Sample viewer

vx.netlux.org/Virus.DOS.Coconut.2324

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:20.232234313Z 48 PC: 170b8 | Get DOS version
2018-12-17T22:45:20.235860551Z 53 PC: 172e7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.237313669Z 37 PC: 172f6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.238586843Z 71 PC: 17326 | Get current directory
2018-12-17T22:45:20.241966491Z 26 PC: 1732d | Set disk transfer address
2018-12-17T22:45:20.242965435Z 42 PC: 17108 | Get date 0x17108: cmp dh, 3
0x1710b: jne 0x17115
0x1710d: cmp dl, 0x14
0x17110: jne 0x17115
0x17112: jmp 0x17398
0x17115: lea dx, word ptr [bp + 0x94e]
0x17119: call 0x171c5
0x1711c: lea dx, word ptr [bp + 0x954]
0x17120: call 0x171c5
0x17123: mov ah, 0x3b
0x17125: lea dx, word ptr [bp + 0xa06]
0x17129: int3
0x1712a: jae 0x17115
0x1712c: cmp byte ptr [bp + 0xa17], 1
0x17131: je 0x17135
0x17133: jmp 0x17159
0x17135: call 0x1732e
0x17138: pop es
0x17139: pop ds
0x1713a: mov ax, es
2018-12-17T22:45:20.244953497Z 78 PC: 171cb | Find first file
2018-12-17T22:45:20.250867034Z 67 PC: 1725c | Get or set file attributes
2018-12-17T22:45:20.269255893Z 61 PC: 17264 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:45:20.276403459Z 63 PC: 171dc | Read file or device (Read 26 bytes on handle 5)
2018-12-17T22:45:20.282542334Z 66 PC: 172e1 | Move file pointer
2018-12-17T22:45:20.284219149Z 63 PC: 17234 | Read file or device (Read 5 bytes on handle 5)
2018-12-17T22:45:20.28676984Z 66 PC: 172d9 | Move file pointer
2018-12-17T22:45:20.290702462Z 66 PC: 172e1 | Move file pointer
2018-12-17T22:45:20.29245782Z 64 PC: 171c4 | Write file or device (Write 5 bytes on handle 5)
2018-12-17T22:45:20.296372605Z 66 PC: 172d9 | Move file pointer
2018-12-17T22:45:20.29814755Z 44 PC: 1736b | Get time 0x1736b: cmp dh, 0
0x1736e: je 0x17368
0x17370: cmp dl, 0
0x17373: je 0x17368
0x17375: mov word ptr [bp + 0xa0b], dx
0x17379: ret
0x1737a: sub cx, cx
0x1737c: mov cl, byte ptr [bp + 0xa6e]
0x17380: lea dx, word ptr [bp + 0xa77]
0x17384: mov ax, 0x4301
0x17387: int3
0x17388: mov cx, word ptr [bp + 0xa6f]
0x1738c: mov dx, word ptr [bp + 0xa71]
0x17390: mov ax, 0x5701
0x17393: int3
0x17394: mov ah, 0x3e
0x17396: int3
0x17397: ret
0x17398: mov ah, 9
0x1739a: push bp
2018-12-17T22:45:20.301911354Z 64 PC: 1797e | Write file or device (Write 2322 bytes on handle 5)
2018-12-17T22:45:20.31122812Z 64 PC: 1798c | Write file or device (Write 2 bytes on handle 5)
2018-12-17T22:45:20.315158382Z 67 PC: 17388 | Get or set file attributes
2018-12-17T22:45:20.326670323Z 87 PC: 17394 | Get or set file date and time
2018-12-17T22:45:20.328484885Z 62 PC: 17397 | Close file
2018-12-17T22:45:20.335868458Z 26 PC: 17334 | Set disk transfer address
2018-12-17T22:45:20.337372263Z 59 PC: 1733b | Change current directory
2018-12-17T22:45:20.345182571Z 37 PC: 1734a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:20.346420178Z 48 PC: 13eb2 | Get DOS version
2018-12-17T22:45:20.347588683Z 74 PC: 13f27 | Reallocate memory
2018-12-17T22:45:20.350209028Z 48 PC: 14efc | Get DOS version
2018-12-17T22:45:20.351732301Z 53 PC: 13f9d | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.352796379Z 37 PC: 13faf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.35455687Z 68 PC: 14044 | I/O control for devices (Set for = '')
2018-12-17T22:45:20.356210018Z 68 PC: 14044 | I/O control for devices
2018-12-17T22:45:20.35746562Z 68 PC: 14044 | I/O control for devices
2018-12-17T22:45:20.359353265Z 68 PC: 14044 | I/O control for devices
2018-12-17T22:45:20.360547223Z 68 PC: 14044 | I/O control for devices
