Sample viewer

vx.netlux.org/Virus.DOS.Jerusalem.Timor

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:01.206537263Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-17T22:31:01.209299749Z 224 PC: 12ada | UNKNOWN!
2018-12-17T22:31:01.211526728Z 224 PC: 12b2e | UNKNOWN!
2018-12-17T22:31:01.212885702Z 74 PC: 12bb2 | Reallocate memory
2018-12-17T22:31:01.214765323Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:01.217475907Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-17T22:31:01.219141842Z 75 PC: 12c43 | Execute program
2018-12-17T22:31:01.235212823Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-17T22:31:01.239025072Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-17T22:31:01.246075528Z 73 PC: 12c49 | Release memory
2018-12-17T22:31:01.247597155Z 77 PC: 12c4d | Get program return code
2018-12-17T22:31:01.248947452Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":12,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:44.485478359Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:44.489058768Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:44.490078983Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:44.491131342Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:44.493359315Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.494697151Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.495909084Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:44.512831576Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:44.51583303Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:44.524333351Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:44.525506606Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:44.526835959Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1991,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:44.534966663Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:44.537190986Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:44.538448259Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:44.539507909Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:44.541216018Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.543335106Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.544318895Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:44.555522446Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:44.558124536Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:44.563708201Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:44.564755812Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:44.567346208Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:44.56275925Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:44.565190054Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:44.566169974Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:44.567124172Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:44.568345667Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.571170352Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.572465352Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:44.584612896Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:44.587444231Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:44.593201974Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:44.594454049Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:44.596502438Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":12,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:44.59542722Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:44.59853473Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:44.599438517Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:44.600388492Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:44.615159769Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.618187211Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.619685927Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:44.634858977Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:44.639337374Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:44.646977051Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:44.648661914Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:44.655519269Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:44.631266599Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:44.633082371Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:44.635167332Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:44.636399212Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:44.637992431Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.639832383Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:44.641200656Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:44.653121583Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:44.656385974Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:44.663338783Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:44.664953542Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:44.667029104Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":12,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:45.246689676Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:45.249607435Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:45.270768443Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:45.272722425Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:45.274595024Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.276248823Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.277756611Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:45.308444651Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:45.311748661Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:45.319440911Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:45.321671296Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:45.323836566Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":12,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:45.223341416Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:45.225979211Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:45.226805328Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:45.227709118Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:45.230463452Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.231647301Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.233067792Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:45.248036195Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:45.250079708Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:45.254709574Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:45.256014353Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:45.265066834Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1991,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:45.268919326Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:45.272679718Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:45.274533001Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:45.275830333Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:45.277733034Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.288960383Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.290725014Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:45.303780384Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:45.311613726Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:45.319952255Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:45.321651647Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:45.326924775Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:45.311320034Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:45.314848858Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:45.315913272Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:45.317092538Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:45.319532182Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.32310083Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.324582172Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:45.339845189Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:45.346867905Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:45.359205604Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:45.360774093Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:45.362808937Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":12,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:45.650956238Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:45.653558821Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:45.655041282Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:45.656300664Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:45.658288304Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.66078343Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.662155753Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:45.676300041Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:45.679339239Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:45.687134136Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:45.688894664Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:45.691643771Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":12,"Month":11,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:45.741841971Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:45.746470796Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:45.747300708Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:45.748419834Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:45.750866267Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.752673818Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.7547686Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:45.773857166Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:45.776642678Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:45.786488834Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:45.788249289Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:45.790080239Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')

{"DateBased":true,"Day":1,"Month":1,"Year":1991,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5543,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:45.818664821Z 42 PC: 12bfd | Get date 0x12bfd: cmp cx, 0x7c7
0x12c01: jbe 0x12c08
0x12c03: cmp dl, 0xc
0x12c06: je 0x12c0b
0x12c08: jmp 0x12ad5
0x12c0b: cmp dh, 0xb
0x12c0e: jne 0x12c13
0x12c10: jmp 0x12d58
0x12c13: jmp 0x12d5f
0x12c16: jae 0x12c8b
0x12c18: outsw dx, word ptr [si]
0x12c19: sub al, 0x20
0x12c1b: inc si
0x12c1c: jb 0x12c83
0x12c1e: outsw dx, word ptr fs:[si]
0x12c21: insw word ptr es:[di], dx
0x12c22: and byte ptr [bp + 0x6f], ah
0x12c25: jb 0x12c47
0x12c27: inc bp
0x12c28: popaw
2018-12-25T11:54:45.821348011Z 224 PC: 12ada | UNKNOWN!
2018-12-25T11:54:45.822405206Z 224 PC: 12b2e | UNKNOWN!
2018-12-25T11:54:45.823485019Z 74 PC: 12bb2 | Reallocate memory
2018-12-25T11:54:45.832737509Z 53 PC: 12bb7 | Get interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.834539362Z 37 PC: 12bcb | Set interrupt vector (Interrupt = '33' AKA 'Random read')
2018-12-25T11:54:45.835986852Z 75 PC: 12c43 | Execute program
2018-12-25T11:54:45.852532522Z 42 PC: 1345d | Get date 0x1345d: cmp cx, 0x7c7
0x13461: jbe 0x13468
0x13463: cmp dl, 0xc
0x13466: je 0x1346b
0x13468: jmp 0x13335
0x1346b: cmp dh, 0xb
0x1346e: jne 0x13473
0x13470: jmp 0x135b8
0x13473: jmp 0x135bf
0x13476: jae 0x134eb
0x13478: outsw dx, word ptr [si]
0x13479: sub al, 0x20
0x1347b: inc si
0x1347c: jb 0x134e3
0x1347e: outsw dx, word ptr fs:[si]
0x13481: insw word ptr es:[di], dx
0x13482: and byte ptr [bp + 0x6f], ah
0x13485: jb 0x134a7
0x13487: inc bp
0x13488: popaw
2018-12-25T11:54:45.855345093Z 9 PC: 13686 | Display string (String= 'Hello - Copyright S & S International, 1990 ')
2018-12-25T11:54:45.863394683Z 73 PC: 12c49 | Release memory
2018-12-25T11:54:45.865174664Z 77 PC: 12c4d | Get program return code
2018-12-25T11:54:45.866659611Z 49 PC: 12c5b | Terminate and stay resident (Return code = '0' | Memory size = '176')