Sample viewer

vx.netlux.org/Virus.DOS.Scrif

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T23:15:29.730837354Z 53 PC: 12ee2 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:15:29.732021339Z 53 PC: 12ee8 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:15:29.733887226Z 37 PC: 12f01 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:15:29.734938192Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:15:29.736474379Z 37 PC: 12d6d | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-17T23:15:29.738195504Z 37 PC: 12d73 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-17T23:15:29.739653675Z 53 PC: 12ad5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:15:29.741107037Z 37 PC: 12ae0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:15:29.742971572Z 67 PC: 12d05 | Get or set file attributes
2018-12-17T23:15:29.748331386Z 67 PC: 12d0e | Get or set file attributes
2018-12-17T23:15:31.834453047Z 61 PC: 12d13 | Open file (Filename = '')
2018-12-17T23:15:31.842558413Z 87 PC: 12d1a | Get or set file date and time
2018-12-17T23:15:31.84425442Z 66 PC: 12acc | Move file pointer
2018-12-17T23:15:31.845857323Z 66 PC: 12d90 | Move file pointer
2018-12-17T23:15:31.848352423Z 63 PC: 12d9f | Read file or device (Read 1296 bytes on handle 5)
2018-12-17T23:15:31.961495121Z 66 PC: 12acc | Move file pointer
2018-12-17T23:15:31.965926701Z 64 PC: 12daa | Write file or device (Write 1296 bytes on handle 5)
2018-12-17T23:15:32.030743353Z 66 PC: 12db1 | Move file pointer
2018-12-17T23:15:32.033471251Z 64 PC: 12db7 | Write file or device (Write 0 bytes on handle 5)
2018-12-17T23:15:32.454015054Z 87 PC: 12d26 | Get or set file date and time
2018-12-17T23:15:32.456539519Z 62 PC: 12d2a | Close file
2018-12-17T23:15:32.491939859Z 67 PC: 12d31 | Get or set file attributes
2018-12-17T23:15:32.858818681Z 37 PC: 12aec | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T23:15:32.861484261Z 42 PC: 12dbe | Get date 0x12dbe: cmp cx, 0x7cb
0x12dc2: jg 0x12dcc
0x12dc4: jne 0x12e06
0x12dc6: cmp dx, 0xa0a
0x12dca: jle 0x12e06
0x12dcc: cmp cx, 0x7ce
0x12dd0: jb 0x12de3
0x12dd2: mov ax, 0xb800
0x12dd5: mov es, ax
0x12dd7: xor si, si
0x12dd9: xor di, di
0x12ddb: mov cx, 0x7d0
0x12dde: rep movsd dword ptr es:[di], dword ptr [si]
0x12de0: cli
0x12de1: jmp 0x12de0
0x12de3: mov ax, 0xf29a
0x12de6: int 0x21
0x12de8: cmp al, 3
0x12dea: je 0x12e06
0x12dec: push es

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5421,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:31.076036046Z 53 PC: 12ee2 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.078236132Z 53 PC: 12ee8 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.079689512Z 37 PC: 12f01 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.08102653Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.083782847Z 37 PC: 12d6d | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.085193284Z 37 PC: 12d73 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.086650331Z 53 PC: 12ad5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.088229798Z 37 PC: 12ae0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.090129304Z 67 PC: 12d05 | Get or set file attributes
2018-12-25T11:54:31.096920396Z 67 PC: 12d0e | Get or set file attributes
2018-12-25T11:54:31.114136124Z 61 PC: 12d13 | Open file (Filename = '')
2018-12-25T11:54:31.120647578Z 87 PC: 12d1a | Get or set file date and time
2018-12-25T11:54:31.122550344Z 66 PC: 12acc | Move file pointer
2018-12-25T11:54:31.123979531Z 66 PC: 12d90 | Move file pointer
2018-12-25T11:54:31.128462953Z 63 PC: 12d9f | Read file or device (Read 1296 bytes on handle 5)
2018-12-25T11:54:31.136945623Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:31.138758541Z 64 PC: 12daa | Write file or device (Write 1296 bytes on handle 5)
2018-12-25T11:54:31.149116084Z 66 PC: 12db1 | Move file pointer
2018-12-25T11:54:31.150718539Z 64 PC: 12db7 | Write file or device (Write 0 bytes on handle 5)
2018-12-25T11:54:31.159280105Z 87 PC: 12d26 | Get or set file date and time
2018-12-25T11:54:31.168359904Z 62 PC: 12d2a | Close file
2018-12-25T11:54:31.177106945Z 67 PC: 12d31 | Get or set file attributes
2018-12-25T11:54:31.188256937Z 37 PC: 12aec | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.189875801Z 42 PC: 12dbe | Get date 0x12dbe: cmp cx, 0x7cb
0x12dc2: jg 0x12dcc
0x12dc4: jne 0x12e06
0x12dc6: cmp dx, 0xa0a
0x12dca: jle 0x12e06
0x12dcc: cmp cx, 0x7ce
0x12dd0: jb 0x12de3
0x12dd2: mov ax, 0xb800
0x12dd5: mov es, ax
0x12dd7: xor si, si
0x12dd9: xor di, di
0x12ddb: mov cx, 0x7d0
0x12dde: rep movsd dword ptr es:[di], dword ptr [si]
0x12de0: cli
0x12de1: jmp 0x12de0
0x12de3: mov ax, 0xf29a
0x12de6: int 0x21
0x12de8: cmp al, 3
0x12dea: je 0x12e06
0x12dec: push es
2018-12-25T11:54:31.193782457Z 74 PC: 12e31 | Reallocate memory
2018-12-25T11:54:31.19575375Z 75 PC: 12e45 | Execute program
2018-12-25T11:54:31.212144342Z 76 PC: 143b0 | Terminate with return code (Return code = '0')
