.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:44:50.103431599Z | 255 | PC: 1317f | UNKNOWN! |
2018-12-17T22:44:50.105798244Z | 42 | PC: 131d1 | Get date 0x131d1: test dx, 0x133 0x131d5: jne 0x131e1 0x131d7: mov ax, 0x3e7 0x131da: mov word ptr [0x70], ax 0x131dd: mov word ptr [0x72], es 0x131e1: push es 0x131e2: pop ds 0x131e3: mov di, 0x2b9 0x131e6: mov byte ptr [di], 0xcf 0x131e9: mov dx, 0x107 0x131ec: mov ax, 0x4b00 0x131ef: int 0x21 0x131f1: mov byte ptr [di], 0x90 0x131f4: pop es 0x131f5: pop ds 0x131f6: clc 0x131f7: jb 0x13200 0x131f9: mov di, 0x100 0x131fc: push di 0x131fd: movsw word ptr es:[di], word ptr [si] |
2018-12-17T22:44:50.108744287Z | 54 | PC: 9f81f | Get free disk space |
2018-12-17T22:44:50.15171892Z | 67 | PC: 9f852 | Get or set file attributes |
2018-12-17T22:44:50.161799604Z | 67 | PC: 9f85e | Get or set file attributes |
2018-12-17T22:44:50.508098054Z | 61 | PC: 9f863 | Open file (Filename = 'c:\command.com') |
2018-12-17T22:44:50.515463387Z | 87 | PC: 9f874 | Get or set file date and time |
2018-12-17T22:44:50.517516063Z | 66 | PC: 9f887 | Move file pointer |
2018-12-17T22:44:50.520795662Z | 63 | PC: 9f893 | Read file or device (Read 4 bytes on handle 5) |
2018-12-17T22:44:50.528220177Z | 66 | PC: 9f9b4 | Move file pointer |
2018-12-17T22:44:50.529938254Z | 63 | PC: 9f8b4 | Read file or device (Read 24 bytes on handle 5) |
2018-12-17T22:44:50.539149233Z | 66 | PC: 9f9b4 | Move file pointer |
2018-12-17T22:44:50.5410486Z | 66 | PC: 9f9b4 | Move file pointer |
2018-12-17T22:44:50.54282662Z | 64 | PC: 9f94f | Write file or device (Write 24 bytes on handle 5) |
2018-12-17T22:44:50.546656162Z | 66 | PC: 9f9b4 | Move file pointer |
2018-12-17T22:44:50.548568314Z | 64 | PC: 9f960 | Write file or device (Write 1000 bytes on handle 5) |
2018-12-17T22:44:50.558875582Z | 87 | PC: 9f971 | Get or set file date and time |
2018-12-17T22:44:50.56103066Z | 62 | PC: 9f975 | Close file |
2018-12-17T22:44:50.569831519Z | 67 | PC: 9f983 | Get or set file attributes |
2018-12-17T22:44:50.579596128Z | 76 | PC: 12a48 | Terminate with return code (Return code = '76') |