Sample viewer

vx.netlux.org/Virus.DOS.VCL.2484

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:31:30.988108387Z 48 PC: 133b1 | Get DOS version
2018-12-17T22:31:30.989871265Z 53 PC: 13408 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:30.990878333Z 37 PC: 13419 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:30.991842856Z 53 PC: 13425 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:30.993424062Z 37 PC: 13436 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:30.994484147Z 71 PC: 13448 | Get current directory
2018-12-17T22:31:30.997149117Z 26 PC: 13457 | Set disk transfer address
2018-12-17T22:31:30.998540586Z 78 PC: 1346a | Find first file
2018-12-17T22:31:31.004437613Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.014698504Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.035305186Z 61 PC: 13683 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:31:31.041752275Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.043287909Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.050513484Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.05242709Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.055120261Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.056763701Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.059227292Z 66 PC: 1373b | Move file pointer
2018-12-17T22:31:31.061025446Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-17T22:31:31.070899699Z 66 PC: 1375f | Move file pointer
2018-12-17T22:31:31.072600325Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.087767419Z 66 PC: 1377d | Move file pointer
2018-12-17T22:31:31.08905313Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:31.092430671Z 66 PC: 1379b | Move file pointer
2018-12-17T22:31:31.093722063Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:31.097044917Z 87 PC: 137bd | Get or set file date and time
2018-12-17T22:31:31.099549351Z 62 PC: 137c6 | Close file
2018-12-17T22:31:31.106868258Z 67 PC: 137d8 | Get or set file attributes
2018-12-17T22:31:31.116288849Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.119410736Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.124848232Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.134278924Z 61 PC: 13683 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:31:31.141083098Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.142378932Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.148458846Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.150092143Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.152629793Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.153987013Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.155898983Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.157592703Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.169702363Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.173165188Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.178526088Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.187794836Z 61 PC: 13683 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:31:31.194151631Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.195477552Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.201426972Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.202820233Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.205124544Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.206380413Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.207548299Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.209814624Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.219488605Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.222076222Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.228268282Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.237585248Z 61 PC: 13683 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:31:31.243841892Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.245574968Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.251714883Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.252869124Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.255521573Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.256845223Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.257930935Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.259929091Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.26956482Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.27214477Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.277809807Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.287596298Z 61 PC: 13683 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:31:31.293794325Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.295461007Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.301443757Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.302671355Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.305323951Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.306510363Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.307566194Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.309966892Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.319389944Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.321803493Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.328345324Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.337923818Z 61 PC: 13683 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:31:31.349881775Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.352465832Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.359555933Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.361097485Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.364298041Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.365959881Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.367609792Z 66 PC: 1373b | Move file pointer
2018-12-17T22:31:31.370179958Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-17T22:31:31.379233896Z 66 PC: 1375f | Move file pointer
2018-12-17T22:31:31.380877641Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.388410314Z 66 PC: 1377d | Move file pointer
2018-12-17T22:31:31.390163151Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:31.393291466Z 66 PC: 1379b | Move file pointer
2018-12-17T22:31:31.395272657Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:31.398265282Z 87 PC: 137bd | Get or set file date and time
2018-12-17T22:31:31.400099917Z 62 PC: 137c6 | Close file
2018-12-17T22:31:31.4108779Z 67 PC: 137d8 | Get or set file attributes
2018-12-17T22:31:31.425177799Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.428448155Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.435060288Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.445328947Z 61 PC: 13683 | Open file (Filename = 'PAH.COM')
2018-12-17T22:31:31.451667839Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.453259111Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.45940591Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.46067299Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.463710646Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.465066599Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.466403968Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.469117018Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.47878231Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.481381712Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.49206156Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.501906653Z 61 PC: 13683 | Open file (Filename = 'TEST.COM')
2018-12-17T22:31:31.508274828Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.510046756Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.516182399Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.517394921Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.519972688Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.521689734Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.53131921Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.533691501Z 59 PC: 134bc | Change current directory
2018-12-17T22:31:31.537814658Z 59 PC: 134da | Change current directory
2018-12-17T22:31:31.546145921Z 78 PC: 1346a | Find first file
2018-12-17T22:31:31.557279566Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.573744973Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.58332778Z 61 PC: 13683 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:31:31.590064976Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.592127897Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.598579001Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.59999143Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.603635458Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.605293441Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.615412673Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.618687571Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.624180543Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.633685324Z 61 PC: 13683 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:31:31.63879749Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.640337497Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.644646043Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.646549912Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.648714937Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.650018463Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.652661351Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.654461184Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.66494617Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.668503323Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.679111813Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.692455403Z 61 PC: 13683 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:31:31.70061991Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.702539306Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.709363946Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.711771522Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.714606782Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.716421917Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.71911564Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.721121107Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.7312044Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.734785826Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.740703118Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.750973143Z 61 PC: 13683 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:31:31.758247366Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.760266549Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.766518248Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.768156998Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.770987652Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.772356528Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.774004789Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.775563446Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.785442053Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.788457318Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.794024388Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.806683116Z 61 PC: 13683 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:31:31.81838762Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.819681771Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.826192084Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.828200068Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.831356455Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.832619962Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.834594215Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.836189032Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.846294241Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.849880922Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.855447988Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.86500877Z 61 PC: 13683 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:31:31.873698514Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.875291383Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.882630515Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.884847667Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.887230428Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.889150572Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.89927417Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.902188935Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.908994697Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.919191708Z 61 PC: 13683 | Open file (Filename = 'PAH.COM')