2018-12-17T22:45:20.362317038Z 74 PC: 15dfe | Reallocate memory
2018-12-17T22:45:20.36489525Z 81 PC: 12e88 | Get current PSP
2018-12-17T22:45:20.36683934Z 64 PC: 1460c | Write file or device (Write 27 bytes on handle 1)
2018-12-17T22:45:20.371733715Z 37 PC: 140fe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-17T22:45:20.373772893Z 76 PC: 140e3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8510,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:03.646205305Z 48 PC: 170b8 | Get DOS version
2018-12-25T12:05:03.648262453Z 53 PC: 172e7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:03.649054542Z 37 PC: 172f6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:03.649810024Z 71 PC: 17326 | Get current directory
2018-12-25T12:05:03.651900096Z 26 PC: 1732d | Set disk transfer address
2018-12-25T12:05:03.652581087Z 42 PC: 17108 | Get date 0x17108: cmp dh, 3
0x1710b: jne 0x17115
0x1710d: cmp dl, 0x14
0x17110: jne 0x17115
0x17112: jmp 0x17398
0x17115: lea dx, word ptr [bp + 0x94e]
0x17119: call 0x171c5
0x1711c: lea dx, word ptr [bp + 0x954]
0x17120: call 0x171c5
0x17123: mov ah, 0x3b
0x17125: lea dx, word ptr [bp + 0xa06]
0x17129: int3
0x1712a: jae 0x17115
0x1712c: cmp byte ptr [bp + 0xa17], 1
0x17131: je 0x17135
0x17133: jmp 0x17159
0x17135: call 0x1732e
0x17138: pop es
0x17139: pop ds
0x1713a: mov ax, es
2018-12-25T12:05:03.653890553Z 78 PC: 171cb | Find first file
2018-12-25T12:05:03.657923309Z 67 PC: 1725c | Get or set file attributes
2018-12-25T12:05:03.673980788Z 61 PC: 17264 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:05:03.680247621Z 63 PC: 171dc | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:05:03.68669511Z 66 PC: 172e1 | Move file pointer
2018-12-25T12:05:03.687879834Z 63 PC: 17234 | Read file or device (Read 5 bytes on handle 5)
2018-12-25T12:05:03.690117688Z 66 PC: 172d9 | Move file pointer
2018-12-25T12:05:03.691743318Z 66 PC: 172e1 | Move file pointer (See above)
2018-12-25T12:05:03.692864894Z 64 PC: 171c4 | Write file or device (Write 5 bytes on handle 5)
2018-12-25T12:05:03.695112672Z 66 PC: 172d9 | Move file pointer (See above)
2018-12-25T12:05:03.696610063Z 44 PC: 1736b | Get time 0x1736b: cmp dh, 0
0x1736e: je 0x17368
0x17370: cmp dl, 0
0x17373: je 0x17368
0x17375: mov word ptr [bp + 0xa0b], dx
0x17379: ret
0x1737a: sub cx, cx
0x1737c: mov cl, byte ptr [bp + 0xa6e]
0x17380: lea dx, word ptr [bp + 0xa77]
0x17384: mov ax, 0x4301
0x17387: int3
0x17388: mov cx, word ptr [bp + 0xa6f]
0x1738c: mov dx, word ptr [bp + 0xa71]
0x17390: mov ax, 0x5701
0x17393: int3
0x17394: mov ah, 0x3e
0x17396: int3
0x17397: ret
0x17398: mov ah, 9
0x1739a: push bp
2018-12-25T12:05:03.699719791Z 64 PC: 1797e | Write file or device (Write 2322 bytes on handle 5)
2018-12-25T12:05:03.708059947Z 64 PC: 1798c | Write file or device (Write 2 bytes on handle 5)
2018-12-25T12:05:03.71230613Z 67 PC: 17388 | Get or set file attributes
2018-12-25T12:05:03.722743399Z 87 PC: 17394 | Get or set file date and time
2018-12-25T12:05:03.723987129Z 62 PC: 17397 | Close file
2018-12-25T12:05:03.7308037Z 26 PC: 17334 | Set disk transfer address
2018-12-25T12:05:03.732523978Z 59 PC: 1733b | Change current directory
2018-12-25T12:05:03.736440931Z 37 PC: 1734a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:03.738063235Z 48 PC: 13eb2 | Get DOS version
2018-12-25T12:05:03.739113131Z 74 PC: 13f27 | Reallocate memory
2018-12-25T12:05:03.74106218Z 48 PC: 14efc | Get DOS version
2018-12-25T12:05:03.742781122Z 53 PC: 13f9d | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:03.743695605Z 37 PC: 13faf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:03.744466733Z 68 PC: 14044 | I/O control for devices (Set for = '')
