12c2d: jne 0x12c39
0x12c2f: mov ah, 9
0x12c31: lea dx, word ptr [bx + 0x1ea]
0x12c35: int 0x21
0x12c37: cli
0x12c38: hlt
0x12c39: ret
0x12c3a: or ax, 0x480a
0x12c3d: popaw
0x12c3e: jo 0x12cb0
0x12c40: jns 0x12c62
0x12c42: bound bp, dword ptr [bx + di + 0x72]
0x12c45: je 0x12caf
0x12c47: popaw
0x12c49: jns 0x12c6b
0x12c4b: je 0x12cbc
0x12c4d: and byte ptr [di + 0x65], ch
0x12c50: and byte ptr [bx + di], ah
0x12c52: or ax, 0x70a
2018-12-25T11:54:31.803252206Z 9 PC: 12c37 | Display string (String= ' Happy birthday to me !  Happy birthday to me ! ')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5419,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:30.826832349Z 26 PC: 12a6d | Set disk transfer address
2018-12-25T11:54:30.828507916Z 78 PC: 12a79 | Find first file
2018-12-25T11:54:30.837360017Z 67 PC: 12c24 | Get or set file attributes
2018-12-25T11:54:30.844089682Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.86163752Z 61 PC: 12aeb | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:30.870383991Z 87 PC: 12c0c | Get or set file date and time
2018-12-25T11:54:30.871931964Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.873936117Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.882100394Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.883761684Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.886672286Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.900867228Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.910545304Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.912352209Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.919882316Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.921968073Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.925238821Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.927104642Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.932032159Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.933864793Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.937080969Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.939527278Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.948325404Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.959634935Z 79 PC: 12a8b | Find next file
2018-12-25T11:54:30.963477718Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.970173906Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.983414651Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:30.990634261Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.992900105Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.994823649Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.002297397Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.004495872Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.007649102Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.009605533Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.019690374Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.021308273Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.028706301Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.030431483Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.032788349Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.033869592Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.036453745Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.037665922Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.039554349Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.041353123Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.046744391Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.053819167Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.056668487Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.061234146Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.067803126Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.07240262Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.073959485Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.07557929Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.08343912Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.086487198Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.089457918Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.091228031Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.102858339Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.104995746Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.112374045Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.115217654Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.119696805Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.121675687Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.124669952Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.12675094Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.129683553Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.131580838Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.140406251Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.14933827Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.152156609Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.159074366Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.170590566Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.175248201Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.177984464Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.18004214Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.187888976Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.190643928Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.194247147Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.196296774Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.206180082Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.209336561Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.216940599Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.218961079Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.223131672Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.225162107Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.22791116Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.230255309Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.233406036Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.234866609Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.248299043Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.25986023Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.262742549Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.26915806Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.280462794Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.287762413Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.289487117Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.292119004Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.299041937Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.300321008Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.303415595Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.304855567Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.314246331Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.315970582Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.323463645Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.324894261Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.32807771Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.329541579Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.332181655Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.334050584Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.336804131Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.338179101Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.346907905Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.433787308Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.435583809Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.439375956Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.648740885Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.660874975Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.662692562Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.665342914Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.669439961Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.670483831Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.673774581Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.675104443Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.692196243Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.693885386Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.698152871Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.69924067Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.705123305Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.706402988Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.708519539Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.710254154Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.712469407Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.71383322Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.720555749Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.732442212Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.735865307Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.742781393Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.753833589Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.761858289Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.764457522Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.766074961Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.773377627Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.775709642Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.7779943Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.780045707Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.790600312Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.792557028Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.800463696Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.803418132Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.806460693Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.807992542Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.811986847Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.813816554Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.816656563Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.818712113Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.827346057Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.838253034Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.841939418Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.848153228Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.858849622Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.872250296Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.873976895Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.875601292Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.88310443Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.884802837Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.892219376Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.894002503Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.902224849Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.913083208Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.915610971Z 26 PC: 12a97 | Set disk transfer address
2018-12-25T11:54:31.916874643Z 42 PC: 12c29 | Get date 0x12c29: cmp dx, 0xb1d
0x12c2d: jne 0x12c39
0x12c2f: mov ah, 9
0x12c31: lea dx, word ptr [bx + 0x1ea]
0x12c35: int 0x21
0x12c37: cli
0x12c38: hlt
0x12c39: ret
0x12c3a: or ax, 0x480a
0x12c3d: popaw
0x12c3e: jo 0x12cb0
0x12c40: jns 0x12c62
0x12c42: bound bp, dword ptr [bx + di + 0x72]
0x12c45: je 0x12caf
0x12c47: popaw
0x12c49: jns 0x12c6b
0x12c4b: je 0x12cbc