2018-12-17T22:31:31.925723445Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.927369173Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.933605128Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.935057786Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.938148804Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:31.939524289Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:31.94093343Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.943437163Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:31.95359314Z 79 PC: 134ac | Find next file
2018-12-17T22:31:31.956177645Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:31.962612044Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:31.97267698Z 61 PC: 13683 | Open file (Filename = 'TEST.COM')
2018-12-17T22:31:31.97939689Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:31.981673342Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:31.988837181Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:31.99036355Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:31.993496839Z 62 PC: 136eb | Close file
2018-12-17T22:31:31.995462033Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:32.005472657Z 79 PC: 134ac | Find next file
2018-12-17T22:31:32.008897839Z 59 PC: 134bc | Change current directory
2018-12-17T22:31:32.018426014Z 78 PC: 134fa | Find first file
2018-12-17T22:31:32.027439705Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.031013284Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.033582336Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.036897243Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.040121159Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.042690634Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.045008119Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.048390136Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.050820723Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.052980798Z 59 PC: 13486 | Change current directory
2018-12-17T22:31:32.055408952Z 78 PC: 13494 | Find first file
2018-12-17T22:31:32.061026755Z 59 PC: 134bc | Change current directory
2018-12-17T22:31:32.064819163Z 59 PC: 134da | Change current directory
2018-12-17T22:31:32.069767937Z 78 PC: 13494 | Find first file
2018-12-17T22:31:32.075693792Z 59 PC: 134bc | Change current directory
2018-12-17T22:31:32.084740985Z 78 PC: 134fa | Find first file
2018-12-17T22:31:32.094091621Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.096588406Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.098935006Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.101736992Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.10407313Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.10635492Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.109737837Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.112260396Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.114730126Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.117854315Z 25 PC: 13591 | Get default drive
2018-12-17T22:31:32.118918161Z 14 PC: 135a1 | Set default drive (Drive = 'C')
2018-12-17T22:31:32.120136542Z 59 PC: 133dc | Change current directory
2018-12-17T22:31:32.124092905Z 78 PC: 1346a | Find first file
2018-12-17T22:31:32.129533954Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:32.134512015Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:32.468978999Z 61 PC: 13683 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:31:32.475579533Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:32.478454201Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.482520312Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:32.484299239Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:32.488254956Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:32.490189956Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:32.492007895Z 66 PC: 1373b | Move file pointer
2018-12-17T22:31:32.495162691Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-17T22:31:32.505401785Z 66 PC: 1375f | Move file pointer
2018-12-17T22:31:32.506853806Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.510219552Z 66 PC: 1377d | Move file pointer
2018-12-17T22:31:32.511696932Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.514842952Z 66 PC: 1379b | Move file pointer
2018-12-17T22:31:32.51650967Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.519493088Z 87 PC: 137bd | Get or set file date and time
2018-12-17T22:31:32.520972952Z 62 PC: 137c6 | Close file
2018-12-17T22:31:32.529266735Z 67 PC: 137d8 | Get or set file attributes
2018-12-17T22:31:32.5381739Z 79 PC: 134ac | Find next file
2018-12-17T22:31:32.541035049Z 59 PC: 134bc | Change current directory
2018-12-17T22:31:32.54648213Z 59 PC: 134da | Change current directory
2018-12-17T22:31:32.549953394Z 78 PC: 1346a | Find first file
2018-12-17T22:31:32.556020548Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:32.561706315Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:32.571139869Z 61 PC: 13683 | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:31:32.577763507Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:32.580524389Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.583458435Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:32.585013367Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:32.588267206Z 62 PC: 136eb | Close file
2018-12-17T22:31:32.590142303Z 67 PC: 136fd | Get or set file attributes
2018-12-17T22:31:32.599105875Z 79 PC: 134ac | Find next file
2018-12-17T22:31:32.602327377Z 59 PC: 134bc | Change current directory
2018-12-17T22:31:32.605808593Z 78 PC: 134fa | Find first file
2018-12-17T22:31:32.611152378Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.614722191Z 79 PC: 1352e | Find next file
2018-12-17T22:31:32.617332771Z 59 PC: 13561 | Change current directory
2018-12-17T22:31:32.623848857Z 78 PC: 1346a | Find first file
2018-12-17T22:31:32.633355248Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:32.639270437Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:32.648874595Z 61 PC: 13683 | Open file (Filename = 'EDIT.COM')
2018-12-17T22:31:32.65599805Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:32.657404679Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.662707787Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:32.665199207Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:32.667568655Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:32.66908075Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:32.670842221Z 66 PC: 1373b | Move file pointer
2018-12-17T22:31:32.67396282Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-17T22:31:32.683058428Z 66 PC: 1375f | Move file pointer
2018-12-17T22:31:32.684572497Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.690094077Z 66 PC: 1377d | Move file pointer
2018-12-17T22:31:32.692485577Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.696228586Z 66 PC: 1379b | Move file pointer
2018-12-17T22:31:32.698004158Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.701948804Z 87 PC: 137bd | Get or set file date and time
2018-12-17T22:31:32.703314611Z 62 PC: 137c6 | Close file
2018-12-17T22:31:32.710302251Z 67 PC: 137d8 | Get or set file attributes
2018-12-17T22:31:32.720673504Z 79 PC: 134ac | Find next file
2018-12-17T22:31:32.723937019Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:32.730773162Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:32.741000969Z 61 PC: 13683 | Open file (Filename = 'FORMAT.COM')
2018-12-17T22:31:32.752696958Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:32.754423691Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.762000948Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:32.763675922Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:32.766898071Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:32.769361284Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:32.770947841Z 66 PC: 1373b | Move file pointer
2018-12-17T22:31:32.772998364Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-17T22:31:32.782932525Z 66 PC: 1375f | Move file pointer
2018-12-17T22:31:32.784600934Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.788315247Z 66 PC: 1377d | Move file pointer
2018-12-17T22:31:32.78999296Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.793060178Z 66 PC: 1379b | Move file pointer
2018-12-17T22:31:32.795488985Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.798605709Z 87 PC: 137bd | Get or set file date and time
2018-12-17T22:31:32.800469643Z 62 PC: 137c6 | Close file
2018-12-17T22:31:32.808138287Z 67 PC: 137d8 | Get or set file attributes
2018-12-17T22:31:32.818039488Z 79 PC: 134ac | Find next file
2018-12-17T22:31:32.82148931Z 67 PC: 13667 | Get or set file attributes
2018-12-17T22:31:32.8282391Z 67 PC: 13678 | Get or set file attributes
2018-12-17T22:31:32.838339371Z 61 PC: 13683 | Open file (Filename = 'KEYB.COM')
2018-12-17T22:31:32.845479213Z 87 PC: 13693 | Get or set file date and time
2018-12-17T22:31:32.849023328Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.854539817Z 66 PC: 136c5 | Move file pointer
2018-12-17T22:31:32.855879238Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-17T22:31:32.859320475Z 66 PC: 1370e | Move file pointer
2018-12-17T22:31:32.861137887Z 66 PC: 1371c | Move file pointer
2018-12-17T22:31:32.863216745Z 66 PC: 1373b | Move file pointer
2018-12-17T22:31:32.865259853Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-17T22:31:32.87426241Z 66 PC: 1375f | Move file pointer
2018-12-17T22:31:32.876612316Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:31:32.879638644Z 66 PC: 1377d | Move file pointer
2018-12-17T22:31:32.88098101Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.885472349Z 66 PC: 1379b | Move file pointer
2018-12-17T22:31:32.8869391Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:31:32.889723929Z 87 PC: 137bd | Get or set file date and time
2018-12-17T22:31:32.892250372Z 62 PC: 137c6 | Close file
2018-12-17T22:31:32.89922024Z 67 PC: 137d8 | Get or set file attributes
2018-12-17T22:31:32.909621677Z 14 PC: 135af | Set default drive (Drive = 'A')
2018-12-17T22:31:32.912010068Z 59 PC: 135b7 | Change current directory
2018-12-17T22:31:32.913688849Z 37 PC: 135c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:31:32.914926284Z 42 PC: 13326 | Get date 0x13326: cmp dh, 5
0x13329: je 0x13331
0x1332b: nop
0x1332c: nop
0x1332d: nop
0x1332e: jmp 0x1335a
0x13330: nop
0x13331: cmp al, 3
0x13333: je 0x1333b
0x13335: nop
0x13336: nop
0x13337: nop
0x13338: jmp 0x1335a
0x1333a: nop
0x1333b: mov ah, 0x2c
0x1333d: int 0x21
0x1333f: cmp ch, 9
0x13342: je 0x13357
0x13344: nop
0x13345: nop
2018-12-17T22:31:32.917638187Z 37 PC: 1336a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-17T22:31:32.918784634Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-17T22:31:32.924230749Z 48 PC: 12a8f | Get DOS version
2018-12-17T22:31:32.926520457Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-17T22:31:32.932813939Z 93 PC: 12afe | File sharing functions
2018-12-17T22:31:32.935993619Z 9 PC: 12a86 | Display string (String= 'Size change=09B4h/02484d. ')