2018-12-25T12:05:03.745755482Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:03.746585748Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:03.74737008Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:03.748516273Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:03.749834337Z 74 PC: 15dfe | Reallocate memory
2018-12-25T12:05:03.751125863Z 81 PC: 12e88 | Get current PSP
2018-12-25T12:05:03.75264005Z 64 PC: 1460c | Write file or device (Write 27 bytes on handle 1)
2018-12-25T12:05:03.755470134Z 37 PC: 140fe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:03.756194333Z 76 PC: 140e3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8510,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:04.222433456Z 48 PC: 170b8 | Get DOS version
2018-12-25T12:05:04.225185122Z 53 PC: 172e7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.226111979Z 37 PC: 172f6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.227146381Z 71 PC: 17326 | Get current directory
2018-12-25T12:05:04.229786584Z 26 PC: 1732d | Set disk transfer address
2018-12-25T12:05:04.230624909Z 42 PC: 17108 | Get date 0x17108: cmp dh, 3
0x1710b: jne 0x17115
0x1710d: cmp dl, 0x14
0x17110: jne 0x17115
0x17112: jmp 0x17398
0x17115: lea dx, word ptr [bp + 0x94e]
0x17119: call 0x171c5
0x1711c: lea dx, word ptr [bp + 0x954]
0x17120: call 0x171c5
0x17123: mov ah, 0x3b
0x17125: lea dx, word ptr [bp + 0xa06]
0x17129: int3
0x1712a: jae 0x17115
0x1712c: cmp byte ptr [bp + 0xa17], 1
0x17131: je 0x17135
0x17133: jmp 0x17159
0x17135: call 0x1732e
0x17138: pop es
0x17139: pop ds
0x1713a: mov ax, es
2018-12-25T12:05:04.232034514Z 78 PC: 171cb | Find first file
2018-12-25T12:05:04.235870813Z 67 PC: 1725c | Get or set file attributes
2018-12-25T12:05:04.247853508Z 61 PC: 17264 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:05:04.251742002Z 63 PC: 171dc | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:05:04.255893295Z 66 PC: 172e1 | Move file pointer
2018-12-25T12:05:04.256768885Z 63 PC: 17234 | Read file or device (Read 5 bytes on handle 5)
2018-12-25T12:05:04.258266652Z 66 PC: 172d9 | Move file pointer
2018-12-25T12:05:04.259543464Z 66 PC: 172e1 | Move file pointer (See above)
2018-12-25T12:05:04.26042735Z 64 PC: 171c4 | Write file or device (Write 5 bytes on handle 5)
2018-12-25T12:05:04.261989774Z 66 PC: 172d9 | Move file pointer (See above)
2018-12-25T12:05:04.263427889Z 44 PC: 1736b | Get time 0x1736b: cmp dh, 0
0x1736e: je 0x17368
0x17370: cmp dl, 0
0x17373: je 0x17368
0x17375: mov word ptr [bp + 0xa0b], dx
0x17379: ret
0x1737a: sub cx, cx
0x1737c: mov cl, byte ptr [bp + 0xa6e]
0x17380: lea dx, word ptr [bp + 0xa77]
0x17384: mov ax, 0x4301
0x17387: int3
0x17388: mov cx, word ptr [bp + 0xa6f]
0x1738c: mov dx, word ptr [bp + 0xa71]
0x17390: mov ax, 0x5701
0x17393: int3
0x17394: mov ah, 0x3e
0x17396: int3
0x17397: ret
0x17398: mov ah, 9
0x1739a: push bp
2018-12-25T12:05:04.265378945Z 64 PC: 1797e | Write file or device (Write 2322 bytes on handle 5)
2018-12-25T12:05:04.27060897Z 64 PC: 1798c | Write file or device (Write 2 bytes on handle 5)
2018-12-25T12:05:04.27311726Z 67 PC: 17388 | Get or set file attributes
2018-12-25T12:05:04.281208454Z 87 PC: 17394 | Get or set file date and time
2018-12-25T12:05:04.282556244Z 62 PC: 17397 | Close file
2018-12-25T12:05:04.290347719Z 26 PC: 17334 | Set disk transfer address
2018-12-25T12:05:04.291387262Z 59 PC: 1733b | Change current directory
2018-12-25T12:05:04.295254216Z 37 PC: 1734a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.297001889Z 48 PC: 13eb2 | Get DOS version
