Sample viewer

vx.netlux.org/Virus.DOS.Riot.BluePoison.487

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:38:00.559110981Z 26 PC: 154be | Set disk transfer address
2018-12-17T22:38:00.560857691Z 71 PC: 15383 | Get current directory
2018-12-17T22:38:00.576041767Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.582017104Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-17T22:38:00.588651514Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.594591933Z 65 PC: 154b7 | Delete file (Filename = 'ANTI-VIR.DAT')
2018-12-17T22:38:00.601732094Z 78 PC: 154be | Find first file
2018-12-17T22:38:00.617217769Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.633933754Z 67 PC: 15410 | Get or set file attributes
2018-12-17T22:38:00.650190687Z 61 PC: 154be | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:38:00.658386275Z 87 PC: 15421 | Get or set file date and time
2018-12-17T22:38:00.659724287Z 63 PC: 154be | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:38:00.666305518Z 66 PC: 1543f | Move file pointer
2018-12-17T22:38:00.668949469Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:38:00.677436951Z 66 PC: 15466 | Move file pointer
2018-12-17T22:38:00.679691787Z 64 PC: 154be | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:38:00.68595398Z 87 PC: 15478 | Get or set file date and time
2018-12-17T22:38:00.688759021Z 62 PC: 1547c | Close file
2018-12-17T22:38:00.697895523Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.707535358Z 79 PC: 154be | Find next file
2018-12-17T22:38:00.710831559Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.716452865Z 67 PC: 15410 | Get or set file attributes
2018-12-17T22:38:00.726268182Z 61 PC: 154be | Open file (Filename = 'PRINT.COM')
2018-12-17T22:38:00.734557207Z 87 PC: 15421 | Get or set file date and time
2018-12-17T22:38:00.735938848Z 63 PC: 154be | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:38:00.742073683Z 66 PC: 1543f | Move file pointer
2018-12-17T22:38:00.744340533Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:38:00.752836479Z 66 PC: 15466 | Move file pointer
2018-12-17T22:38:00.754860828Z 64 PC: 154be | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:38:00.762727382Z 87 PC: 15478 | Get or set file date and time
2018-12-17T22:38:00.764511702Z 62 PC: 1547c | Close file
2018-12-17T22:38:00.771955751Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.782301884Z 79 PC: 154be | Find next file
2018-12-17T22:38:00.785645959Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.791234056Z 67 PC: 15410 | Get or set file attributes
2018-12-17T22:38:00.808812625Z 61 PC: 154be | Open file (Filename = 'HELLO.COM')
2018-12-17T22:38:00.820951096Z 87 PC: 15421 | Get or set file date and time
2018-12-17T22:38:00.8226354Z 63 PC: 154be | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:38:00.829626655Z 66 PC: 1543f | Move file pointer
2018-12-17T22:38:00.832357921Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:38:00.840641386Z 66 PC: 15466 | Move file pointer
2018-12-17T22:38:00.842264549Z 64 PC: 154be | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:38:00.849763581Z 87 PC: 15478 | Get or set file date and time
2018-12-17T22:38:00.851317605Z 62 PC: 1547c | Close file
2018-12-17T22:38:00.858988657Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.869658662Z 79 PC: 154be | Find next file
2018-12-17T22:38:00.872292699Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.87803623Z 67 PC: 15410 | Get or set file attributes
2018-12-17T22:38:00.889588087Z 61 PC: 154be | Open file (Filename = 'PHANG.COM')
2018-12-17T22:38:00.896388758Z 87 PC: 15421 | Get or set file date and time
2018-12-17T22:38:00.898085353Z 63 PC: 154be | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:38:00.905500613Z 66 PC: 1543f | Move file pointer
2018-12-17T22:38:00.907740008Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:38:00.915864084Z 66 PC: 15466 | Move file pointer
2018-12-17T22:38:00.918161832Z 64 PC: 154be | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:38:00.924572437Z 87 PC: 15478 | Get or set file date and time
2018-12-17T22:38:00.926312373Z 62 PC: 1547c | Close file
2018-12-17T22:38:00.934994701Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.945350142Z 79 PC: 154be | Find next file
2018-12-17T22:38:00.948781729Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:00.955905128Z 67 PC: 15410 | Get or set file attributes
2018-12-17T22:38:00.966068949Z 61 PC: 154be | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:38:00.973083848Z 87 PC: 15421 | Get or set file date and time
2018-12-17T22:38:00.975422772Z 63 PC: 154be | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:38:00.981564872Z 66 PC: 1543f | Move file pointer
2018-12-17T22:38:00.983360243Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:38:00.992863912Z 66 PC: 15466 | Move file pointer
2018-12-17T22:38:00.994015302Z 64 PC: 154be | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:38:00.998446455Z 87 PC: 15478 | Get or set file date and time
2018-12-17T22:38:01.00015532Z 62 PC: 1547c | Close file
2018-12-17T22:38:01.005139848Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:01.011259712Z 79 PC: 154be | Find next file
2018-12-17T22:38:01.013964145Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:01.017634653Z 67 PC: 15410 | Get or set file attributes
2018-12-17T22:38:01.025887534Z 61 PC: 154be | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:38:01.031300035Z 87 PC: 15421 | Get or set file date and time
2018-12-17T22:38:01.032526467Z 63 PC: 154be | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:38:01.036665165Z 66 PC: 1543f | Move file pointer
2018-12-17T22:38:01.038369488Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:38:01.043917666Z 66 PC: 15466 | Move file pointer
2018-12-17T22:38:01.04688137Z 64 PC: 154be | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:38:01.054633214Z 87 PC: 15478 | Get or set file date and time
2018-12-17T22:38:01.056041055Z 62 PC: 1547c | Close file
2018-12-17T22:38:01.063766819Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:01.074012282Z 79 PC: 154be | Find next file
2018-12-17T22:38:01.076505195Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:01.082043862Z 67 PC: 15410 | Get or set file attributes
2018-12-17T22:38:01.092186529Z 61 PC: 154be | Open file (Filename = 'PAH.COM')
2018-12-17T22:38:01.099085252Z 87 PC: 15421 | Get or set file date and time
2018-12-17T22:38:01.100409878Z 63 PC: 154be | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:38:01.107543532Z 66 PC: 1543f | Move file pointer
2018-12-17T22:38:01.109041309Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-17T22:38:01.116955311Z 66 PC: 15466 | Move file pointer
2018-12-17T22:38:01.118944044Z 64 PC: 154be | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:38:01.125273004Z 87 PC: 15478 | Get or set file date and time
2018-12-17T22:38:01.126665798Z 62 PC: 1547c | Close file
2018-12-17T22:38:01.134499268Z 67 PC: 154be | Get or set file attributes
2018-12-17T22:38:01.145402683Z 79 PC: 154be | Find next file
2018-12-17T22:38:01.147797011Z 59 PC: 154be | Change current directory
2018-12-17T22:38:01.152386946Z 59 PC: 154be | Change current directory
2018-12-17T22:38:01.154903698Z 26 PC: 153b2 | Set disk transfer address
2018-12-17T22:38:01.155895873Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-17T22:38:01.158567654Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-17T22:38:01.161524482Z 26 PC: 1524a | Set disk transfer address
2018-12-17T22:38:01.162532392Z 71 PC: 1525d | Get current directory
2018-12-17T22:38:01.165286809Z 78 PC: 15252 | Find first file
2018-12-17T22:38:01.171864659Z 61 PC: 15252 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:38:01.178845462Z 63 PC: 15252 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:38:01.185233565Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.187695912Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.189184231Z 64 PC: 15252 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:38:01.192389004Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.194946824Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-17T22:38:01.203498733Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.205129989Z 62 PC: 15252 | Close file
2018-12-17T22:38:01.213812074Z 79 PC: 15252 | Find next file
2018-12-17T22:38:01.216338701Z 61 PC: 15252 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:38:01.223479674Z 63 PC: 15252 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:38:01.230883218Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.232400144Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.233773108Z 64 PC: 15252 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:38:01.236311746Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.237767658Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-17T22:38:01.242531814Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.243764183Z 62 PC: 15252 | Close file
2018-12-17T22:38:01.249181337Z 79 PC: 15252 | Find next file
2018-12-17T22:38:01.250973353Z 61 PC: 15252 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:38:01.256004935Z 63 PC: 15252 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:38:01.258273075Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.259327166Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.261068052Z 64 PC: 15252 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:38:01.262794626Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.26410439Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-17T22:38:01.270197645Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.271519841Z 62 PC: 15252 | Close file
2018-12-17T22:38:01.277079267Z 79 PC: 15252 | Find next file
2018-12-17T22:38:01.279385393Z 61 PC: 15252 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:38:01.283711328Z 63 PC: 15252 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:38:01.285530301Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.286882712Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.287829752Z 64 PC: 15252 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:38:01.289579885Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.291161835Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-17T22:38:01.293273284Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.294528697Z 62 PC: 15252 | Close file
2018-12-17T22:38:01.30053689Z 79 PC: 15252 | Find next file
2018-12-17T22:38:01.302529438Z 61 PC: 15252 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:38:01.306906859Z 63 PC: 15252 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:38:01.309784134Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.310849449Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.311891337Z 64 PC: 15252 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:38:01.314182209Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.315248116Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-17T22:38:01.317467872Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.319119235Z 62 PC: 15252 | Close file
2018-12-17T22:38:01.324000226Z 79 PC: 15252 | Find next file
2018-12-17T22:38:01.325691749Z 61 PC: 15252 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:38:01.329990471Z 63 PC: 15252 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:38:01.332458675Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.333690765Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.33627542Z 64 PC: 15252 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:38:01.33898541Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.340766558Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-17T22:38:01.349958434Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.351300081Z 62 PC: 15252 | Close file
2018-12-17T22:38:01.444288831Z 79 PC: 15252 | Find next file
2018-12-17T22:38:01.447100523Z 61 PC: 15252 | Open file (Filename = 'PAH.COM')
2018-12-17T22:38:01.455533361Z 63 PC: 15252 | Read file or device (Read 6 bytes on handle 5)
2018-12-17T22:38:01.460596631Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.462322739Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.463332705Z 64 PC: 15252 | Write file or device (Write 6 bytes on handle 5)
2018-12-17T22:38:01.465585305Z 66 PC: 15252 | Move file pointer
2018-12-17T22:38:01.467395599Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-17T22:38:01.472292299Z 87 PC: 15252 | Get or set file date and time
2018-12-17T22:38:01.473741886Z 62 PC: 15252 | Close file
2018-12-17T22:38:01.567481437Z 79 PC: 15252 | Find next file
2018-12-17T22:38:01.570637583Z 59 PC: 1523e | Change current directory
2018-12-17T22:38:01.574989926Z 59 PC: 15266 | Change current directory
2018-12-17T22:38:01.579570541Z 26 PC: 1524a | Set disk transfer address
2018-12-17T22:38:01.580903419Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-17T22:38:01.58340718Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:48.386055522Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:48.395097931Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:48.398593211Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.405129972Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:48.411743839Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.419336931Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:48.431248209Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:48.443839961Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.45212114Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:49.175617013Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.183819148Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:49.186038857Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.196774694Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:49.198271962Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:49.207490274Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:49.208889317Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.213461661Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:49.215583475Z 62 PC: 1547c | Close file