2018-12-17T22:31:32.94027396Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5626,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:55:01.159242363Z 48 PC: 133b1 | Get DOS version
2018-12-25T11:55:01.162009969Z 53 PC: 13408 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:01.163614249Z 37 PC: 13419 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:01.165113621Z 53 PC: 13425 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:01.16773842Z 37 PC: 13436 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:01.169614917Z 71 PC: 13448 | Get current directory
2018-12-25T11:55:01.173546712Z 26 PC: 13457 | Set disk transfer address
2018-12-25T11:55:01.176195114Z 78 PC: 1346a | Find first file
2018-12-25T11:55:01.184610679Z 67 PC: 13667 | Get or set file attributes
2018-12-25T11:55:01.192390943Z 67 PC: 13678 | Get or set file attributes
2018-12-25T11:55:01.210776425Z 61 PC: 13683 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:01.222682395Z 87 PC: 13693 | Get or set file date and time
2018-12-25T11:55:01.224691416Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-25T11:55:01.232710813Z 66 PC: 136c5 | Move file pointer
2018-12-25T11:55:01.235457987Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-25T11:55:01.238423331Z 66 PC: 1370e | Move file pointer
2018-12-25T11:55:01.24016182Z 66 PC: 1371c | Move file pointer
2018-12-25T11:55:01.243003458Z 66 PC: 1373b | Move file pointer
2018-12-25T11:55:01.24501036Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-25T11:55:01.256267362Z 66 PC: 1375f | Move file pointer
2018-12-25T11:55:01.266293496Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-25T11:55:01.27502774Z 66 PC: 1377d | Move file pointer
2018-12-25T11:55:01.277242697Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-25T11:55:01.281269781Z 66 PC: 1379b | Move file pointer
2018-12-25T11:55:01.284369677Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-25T11:55:01.287581749Z 87 PC: 137bd | Get or set file date and time
2018-12-25T11:55:01.289258716Z 62 PC: 137c6 | Close file
2018-12-25T11:55:01.299253005Z 67 PC: 137d8 | Get or set file attributes
2018-12-25T11:55:01.31024761Z 79 PC: 134ac | Find next file
2018-12-25T11:55:01.313374903Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:01.322140041Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:01.333624937Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:01.341261975Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:01.343290675Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:01.350710676Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:01.352521034Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:01.358834623Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:01.361521903Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:01.363751268Z 62 PC: 136eb | Close file
2018-12-25T11:55:01.366042005Z 67 PC: 136fd | Get or set file attributes
2018-12-25T11:55:01.378553308Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:01.383146155Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:01.389518811Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:01.401062166Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:01.408951644Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:01.410516746Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:01.419004252Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:01.4205327Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:01.423123299Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:01.425340504Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:01.426818811Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:01.428658654Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:01.440529269Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:01.444319144Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:01.451653144Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:01.622175099Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:01.629980854Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:01.631622652Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:01.638710234Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:01.641102301Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:01.643758704Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:01.64542191Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:01.647747049Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:01.649872186Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:01.663076717Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:01.667059327Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:01.675036529Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:01.694529716Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:01.702232302Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:01.704341598Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:01.712377549Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:01.71700716Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:01.721297119Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:01.723359948Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:01.725810833Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:01.729348286Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:01.746978057Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:01.750551561Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:01.759816856Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:01.777958989Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:01.786000361Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:01.789195354Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:01.797232033Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:01.79900577Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:01.801924276Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:01.804612486Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:01.806414433Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:01.808457226Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:01.840191833Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:01.841711796Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:01.850328622Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:01.852578247Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:01.856471232Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:01.858056927Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:01.861909616Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:01.863674469Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:01.899789135Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:01.938323267Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:01.94240624Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:01.948171125Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:01.988547367Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.002828718Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.005017482Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.01300526Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.016150508Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.019493972Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.021629746Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.024308088Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.026284401Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.064326066Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.068080151Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.074806922Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.10874093Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.113841366Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.115016641Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.119464086Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.121019298Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.122727053Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.123971329Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.130771379Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.132409107Z 59 PC: 134bc | Change current directory
2018-12-25T11:55:02.134894465Z 59 PC: 134da | Change current directory
2018-12-25T11:55:02.137802148Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:02.141643193Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.151405671Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.166190137Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.174542065Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.175809529Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.180871582Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.182547388Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.184396752Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.186565846Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.193231673Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.195274107Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.202477115Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.213521679Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.221005201Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.22323226Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.230379178Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.231759343Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.234871376Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.236484986Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.238080777Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.240569055Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.252007857Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.255067326Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.262098835Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.276775588Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.284114244Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.285785352Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.293054659Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.294586877Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.297491457Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.299628422Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.301184652Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.303153445Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.329097695Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.332678919Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.339526388Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.350837097Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.357629584Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.359205555Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.366380563Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.367681715Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.371081663Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.373858231Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.375005096Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.376441083Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.383968235Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.386327514Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.390163663Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.397531624Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.401996506Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.40314541Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.408967838Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.414621488Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.417738121Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.429019357Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.435969621Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.439104043Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.451352418Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.455328165Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.461950563Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.474142395Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.482438987Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.484380696Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.49246718Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.495213554Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.498208946Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.501346983Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.513692682Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.517191539Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.524157795Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.536174656Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.543628426Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.545063352Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.55295087Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.55448373Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.557182645Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.576406262Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.578620846Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.580313584Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.59382398Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.596990767Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.603710152Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.615818059Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.624678458Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.626305711Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.63487541Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.63669322Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.639410174Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.642594292Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.653987201Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.656728357Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:02.672518898Z 78 PC: 134fa | Find first file
2018-12-25T11:55:02.678726879Z 79 PC: 1352e | Find next file
2018-12-25T11:55:02.68136288Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.684541429Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.68725087Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.691819048Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.69552235Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.698161376Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.700294117Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.703292257Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.70535498Z 59 PC: 13486 | Change current directory
2018-12-25T11:55:02.707082439Z 78 PC: 13494 | Find first file
2018-12-25T11:55:02.712212058Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:02.715950326Z 59 PC: 134da | Change current directory (See above)
2018-12-25T11:55:02.720699107Z 78 PC: 13494 | Find first file (See above)
2018-12-25T11:55:02.728629981Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:02.736862008Z 78 PC: 134fa | Find first file (See above)
2018-12-25T11:55:02.743687435Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.747297337Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.750469037Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.753479312Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.756731101Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.759390779Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.762100601Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.766605888Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.769265902Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.771748946Z 25 PC: 13591 | Get default drive
2018-12-25T11:55:02.773405411Z 14 PC: 135a1 | Set default drive (Drive = 'C')
2018-12-25T11:55:02.77467394Z 59 PC: 133dc | Change current directory
2018-12-25T11:55:02.778455141Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:02.785527631Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.791502979Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.146923905Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.155171151Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.157694852Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.161069919Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.163879759Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.16740053Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.169412209Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.172132638Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.174268493Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.186354441Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.189299573Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.192397808Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.193775695Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.197738449Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.199388569Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.202859203Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.205020172Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.21292059Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.222597423Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.226042955Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:03.230424239Z 59 PC: 134da | Change current directory (See above)
2018-12-25T11:55:03.235864551Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:03.243079617Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.250525343Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.260634274Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.268465483Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.270876287Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.274262667Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.276869371Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.28001685Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.28237578Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.292716809Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.29586349Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:03.300144337Z 78 PC: 134fa | Find first file (See above)
2018-12-25T11:55:03.30675298Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.309918003Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.313376621Z 59 PC: 13561 | Change current directory
2018-12-25T11:55:03.321239256Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:03.331331161Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.337183117Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.347910638Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.355440483Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.35787685Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.364402974Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.366080104Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.370262343Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.371810649Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.373292421Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.375634116Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.385482106Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.386784705Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.393281263Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.394786683Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.398542184Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.401234892Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.404740426Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.406775054Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.416008943Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.426612906Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.430968974Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.437822269Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.447878856Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.455995638Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.458154664Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.464115828Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.465556112Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.468506013Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.469934354Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.471609333Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.473702872Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.483846566Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.486372216Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.489280414Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.490698714Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.495141878Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.49659962Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.49959268Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.502081266Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.509959898Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.521423229Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.526076643Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.532717723Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.54327174Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.551571238Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.553319205Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.559781105Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.562569906Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.56580321Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.567621082Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.569767532Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.571703173Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.581443093Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.585603261Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.589168604Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.590673388Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.595339546Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.597167222Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.600563755Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.602954641Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.610836243Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.621277779Z 14 PC: 135af | Set default drive (Drive = 'A')
2018-12-25T11:55:03.623180386Z 59 PC: 135b7 | Change current directory
2018-12-25T11:55:03.625396582Z 37 PC: 135c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:03.627224479Z 42 PC: 13326 | Get date 0x13326: cmp dh, 5
0x13329: je 0x13331
0x1332b: nop
0x1332c: nop
0x1332d: nop
0x1332e: jmp 0x1335a
0x13330: nop
0x13331: cmp al, 3
0x13333: je 0x1333b
0x13335: nop
0x13336: nop
0x13337: nop
0x13338: jmp 0x1335a
0x1333a: nop
0x1333b: mov ah, 0x2c
0x1333d: int 0x21
0x1333f: cmp ch, 9
0x13342: je 0x13357
0x13344: nop
0x13345: nop
2018-12-25T11:55:03.630598181Z 37 PC: 1336a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:03.631987938Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-25T11:55:03.638276083Z 48 PC: 12a8f | Get DOS version
2018-12-25T11:55:03.641035975Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-25T11:55:03.648666947Z 93 PC: 12afe | File sharing functions
2018-12-25T11:55:03.650977872Z 9 PC: 12a86 | Display string (See above)
2018-12-25T11:55:03.657039187Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5626,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:55:01.878795343Z 48 PC: 133b1 | Get DOS version
