Sample viewer




Time Syscall Op Syscall Name
2018-12-17T22:32:51.403447883Z 44 PC: 12b24 | Get time 0x12b24: cmp byte ptr [0x106], 0
0x12b29: je 0x12b2b
0x12b2b: cmp dl, 0
0x12b2e: je 0x12b20
0x12b30: mov byte ptr [0x106], dl
0x12b34: mov byte ptr [0x169], 0
0x12b39: mov byte ptr [0x16a], 2
0x12b3e: mov byte ptr [0x173], 0
0x12b43: mov cx, 0x27
0x12b46: mov dx, 0x146
0x12b49: mov ah, 0x4e
0x12b4b: int 0x21
0x12b4d: cmp ax, 0x12
0x12b50: je 0x12b55
0x12b52: call 0x12b77
0x12b55: mov cx, 0x27
0x12b58: mov dx, 0x14c
0x12b5b: mov ah, 0x4e
0x12b5d: int 0x21
0x12b5f: cmp ax, 0x12
2018-12-17T22:32:51.406487619Z 78 PC: 12b4d | Find first file
2018-12-17T22:32:51.412298338Z 67 PC: 12b98 | Get or set file attributes
2018-12-17T22:32:51.429163848Z 61 PC: 12b9e | Open file (Filename = 'TEST.EXE')
2018-12-17T22:32:51.436517393Z 63 PC: 12bad | Read file or device (Read 20 bytes on handle 5)
2018-12-17T22:32:51.439305629Z 62 PC: 12be1 | Close file
2018-12-17T22:32:51.44119061Z 61 PC: 12bea | Open file (Filename = 'TEST.EXE')
2018-12-17T22:32:51.449191497Z 64 PC: 12a65 | Write file or device (Write 666 bytes on handle 5)
2018-12-17T22:32:51.454973831Z 87 PC: 12c12 | Get or set file date and time
2018-12-17T22:32:51.456075081Z 62 PC: 12c1a | Close file
2018-12-17T22:32:51.461232675Z 67 PC: 12c27 | Get or set file attributes
2018-12-17T22:32:51.46740513Z 79 PC: 12bd1 | Find next file
2018-12-17T22:32:51.471760107Z 78 PC: 12b5f | Find first file
2018-12-17T22:32:51.476510323Z 67 PC: 12b98 | Get or set file attributes
2018-12-17T22:32:51.483748244Z 61 PC: 12b9e | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:51.490306867Z 63 PC: 12bad | Read file or device (Read 20 bytes on handle 5)
2018-12-17T22:32:51.496782101Z 62 PC: 12be1 | Close file
2018-12-17T22:32:51.499362152Z 61 PC: 12bea | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:32:51.506496987Z 64 PC: 12a65 | Write file or device (Write 666 bytes on handle 5)
2018-12-17T22:32:51.515125302Z 87 PC: 12c12 | Get or set file date and time
2018-12-17T22:32:51.51804179Z 62 PC: 12c1a | Close file
2018-12-17T22:32:51.525931537Z 67 PC: 12c27 | Get or set file attributes