2018-12-25T11:59:49.224423588Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.236475918Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.240030358Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.245558948Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.26362529Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.271335266Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.273155581Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.280295726Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.282223965Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.291415135Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.29293558Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.300488256Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.302527996Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.311478755Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.322728389Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.326438387Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.33290607Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.343787795Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.358156828Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.360166116Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.367278648Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.369967815Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.379295042Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.381275906Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.389291339Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.391752627Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.400967246Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.412261364Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.415383101Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.421687129Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.43306823Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.441484328Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.442976769Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.450247635Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.452853733Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.462087143Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.463824625Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.471608386Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.473490244Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.482173492Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.494732836Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.497659769Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.503846838Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.515356171Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.523231389Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.524924295Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.532804516Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.534479471Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.54323951Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.544824704Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.552760855Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.554283335Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.563174308Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.576103347Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.57801952Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.582038926Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.589943456Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.601101202Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.603160026Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.611820375Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.61393235Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.624420447Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.627187508Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.633973551Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.635808363Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.644554634Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.654833685Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.65760767Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.661833748Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.674264594Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.689270057Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.691243005Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.69963257Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.701916477Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.712975018Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.715816714Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.723834105Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.725890019Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.73598271Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.747621875Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.750387076Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.75567643Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.757967508Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:49.759106637Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:49.762663276Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:49.766364301Z 26 PC: 1524a | Set disk transfer address
2018-12-25T11:59:49.767928079Z 71 PC: 1525d | Get current directory
2018-12-25T11:59:49.77157418Z 78 PC: 15252 | Find first file
2018-12-25T11:59:49.779733427Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.787659538Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.794930466Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.797680503Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.799298265Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.802121088Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.804472964Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-25T11:59:49.814488391Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.817434857Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.827306492Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:49.830683472Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.838130832Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.845720937Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.848423633Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.850326789Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.853755117Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.856707821Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:49.865154136Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.874501699Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.884648339Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:49.888444752Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.896781596Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.90529405Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.907523216Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.909431448Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.913123906Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.915121422Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:49.925242518Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.928061827Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.946961269Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:49.951823093Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.960538799Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.970110638Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.971813408Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.973972777Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.97806653Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.979791507Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:49.988804375Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.991073103Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.99941553Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.002452937Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.010430115Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.017836817Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.020444553Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.022143576Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.025265591Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.027487168Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.036347095Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.037996462Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.047004028Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.050668657Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.058379435Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.066212788Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.068155222Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.069623153Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.072031383Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.074191499Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.085246865Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.087409019Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.096729677Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.099498725Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.106850897Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.110105734Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.111777571Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.113503225Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.11797694Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.119713358Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.123215624Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.125451038Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.133090276Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.134882951Z 59 PC: 1523e | Change current directory
2018-12-25T11:59:50.138436262Z 59 PC: 15266 | Change current directory
2018-12-25T11:59:50.148806828Z 26 PC: 1524a | Set disk transfer address (See above)
2018-12-25T11:59:50.150314034Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T11:59:50.15352995Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:48.609457698Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:48.611208309Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:48.613111374Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.616897746Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:48.624710537Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.628324118Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:48.631923195Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:48.636240114Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.639815052Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:49.180968902Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.200136598Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:49.202100003Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.210442733Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:49.217720897Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:49.231412174Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:49.233342387Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.24156377Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:49.243675713Z 62 PC: 1547c | Close file