2018-12-25T11:55:01.881105684Z 53 PC: 13408 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:01.882342081Z 37 PC: 13419 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:01.883525574Z 53 PC: 13425 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:01.885891953Z 37 PC: 13436 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:01.886993774Z 71 PC: 13448 | Get current directory
2018-12-25T11:55:01.889714323Z 26 PC: 13457 | Set disk transfer address
2018-12-25T11:55:01.890704901Z 78 PC: 1346a | Find first file
2018-12-25T11:55:01.897367676Z 67 PC: 13667 | Get or set file attributes
2018-12-25T11:55:01.912606743Z 67 PC: 13678 | Get or set file attributes
2018-12-25T11:55:01.929342626Z 61 PC: 13683 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:01.939796429Z 87 PC: 13693 | Get or set file date and time
2018-12-25T11:55:01.941235795Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-25T11:55:01.956610149Z 66 PC: 136c5 | Move file pointer
2018-12-25T11:55:01.95858993Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-25T11:55:01.961170177Z 66 PC: 1370e | Move file pointer
2018-12-25T11:55:01.962744914Z 66 PC: 1371c | Move file pointer
2018-12-25T11:55:01.965755326Z 66 PC: 1373b | Move file pointer
2018-12-25T11:55:01.967838379Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-25T11:55:01.977113449Z 66 PC: 1375f | Move file pointer
2018-12-25T11:55:01.981109673Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-25T11:55:01.988019883Z 66 PC: 1377d | Move file pointer
2018-12-25T11:55:01.989436802Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-25T11:55:01.993757307Z 66 PC: 1379b | Move file pointer
2018-12-25T11:55:01.995499186Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-25T11:55:01.99851424Z 87 PC: 137bd | Get or set file date and time
2018-12-25T11:55:02.000863668Z 62 PC: 137c6 | Close file
2018-12-25T11:55:02.008929216Z 67 PC: 137d8 | Get or set file attributes
2018-12-25T11:55:02.018679584Z 79 PC: 134ac | Find next file
2018-12-25T11:55:02.022009901Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.027895142Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.037566564Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.044799706Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.046408494Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.052573563Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.054933959Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.058488906Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.060125562Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.061752624Z 62 PC: 136eb | Close file
2018-12-25T11:55:02.063948503Z 67 PC: 136fd | Get or set file attributes
2018-12-25T11:55:02.073753185Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.076416853Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.082396911Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.091870253Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.098311251Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.100177428Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.109815985Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.11146454Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.11463845Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.116250854Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.117846209Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.120542214Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.130854655Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.133665375Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.139824623Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.149512061Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.156792548Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.159594362Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.165960038Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.167279292Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.170409724Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.171718742Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.173070467Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.17547813Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.184948764Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.187595496Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.194538392Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.203989843Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.210196037Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.21243595Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.218472648Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.219745117Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.222836462Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.224158803Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.225480713Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.228072026Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.238441795Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.241993624Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.248485168Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.258347643Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.264628542Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.26674702Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.27288912Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.274548437Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.277309423Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.279026823Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.280663154Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:02.282910093Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:02.291691612Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:02.293684261Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:02.299899084Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:02.301621913Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:02.304957543Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:02.30675879Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:02.309711526Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:02.311704953Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:02.319471983Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:02.329763399Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.332757605Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.338426547Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.348352331Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.354842136Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.356186048Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.362949242Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.364356677Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.366804417Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.368841108Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.370231381Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.371973981Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.382517204Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.385201445Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.395902645Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.406332961Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.412836082Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.414265771Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.421912565Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.423392236Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.425813332Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.42885221Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.439028947Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.441803355Z 59 PC: 134bc | Change current directory
2018-12-25T11:55:02.446834395Z 59 PC: 134da | Change current directory
2018-12-25T11:55:02.455514511Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:02.467014673Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.473682929Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.483453238Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.49009549Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.492436804Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.498837309Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.499992277Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.503026372Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.504801172Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.514520912Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.517733744Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.528667232Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.538139604Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.544706099Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.546331139Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.552478774Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.553549507Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.555861099Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.557014364Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.558082295Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.560413747Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.56999624Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.572893264Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.578657709Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.590944445Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.597289097Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.599527702Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.605798104Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.607074079Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.610562521Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.611833767Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.613097189Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.616502384Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.626692274Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.629349778Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.635382102Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.64501977Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.656407391Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.658521323Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.664675204Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.665827394Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.668653238Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.66987059Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.671071477Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.673388323Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.683099438Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.685506575Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.691300415Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.700745163Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.707222998Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.709762677Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.716713898Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.718161948Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.721705733Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.723197606Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.724668406Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.727529313Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.737380379Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.74026657Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.747040306Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.756725132Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.76310206Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.76492216Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.771016322Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.772219254Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.775165917Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.77683789Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.789017336Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.792184706Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.797688371Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.807083759Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.814100581Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.815358496Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.821533019Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.823392349Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.825675493Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.826898048Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.828583532Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.830210537Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.839861857Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.843262372Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.853911253Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.863548308Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.870959325Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.872583827Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.879350086Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.8818316Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.884568615Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.886401935Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.896793052Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.899671436Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:02.90487921Z 78 PC: 134fa | Find first file
