Sample viewer

vx.netlux.org/Virus.DOS.Vienna.Skate.215

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:32:39.078940821Z 26 PC: 12a5c | Set disk transfer address
2018-12-17T22:32:39.08043233Z 78 PC: 12a67 | Find first file
2018-12-17T22:32:39.088678182Z 61 PC: 12a74 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:39.096185776Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.098642319Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.106750789Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.108567863Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.122691364Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.136403572Z 61 PC: 12ac5 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:39.144344533Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.152327725Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.155042078Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.16343779Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.1663405Z 61 PC: 12a74 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:32:39.173791803Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.176070097Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.183544775Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.185518548Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.18921768Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.197768687Z 61 PC: 12ac5 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:32:39.208256819Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.21198989Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.213670078Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.224555706Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.228774408Z 61 PC: 12a74 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:32:39.23604886Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.237622073Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.258850111Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.26066752Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.264444954Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.273974242Z 61 PC: 12ac5 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:32:39.282484056Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.285498035Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.287152422Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.295347495Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.299129362Z 61 PC: 12a74 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:32:39.306598195Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.309471845Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.3165202Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.317899718Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.321538119Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.469647413Z 61 PC: 12ac5 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:32:39.476970291Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.480764278Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.482589529Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.568216994Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.571674556Z 61 PC: 12a74 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:32:39.578904349Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.580309335Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.587727377Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.589301813Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.592108247Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.716290597Z 61 PC: 12ac5 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:32:39.725628682Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.728877389Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.730991704Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.737635734Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.740562625Z 61 PC: 12a74 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:32:39.753493897Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.756020038Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.763312229Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.765256414Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.775248717Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.784767587Z 61 PC: 12ac5 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:32:39.792292084Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.806891463Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.808768712Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.817049692Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.820765673Z 61 PC: 12a74 | Open file (Filename = 'PAH.COM')
2018-12-17T22:32:39.828192637Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.82992383Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.837036191Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.839361595Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.842614568Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.85127189Z 61 PC: 12ac5 | Open file (Filename = 'PAH.COM')
2018-12-17T22:32:39.859992751Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.864140298Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.865741742Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.874011128Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.876869924Z 61 PC: 12a74 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:39.88451214Z 87 PC: 12a7b | Get or set file date and time
2018-12-17T22:32:39.886973104Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-17T22:32:39.894024171Z 66 PC: 12a93 | Move file pointer
2018-12-17T22:32:39.895642948Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-17T22:32:39.899610273Z 62 PC: 12aba | Close file
2018-12-17T22:32:39.907931366Z 61 PC: 12ac5 | Open file (Filename = 'TEST.COM')
2018-12-17T22:32:39.912734465Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T22:32:39.915177592Z 87 PC: 12adb | Get or set file date and time
2018-12-17T22:32:39.91690303Z 62 PC: 12adf | Close file
2018-12-17T22:32:39.924680236Z 79 PC: 12ae3 | Find next file
2018-12-17T22:32:39.931203032Z 42 PC: 12ae9 | Get date 0x12ae9: cmp dx, 0x511
0x12aed: jne 0x12af1
0x12aef: int 0x20
0x12af1: pop cx
0x12af2: xor ax, ax
0x12af4: xor bx, bx
0x12af6: xor cx, cx
0x12af8: xor dx, dx
0x12afa: nop
0x12afb: xor si, si
0x12afd: mov di, 0x100
0x12b00: nop
0x12b01: push di
0x12b02: xor di, di
0x12b04: ret 0xffff
0x12b07: jmp 0x12b0b
0x12b09: nop
0x12b0a: jmp 0x12be5
0x12b0d: sub ch, byte ptr [0x4f43]
0x12b11: dec bp

{"DateBased":true,"Day":17,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5833,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:55:30.673079202Z 26 PC: 12a5c | Set disk transfer address
2018-12-25T11:55:30.676074581Z 78 PC: 12a67 | Find first file
2018-12-25T11:55:30.68310081Z 61 PC: 12a74 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:30.690801304Z 87 PC: 12a7b | Get or set file date and time
2018-12-25T11:55:30.693725429Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:55:30.712746724Z 66 PC: 12a93 | Move file pointer
2018-12-25T11:55:30.714494085Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-25T11:55:30.728625657Z 62 PC: 12aba | Close file
2018-12-25T11:55:30.735459082Z 61 PC: 12ac5 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:30.742764456Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:55:30.750084753Z 87 PC: 12adb | Get or set file date and time
2018-12-25T11:55:30.772527643Z 62 PC: 12adf | Close file
2018-12-25T11:55:30.781052969Z 79 PC: 12ae3 | Find next file
