Sample viewer




Time Syscall Op Syscall Name
2018-12-17T21:55:37.964465656Z 44 PC: 12b6e | Get time 0x12b6e: cmp byte ptr [0x103], 0
0x12b73: je 0x12b7a
0x12b75: cmp dh, 0xf
0x12b78: jg 0x12b83
0x12b7a: cmp dl, 0
0x12b7d: je 0x12b6a
0x12b7f: mov byte ptr [0x103], dl
0x12b83: mov byte ptr [0x21f], 0
0x12b88: mov byte ptr [0x220], 4
0x12b8d: mov byte ptr [0x229], 0
0x12b92: mov cx, 0x27
0x12b95: mov dx, 0x115
0x12b98: mov ah, 0x4e
0x12b9a: int 0x21
0x12b9c: cmp ax, 0x12
0x12b9f: je 0x12ba4
0x12ba1: call 0x12bc6
0x12ba4: mov cx, 0x27
0x12ba7: mov dx, 0x11b
0x12baa: mov ah, 0x4e
2018-12-17T21:55:37.966208304Z 78 PC: 12b9c | Find first file
2018-12-17T21:55:37.970218729Z 78 PC: 12bae | Find first file
2018-12-17T21:55:37.973855427Z 67 PC: 12be7 | Get or set file attributes
2018-12-17T21:55:39.280136766Z 61 PC: 12bed | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:55:39.286616984Z 63 PC: 12bfc | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:55:39.292922175Z 62 PC: 12c30 | Close file
2018-12-17T21:55:39.294674978Z 61 PC: 12c39 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:55:39.298764518Z 64 PC: 12a54 | Write file or device (Write 625 bytes on handle 5)
2018-12-17T21:55:39.398487926Z 87 PC: 12c61 | Get or set file date and time
2018-12-17T21:55:39.400302637Z 62 PC: 12c69 | Close file
2018-12-17T21:55:39.407956788Z 67 PC: 12c76 | Get or set file attributes
2018-12-17T21:55:39.412639876Z 79 PC: 12c20 | Find next file
2018-12-17T21:55:39.415381254Z 67 PC: 12be7 | Get or set file attributes
2018-12-17T21:55:39.428618254Z 61 PC: 12bed | Open file (Filename = 'PRINT.COM')
2018-12-17T21:55:39.434954736Z 63 PC: 12bfc | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:55:39.441059999Z 62 PC: 12c30 | Close file
2018-12-17T21:55:39.44329653Z 61 PC: 12c39 | Open file (Filename = 'PRINT.COM')
2018-12-17T21:55:39.449656804Z 64 PC: 12a54 | Write file or device (Write 625 bytes on handle 5)
2018-12-17T21:55:39.45733404Z 87 PC: 12c61 | Get or set file date and time
2018-12-17T21:55:39.459139438Z 62 PC: 12c69 | Close file
2018-12-17T21:55:39.466485908Z 67 PC: 12c76 | Get or set file attributes
2018-12-17T21:55:39.470997647Z 79 PC: 12c20 | Find next file
2018-12-17T21:55:39.474549981Z 67 PC: 12be7 | Get or set file attributes
2018-12-17T21:55:39.486248955Z 61 PC: 12bed | Open file (Filename = 'HELLO.COM')
2018-12-17T21:55:39.493175628Z 63 PC: 12bfc | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:55:39.499725208Z 62 PC: 12c30 | Close file
2018-12-17T21:55:39.501340411Z 61 PC: 12c39 | Open file (Filename = 'HELLO.COM')
2018-12-17T21:55:39.507785616Z 64 PC: 12a54 | Write file or device (Write 625 bytes on handle 5)
2018-12-17T21:55:39.515938103Z 87 PC: 12c61 | Get or set file date and time
2018-12-17T21:55:39.517382722Z 62 PC: 12c69 | Close file
2018-12-17T21:55:39.524948724Z 67 PC: 12c76 | Get or set file attributes
2018-12-17T21:55:39.53068505Z 79 PC: 12c20 | Find next file
2018-12-17T21:55:39.533322243Z 67 PC: 12be7 | Get or set file attributes
2018-12-17T21:55:39.543277001Z 61 PC: 12bed | Open file (Filename = 'PHANG.COM')
2018-12-17T21:55:39.554634759Z 63 PC: 12bfc | Read file or device (Read 20 bytes on handle 5)
2018-12-17T21:55:39.560891438Z 62 PC: 12c30 | Close file
2018-12-17T21:55:39.562523591Z 61 PC: 12c39 | Open file (Filename = 'PHANG.COM')
2018-12-17T21:55:39.568744324Z 64 PC: 12a54 | Write file or device (Write 625 bytes on handle 5)
2018-12-17T21:55:39.575340532Z 87 PC: 12c61 | Get or set file date and time
2018-12-17T21:55:39.576874672Z 62 PC: 12c69 | Close file
2018-12-17T21:55:39.58444486Z 67 PC: 12c76 | Get or set file attributes
2018-12-17T21:55:39.589498282Z 9 PC: 12ca4 | Display string (String= ' Error #2693 - Execution Halted')
2018-12-17T21:55:39.594082062Z 76 PC: 12ca8 | Terminate with return code (Return code = '36')