2018-12-25T11:59:49.264014375Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.278679354Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.282944232Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.28881756Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.300793702Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.307611574Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.308820881Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.314329572Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.316367347Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.32337115Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.324602456Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.330294915Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.331628186Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.338112266Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.346068916Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.355010044Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.362375062Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.37911878Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.386789236Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.38901687Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.396725076Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.399009756Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.40929926Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.411122206Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.417586359Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.419229148Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.427776731Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.440477554Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.443788298Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.450307064Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.462390944Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.469777121Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.471345191Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.479104153Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.481222553Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.490297417Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.493202574Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.501837863Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.503828276Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.513339031Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.525997556Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.529453697Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.536277975Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.548631523Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.562057302Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.564923418Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.573533072Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.576232057Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.585336244Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.587281406Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.59274109Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.594119134Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.601222445Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.608026683Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.610630058Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.617292871Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.629253555Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.639483675Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.641203051Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.650236867Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.652560354Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.662650578Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.665580875Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.67406804Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.67607874Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.686166968Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.698269843Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.701777379Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.709348111Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.721717697Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.7312288Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.734086368Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.74201034Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.743810826Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.753613379Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.755841534Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.765743348Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.768741694Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.778269661Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.789694851Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.793473392Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.799088249Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.80131035Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:49.802629912Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:49.807209202Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:49.809568862Z 26 PC: 1524a | Set disk transfer address
2018-12-25T11:59:49.811221451Z 71 PC: 1525d | Get current directory
2018-12-25T11:59:49.815183778Z 78 PC: 15252 | Find first file
2018-12-25T11:59:49.835718276Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.842027647Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.849539106Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.851094991Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.852909609Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.856725937Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.858924949Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-25T11:59:49.869113377Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.872069629Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.882040208Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:49.88566717Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.892416358Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.8974115Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.898842487Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.900405666Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.902796175Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.904008124Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:49.908911003Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.910705695Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.916055513Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:49.918310902Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.923222042Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.92900844Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.930771248Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.932643342Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.936249596Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.937689614Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:49.943527313Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.945027698Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.954234457Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:49.957909328Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.96570068Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.973677755Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.976320009Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.97773538Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.980507685Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.983607536Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:49.991931262Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.993881722Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.005159104Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.008120221Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.016421731Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.020020829Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.022119038Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.023586528Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.027581267Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.029486221Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.033241049Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.035741792Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.045607152Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.049167273Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.055060946Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.058285106Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.060153852Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.062590958Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.064666076Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.065920605Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.072509033Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.073822792Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.079480162Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.081913434Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.086800583Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.089654826Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.091666318Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.093126637Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.095767074Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.098136688Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.101767314Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.10350007Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.113650417Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.116483523Z 59 PC: 1523e | Change current directory
2018-12-25T11:59:50.121240104Z 59 PC: 15266 | Change current directory
2018-12-25T11:59:50.127062351Z 26 PC: 1524a | Set disk transfer address (See above)
2018-12-25T11:59:50.128724069Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T11:59:50.131403652Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":31,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:48.921083354Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:48.922657968Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:48.925216531Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.930598078Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:48.936424068Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.941693544Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:48.951682417Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:48.962424885Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:48.967717152Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:49.301273329Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.328108853Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:49.329759933Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.33624801Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:49.339527226Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:49.350358972Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:49.352134599Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.369230292Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:49.370955103Z 62 PC: 1547c | Close file
2018-12-25T11:59:49.378997236Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.388922692Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.392051132Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.397989592Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.408018015Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.422779161Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.423840073Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.42923742Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.4313044Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.438479574Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.440266253Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.448200826Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.449470222Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.45520072Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.462618247Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.465799689Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.472404109Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.483276598Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.490248568Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.492640157Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.50164861Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.503562228Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.524381515Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.526489785Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.53313072Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.534568358Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.576036231Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.586751057Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.589905487Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.596234655Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.606443138Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.613196626Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.615815092Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.622371955Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.623893288Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.632980865Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.63469042Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.641228193Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.644495536Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.652466639Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.662399039Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.665478376Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.672232821Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.681918025Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.688770222Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.691067928Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.697481653Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.698939146Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.707761336Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.709091942Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.715489942Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.717457583Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.725104354Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.734752555Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.737402845Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.742846207Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.752202585Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.764662775Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.766374586Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.772841164Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.775906734Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.783958168Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.785520072Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.79255275Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.79384267Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.800093762Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.810160579Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.813089569Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.818884232Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.829714379Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.840462638Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.84209489Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.849166462Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.850880458Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.8599213Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.862461044Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.869405062Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.871025953Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.878986605Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.889816531Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.893440724Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.898874701Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.901611765Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:49.902712104Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:49.114407734Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:49.115849421Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:49.118444536Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.123873532Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:49.129737867Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.135077846Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:49.145253895Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:49.155979998Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.166456854Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:49.299005188Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.321831236Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:49.324570557Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.331456824Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:49.334402794Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:49.346402816Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:49.347758859Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.354323482Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:49.356558665Z 62 PC: 1547c | Close file
2018-12-25T11:59:49.364074678Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.374330948Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.37797093Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.383776758Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.39412941Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.406316406Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.407660895Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.414249648Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.416336056Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.424601713Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.425853001Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.432687811Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.434020864Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.441659609Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.452091233Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.454807151Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.460525377Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.471002318Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.478579553Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.480101602Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.48741741Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.489167638Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.49699914Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.498738505Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.505022324Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.506889566Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.525501009Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.574705871Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.578689526Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.599181766Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.610459432Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.619158979Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.621755034Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.629001144Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.630855065Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.640124514Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.641877449Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.647240607Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.648897486Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.654522284Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.662517985Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.66529642Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.670575785Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.679624411Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.691449027Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.693345632Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.699673011Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.701418247Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.709680831Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.711174113Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.71816502Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.719717817Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.729254748Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.74021126Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.742344588Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.748279123Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.758428455Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.77055266Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.771890155Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.778146609Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.780145863Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.78835973Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.790277421Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.797754573Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.799230127Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.807112203Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.817690913Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.820250985Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.825924623Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.836807652Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.84342288Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.844913112Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.853251021Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.855138654Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.864259054Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.867065637Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.873695387Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.875678917Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.884568774Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.89451665Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.897656379Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.904436688Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:49.906456363Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:49.907741337Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:49.912486847Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:49.915012955Z 26 PC: 1524a | Set disk transfer address
2018-12-25T11:59:49.916443262Z 71 PC: 1525d | Get current directory
2018-12-25T11:59:49.920167765Z 78 PC: 15252 | Find first file
2018-12-25T11:59:49.924699541Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.928788864Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.933593838Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.934827368Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.935963599Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.938642385Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.939841019Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-25T11:59:49.94551377Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.948215485Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:49.954673878Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:49.956703987Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:49.963076735Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:49.969057235Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:49.97042362Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.985434464Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:49.988100864Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:49.989651975Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:49.997993301Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.001390026Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.009007539Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.012640723Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.019389639Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.025918424Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.028431566Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.030551677Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.03342728Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.036010806Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.045494045Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.047251585Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.055842375Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.059166799Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.065789367Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.072363108Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.074025395Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.075596765Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.078571723Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.080560612Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.087558516Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.089369643Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.096821501Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.099297853Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.105979611Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.112607541Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.114054517Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.116225508Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.11892936Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.120396474Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.128563873Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.129959563Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.137216407Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.139905152Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.146526056Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.149143336Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.151499168Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.152730331Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.155164363Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.156894767Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.165078274Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.166666985Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.176232346Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.178717451Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.18562314Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.189196021Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.191375845Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.192625799Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.200874095Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.202803774Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.206462964Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.209745018Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.216892581Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.219359008Z 59 PC: 1523e | Change current directory
2018-12-25T11:59:50.225696515Z 59 PC: 15266 | Change current directory
2018-12-25T11:59:50.229817201Z 26 PC: 1524a | Set disk transfer address (See above)
2018-12-25T11:59:50.231176124Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T11:59:50.234587238Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":27,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:49.61100755Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:49.612995275Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:49.615859909Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.621796674Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:49.626698678Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.630753311Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:49.637289473Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:49.646526269Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.654176705Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:49.674104176Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.679031159Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:49.68145526Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.688272296Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:49.694894961Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:49.702951015Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:49.704610775Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.71155567Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:49.713419853Z 62 PC: 1547c | Close file