2018-12-25T11:55:02.916016098Z 79 PC: 1352e | Find next file
2018-12-25T11:55:02.919034313Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.923078838Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.925879155Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.928684683Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.931648078Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.934148305Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.936488358Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.939781488Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.942053802Z 59 PC: 13486 | Change current directory
2018-12-25T11:55:02.94366378Z 78 PC: 13494 | Find first file
2018-12-25T11:55:02.949811289Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:02.95353647Z 59 PC: 134da | Change current directory (See above)
2018-12-25T11:55:02.957275107Z 78 PC: 13494 | Find first file (See above)
2018-12-25T11:55:02.963975868Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:02.973048582Z 78 PC: 134fa | Find first file (See above)
2018-12-25T11:55:02.984467366Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.98750451Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.989898394Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.992399682Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.9958604Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:02.998294047Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.000742249Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.00417663Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.006496268Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.008558837Z 25 PC: 13591 | Get default drive
2018-12-25T11:55:03.012975712Z 14 PC: 135a1 | Set default drive (Drive = 'C')
2018-12-25T11:55:03.014021056Z 59 PC: 133dc | Change current directory
2018-12-25T11:55:03.017517422Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:03.023715787Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.028575258Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.358274864Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.364367777Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.365658831Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.368510187Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.370496888Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.372902565Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.374590983Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.37598284Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.377501281Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.387628185Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.388836126Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.391430686Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.393426202Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.39643522Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.397625097Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.400405538Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.401950134Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.408956606Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.417730703Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.420012538Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:03.423786139Z 59 PC: 134da | Change current directory (See above)
2018-12-25T11:55:03.42711654Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:03.432366449Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.438410398Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.447069475Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.452933437Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.454609511Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.457081799Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.458372105Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.461181655Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.462688733Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.471541342Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.474073596Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:03.477312979Z 78 PC: 134fa | Find first file (See above)
2018-12-25T11:55:03.482670647Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.484893562Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.487127096Z 59 PC: 13561 | Change current directory
2018-12-25T11:55:03.493309236Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:03.502317374Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.507662539Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.516904019Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.523078486Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.524151478Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.529366751Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.530512626Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.533026833Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.534224332Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.535409209Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.537228838Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.544997229Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.546103386Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.551936528Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.553447505Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.556335819Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.557636449Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.560180816Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.562171138Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.56960752Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.578566995Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.582532083Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.588169724Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.597214022Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.604141613Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.605444695Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.610791819Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.613089233Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.6154312Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.61670341Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.61900146Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.62047151Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.629143075Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.630424422Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.633986704Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.635406784Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.638475386Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.63960906Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.642797424Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.644068814Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.650795385Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.660254936Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.663163174Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.668570942Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.677432101Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.683754305Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.685296902Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.699774241Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.700938631Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.71126864Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.7130543Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.714346532Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.72244856Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.730861418Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.73219988Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.735235155Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.736439021Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.739717178Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.741053919Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.743594449Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.745314562Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.752107213Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.760928894Z 14 PC: 135af | Set default drive (Drive = 'A')
2018-12-25T11:55:03.762390962Z 59 PC: 135b7 | Change current directory
2018-12-25T11:55:03.763919284Z 37 PC: 135c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:03.764879668Z 42 PC: 13326 | Get date 0x13326: cmp dh, 5
0x13329: je 0x13331
0x1332b: nop
0x1332c: nop
0x1332d: nop
0x1332e: jmp 0x1335a
0x13330: nop
0x13331: cmp al, 3
0x13333: je 0x1333b
0x13335: nop
0x13336: nop
0x13337: nop
0x13338: jmp 0x1335a
0x1333a: nop
0x1333b: mov ah, 0x2c
0x1333d: int 0x21
0x1333f: cmp ch, 9
0x13342: je 0x13357
0x13344: nop
0x13345: nop
2018-12-25T11:55:03.76885754Z 37 PC: 1336a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:03.769847537Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-25T11:55:03.778437755Z 48 PC: 12a8f | Get DOS version
2018-12-25T11:55:03.782360107Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-25T11:55:03.789443841Z 93 PC: 12afe | File sharing functions
2018-12-25T11:55:03.791422153Z 9 PC: 12a86 | Display string (See above)
2018-12-25T11:55:03.795353294Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":7,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5626,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:55:02.367418988Z 48 PC: 133b1 | Get DOS version
2018-12-25T11:55:02.370192011Z 53 PC: 13408 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:02.372907876Z 37 PC: 13419 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:02.374583041Z 53 PC: 13425 | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:02.376281273Z 37 PC: 13436 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:02.379246911Z 71 PC: 13448 | Get current directory
2018-12-25T11:55:02.382639476Z 26 PC: 13457 | Set disk transfer address
2018-12-25T11:55:02.384059896Z 78 PC: 1346a | Find first file
2018-12-25T11:55:02.399725179Z 67 PC: 13667 | Get or set file attributes
2018-12-25T11:55:02.412885457Z 67 PC: 13678 | Get or set file attributes
