Sample viewer

vx.netlux.org/Virus.DOS.IVP.Birgit.425

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:26.485160966Z 26 PC: 12b6c | Set disk transfer address
2018-12-17T22:31:26.486231317Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:26.48807656Z 37 PC: 12a7d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:26.489161577Z 71 PC: 12a89 | Get current directory
2018-12-17T22:31:26.492201349Z 78 PC: 12ac4 | Find first file
2018-12-17T22:31:26.499060203Z 61 PC: 12b75 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:31:26.512515535Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:31:26.520018555Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:26.522564386Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.541752248Z 61 PC: 12b75 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:31:26.549329522Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:31:26.553714153Z 66 PC: 12b67 | Move file pointer
2018-12-17T22:31:26.555269931Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-17T22:31:26.558744289Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-17T22:31:26.568217737Z 87 PC: 12b50 | Get or set file date and time
2018-12-17T22:31:26.570226243Z 62 PC: 12b54 | Close file
2018-12-17T22:31:26.578956448Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.587976953Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:26.590881921Z 61 PC: 12b75 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:31:26.597674861Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:31:26.604301715Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:26.606831904Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.613910651Z 61 PC: 12b75 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:31:26.621075665Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:31:26.624688252Z 66 PC: 12b67 | Move file pointer
2018-12-17T22:31:26.626203735Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-17T22:31:26.628814832Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-17T22:31:26.632417402Z 87 PC: 12b50 | Get or set file date and time
2018-12-17T22:31:26.634035262Z 62 PC: 12b54 | Close file
2018-12-17T22:31:26.642931794Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.654452069Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:26.657354024Z 61 PC: 12b75 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:31:26.66458446Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:31:26.670638177Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:26.672497709Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.683377172Z 61 PC: 12b75 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:31:26.691148939Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:31:26.694334868Z 66 PC: 12b67 | Move file pointer
2018-12-17T22:31:26.695793497Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-17T22:31:26.698350923Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-17T22:31:26.708653611Z 87 PC: 12b50 | Get or set file date and time
2018-12-17T22:31:26.710258498Z 62 PC: 12b54 | Close file
2018-12-17T22:31:26.719617147Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.73198458Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:26.735022694Z 61 PC: 12b75 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:31:26.742414446Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:31:26.750401673Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:26.753216715Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.765162197Z 61 PC: 12b75 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:31:26.773020394Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:31:26.776152328Z 66 PC: 12b67 | Move file pointer
2018-12-17T22:31:26.777467397Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-17T22:31:26.780612921Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-17T22:31:26.783816255Z 87 PC: 12b50 | Get or set file date and time
2018-12-17T22:31:26.785240941Z 62 PC: 12b54 | Close file
2018-12-17T22:31:26.79349004Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.800438281Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:26.803173237Z 61 PC: 12b75 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:31:26.810317994Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:31:26.817052726Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:26.819108116Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.832424725Z 61 PC: 12b75 | Open file (Filename = 'PRINTA~1.COM�')
2018-12-17T22:31:26.837790854Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:31:26.840752807Z 66 PC: 12b67 | Move file pointer
2018-12-17T22:31:26.842615705Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-17T22:31:26.845385702Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 2)
2018-12-17T22:31:26.857994691Z 87 PC: 12b50 | Get or set file date and time
2018-12-17T22:31:26.859652906Z 62 PC: 12b54 | Close file
2018-12-17T22:31:26.862232242Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.866835808Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:26.873609138Z 61 PC: 12b75 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:31:26.881130825Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 2)
2018-12-17T22:31:26.887891342Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:26.890184126Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.903091712Z 61 PC: 12b75 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:31:26.910359193Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:31:26.912882158Z 66 PC: 12b67 | Move file pointer
2018-12-17T22:31:26.914781241Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-17T22:31:26.916801202Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 2)
2018-12-17T22:31:26.922416309Z 87 PC: 12b50 | Get or set file date and time
2018-12-17T22:31:26.92467784Z 62 PC: 12b54 | Close file
2018-12-17T22:31:26.930649745Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.942400534Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:26.946308261Z 61 PC: 12b75 | Open file (Filename = 'PAH.COM')
2018-12-17T22:31:26.953872286Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 2)
2018-12-17T22:31:26.961192113Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:26.965565757Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:26.977048485Z 61 PC: 12b75 | Open file (Filename = 'PAH.COM')
2018-12-17T22:31:26.984818073Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 2)
2018-12-17T22:31:26.987327377Z 66 PC: 12b67 | Move file pointer
2018-12-17T22:31:26.98917483Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-17T22:31:26.991106826Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 2)
2018-12-17T22:31:26.993083054Z 87 PC: 12b50 | Get or set file date and time
2018-12-17T22:31:26.995003026Z 62 PC: 12b54 | Close file
2018-12-17T22:31:27.003278458Z 67 PC: 12b80 | Get or set file attributes
2018-12-17T22:31:27.014183741Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:27.018090671Z 61 PC: 12b75 | Open file (Filename = 'TEST.COM')
2018-12-17T22:31:27.025480537Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 2)
2018-12-17T22:31:27.033098502Z 62 PC: 12ae3 | Close file
2018-12-17T22:31:27.035574953Z 79 PC: 12ac4 | Find next file
2018-12-17T22:31:27.040400743Z 59 PC: 12a98 | Change current directory
2018-12-17T22:31:27.044767277Z 9 PC: 12aa2 | Display string (String= 'Birgit [IVP] ')
2018-12-17T22:31:27.053802893Z 37 PC: 12aac | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:27.055037927Z 59 PC: 12ab6 | Change current directory
2018-12-17T22:31:27.056859239Z 26 PC: 12b6c | Set disk transfer address

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":5616,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:59.528445921Z 26 PC: 12b6c | Set disk transfer address
2018-12-25T11:54:59.530414102Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.531874767Z 37 PC: 12a7d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.532991372Z 71 PC: 12a89 | Get current directory
2018-12-25T11:54:59.53719999Z 78 PC: 12ac4 | Find first file
2018-12-25T11:54:59.544181156Z 61 PC: 12b75 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:59.550762819Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-25T11:54:59.561280917Z 62 PC: 12ae3 | Close file
2018-12-25T11:54:59.570660093Z 67 PC: 12b80 | Get or set file attributes
2018-12-25T11:54:59.599195104Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.611228918Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:54:59.614640743Z 66 PC: 12b67 | Move file pointer
2018-12-25T11:54:59.615997144Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-25T11:54:59.618424775Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-25T11:54:59.627961745Z 87 PC: 12b50 | Get or set file date and time
2018-12-25T11:54:59.629768798Z 62 PC: 12b54 | Close file