2018-12-25T11:59:49.721253773Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.731278122Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.733810686Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.739306517Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.749572765Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.756003314Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.75738392Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.764195597Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.766058843Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.773831324Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.776516879Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.783517112Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.784853085Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.792697246Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.802740726Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.805508147Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.811733598Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.821828414Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.828519915Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.830098441Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.836871199Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.838727128Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.846718902Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.848476865Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.854782429Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.856268826Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.864829126Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.875412786Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.877941015Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.884265724Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.895069684Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.9017273Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.904406232Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.910781971Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.912884803Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.922069123Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.923574663Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.929232986Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.930752939Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.938048204Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.948118705Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.961907372Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.967775975Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.997033087Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.005380403Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.007271136Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.013912202Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.016376889Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.024773662Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.026198254Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.033187228Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.034844737Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.042780321Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.053290317Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.055975199Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.061806141Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.072792595Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.079674929Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.081301973Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.088609965Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.090778112Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.098900852Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.100381548Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.107611871Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.109404774Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.118189181Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.129318156Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.132134077Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.13792128Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.148452886Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.154913843Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.156248292Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.163138125Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.164807945Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.172980848Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.17538355Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.181691138Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.183115944Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.191249783Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.201374252Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.204115508Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.208844282Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.210812747Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:50.21215541Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:50.215495054Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:50.217665289Z 9 PC: 15188 | Display string (String= 'FATEC-SP Brasil 1996')
2018-12-25T11:59:50.220189568Z 76 PC: 15190 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:49.659149106Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:49.661032224Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:49.664304856Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.670963671Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:49.677725046Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.684478634Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:49.696219257Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:49.70911942Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.715563628Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:49.733175649Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.737728208Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:49.740186955Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.744406386Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:49.745635074Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:49.751675524Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:49.753301748Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.776172136Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:49.778354246Z 62 PC: 1547c | Close file
2018-12-25T11:59:49.787083698Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.807307533Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.811159672Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.818167702Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.829328231Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.838767834Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.844674318Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.851804439Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.85351622Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.863078769Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.864638531Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.871903688Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.874546742Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.88336838Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.894756522Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.898250744Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.905277293Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.914743169Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.919714978Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.920912667Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.925203822Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.926992753Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.932302924Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.933281869Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.938909604Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:49.940037858Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:49.945398981Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.956663626Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.959499521Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.964300251Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:49.971575146Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.976554621Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:49.977854579Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.983336872Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:49.986495618Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:49.992696415Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:49.994100419Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.999471362Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.000968129Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.009402465Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.020950011Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.023877465Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.030620656Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.042745879Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.0500862Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.051853301Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.061868725Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.064559128Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.074330108Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.076344825Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.081069358Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.089222043Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.098748083Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.10991269Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.112746414Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.119201082Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.130429756Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.138130013Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.139731347Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.14755832Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.149413036Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.15843119Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.160796767Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.168655038Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.170377153Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.179699065Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.191717771Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.195123551Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.202914314Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.211798355Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.22643677Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.228842137Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.236468498Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.238133645Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.247257794Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.249537223Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.256983603Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.258781704Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.267919172Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.278962918Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.282352394Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.288435981Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.290509462Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:50.291860434Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:50.295511018Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:50.29787649Z 26 PC: 1524a | Set disk transfer address
2018-12-25T11:59:50.299053547Z 71 PC: 1525d | Get current directory
2018-12-25T11:59:50.302802656Z 78 PC: 15252 | Find first file