2018-12-25T11:55:30.784250393Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:30.792319096Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:30.794113865Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:30.801637252Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:30.804393971Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:30.807984858Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:30.816795596Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:30.830196182Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:30.834226217Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:30.836255569Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:30.844214468Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:30.848251587Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:30.855550436Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:30.857308172Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:30.865323503Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:30.866964776Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:30.869938869Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:30.879571584Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:30.887062322Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:30.890148118Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:30.892462177Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:30.900784327Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:30.903892789Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:30.911540681Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:30.913260318Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:30.9202831Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:30.922144721Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:30.925913871Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:30.935144427Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:30.942681575Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:30.946509656Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:30.948494264Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:30.956752466Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:30.960389596Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:30.968190204Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:30.970218595Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:30.978797674Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:30.98127336Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:30.984706469Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:30.994062775Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.001952055Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.004739008Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.006347571Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.014454801Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.017385184Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.024674015Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.02668787Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.03360308Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.034898105Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.04342008Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.053026514Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.06112458Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.068839765Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.070830013Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.078699546Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.082202896Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.089432817Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.09067778Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.098268553Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.099774406Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.10260375Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.112037965Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.119408909Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.122290212Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.123918875Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.132948669Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.135609996Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.142895239Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.14554641Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.148395816Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.149970981Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.153974501Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.162635669Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.170010226Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.174192657Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.175897749Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.184248714Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.187764609Z 42 PC: 12ae9 | Get date 0x12ae9: cmp dx, 0x511
0x12aed: jne 0x12af1
0x12aef: int 0x20
0x12af1: pop cx
0x12af2: xor ax, ax
0x12af4: xor bx, bx
0x12af6: xor cx, cx
0x12af8: xor dx, dx
0x12afa: nop
0x12afb: xor si, si
0x12afd: mov di, 0x100
0x12b00: nop
0x12b01: push di
0x12b02: xor di, di
0x12b04: ret 0xffff
0x12b07: jmp 0x12b0b
0x12b09: nop
0x12b0a: jmp 0x12be5
0x12b0d: sub ch, byte ptr [0x4f43]
0x12b11: dec bp

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5833,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:55:31.342936152Z 26 PC: 12a5c | Set disk transfer address
2018-12-25T11:55:31.3505043Z 78 PC: 12a67 | Find first file
2018-12-25T11:55:31.356542495Z 61 PC: 12a74 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:31.367032705Z 87 PC: 12a7b | Get or set file date and time
2018-12-25T11:55:31.375985491Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:55:31.382514852Z 66 PC: 12a93 | Move file pointer
2018-12-25T11:55:31.383965974Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-25T11:55:31.397985092Z 62 PC: 12aba | Close file
2018-12-25T11:55:31.406461545Z 61 PC: 12ac5 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:31.413125953Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:55:31.419800285Z 87 PC: 12adb | Get or set file date and time
2018-12-25T11:55:31.422000259Z 62 PC: 12adf | Close file
2018-12-25T11:55:31.429577958Z 79 PC: 12ae3 | Find next file
2018-12-25T11:55:31.433049491Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.440683408Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.442187431Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.44859325Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.451171795Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.454424154Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.462320051Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.469473924Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.472275683Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.473676885Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.481602796Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.4853429Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.492491316Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.494739068Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.500954142Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.502339264Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.506081084Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.514649538Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.521161857Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.524098328Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.526096826Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.533414186Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.538678084Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.547421207Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.548874104Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.55580212Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.558484325Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.5612959Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.573679595Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.581369363Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.584115448Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.585582755Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.594817562Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