2018-12-25T11:54:59.637980808Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.662327685Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.665932178Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.672668245Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.680340005Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.682386526Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.692452377Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.699776211Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.703237117Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.704685278Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.707850625Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.711171102Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.71296375Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.721091934Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.734073698Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.736982114Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.743971824Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.751338618Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.753394317Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.763341342Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.770636755Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.773339975Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.774628863Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.777736842Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.786087602Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.787794225Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.796779998Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.8065896Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.809416216Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.816979119Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.823465587Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.825554334Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.836397421Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.843586618Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.846621551Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.849047752Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.852000871Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.855862856Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.857787743Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.86589416Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.875884126Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.890969907Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.898428838Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.904881823Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.907132389Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.914506941Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.917862109Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.92008038Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.921836121Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.92353141Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.930567776Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.932322968Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.933639691Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.936555361Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.939030847Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.943098006Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.947274767Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.949380485Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.955530002Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.959691063Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.962107889Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.963243982Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.964977451Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.970668344Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.971919595Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.976884211Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.983570378Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.985375327Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.989861636Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.994592868Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.995951773Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.002714205Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.011592972Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.01796223Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.01932662Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.022531059Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.024481021Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.025620434Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.031128322Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.03748339Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.039353657Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.046546083Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.050962775Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.052282257Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.054145508Z 59 PC: 12a98 | Change current directory
2018-12-25T11:55:00.061783562Z 9 PC: 12aa2 | Display string (String= 'Birgit [IVP] ')
2018-12-25T11:55:00.069643915Z 37 PC: 12aac | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:00.071334382Z 59 PC: 12ab6 | Change current directory
2018-12-25T11:55:00.074408808Z 26 PC: 12b6c | Set disk transfer address (See above)

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":5616,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:59.535682136Z 26 PC: 12b6c | Set disk transfer address
2018-12-25T11:54:59.540197334Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.541637445Z 37 PC: 12a7d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.542977419Z 71 PC: 12a89 | Get current directory
2018-12-25T11:54:59.549844721Z 78 PC: 12ac4 | Find first file
2018-12-25T11:54:59.557060382Z 61 PC: 12b75 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:59.563819122Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-25T11:54:59.571365335Z 62 PC: 12ae3 | Close file
2018-12-25T11:54:59.573807668Z 67 PC: 12b80 | Get or set file attributes
2018-12-25T11:54:59.598984881Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.606182486Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:54:59.609818185Z 66 PC: 12b67 | Move file pointer
2018-12-25T11:54:59.611452276Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-25T11:54:59.614749082Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-25T11:54:59.638773638Z 87 PC: 12b50 | Get or set file date and time
2018-12-25T11:54:59.644210577Z 62 PC: 12b54 | Close file
2018-12-25T11:54:59.652062665Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.663100382Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.666085368Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.672875383Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.681161189Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.683459058Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.706694153Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.713980649Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.719429882Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.721945957Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.725198507Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.730493725Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.732018168Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.739443072Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.750867275Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.754160187Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.761519782Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.768468868Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.771488171Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.781699328Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.789205409Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.794049153Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.795749326Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.798471068Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.807929764Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.809857266Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.817482928Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.828065921Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.831254751Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.83797202Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.845186645Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.848142256Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.858642613Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.865414575Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.869534941Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.87125833Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.874474713Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.878403694Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.880592475Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.888470091Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.899434412Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.902373567Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.908690888Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.915124241Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.917959495Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.923232551Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.928063613Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.931995572Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.933618329Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.936235459Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.94674012Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.94847566Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.950449725Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.955892533Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.958724719Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.965808418Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.973036784Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.975404617Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.985637396Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.993087969Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.996397164Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.998036691Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.001338847Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.006998747Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.00807536Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.017829484Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.052930832Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.059035306Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.065598638Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.072419165Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.074168245Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.084019595Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.091068841Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.094141541Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.095783726Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.098723492Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.101576805Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.103003046Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.110336708Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.120898577Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.123806626Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.13152029Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.134602795Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.13675164Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.140520136Z 59 PC: 12a98 | Change current directory
2018-12-25T11:55:00.145013828Z 9 PC: 12aa2 | Display string (String= 'Birgit [IVP] ')
2018-12-25T11:55:00.151841899Z 37 PC: 12aac | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:00.161410502Z 59 PC: 12ab6 | Change current directory
2018-12-25T11:55:00.163448769Z 26 PC: 12b6c | Set disk transfer address (See above)

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":5616,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:59.704027799Z 26 PC: 12b6c | Set disk transfer address
2018-12-25T11:54:59.706946837Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.708464841Z 37 PC: 12a7d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.709795431Z 71 PC: 12a89 | Get current directory
2018-12-25T11:54:59.712802803Z 78 PC: 12ac4 | Find first file
2018-12-25T11:54:59.72709632Z 61 PC: 12b75 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:59.733685641Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-25T11:54:59.740092811Z 62 PC: 12ae3 | Close file
2018-12-25T11:54:59.743105392Z 67 PC: 12b80 | Get or set file attributes
2018-12-25T11:54:59.759546956Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.766243756Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:54:59.770256079Z 66 PC: 12b67 | Move file pointer
2018-12-25T11:54:59.775981718Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-25T11:54:59.778444889Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-25T11:54:59.787810721Z 87 PC: 12b50 | Get or set file date and time
2018-12-25T11:54:59.789873805Z 62 PC: 12b54 | Close file
2018-12-25T11:54:59.797825516Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.808496899Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.811111292Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.817508106Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.824141998Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.826571615Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.844625994Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.855331397Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.864226481Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.867024657Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.86980279Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.873579612Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.875289594Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.882664376Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.893277554Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.902744151Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.909808167Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.918356969Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.920103608Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.929939743Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.936679035Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:54:59.939452958Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:54:59.940774482Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:54:59.943829546Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:54:59.952219472Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:54:59.953976826Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:54:59.962094817Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.972045212Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.975645503Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.982912767Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.989344187Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.99146781Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.002224737Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.009154892Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.012206099Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.01409381Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.017106435Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.01989488Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.021322661Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.029230677Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.039657715Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.04253368Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.049784224Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.056172086Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.058230244Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.063118227Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.06788106Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.070768274Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.072754909Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.075279239Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.088682767Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.09122184Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.093163853Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.097503146Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.100888226Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.111586661Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.117886871Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.12080164Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.131026227Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.137688293Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.141380229Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.143323048Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.145881933Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.155771614Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.157551444Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.169268214Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.180081538Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.183096322Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.189680355Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.196322138Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.199246769Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.209268921Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.21597665Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.219967613Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.221602042Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.224220059Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.228299281Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.230033104Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.237850853Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.248678826Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.251502305Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.258111429Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.261650128Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.263963907Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.266584963Z 59 PC: 12a98 | Change current directory
