.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:43:29.202617013Z | 44 | PC: 1314e | Get time 0x1314e: cmp byte ptr [0x103], 0 0x13153: je 0x1315a 0x13155: cmp dh, 0x1e 0x13158: jg 0x13163 0x1315a: cmp dl, 0 0x1315d: je 0x1314a 0x1315f: mov byte ptr [0x103], dl 0x13163: mov byte ptr [0x7ff], 0 0x13168: mov byte ptr [0x800], 4 0x1316d: mov byte ptr [0x809], 0 0x13172: mov cx, 0x27 0x13175: mov dx, 0x115 0x13178: mov ah, 0x4e 0x1317a: int 0x21 0x1317c: cmp ax, 0x12 0x1317f: je 0x13184 0x13181: call 0x131a6 0x13184: mov cx, 0x27 0x13187: mov dx, 0x11b 0x1318a: mov ah, 0x4e |
2018-12-17T22:43:29.205425347Z | 78 | PC: 1317c | Find first file |
2018-12-17T22:43:29.212351656Z | 78 | PC: 1318e | Find first file |
2018-12-17T22:43:29.218400867Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:43:29.233722073Z | 61 | PC: 131cd | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:43:29.241244882Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:43:29.247841421Z | 62 | PC: 13210 | Close file |
2018-12-17T22:43:29.249990919Z | 61 | PC: 13219 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:43:29.263966788Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:43:29.272970287Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:43:29.274578688Z | 62 | PC: 13249 | Close file |
2018-12-17T22:43:29.283287716Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:43:29.288878316Z | 79 | PC: 13200 | Find next file |
2018-12-17T22:43:29.292504176Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:43:29.304434122Z | 61 | PC: 131cd | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:43:29.312122753Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:43:29.319501421Z | 62 | PC: 13210 | Close file |
2018-12-17T22:43:29.322818371Z | 61 | PC: 13219 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:43:29.332207014Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:43:29.34142644Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:43:29.343681345Z | 62 | PC: 13249 | Close file |
2018-12-17T22:43:29.352354094Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:43:29.357966645Z | 79 | PC: 13200 | Find next file |
2018-12-17T22:43:29.36179207Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:43:29.372937523Z | 61 | PC: 131cd | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:43:29.380237263Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:43:29.387519751Z | 62 | PC: 13210 | Close file |
2018-12-17T22:43:29.3906286Z | 61 | PC: 13219 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:43:29.397486981Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:43:29.413284422Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:43:29.422046898Z | 62 | PC: 13249 | Close file |
2018-12-17T22:43:29.429587281Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:43:29.434002794Z | 79 | PC: 13200 | Find next file |
2018-12-17T22:43:29.439859073Z | 67 | PC: 131c7 | Get or set file attributes |
2018-12-17T22:43:29.449341322Z | 61 | PC: 131cd | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:43:29.459966448Z | 63 | PC: 131dc | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:43:29.467089216Z | 62 | PC: 13210 | Close file |
2018-12-17T22:43:29.468962044Z | 61 | PC: 13219 | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:43:29.475432335Z | 64 | PC: 12a54 | Write file or device (Write 2209 bytes on handle 5) |
2018-12-17T22:43:29.490302364Z | 87 | PC: 13241 | Get or set file date and time |
2018-12-17T22:43:29.492242448Z | 62 | PC: 13249 | Close file |
2018-12-17T22:43:29.499558068Z | 67 | PC: 13256 | Get or set file attributes |
2018-12-17T22:43:29.504110448Z | 9 | PC: 132d5 | Display string (String= ' Error #2307 - Too big to fit in memory') |
2018-12-17T22:43:29.508870869Z | 76 | PC: 132d9 | Terminate with return code (Return code = '36') |