.597656805Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.604678041Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.607023936Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.613121529Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.61443947Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.617739457Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.625869729Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.632706364Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.6367743Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.638469973Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.645667938Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.649039842Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.655746603Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.657003728Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.663415818Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.664895558Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.672889552Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.681227183Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.693685785Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.700382367Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.702148272Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.71109399Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.713671871Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.719527123Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.721354548Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.725298829Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.726484304Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.729603846Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.735632872Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.740552748Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.743409057Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.74475363Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.750359098Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.761718636Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.768577927Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.769863001Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.776618808Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.777947053Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.78065249Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.788762988Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.79535191Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.798158227Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.800259689Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.8075928Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.809916655Z 42 PC: 12ae9 | Get date 0x12ae9: cmp dx, 0x511
0x12aed: jne 0x12af1
0x12aef: int 0x20
0x12af1: pop cx
0x12af2: xor ax, ax
0x12af4: xor bx, bx
0x12af6: xor cx, cx
0x12af8: xor dx, dx
0x12afa: nop
0x12afb: xor si, si
0x12afd: mov di, 0x100
0x12b00: nop
0x12b01: push di
0x12b02: xor di, di
0x12b04: ret 0xffff
0x12b07: jmp 0x12b0b
0x12b09: nop
0x12b0a: jmp 0x12be5
0x12b0d: sub ch, byte ptr [0x4f43]
0x12b11: dec bp

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5833,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:55:31.420778443Z 26 PC: 12a5c | Set disk transfer address
2018-12-25T11:55:31.423040606Z 78 PC: 12a67 | Find first file
2018-12-25T11:55:31.428532479Z 61 PC: 12a74 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:31.434664451Z 87 PC: 12a7b | Get or set file date and time
2018-12-25T11:55:31.436492392Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:55:31.442821226Z 66 PC: 12a93 | Move file pointer
2018-12-25T11:55:31.444448159Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-25T11:55:31.47116704Z 62 PC: 12aba | Close file
2018-12-25T11:55:31.478992738Z 61 PC: 12ac5 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:31.485316463Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:55:31.492068695Z 87 PC: 12adb | Get or set file date and time
2018-12-25T11:55:31.493574929Z 62 PC: 12adf | Close file
2018-12-25T11:55:31.500746972Z 79 PC: 12ae3 | Find next file
2018-12-25T11:55:31.504059629Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.514902067Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.523106862Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.529534805Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.531023163Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.533617959Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.54084973Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.552611285Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.558433915Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.560082987Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.573370686Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.576086368Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.582551474Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.584829809Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.591840926Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.59452545Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.598520475Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.606797628Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.613663465Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.618269658Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.619833198Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.627499256Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.630455692Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.636535181Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.63785116Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.644281973Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.645704712Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.648641864Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.656608142Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.663066028Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.665584177Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.667071402Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.675419335Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.677942629Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.689578358Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.691922848Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.696759036Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.698387345Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.702099618Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.709565031Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.713865615Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.71624233Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.717507049Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.722778237Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.725380321Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.731650412Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.73278777Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.739751739Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.741376968Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.749759537Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.758289375Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.764512815Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.770780243Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.772662407Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.779615519Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.782015907Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.788744952Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.789938678Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.796199642Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.798683614Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.801300751Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.809013815Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.821051552Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.827671147Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.829108498Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.836949983Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.839415972Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.845832466Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.847846039Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.853986966Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.855416516Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.859149673Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.867340957Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.87392265Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.877300666Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.880041576Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.887425846Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.890710456Z 42 PC: 12ae9 | Get date 0x12ae9: cmp dx, 0x511