2018-12-25T12:05:04.298372082Z 74 PC: 13f27 | Reallocate memory
2018-12-25T12:05:04.300525007Z 48 PC: 14efc | Get DOS version
2018-12-25T12:05:04.302148689Z 53 PC: 13f9d | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.303262893Z 37 PC: 13faf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.304270754Z 68 PC: 14044 | I/O control for devices (Set for = '')
2018-12-25T12:05:04.305817646Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.307029752Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.308228595Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.31801367Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.320260115Z 74 PC: 15dfe | Reallocate memory
2018-12-25T12:05:04.322460266Z 81 PC: 12e88 | Get current PSP
2018-12-25T12:05:04.324932021Z 64 PC: 1460c | Write file or device (Write 27 bytes on handle 1)
2018-12-25T12:05:04.329857565Z 37 PC: 140fe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.330830052Z 76 PC: 140e3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":8510,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:04.239617852Z 48 PC: 170b8 | Get DOS version
2018-12-25T12:05:04.241172212Z 53 PC: 172e7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.242443608Z 37 PC: 172f6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.243234817Z 71 PC: 17326 | Get current directory
2018-12-25T12:05:04.244939079Z 26 PC: 1732d | Set disk transfer address
2018-12-25T12:05:04.245964621Z 42 PC: 17108 | Get date 0x17108: cmp dh, 3
0x1710b: jne 0x17115
0x1710d: cmp dl, 0x14
0x17110: jne 0x17115
0x17112: jmp 0x17398
0x17115: lea dx, word ptr [bp + 0x94e]
0x17119: call 0x171c5
0x1711c: lea dx, word ptr [bp + 0x954]
0x17120: call 0x171c5
0x17123: mov ah, 0x3b
0x17125: lea dx, word ptr [bp + 0xa06]
0x17129: int3
0x1712a: jae 0x17115
0x1712c: cmp byte ptr [bp + 0xa17], 1
0x17131: je 0x17135
0x17133: jmp 0x17159
0x17135: call 0x1732e
0x17138: pop es
0x17139: pop ds
0x1713a: mov ax, es
2018-12-25T12:05:04.247453831Z 78 PC: 171cb | Find first file
2018-12-25T12:05:04.250926665Z 67 PC: 1725c | Get or set file attributes
2018-12-25T12:05:04.262371421Z 61 PC: 17264 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:05:04.266239513Z 63 PC: 171dc | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:05:04.269967492Z 66 PC: 172e1 | Move file pointer
2018-12-25T12:05:04.271182432Z 63 PC: 17234 | Read file or device (Read 5 bytes on handle 5)
2018-12-25T12:05:04.27285666Z 66 PC: 172d9 | Move file pointer
2018-12-25T12:05:04.274124094Z 66 PC: 172e1 | Move file pointer (See above)
2018-12-25T12:05:04.275611211Z 64 PC: 171c4 | Write file or device (Write 5 bytes on handle 5)
2018-12-25T12:05:04.278011301Z 66 PC: 172d9 | Move file pointer (See above)
2018-12-25T12:05:04.278913012Z 44 PC: 1736b | Get time 0x1736b: cmp dh, 0
0x1736e: je 0x17368
0x17370: cmp dl, 0
0x17373: je 0x17368
0x17375: mov word ptr [bp + 0xa0b], dx
0x17379: ret
0x1737a: sub cx, cx
0x1737c: mov cl, byte ptr [bp + 0xa6e]
0x17380: lea dx, word ptr [bp + 0xa77]
0x17384: mov ax, 0x4301
0x17387: int3
0x17388: mov cx, word ptr [bp + 0xa6f]
0x1738c: mov dx, word ptr [bp + 0xa71]
0x17390: mov ax, 0x5701
0x17393: int3
0x17394: mov ah, 0x3e
0x17396: int3
0x17397: ret
0x17398: mov ah, 9
0x1739a: push bp
2018-12-25T12:05:04.281127873Z 64 PC: 1797e | Write file or device (Write 2322 bytes on handle 5)
2018-12-25T12:05:04.286303752Z 64 PC: 1798c | Write file or device (Write 2 bytes on handle 5)
2018-12-25T12:05:04.288435551Z 67 PC: 17388 | Get or set file attributes
2018-12-25T12:05:04.29800731Z 87 PC: 17394 | Get or set file date and time