2018-12-25T11:55:02.431016497Z 61 PC: 13683 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:02.44050338Z 87 PC: 13693 | Get or set file date and time
2018-12-25T11:55:02.443081453Z 63 PC: 136ab | Read file or device (Read 4 bytes on handle 5)
2018-12-25T11:55:02.450595001Z 66 PC: 136c5 | Move file pointer
2018-12-25T11:55:02.453504439Z 63 PC: 136d5 | Read file or device (Read 1 bytes on handle 5)
2018-12-25T11:55:02.457044165Z 66 PC: 1370e | Move file pointer
2018-12-25T11:55:02.459008105Z 66 PC: 1371c | Move file pointer
2018-12-25T11:55:02.461406638Z 66 PC: 1373b | Move file pointer
2018-12-25T11:55:02.464680935Z 64 PC: 1374e | Write file or device (Write 2480 bytes on handle 5)
2018-12-25T11:55:02.475189164Z 66 PC: 1375f | Move file pointer
2018-12-25T11:55:02.47715546Z 63 PC: 1376f | Read file or device (Read 4 bytes on handle 5)
2018-12-25T11:55:02.4926167Z 66 PC: 1377d | Move file pointer
2018-12-25T11:55:02.496831367Z 64 PC: 1378d | Write file or device (Write 4 bytes on handle 5)
2018-12-25T11:55:02.500309138Z 66 PC: 1379b | Move file pointer
2018-12-25T11:55:02.503017861Z 64 PC: 137ab | Write file or device (Write 4 bytes on handle 5)
2018-12-25T11:55:02.506314124Z 87 PC: 137bd | Get or set file date and time
2018-12-25T11:55:02.508088376Z 62 PC: 137c6 | Close file
2018-12-25T11:55:02.517828255Z 67 PC: 137d8 | Get or set file attributes
2018-12-25T11:55:02.528824956Z 79 PC: 134ac | Find next file
2018-12-25T11:55:02.533473574Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.542564626Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.554609625Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.562782431Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.5645603Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.572605967Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.574204831Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.577021254Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.579474905Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.581183026Z 62 PC: 136eb | Close file
2018-12-25T11:55:02.583187946Z 67 PC: 136fd | Get or set file attributes
2018-12-25T11:55:02.595672015Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.598843363Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.605238916Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.618329548Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.626479199Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.627979882Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.63600242Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.648704507Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.65202266Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.654033362Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.656695655Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.659079523Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.670704353Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.6754207Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.682528902Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.693897968Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.717882889Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.719622366Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.728619507Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.730905021Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.73698688Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.73902678Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.74072366Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.745374672Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.758350174Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.76159419Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.768614804Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.781831223Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.786787335Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.788522691Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:02.793954133Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:02.795357812Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:02.798479625Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:02.800249361Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:02.80182932Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:02.804523961Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:02.907270961Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:02.910619251Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:02.922663938Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:02.979152889Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:02.994958994Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:02.996339009Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.002866669Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.003980293Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.00586119Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.007900521Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.009381087Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:03.011049675Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:03.146492529Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:03.150273517Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:03.157703616Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:03.161751506Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:03.16561463Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:03.16751977Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:03.171837934Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:03.174319507Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:03.183737173Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:03.195170199Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.200295967Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.207045381Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.218416961Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.229405063Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.231364285Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.238700711Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.241056227Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.244492235Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.246419546Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.248933465Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.251034373Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.262111965Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.265476866Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.272499024Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.284302919Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.29312127Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.296373843Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.30387693Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.305806064Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.309804295Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.31261556Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.324076426Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.327202347Z 59 PC: 134bc | Change current directory
2018-12-25T11:55:03.331126104Z 59 PC: 134da | Change current directory
2018-12-25T11:55:03.33481212Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:03.341114593Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.35120273Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.372406012Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.378952037Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.380857544Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.386968423Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.388814902Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.392208465Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.39420209Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.403432238Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.407430186Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.413169885Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.42204156Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.429775016Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.431518157Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.437673498Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.440102931Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.442762299Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.44417711Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.446006578Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.447798278Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.457956395Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.460714217Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.464491141Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.472016398Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.480370861Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.482279025Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.489786429Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.49280235Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.496555291Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.498286438Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.500687363Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.503079721Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.512528586Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.515276043Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.51907774Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.527035274Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.531798668Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.53342144Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.540588332Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.543143901Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.545785865Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.547267014Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.549130099Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.551206485Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.562750822Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.566248348Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.57266978Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.585105188Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.594138134Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.59644791Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.603827004Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.605927969Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.610123136Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.611850031Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.613784473Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.616302469Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.627629871Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.631002141Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.638727493Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.649732451Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.657383983Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.660289108Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.667657892Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.669068706Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.672896428Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.674784258Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.68564477Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.689305262Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.696379672Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.707208512Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.715485964Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.717114273Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.724146744Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.7269618Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.729686654Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:03.731256324Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:03.733637389Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.735621876Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.746408985Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.75033928Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.756559073Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:03.768026128Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:03.775746781Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:03.777328876Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:03.784320652Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:03.786954148Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:03.789712625Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:03.791756078Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:03.803192709Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:03.805653205Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:03.809887528Z 78 PC: 134fa | Find first file