2018-12-25T11:54:31.216710413Z 53 PC: 12ad5 | Get interrupt vector (See above)
2018-12-25T11:54:31.218225431Z 37 PC: 12ae0 | Set interrupt vector (See above)
2018-12-25T11:54:31.219676417Z 67 PC: 12d05 | Get or set file attributes (See above)
2018-12-25T11:54:31.227089134Z 67 PC: 12d0e | Get or set file attributes (See above)
2018-12-25T11:54:31.238011178Z 61 PC: 12d13 | Open file (See above)
2018-12-25T11:54:31.247066406Z 87 PC: 12d1a | Get or set file date and time (See above)
2018-12-25T11:54:31.252638441Z 63 PC: 12afb | Read file or device (Read 1296 bytes on handle 5)
2018-12-25T11:54:31.26317126Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:31.26549021Z 64 PC: 12b05 | Write file or device (Write 1296 bytes on handle 5)
2018-12-25T11:54:31.276486008Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:31.278240588Z 64 PC: 12b11 | Write file or device (Write 32 bytes on handle 5)
2018-12-25T11:54:31.282206138Z 64 PC: 12b1d | Write file or device (Write 1264 bytes on handle 5)
2018-12-25T11:54:31.300156943Z 87 PC: 12d26 | Get or set file date and time (See above)
2018-12-25T11:54:31.30209272Z 62 PC: 12d2a | Close file (See above)
2018-12-25T11:54:31.311757613Z 67 PC: 12d31 | Get or set file attributes (See above)
2018-12-25T11:54:31.323880305Z 37 PC: 12aec | Set interrupt vector (See above)
2018-12-25T11:54:31.327193075Z 77 PC: 12e68 | Get program return code
2018-12-25T11:54:31.328986582Z 76 PC: 12e6c | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1995,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5421,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:31.209424666Z 53 PC: 12ee2 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.211303507Z 53 PC: 12ee8 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.213083717Z 37 PC: 12f01 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.214306862Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.216173261Z 37 PC: 12d6d | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.217722004Z 37 PC: 12d73 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.21902531Z 53 PC: 12ad5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.220393639Z 37 PC: 12ae0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.223480644Z 67 PC: 12d05 | Get or set file attributes
2018-12-25T11:54:31.230185946Z 67 PC: 12d0e | Get or set file attributes
2018-12-25T11:54:31.247659658Z 61 PC: 12d13 | Open file (Filename = '')
2018-12-25T11:54:31.255356681Z 87 PC: 12d1a | Get or set file date and time
2018-12-25T11:54:31.257289185Z 66 PC: 12acc | Move file pointer
2018-12-25T11:54:31.258944642Z 66 PC: 12d90 | Move file pointer
2018-12-25T11:54:31.261049235Z 63 PC: 12d9f | Read file or device (Read 1296 bytes on handle 5)
2018-12-25T11:54:31.26894002Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:31.27045618Z 64 PC: 12daa | Write file or device (Write 1296 bytes on handle 5)
2018-12-25T11:54:31.279109887Z 66 PC: 12db1 | Move file pointer
2018-12-25T11:54:31.280820375Z 64 PC: 12db7 | Write file or device (Write 0 bytes on handle 5)
2018-12-25T11:54:31.289681874Z 87 PC: 12d26 | Get or set file date and time
2018-12-25T11:54:31.291302812Z 62 PC: 12d2a | Close file
2018-12-25T11:54:31.29831919Z 67 PC: 12d31 | Get or set file attributes
2018-12-25T11:54:31.310556626Z 37 PC: 12aec | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.311770916Z 42 PC: 12dbe | Get date 0x12dbe: cmp cx, 0x7cb
0x12dc2: jg 0x12dcc
0x12dc4: jne 0x12e06
0x12dc6: cmp dx, 0xa0a
0x12dca: jle 0x12e06
0x12dcc: cmp cx, 0x7ce
0x12dd0: jb 0x12de3
0x12dd2: mov ax, 0xb800
0x12dd5: mov es, ax
0x12dd7: xor si, si
0x12dd9: xor di, di
0x12ddb: mov cx, 0x7d0
0x12dde: rep movsd dword ptr es:[di], dword ptr [si]
0x12de0: cli
0x12de1: jmp 0x12de0
0x12de3: mov ax, 0xf29a
0x12de6: int 0x21
0x12de8: cmp al, 3
0x12dea: je 0x12e06
0x12dec: push es
2018-12-25T11:54:31.313643441Z 74 PC: 12e31 | Reallocate memory
2018-12-25T11:54:31.318022857Z 75 PC: 12e45 | Execute program
2018-12-25T11:54:31.334384381Z 76 PC: 143b0 | Terminate with return code (Return code = '0')
2018-12-25T11:54:31.337828637Z 53 PC: 12ad5 | Get interrupt vector (See above)
2018-12-25T11:54:31.340089172Z 37 PC: 12ae0 | Set interrupt vector (See above)
2018-12-25T11:54:31.341605549Z 67 PC: 12d05 | Get or set file attributes (See above)
2018-12-25T11:54:31.348347799Z 67 PC: 12d0e | Get or set file attributes (See above)
2018-12-25T11:54:31.357651759Z 61 PC: 12d13 | Open file (See above)
2018-12-25T11:54:31.365830131Z 87 PC: 12d1a | Get or set file date and time (See above)
2018-12-25T11:54:31.366885026Z 63 PC: 12afb | Read file or device (Read 1296 bytes on handle 5)
2018-12-25T11:54:31.371799012Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:31.373437836Z 64 PC: 12b05 | Write file or device (Write 1296 bytes on handle 5)