0x12aed: jne 0x12af1
0x12aef: int 0x20
0x12af1: pop cx
0x12af2: xor ax, ax
0x12af4: xor bx, bx
0x12af6: xor cx, cx
0x12af8: xor dx, dx
0x12afa: nop
0x12afb: xor si, si
0x12afd: mov di, 0x100
0x12b00: nop
0x12b01: push di
0x12b02: xor di, di
0x12b04: ret 0xffff
0x12b07: jmp 0x12b0b
0x12b09: nop
0x12b0a: jmp 0x12be5
0x12b0d: sub ch, byte ptr [0x4f43]
0x12b11: dec bp

{"DateBased":true,"Day":17,"Month":5,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":5833,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:55:31.591408297Z 26 PC: 12a5c | Set disk transfer address
2018-12-25T11:55:31.597898823Z 78 PC: 12a67 | Find first file
2018-12-25T11:55:31.603724252Z 61 PC: 12a74 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:31.609853931Z 87 PC: 12a7b | Get or set file date and time
2018-12-25T11:55:31.611759Z 63 PC: 12a8a | Read file or device (Read 3 bytes on handle 5)
2018-12-25T11:55:31.617954933Z 66 PC: 12a93 | Move file pointer
2018-12-25T11:55:31.619657734Z 64 PC: 12ab5 | Write file or device (Write 215 bytes on handle 5)
2018-12-25T11:55:31.634736804Z 62 PC: 12aba | Close file
2018-12-25T11:55:31.643375614Z 61 PC: 12ac5 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:55:31.648819799Z 64 PC: 12ad2 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:55:31.653181355Z 87 PC: 12adb | Get or set file date and time
2018-12-25T11:55:31.656077853Z 62 PC: 12adf | Close file
2018-12-25T11:55:31.675117329Z 79 PC: 12ae3 | Find next file
2018-12-25T11:55:31.678035239Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.685488849Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.687469282Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.69583563Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.698636657Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.703260632Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.710796919Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.718373024Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.721269766Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.722809612Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.740316196Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.742968956Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.749068676Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.750799618Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.756847214Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.758845199Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.763289796Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.770633707Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.775687449Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.778643834Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.780671459Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.788068851Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.793225595Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.805811789Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.808244358Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.815086254Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.819232683Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.824188218Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.831977529Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.842355766Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.845406739Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.84739288Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.854927538Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.857374023Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.864014832Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.865280238Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.87160423Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.873109876Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.875955402Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.883471376Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.890458787Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.893194461Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.894507213Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.901621497Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.904383237Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.910638037Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.912182504Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.91888089Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.920113894Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.927847998Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.936469668Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:31.942814102Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:31.949028706Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:31.952071355Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:31.959396281Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:31.962320362Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:31.969894431Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:31.971480662Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:31.977988205Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:31.980636998Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:31.983555621Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:31.991402217Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:32.004468092Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:32.010785638Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:32.012109912Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:32.019472567Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:32.02129795Z 61 PC: 12a74 | Open file (See above)
2018-12-25T11:55:32.025236703Z 87 PC: 12a7b | Get or set file date and time (See above)
2018-12-25T11:55:32.026491782Z 63 PC: 12a8a | Read file or device (See above)
2018-12-25T11:55:32.030500927Z 66 PC: 12a93 | Move file pointer (See above)
2018-12-25T11:55:32.031443898Z 64 PC: 12ab5 | Write file or device (See above)
2018-12-25T11:55:32.033485474Z 62 PC: 12aba | Close file (See above)
2018-12-25T11:55:32.038451407Z 61 PC: 12ac5 | Open file (See above)
2018-12-25T11:55:32.042906183Z 64 PC: 12ad2 | Write file or device (See above)
2018-12-25T11:55:32.045419444Z 87 PC: 12adb | Get or set file date and time (See above)
2018-12-25T11:55:32.046674528Z 62 PC: 12adf | Close file (See above)
2018-12-25T11:55:32.054137411Z 79 PC: 12ae3 | Find next file (See above)
2018-12-25T11:55:32.063790068Z 42 PC: 12ae9 | Get date 0x12ae9: cmp dx, 0x511
0x12aed: jne 0x12af1
0x12aef: int 0x20
0x12af1: pop cx
0x12af2: xor ax, ax
0x12af4: xor bx, bx
0x12af6: xor cx, cx
0x12af8: xor dx, dx
0x12afa: nop
0x12afb: xor si, si
0x12afd: mov di, 0x100
0x12b00: nop
0x12b01: push di
0x12b02: xor di, di
0x12b04: ret 0xffff
0x12b07: jmp 0x12b0b
0x12b09: nop
0x12b0a: jmp 0x12be5
0x12b0d: sub ch, byte ptr [0x4f43]
0x12b11: dec bp