2018-12-25T11:59:50.309739559Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.317399041Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.325534675Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.327030136Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.328555323Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.332489332Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.33413038Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-25T11:59:50.343905945Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.346801722Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.356375245Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.359702515Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.368229359Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.375863174Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.3778581Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.380445623Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.383627564Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.385613437Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.396547257Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.398677397Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.407367537Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.4109674Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.41911779Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.427170193Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.429148571Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.431885059Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.435260428Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.437385428Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.449989031Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.451899076Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.460916257Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.465109749Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.472558497Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.480105754Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.497685018Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.499820336Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.503225579Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.506181068Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.515723467Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.51844758Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.528077988Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.531319893Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.539045231Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.548775783Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.551162592Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.553141721Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.557524696Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.559455414Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.568007758Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.570593121Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.579834218Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.583606563Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.592205475Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.600937142Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.60323332Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.605591102Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.609570104Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.61143042Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.621549902Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.624817386Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.635356353Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.638807836Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:50.648190438Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:50.651640722Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.653661317Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.656835187Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:50.660298833Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:50.662388399Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:50.667559597Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:50.670081812Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:50.679324157Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:50.683473299Z 59 PC: 1523e | Change current directory
2018-12-25T11:59:50.688790353Z 59 PC: 15266 | Change current directory
2018-12-25T11:59:50.693618177Z 26 PC: 1524a | Set disk transfer address (See above)
2018-12-25T11:59:50.696008886Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T11:59:50.699453766Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":27,"Month":6,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:49.843873877Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:49.84713554Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:49.851002731Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.858124639Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:49.86616998Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.873759007Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:49.889163314Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:49.897464995Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.909119994Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:49.926722968Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:49.93379181Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:49.9365987Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:49.944034284Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:49.946737941Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:49.957406763Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:49.959143763Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:49.967095417Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:49.970307273Z 62 PC: 1547c | Close file
2018-12-25T11:59:49.979023029Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.990227347Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:49.993571758Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.00081718Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.011513798Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.024967679Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.027963373Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.035323651Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.037165007Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.0466115Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.04848724Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.056007155Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.059659966Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.068255512Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.079489544Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.082915686Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.089779593Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.101134051Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.109179575Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.112077573Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.119473633Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.121320692Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.13024788Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.131912304Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.139104428Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.14150244Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.150300076Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.162505817Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.166777515Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.173771529Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.184836292Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.193376712Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.195237163Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.203228384Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.205624931Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.214806953Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.216343688Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.224029511Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.225728721Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.234013296Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.244908064Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.248926476Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.255197644Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.266282969Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.279765762Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.282961802Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.290994307Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.293364509Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.302583254Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.304523695Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.313176126Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.315660521Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.324477102Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.337043595Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.339996139Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.351263209Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.362615323Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.37164302Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.373198838Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.380409113Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.382430232Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.392806314Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.395010032Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.404031519Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.406134898Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.415677533Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.427952148Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.431716632Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.438553169Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.451298688Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.460052119Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.462071245Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.470276628Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.47236818Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.483769458Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.485948046Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.495291531Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.497712708Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.517470319Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.534667857Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.537223766Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.545016393Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.548011318Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:50.549601691Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:50.562557639Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:50.568391934Z 9 PC: 15188 | Display string (String= 'FATEC-SP Brasil 1996')
2018-12-25T11:59:50.572765946Z 76 PC: 15190 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":31,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:49.933982922Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:49.935769951Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:49.939103716Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.94542984Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:49.951644117Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.958143407Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:49.970284066Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:49.981870152Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:49.988657284Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:50.005507253Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.010098372Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:50.012254483Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.016341298Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:50.017994989Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:50.024097279Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:50.025514411Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.032566798Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:50.042793896Z 62 PC: 1547c | Close file
2018-12-25T11:59:50.051784473Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.062749307Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.067483724Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.074173552Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.084780546Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.092881446Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.095042205Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.101999568Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.103626163Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.113204095Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.114815694Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.121958012Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.124447951Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.133552291Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.144700323Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.148429681Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.154639522Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.165622237Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.173852289Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.175608847Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.182790555Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.184888751Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.195731782Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.197379271Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.204745694Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.207518465Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.216121516Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.227007786Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.230437003Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.236722109Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.248167841Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.261559638Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.262893522Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.269918039Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.272260185Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.281098318Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.283338418Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.290450182Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.292326182Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.300638208Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.311363012Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.314981934Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.322097983Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.332970199Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.341369473Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.345020718Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.352286962Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.355181143Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.364772256Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.366336316Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.374196882Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.376107461Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.385443103Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.3976957Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.402349046Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.409515862Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.422718538Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.43244921Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.434623973Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.442274075Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.445463122Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.455720981Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.45768135Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.466791592Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.469223326Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.478821368Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.497134464Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.50036951Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.506823499Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.531542924Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.545153857Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.547083678Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.555671518Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.558446671Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.573419112Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.577767462Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.600423915Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.602322695Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.613943924Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.638530919Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.643167037Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.647418434Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:50.65057528Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:50.653928017Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:50.431159651Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:50.435303738Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:50.438429606Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.444430544Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:50.450956234Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.456597326Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:50.467327328Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:50.477862638Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.481623746Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:50.49816769Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.504772163Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:50.506462996Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.512811774Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:50.514446099Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:50.5228762Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:50.524569096Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.531283582Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:50.546309883Z 62 PC: 1547c | Close file
2018-12-25T11:59:50.554195138Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.564040453Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.567436832Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.573265689Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.593208981Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.600292713Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.601626585Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.60873575Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.611108884Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.620750118Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.622571376Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.630761385Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.632612235Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.640590259Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.652456331Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.65535145Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.661234632Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.671512745Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.678758815Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.680773599Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.688244784Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.689545448Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.694724283Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.69666751Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.704385157Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.706402827Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.715056415Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.729674375Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.732880488Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.739883389Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.750670192Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.757596308Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.759423728Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.767135581Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.769115603Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.777823611Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.780683566Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.787416274Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.789296482Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.798460473Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.808634586Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.811572665Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.818383999Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.82837034Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.835138819Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.837765173Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.844650718Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.846230365Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.855086889Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.856495657Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.862741563Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.86505109Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.872980548Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.883100987Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.886026073Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.895845063Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.905623354Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.912395316Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.91427116Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.920419759Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.922193027Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.931181167Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.932687571Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.940071743Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.942659165Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.950392167Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.960451819Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.964141774Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.969787261Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.979452149Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.991272467Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.992700629Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.998843164Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:51.002049317Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:51.009936246Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:51.011283205Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:51.018826453Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:51.020295965Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:51.0277327Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:51.038849066Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:51.041310364Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:51.045298127Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:51.048313246Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:51.049372731Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:51.052073108Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:51.055211623Z 26 PC: 1524a | Set disk transfer address
2018-12-25T11:59:51.056770983Z 71 PC: 1525d | Get current directory
2018-12-25T11:59:51.059922049Z 78 PC: 15252 | Find first file
2018-12-25T11:59:51.071245426Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.078202489Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.084543783Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.085950491Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.088060478Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.090600954Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.092057144Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-25T11:59:51.101128488Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.10261557Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.110156297Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.114232Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.120781447Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.127172718Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.129448005Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.131006543Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.133728242Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.13614321Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.144193145Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.145828912Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.154340784Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.157204587Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.163727508Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.170726356Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.172253545Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.173787363Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.177150066Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.17879376Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.187350215Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.189755605Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.197645549Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.200382173Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.207961308Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.214500656Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.21608665Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.218215626Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.220737991Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.222107472Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.230540775Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.232226806Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.239804536Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.243332702Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.250183521Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.256546538Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.258849775Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.260668514Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.26343226Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.265818973Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.273694245Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.275380206Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.282961689Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.286527912Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.293117177Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.299533726Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.302087057Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.303631817Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.306410232Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.309268356Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.31836811Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.320119353Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.328907931Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.331622457Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.33879312Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.346902585Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.348679568Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.350430417Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.354205207Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.35631347Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.363476345Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.366091539Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.374072758Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.376799311Z 59 PC: 1523e | Change current directory