2018-12-25T11:54:31.648428022Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:31.64990931Z 64 PC: 12b11 | Write file or device (Write 32 bytes on handle 5)
2018-12-25T11:54:31.658090666Z 64 PC: 12b1d | Write file or device (Write 1264 bytes on handle 5)
2018-12-25T11:54:31.682274539Z 87 PC: 12d26 | Get or set file date and time (See above)
2018-12-25T11:54:31.683986754Z 62 PC: 12d2a | Close file (See above)
2018-12-25T11:54:31.693157332Z 67 PC: 12d31 | Get or set file attributes (See above)
2018-12-25T11:54:31.704086952Z 37 PC: 12aec | Set interrupt vector (See above)
2018-12-25T11:54:31.705685807Z 77 PC: 12e68 | Get program return code
2018-12-25T11:54:31.708219374Z 76 PC: 12e6c | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1996,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5421,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:31.194332045Z 53 PC: 12ee2 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.195856099Z 53 PC: 12ee8 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.196790552Z 37 PC: 12f01 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.197578195Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.199111513Z 37 PC: 12d6d | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.200206745Z 37 PC: 12d73 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.201211629Z 53 PC: 12ad5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.20314755Z 37 PC: 12ae0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.204223256Z 67 PC: 12d05 | Get or set file attributes
2018-12-25T11:54:31.209771566Z 67 PC: 12d0e | Get or set file attributes
2018-12-25T11:54:31.974106377Z 61 PC: 12d13 | Open file (Filename = '')
2018-12-25T11:54:31.980996681Z 87 PC: 12d1a | Get or set file date and time
2018-12-25T11:54:31.982411687Z 66 PC: 12acc | Move file pointer
2018-12-25T11:54:31.984414456Z 66 PC: 12d90 | Move file pointer
2018-12-25T11:54:31.985670387Z 63 PC: 12d9f | Read file or device (Read 1296 bytes on handle 5)
2018-12-25T11:54:32.548782462Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.550539877Z 64 PC: 12daa | Write file or device (Write 1296 bytes on handle 5)
2018-12-25T11:54:32.56180545Z 66 PC: 12db1 | Move file pointer
2018-12-25T11:54:32.563079911Z 64 PC: 12db7 | Write file or device (Write 0 bytes on handle 5)
2018-12-25T11:54:32.605276741Z 87 PC: 12d26 | Get or set file date and time
2018-12-25T11:54:32.606652603Z 62 PC: 12d2a | Close file
2018-12-25T11:54:32.645440172Z 67 PC: 12d31 | Get or set file attributes
2018-12-25T11:54:32.660654294Z 37 PC: 12aec | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:32.661662275Z 42 PC: 12dbe | Get date 0x12dbe: cmp cx, 0x7cb
0x12dc2: jg 0x12dcc
0x12dc4: jne 0x12e06
0x12dc6: cmp dx, 0xa0a
0x12dca: jle 0x12e06
0x12dcc: cmp cx, 0x7ce
0x12dd0: jb 0x12de3
0x12dd2: mov ax, 0xb800
0x12dd5: mov es, ax
0x12dd7: xor si, si
0x12dd9: xor di, di
0x12ddb: mov cx, 0x7d0
0x12dde: rep movsd dword ptr es:[di], dword ptr [si]
0x12de0: cli
0x12de1: jmp 0x12de0
0x12de3: mov ax, 0xf29a
0x12de6: int 0x21
0x12de8: cmp al, 3
0x12dea: je 0x12e06
0x12dec: push es
2018-12-25T11:54:32.663147131Z 242 PC: 12de8 | UNKNOWN!
2018-12-25T11:54:32.664609257Z 53 PC: 12df2 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:32.665824469Z 53 PC: 12c90 | Get interrupt vector (Interrupt = '42' AKA 'Get date')
2018-12-25T11:54:32.666903765Z 74 PC: 12e31 | Reallocate memory
2018-12-25T11:54:32.669530307Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.671505598Z 75 PC: 12e45 | Execute program
2018-12-25T11:54:32.686631247Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.688080025Z 76 PC: 143b0 | Terminate with return code (Return code = '0')
2018-12-25T11:54:32.691372791Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.692509465Z 53 PC: 12ad5 | Get interrupt vector (See above)
2018-12-25T11:54:32.694077112Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.69559908Z 37 PC: 12ae0 | Set interrupt vector (See above)
2018-12-25T11:54:32.69696939Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.69903567Z 67 PC: 12d05 | Get or set file attributes (See above)
2018-12-25T11:54:32.705513785Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.706554328Z 67 PC: 12d0e | Get or set file attributes (See above)
2018-12-25T11:54:32.723037116Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.72460114Z 61 PC: 12d13 | Open file (See above)
2018-12-25T11:54:32.731324054Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.732432689Z 87 PC: 12d1a | Get or set file date and time (See above)
2018-12-25T11:54:32.734373379Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.735504861Z 63 PC: 12afb | Read file or device (Read 1296 bytes on handle 5)
2018-12-25T11:54:32.742563208Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.74449146Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.746223227Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.747419538Z 64 PC: 12b05 | Write file or device (Write 1296 bytes on handle 5)