0x12c4d: and byte ptr [di + 0x65], ch
0x12c50: and byte ptr [bx + di], ah
0x12c52: or ax, 0x70a
2018-12-25T11:54:31.919085568Z 76 PC: 12a50 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":29,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5419,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:30.88733674Z 26 PC: 12a6d | Set disk transfer address
2018-12-25T11:54:30.888880367Z 78 PC: 12a79 | Find first file
2018-12-25T11:54:30.896368116Z 67 PC: 12c24 | Get or set file attributes
2018-12-25T11:54:30.903085907Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:30.921351748Z 61 PC: 12aeb | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:30.93049223Z 87 PC: 12c0c | Get or set file date and time
2018-12-25T11:54:30.934120849Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.938129131Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.946312037Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.948255225Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.950906707Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.952981891Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.963101462Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.964621678Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:30.972614117Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.974207936Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.9771399Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.979018719Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.98214049Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:30.984371186Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:30.987553828Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:30.989780214Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:30.998453773Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.009590957Z 79 PC: 12a8b | Find next file
2018-12-25T11:54:31.016476792Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.022643853Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.033406352Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.041417062Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.043368064Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.045290111Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.053602848Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.05617492Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.060415278Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.063410823Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.073252913Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.075179754Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.082650843Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.084700373Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.087959632Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.089802828Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.093101288Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.095222955Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.098050861Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.101080228Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.120766635Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.132317582Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.136257929Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.142993519Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.154165872Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.163225313Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.165127592Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.167188727Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.175519472Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.177366166Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.180341224Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.182530991Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.192388544Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.193718848Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.198094214Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.200217694Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.203176859Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.204913514Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.208798452Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.210428403Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.213189967Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.215958022Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.224183509Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.234775289Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.238460997Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.244279051Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.254037285Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.269375864Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.271407529Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.272880745Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.280362845Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.282886341Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.285528505Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.286989155Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.296632468Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.298005058Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.304722279Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.306749898Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.309728182Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.311278054Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.314457951Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.315737273Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.317751417Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.31957101Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.328763329Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.340044034Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.344795026Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.352012074Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.648515743Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.656856201Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.658503294Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.660023991Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.667315362Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.669444643Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.672162026Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.673734542Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.684280034Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.685827453Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.69271458Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.694114485Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.695997007Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.697138732Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.699649151Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.700920026Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.702851687Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.704779595Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.710130663Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.717219655Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.71985707Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.726092426Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.732909278Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.737986341Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.739457718Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.740945926Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.748542547Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.750057559Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.75266447Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.754843576Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.764279826Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.766271414Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.77405502Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.775733867Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.78437274Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.785904176Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.789728798Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.791249783Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.794360585Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.796249145Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.805298218Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.816255053Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.819758788Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.82593595Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.837078453Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.850686129Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.852232695Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.853661649Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.860837273Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.862303622Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.865003967Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.867495289Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.876824944Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.878082466Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.885090166Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.886557985Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.889135421Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.891158048Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.893978392Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.895513811Z 64 PC: 12c0c | Write file or device (See above)
2018-12-25T11:54:31.898862133Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.90067612Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.909395032Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.920353864Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.923323856Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.929949326Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.941507108Z 61 PC: 12aeb | Open file (See above)
2018-12-25T11:54:31.948931282Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.95072731Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.952979363Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.960340797Z 66 PC: 12c0c | Move file pointer (See above)
2018-12-25T11:54:31.962257712Z 63 PC: 12c0c | Read file or device (See above)
2018-12-25T11:54:31.970724971Z 87 PC: 12c0c | Get or set file date and time (See above)
2018-12-25T11:54:31.972422965Z 62 PC: 12c0c | Close file (See above)
2018-12-25T11:54:31.98179363Z 67 PC: 12c24 | Get or set file attributes (See above)
2018-12-25T11:54:31.993192718Z 79 PC: 12a8b | Find next file (See above)
2018-12-25T11:54:31.995754093Z 26 PC: 12a97 | Set disk transfer address
2018-12-25T11:54:31.996979711Z 42 PC: 12c29 | Get date 0x12c29: cmp dx, 0xb1d
0x12c2d: jne 0x12c39
0x12c2f: mov ah, 9
0x12c31: lea dx, word ptr [bx + 0x1ea]
0x12c35: int 0x21
0x12c37: cli
0x12c38: hlt
0x12c39: ret
0x12c3a: or ax, 0x480a
0x12c3d: popaw
0x12c3e: jo 0x12cb0
0x12c40: jns 0x12c62
0x12c42: bound bp, dword ptr [bx + di + 0x72]
0x12c45: je 0x12caf
0x12c47: popaw
0x12c49: jns 0x12c6b
0x12c4b: je 0x12cbc
0x12c4d: and byte ptr [di + 0x65], ch
0x12c50: and byte ptr [bx + di], ah
0x12c52: or ax, 0x70a
2018-12-25T11:54:32.00026909Z 9 PC: 12c37 | Display string (String= ' Happy birthday to me !  Happy birthday to me ! ')