2018-12-25T11:59:51.381931258Z 59 PC: 15266 | Change current directory
2018-12-25T11:59:51.386777552Z 26 PC: 1524a | Set disk transfer address (See above)
2018-12-25T11:59:51.388099593Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T11:59:51.391430522Z 76 PC: 12a56 | Terminate with return code (Return code = '0')

{"DateBased":true,"Day":1,"Month":12,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":false,"OriginalID":6556,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T11:59:50.384793293Z 26 PC: 154be | Set disk transfer address
2018-12-25T11:59:50.386707602Z 71 PC: 15383 | Get current directory
2018-12-25T11:59:50.390145237Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.394734261Z 65 PC: 154b7 | Delete file (Filename = 'CHKLIST.CPS')
2018-12-25T11:59:50.404855676Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.414628605Z 65 PC: 154b7 | Delete file (See above)
2018-12-25T11:59:50.42078631Z 78 PC: 154be | Find first file (See above)
2018-12-25T11:59:50.427224938Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.432505415Z 67 PC: 15410 | Get or set file attributes
2018-12-25T11:59:50.450553657Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.458334441Z 87 PC: 15421 | Get or set file date and time
2018-12-25T11:59:50.459960621Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.467585961Z 66 PC: 1543f | Move file pointer
2018-12-25T11:59:50.469901513Z 64 PC: 155fb | Write file or device (Write 487 bytes on handle 5)
2018-12-25T11:59:50.483732151Z 66 PC: 15466 | Move file pointer
2018-12-25T11:59:50.485842348Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.494038333Z 87 PC: 15478 | Get or set file date and time
2018-12-25T11:59:50.496833736Z 62 PC: 1547c | Close file
2018-12-25T11:59:50.506461866Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.517802327Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.522055905Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.529493297Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.540626062Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.554952891Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.557413458Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.565013041Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.567525564Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.577174581Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.580312428Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.587905519Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.59129606Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.600393041Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.61402884Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.617363188Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.622171095Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.629336504Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.634337452Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.635514895Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.639921004Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.641826622Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.647256391Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.648592675Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.655643355Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.657525766Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.663720043Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.671258033Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.673504247Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.677402126Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.686890711Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.697182479Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.699154498Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.707016247Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.711493393Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.721088242Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.723138703Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.731932052Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.734338475Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.743597515Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.764007262Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.767053529Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.773501601Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.784923638Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.793316819Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.795330946Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.804337513Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.817085783Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.826889447Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.828503212Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.83676974Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.838675318Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.847145229Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.858587536Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.86678347Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.873228238Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.884570763Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.892802514Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.894454936Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.902502351Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:50.90556857Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:50.915103296Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:50.91721738Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:50.925929635Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:50.928233588Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:50.937435463Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.958026716Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:50.962029656Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:50.968534886Z 67 PC: 15410 | Get or set file attributes (See above)
2018-12-25T11:59:50.980380749Z 61 PC: 154be | Open file (See above)
2018-12-25T11:59:50.988436264Z 87 PC: 15421 | Get or set file date and time (See above)
2018-12-25T11:59:50.990447868Z 63 PC: 154be | Read file or device (See above)
2018-12-25T11:59:50.998449476Z 66 PC: 1543f | Move file pointer (See above)
2018-12-25T11:59:51.000726679Z 64 PC: 155fb | Write file or device (See above)
2018-12-25T11:59:51.009993582Z 66 PC: 15466 | Move file pointer (See above)
2018-12-25T11:59:51.012136371Z 64 PC: 154be | Write file or device (See above)
2018-12-25T11:59:51.020412193Z 87 PC: 15478 | Get or set file date and time (See above)
2018-12-25T11:59:51.022368335Z 62 PC: 1547c | Close file (See above)
2018-12-25T11:59:51.031878702Z 67 PC: 154be | Get or set file attributes (See above)
2018-12-25T11:59:51.043524202Z 79 PC: 154be | Find next file (See above)
2018-12-25T11:59:51.046625146Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:51.051548198Z 59 PC: 154be | Change current directory (See above)
2018-12-25T11:59:51.05424862Z 26 PC: 153b2 | Set disk transfer address
2018-12-25T11:59:51.055734501Z 42 PC: 153b6 | Get date 0x153b6: cmp dh, 0xc
0x153b9: jne 0x153d1
0x153bb: cmp dl, 0x1f
0x153be: jne 0x153d1
0x153c0: mov al, 2
0x153c2: mov cx, 0x100
0x153c5: cdq
0x153c6: pushaw
0x153c7: int 0x26
0x153c9: popf
0x153ca: popaw
0x153cb: inc al
0x153cd: int 0x26
0x153cf: jmp 0x153cf
0x153d1: mov bp, si
0x153d3: mov di, 0x2a7
0x153d6: add di, bp
0x153d8: push di
0x153d9: mov si, 0x9f
0x153dc: add si, bp
2018-12-25T11:59:51.059156172Z 42 PC: 15179 | Get date 0x15179: cmp dx, 0x61b
0x1517d: jne 0x15190
0x1517f: mov ax, 0x900
0x15182: lea dx, word ptr [bp + 0x2c4]
0x15186: int 0x21
0x15188: call 0x1528a
0x1518b: mov ax, 0x4c00
0x1518e: int 0x21
0x15190: lea dx, word ptr [bp + 0x332]
0x15194: call 0x15246
0x15197: inc byte ptr cs:[bp + 0x20d]
0x1519c: mov byte ptr cs:[bp + 0x35c], 2
0x151a2: call 0x15253
0x151a5: mov ah, 0x4e
0x151a7: lea dx, word ptr [bp + 0x2bb]
0x151ab: xor cx, cx
0x151ad: call 0x15250
0x151b0: jb 0x15228
0x151b2: mov ax, 0x3d02
0x151b5: lea dx, word ptr [bp + 0x350]
2018-12-25T11:59:51.062629255Z 26 PC: 1524a | Set disk transfer address
2018-12-25T11:59:51.064227009Z 71 PC: 1525d | Get current directory
2018-12-25T11:59:51.067702914Z 78 PC: 15252 | Find first file
2018-12-25T11:59:51.075617482Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.088672814Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.096599458Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.099316272Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.101531972Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.104822782Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.107036557Z 64 PC: 15214 | Write file or device (Write 500 bytes on handle 5)
2018-12-25T11:59:51.117862115Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.119505252Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.138332337Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.142461997Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.149952495Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.157684666Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.160353217Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.162563262Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.165784714Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.168514203Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.176776578Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.17879307Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.187330457Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.191322165Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.19885223Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.206249215Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.209474519Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.211419066Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.214668272Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.21783767Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.228073872Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.230125881Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.240260388Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.243512121Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.25095322Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.25929682Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.261623431Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.263503227Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.26760034Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.269891363Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.277959661Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.280807441Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.289672861Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.293724523Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.302248521Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.309541725Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.31149063Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.313635751Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.317837028Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.319444132Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.327518749Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.329914257Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.338334987Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.341745314Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.350082421Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.357781018Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.359397288Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.362653524Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.36586349Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.367898189Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.378355989Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.380359219Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.389299845Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.393172943Z 61 PC: 15252 | Open file (See above)
2018-12-25T11:59:51.404653772Z 63 PC: 15252 | Read file or device (See above)
2018-12-25T11:59:51.412000272Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.41485853Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.416620955Z 64 PC: 15252 | Write file or device (See above)
2018-12-25T11:59:51.419712145Z 66 PC: 15252 | Move file pointer (See above)
2018-12-25T11:59:51.422768587Z 64 PC: 15214 | Write file or device (See above)
2018-12-25T11:59:51.431195565Z 87 PC: 15252 | Get or set file date and time (See above)
2018-12-25T11:59:51.433045521Z 62 PC: 15252 | Close file (See above)
2018-12-25T11:59:51.442531933Z 79 PC: 15252 | Find next file (See above)
2018-12-25T11:59:51.445582575Z 59 PC: 1523e | Change current directory
2018-12-25T11:59:51.45044353Z 59 PC: 15266 | Change current directory
2018-12-25T11:59:51.456149503Z 26 PC: 1524a | Set disk transfer address (See above)
2018-12-25T11:59:51.457718547Z 9 PC: 12a51 | Display string (String= 'This is a sample! (10.000 bytes)')
2018-12-25T11:59:51.46059958Z 76 PC: 12a56 | Terminate with return code (Return code = '0')