2018-12-25T11:55:03.817624555Z 79 PC: 1352e | Find next file
2018-12-25T11:55:03.821113602Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.824047504Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.828460422Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.831352032Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.834142143Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.838306303Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.841154072Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.844199559Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.848142186Z 59 PC: 13486 | Change current directory
2018-12-25T11:55:03.860412369Z 78 PC: 13494 | Find first file
2018-12-25T11:55:03.866997008Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:03.872723324Z 59 PC: 134da | Change current directory (See above)
2018-12-25T11:55:03.877397269Z 78 PC: 13494 | Find first file (See above)
2018-12-25T11:55:03.884112976Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:03.889546636Z 78 PC: 134fa | Find first file (See above)
2018-12-25T11:55:03.896239778Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.899168335Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.903140173Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.906402274Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.910563568Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.914420658Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.918075506Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.921828439Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.926347436Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:03.929307094Z 25 PC: 13591 | Get default drive
2018-12-25T11:55:03.930863733Z 14 PC: 135a1 | Set default drive (Drive = 'C')
2018-12-25T11:55:03.934247636Z 59 PC: 133dc | Change current directory
2018-12-25T11:55:03.939125822Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:03.946021127Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:03.952826373Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:04.304875775Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:04.312573217Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:04.314692541Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:04.320365307Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:04.32279844Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:04.32634118Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:04.329997673Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:04.331985504Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:04.334208912Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:04.34813559Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:04.350155214Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:04.353540047Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:04.356569188Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:04.360268444Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:04.361764381Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:04.365976742Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:04.367703551Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:04.375774711Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:04.38627475Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:04.389215848Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:04.394133414Z 59 PC: 134da | Change current directory (See above)
2018-12-25T11:55:04.398649121Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:04.404849575Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:04.410692913Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:04.421823017Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:04.428858835Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:04.430528131Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:04.434724358Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:04.435792129Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:04.437770473Z 62 PC: 136eb | Close file (See above)
2018-12-25T11:55:04.439404389Z 67 PC: 136fd | Get or set file attributes (See above)
2018-12-25T11:55:04.44912097Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:04.451553699Z 59 PC: 134bc | Change current directory (See above)
2018-12-25T11:55:04.456334532Z 78 PC: 134fa | Find first file (See above)
2018-12-25T11:55:04.461920524Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:04.464789351Z 79 PC: 1352e | Find next file (See above)
2018-12-25T11:55:04.468062507Z 59 PC: 13561 | Change current directory
2018-12-25T11:55:04.47453255Z 78 PC: 1346a | Find first file (See above)
2018-12-25T11:55:04.484597416Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:04.492332438Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:04.502845849Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:04.510820757Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:04.513484586Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:04.520282046Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:04.521858414Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:04.52504402Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:04.526782958Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:04.529011095Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:04.531140083Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:04.540339249Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:04.542743931Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:04.548738931Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:04.550168928Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:04.554398169Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:04.55610918Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:04.559209504Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:04.561532627Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:04.569961923Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:04.580010681Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:04.588351725Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:04.592613346Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:04.598669958Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:04.603423524Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:04.604629036Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:04.608334201Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:04.610357863Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:04.612225648Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:04.61374687Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:04.615847853Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:04.617515599Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:04.627367039Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:04.629534198Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:04.632250378Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:04.633672497Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:04.637598765Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:04.63899054Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:04.642470589Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:04.644164549Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:04.651612892Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:04.662916691Z 79 PC: 134ac | Find next file (See above)
2018-12-25T11:55:04.665244409Z 67 PC: 13667 | Get or set file attributes (See above)
2018-12-25T11:55:04.671446786Z 67 PC: 13678 | Get or set file attributes (See above)
2018-12-25T11:55:04.682302915Z 61 PC: 13683 | Open file (See above)
2018-12-25T11:55:04.691049725Z 87 PC: 13693 | Get or set file date and time (See above)
2018-12-25T11:55:04.692591472Z 63 PC: 136ab | Read file or device (See above)
2018-12-25T11:55:04.69941486Z 66 PC: 136c5 | Move file pointer (See above)
2018-12-25T11:55:04.700935681Z 63 PC: 136d5 | Read file or device (See above)
2018-12-25T11:55:04.703806885Z 66 PC: 1370e | Move file pointer (See above)
2018-12-25T11:55:04.706192101Z 66 PC: 1371c | Move file pointer (See above)
2018-12-25T11:55:04.70804956Z 66 PC: 1373b | Move file pointer (See above)
2018-12-25T11:55:04.709813609Z 64 PC: 1374e | Write file or device (See above)
2018-12-25T11:55:04.720845059Z 66 PC: 1375f | Move file pointer (See above)
2018-12-25T11:55:04.722382728Z 63 PC: 1376f | Read file or device (See above)
2018-12-25T11:55:04.725412085Z 66 PC: 1377d | Move file pointer (See above)
2018-12-25T11:55:04.727120584Z 64 PC: 1378d | Write file or device (See above)
2018-12-25T11:55:04.731311645Z 66 PC: 1379b | Move file pointer (See above)
2018-12-25T11:55:04.73343235Z 64 PC: 137ab | Write file or device (See above)
2018-12-25T11:55:04.736816191Z 87 PC: 137bd | Get or set file date and time (See above)
2018-12-25T11:55:04.738367059Z 62 PC: 137c6 | Close file (See above)
2018-12-25T11:55:04.748793975Z 67 PC: 137d8 | Get or set file attributes (See above)
2018-12-25T11:55:04.759839008Z 14 PC: 135af | Set default drive (Drive = 'A')
2018-12-25T11:55:04.761233409Z 59 PC: 135b7 | Change current directory
2018-12-25T11:55:04.763762203Z 37 PC: 135c7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T11:55:04.765108257Z 42 PC: 13326 | Get date 0x13326: cmp dh, 5
0x13329: je 0x13331
0x1332b: nop
0x1332c: nop
0x1332d: nop
0x1332e: jmp 0x1335a
0x13330: nop
0x13331: cmp al, 3
0x13333: je 0x1333b
0x13335: nop
0x13336: nop
0x13337: nop
0x13338: jmp 0x1335a
0x1333a: nop
0x1333b: mov ah, 0x2c
0x1333d: int 0x21
0x1333f: cmp ch, 9
0x13342: je 0x13357
0x13344: nop
0x13345: nop
2018-12-25T11:55:04.767506584Z 44 PC: 1333f | Get time 0x1333f: cmp ch, 9
0x13342: je 0x13357
0x13344: nop
0x13345: nop
0x13346: nop
0x13347: cmp ch, 0xa
0x1334a: je 0x13357
0x1334c: nop
0x1334d: nop
0x1334e: nop
0x1334f: cmp ch, 0xf
0x13352: jne 0x1335a
0x13354: nop
0x13355: nop
0x13356: nop
0x13357: call 0x1339d
0x1335a: ret
0x1335b: mov dx, word ptr [si + 0xa51]
0x1335f: mov ax, word ptr [si + 0xa53]
0x13363: mov ds, ax
2018-12-25T11:55:04.772381564Z 37 PC: 1336a | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records')
2018-12-25T11:55:04.77417058Z 9 PC: 12a86 | Display string (String= 'Goat file (COM/....). Size=00000834h/0000002100d bytes. ')
2018-12-25T11:55:04.780717922Z 48 PC: 12a8f | Get DOS version
2018-12-25T11:55:04.782991745Z 61 PC: 12b5c | Open file (Filename = '')
2018-12-25T11:55:04.790843594Z 93 PC: 12afe | File sharing functions
2018-12-25T11:55:04.792669113Z 9 PC: 12a86 | Display string (See above)
2018-12-25T11:55:04.804302787Z 76 PC: 12ae3 | Terminate with return code (Return code = '1')