2018-12-25T11:55:00.27157169Z 9 PC: 12aa2 | Display string (String= 'Birgit [IVP] ')
2018-12-25T11:55:00.279533049Z 37 PC: 12aac | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:00.2806779Z 59 PC: 12ab6 | Change current directory
2018-12-25T11:55:00.282999857Z 26 PC: 12b6c | Set disk transfer address (See above)

{"DateBased":false,"Day":0,"Month":0,"Year":0,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":5616,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:54:59.84154208Z 26 PC: 12b6c | Set disk transfer address
2018-12-25T11:54:59.843910683Z 53 PC: 12a6b | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.845342871Z 37 PC: 12a7d | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:54:59.846745439Z 71 PC: 12a89 | Get current directory
2018-12-25T11:54:59.850919281Z 78 PC: 12ac4 | Find first file
2018-12-25T11:54:59.862514038Z 61 PC: 12b75 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:54:59.874041941Z 63 PC: 12adf | Read file or device (Read 26 bytes on handle 5)
2018-12-25T11:54:59.881234773Z 62 PC: 12ae3 | Close file
2018-12-25T11:54:59.883355086Z 67 PC: 12b80 | Get or set file attributes
2018-12-25T11:54:59.898996343Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.906218934Z 64 PC: 12b29 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:54:59.909798895Z 66 PC: 12b67 | Move file pointer
2018-12-25T11:54:59.911444015Z 44 PC: 12b34 | Get time 0x12b34: cmp dh, 0
0x12b37: je 0x12b30
0x12b39: mov byte ptr cs:[bp + 0x2ab], dh
0x12b3e: call 0x12ba2
0x12b41: mov ax, 0x5701
0x12b44: mov cx, word ptr cs:[bp + 0x31e]
0x12b49: mov dx, word ptr cs:[bp + 0x320]
0x12b4e: int 0x21
0x12b50: mov ah, 0x3e
0x12b52: int 0x21
0x12b54: xor cx, cx
0x12b56: mov cl, byte ptr cs:[bp + 0x31d]
0x12b5b: call 0x12b77
0x12b5e: ret
0x12b5f: mov ah, 0x42
0x12b61: xor cx, cx
0x12b63: xor dx, dx
0x12b65: int 0x21
0x12b67: ret
0x12b68: mov ah, 0x1a
2018-12-25T11:54:59.914890804Z 64 PC: 12bff | Write file or device (Write 425 bytes on handle 5)
2018-12-25T11:54:59.924055692Z 87 PC: 12b50 | Get or set file date and time
2018-12-25T11:54:59.925893291Z 62 PC: 12b54 | Close file
2018-12-25T11:54:59.933585622Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.94507269Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:54:59.947960135Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:54:59.955325415Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:54:59.962639936Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:54:59.964879535Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:54:59.974814305Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.010569226Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.013362225Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.014861333Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.018792644Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.021992667Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.023878814Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.032368312Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.042217705Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.044810583Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.051582295Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.058241434Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.060455079Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.070388175Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.077086158Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.080094593Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.081880314Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.085272703Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.09389155Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.095620668Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.102219911Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.109090418Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.111943416Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.119513614Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.1285221Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.130642887Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.141390472Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.148339453Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.15136983Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.153187534Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.156720675Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.160546001Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.162277295Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.170370105Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.180188111Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.182994238Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.200408298Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.220699508Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.222540115Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.22762147Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.232610962Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.235733572Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.238128482Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.240848154Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.25110681Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.253420628Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.255517251Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.260104734Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.26372565Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.270446603Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.276913575Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.279754583Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.292725223Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.300196401Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.307745084Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.309496533Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.312093435Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.320547789Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.322491285Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.330140077Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.340564093Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.343634977Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.350156236Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.357141708Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.359416205Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.369437272Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.376342081Z 64 PC: 12b29 | Write file or device (See above)
2018-12-25T11:55:00.379586421Z 66 PC: 12b67 | Move file pointer (See above)
2018-12-25T11:55:00.381167635Z 44 PC: 12b34 | Get time (See above)
2018-12-25T11:55:00.383899206Z 64 PC: 12bff | Write file or device (See above)
2018-12-25T11:55:00.387168771Z 87 PC: 12b50 | Get or set file date and time (See above)
2018-12-25T11:55:00.388709222Z 62 PC: 12b54 | Close file (See above)
2018-12-25T11:55:00.396213605Z 67 PC: 12b80 | Get or set file attributes (See above)
2018-12-25T11:55:00.4065576Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.414621883Z 61 PC: 12b75 | Open file (See above)
2018-12-25T11:55:00.444491455Z 63 PC: 12adf | Read file or device (See above)
2018-12-25T11:55:00.45143495Z 62 PC: 12ae3 | Close file (See above)
2018-12-25T11:55:00.453433789Z 79 PC: 12ac4 | Find next file (See above)
2018-12-25T11:55:00.456017662Z 59 PC: 12a98 | Change current directory
2018-12-25T11:55:00.460687753Z 9 PC: 12aa2 | Display string (String= 'Birgit [IVP] ')
2018-12-25T11:55:00.466906488Z 37 PC: 12aac | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:00.468237104Z 59 PC: 12ab6 | Change current directory
2018-12-25T11:55:00.47117162Z 26 PC: 12b6c | Set disk transfer address (See above)