2018-12-25T11:54:32.766725588Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.767974832Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.769503822Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.771434144Z 64 PC: 12b11 | Write file or device (Write 32 bytes on handle 5)
2018-12-25T11:54:32.774363093Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.77839978Z 64 PC: 12b1d | Write file or device (Write 1264 bytes on handle 5)
2018-12-25T11:54:32.797121441Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.798339094Z 87 PC: 12d26 | Get or set file date and time (See above)
2018-12-25T11:54:32.800022795Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.801614383Z 62 PC: 12d2a | Close file (See above)
2018-12-25T11:54:32.841813805Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.843023143Z 67 PC: 12d31 | Get or set file attributes (See above)
2018-12-25T11:54:32.90795476Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.909196767Z 37 PC: 12aec | Set interrupt vector (See above)
2018-12-25T11:54:32.911085064Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.912798545Z 49 PC: 12cf9 | Terminate and stay resident (Return code = '0' | Memory size = '220')
2018-12-25T11:54:32.914535636Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.915732063Z 77 PC: 11fe0 | Get program return code
2018-12-25T11:54:32.917917809Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.919084053Z 72 PC: 12174 | Allocate memory
2018-12-25T11:54:32.920961516Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.92238933Z 72 PC: 1218d | Allocate memory
2018-12-25T11:54:32.92412969Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.92531391Z 37 PC: 123c4 | Set interrupt vector (Interrupt = '34' AKA 'Random write')
2018-12-25T11:54:32.927123137Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.928129767Z 37 PC: 123cb | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:54:32.929436195Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.932882948Z 37 PC: 123d2 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:32.935079509Z 87 PC: 12c19 | Get or set file date and time
2018-12-25T11:54:32.936582078Z 53 PC: 12c21 | Get interrupt vector (Interrupt = '64' AKA 'Write file or device')
2018-12-25T11:54:32.937893409Z 37 PC: 12c34 | Set interrupt vector (Interrupt = '64' AKA 'Write file or device')
2018-12-25T11:54:32.938840416Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.940101225Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.941892797Z 37 PC: 12c7d | Set interrupt vector (Interrupt = '64' AKA 'Write file or device')
2018-12-25T11:54:32.942730414Z 87 PC: 12c84 | Get or set file date and time
2018-12-25T11:54:32.943976266Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.945353316Z 62 PC: 122ab | Close file
2018-12-25T11:54:32.946923084Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:32.948074822Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:32.949283133Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:32.95031458Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.951706237Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.95356421Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:32.954359202Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:32.955339233Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.956727833Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:32.957878359Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:32.95900995Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:32.9602653Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:32.960991655Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.961906476Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.96326476Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:32.964029176Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:32.965017617Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.966218163Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:32.967333222Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:32.968239103Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:32.969737956Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:32.970586115Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.971652721Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.972929644Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:32.973802943Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:32.974802712Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.979138198Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:32.981097553Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:32.982363615Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:32.983563214Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:32.984488577Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.986155912Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.988332749Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:32.989291171Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:32.99024233Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:32.991546479Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:32.992917616Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:32.993959151Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:32.995505331Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:32.996393696Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.997467558Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.998847359Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:32.999585957Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.000574465Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.002178649Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.003342008Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.004495453Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.010097192Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.011498549Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.012845965Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.014622501Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.015939177Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.017332878Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.019000441Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.020792062Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.022109426Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.02384833Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.025008302Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.0263556Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.028604158Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.030774858Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.0323252Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.034006677Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.03583597Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.037262296Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.039290801Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.040292624Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.041500965Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.04326403Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.044246541Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.045742777Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.047452585Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.049567087Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.051305939Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.053699392Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.054473637Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.055453999Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.057392752Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.058571957Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.060070274Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.061798877Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.063990814Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.065279629Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.067065498Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.068294087Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.069876265Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.071930757Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.073278143Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.075908749Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.077315647Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.079388531Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.08293182Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.084496034Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.08601219Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.08851476Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.090172678Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.091486989Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.093841554Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.095377157Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.097403829Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.100224736Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.101480061Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.102690764Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.105042831Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.106735503Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.108146506Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.110075014Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.11115844Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.112785551Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.115203762Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.116547267Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.117846864Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.120033607Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.121574925Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.122784279Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.12553172Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.12697704Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.129239238Z 87 PC: 12c19 | Get or set file date and time (See above)
2018-12-25T11:54:33.13106632Z 53 PC: 12c21 | Get interrupt vector (See above)
2018-12-25T11:54:33.13223899Z 37 PC: 12c34 | Set interrupt vector (See above)
2018-12-25T11:54:33.13355505Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.134983285Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:33.13628565Z 37 PC: 12c7d | Set interrupt vector (See above)
2018-12-25T11:54:33.137697844Z 87 PC: 12c84 | Get or set file date and time (See above)
2018-12-25T11:54:33.139106827Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.140275267Z 62 PC: 122ab | Close file (See above)
2018-12-25T11:54:33.143719516Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.14490995Z 99 PC: 9a5d7 | Get DBCS lead byte table pointer
2018-12-25T11:54:33.146193181Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.148196085Z 56 PC: 94df9 | Get or set country info
2018-12-25T11:54:33.150403864Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.151333134Z 64 PC: 9a848 | Write file or device (Write 2 bytes on handle 1)
2018-12-25T11:54:33.154397818Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.155559611Z 25 PC: 94e62 | Get default drive
2018-12-25T11:54:33.157109767Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.158415807Z 71 PC: 970dd | Get current directory
2018-12-25T11:54:33.162388817Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.163494578Z 64 PC: 9a848 | Write file or device (See above)
2018-12-25T11:54:33.167036997Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.16807774Z 2 PC: 970b2 | Character output (Char = '3e')
2018-12-25T11:54:33.169842379Z 93 PC: 94f20 | File sharing functions
2018-12-25T11:54:33.172006185Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.17305959Z 93 PC: 94f27 | File sharing functions
2018-12-25T11:54:33.174973052Z 53 PC: 12c90 | Get interrupt vector (See above)
2018-12-25T11:54:33.176186722Z 10 PC: 94f39 | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1998,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5421,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:31.19951212Z 53 PC: 12ee2 | Get interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.200575405Z 53 PC: 12ee8 | Get interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.201326451Z 37 PC: 12f01 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.202043842Z 37 PC: 12f08 | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.203400875Z 37 PC: 12d6d | Set interrupt vector (Interrupt = '3' AKA 'Auxiliary input')
2018-12-25T11:54:31.204152195Z 37 PC: 12d73 | Set interrupt vector (Interrupt = '1' AKA 'Character input')
2018-12-25T11:54:31.204873726Z 53 PC: 12ad5 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.205914697Z 37 PC: 12ae0 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:31.206732958Z 67 PC: 12d05 | Get or set file attributes
2018-12-25T11:54:31.210128763Z 67 PC: 12d0e | Get or set file attributes
2018-12-25T11:54:31.97408947Z 61 PC: 12d13 | Open file (Filename = '')
2018-12-25T11:54:32.549290006Z 87 PC: 12d1a | Get or set file date and time
2018-12-25T11:54:32.550563755Z 66 PC: 12acc | Move file pointer
2018-12-25T11:54:32.552858599Z 66 PC: 12d90 | Move file pointer
2018-12-25T11:54:32.554089362Z 63 PC: 12d9f | Read file or device (Read 1296 bytes on handle 5)
2018-12-25T11:54:32.561201786Z 66 PC: 12acc | Move file pointer (See above)
2018-12-25T11:54:32.563493453Z 64 PC: 12daa | Write file or device (Write 1296 bytes on handle 5)
2018-12-25T11:54:32.58989322Z 66 PC: 12db1 | Move file pointer
2018-12-25T11:54:32.591425537Z 64 PC: 12db7 | Write file or device (Write 0 bytes on handle 5)
2018-12-25T11:54:32.650778353Z 87 PC: 12d26 | Get or set file date and time
2018-12-25T11:54:32.65218776Z 62 PC: 12d2a | Close file
2018-12-25T11:54:32.689133792Z 67 PC: 12d31 | Get or set file attributes
2018-12-25T11:54:32.703648956Z 37 PC: 12aec | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:32.704755535Z 42 PC: 12dbe | Get date 0x12dbe: cmp cx, 0x7cb
0x12dc2: jg 0x12dcc
0x12dc4: jne 0x12e06
0x12dc6: cmp dx, 0xa0a
0x12dca: jle 0x12e06
0x12dcc: cmp cx, 0x7ce
0x12dd0: jb 0x12de3
0x12dd2: mov ax, 0xb800
0x12dd5: mov es, ax
0x12dd7: xor si, si
0x12dd9: xor di, di
0x12ddb: mov cx, 0x7d0
0x12dde: rep movsd dword ptr es:[di], dword ptr [si]
0x12de0: cli
0x12de1: jmp 0x12de0
0x12de3: mov ax, 0xf29a
0x12de6: int 0x21
0x12de8: cmp al, 3
0x12dea: je 0x12e06
0x12dec: push es