2018-12-25T12:05:04.299501213Z 62 PC: 17397 | Close file
2018-12-25T12:05:04.308878334Z 26 PC: 17334 | Set disk transfer address
2018-12-25T12:05:04.310229729Z 59 PC: 1733b | Change current directory
2018-12-25T12:05:04.313402029Z 37 PC: 1734a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.314634601Z 48 PC: 13eb2 | Get DOS version
2018-12-25T12:05:04.316400062Z 74 PC: 13f27 | Reallocate memory
2018-12-25T12:05:04.31860463Z 48 PC: 14efc | Get DOS version
2018-12-25T12:05:04.319928579Z 53 PC: 13f9d | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.321421382Z 37 PC: 13faf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.322409038Z 68 PC: 14044 | I/O control for devices (Set for = '')
2018-12-25T12:05:04.323808625Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.325151361Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.326087563Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.326961614Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.328540449Z 74 PC: 15dfe | Reallocate memory
2018-12-25T12:05:04.329908382Z 81 PC: 12e88 | Get current PSP
2018-12-25T12:05:04.331141693Z 64 PC: 1460c | Write file or device (Write 27 bytes on handle 1)
2018-12-25T12:05:04.334317708Z 37 PC: 140fe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.335078095Z 76 PC: 140e3 | Terminate with return code (Return code = '1')

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":1,"TimeBased":true,"OriginalID":8510,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:04.263343152Z 48 PC: 170b8 | Get DOS version
2018-12-25T12:05:04.266341464Z 53 PC: 172e7 | Get interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.267449349Z 37 PC: 172f6 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.268387385Z 71 PC: 17326 | Get current directory
2018-12-25T12:05:04.271403212Z 26 PC: 1732d | Set disk transfer address
2018-12-25T12:05:04.272277575Z 42 PC: 17108 | Get date 0x17108: cmp dh, 3
0x1710b: jne 0x17115
0x1710d: cmp dl, 0x14
0x17110: jne 0x17115
0x17112: jmp 0x17398
0x17115: lea dx, word ptr [bp + 0x94e]
0x17119: call 0x171c5
0x1711c: lea dx, word ptr [bp + 0x954]
0x17120: call 0x171c5
0x17123: mov ah, 0x3b
0x17125: lea dx, word ptr [bp + 0xa06]
0x17129: int3
0x1712a: jae 0x17115
0x1712c: cmp byte ptr [bp + 0xa17], 1
0x17131: je 0x17135
0x17133: jmp 0x17159
0x17135: call 0x1732e
0x17138: pop es
0x17139: pop ds
0x1713a: mov ax, es
2018-12-25T12:05:04.2741766Z 78 PC: 171cb | Find first file
2018-12-25T12:05:04.2804486Z 67 PC: 1725c | Get or set file attributes
2018-12-25T12:05:04.297941787Z 61 PC: 17264 | Open file (Filename = 'SLEEP.COM')
2018-12-25T12:05:04.304913422Z 63 PC: 171dc | Read file or device (Read 26 bytes on handle 5)
2018-12-25T12:05:04.311762695Z 66 PC: 172e1 | Move file pointer
2018-12-25T12:05:04.313194421Z 63 PC: 17234 | Read file or device (Read 5 bytes on handle 5)
2018-12-25T12:05:04.31553423Z 66 PC: 172d9 | Move file pointer
2018-12-25T12:05:04.318205586Z 66 PC: 172e1 | Move file pointer (See above)
2018-12-25T12:05:04.319341321Z 64 PC: 171c4 | Write file or device (Write 5 bytes on handle 5)
2018-12-25T12:05:04.321260867Z 66 PC: 172d9 | Move file pointer (See above)
2018-12-25T12:05:04.322674511Z 44 PC: 1736b | Get time 0x1736b: cmp dh, 0
0x1736e: je 0x17368
0x17370: cmp dl, 0
0x17373: je 0x17368
0x17375: mov word ptr [bp + 0xa0b], dx
0x17379: ret
0x1737a: sub cx, cx
0x1737c: mov cl, byte ptr [bp + 0xa6e]
0x17380: lea dx, word ptr [bp + 0xa77]
0x17384: mov ax, 0x4301
0x17387: int3
0x17388: mov cx, word ptr [bp + 0xa6f]
0x1738c: mov dx, word ptr [bp + 0xa71]
0x17390: mov ax, 0x5701
0x17393: int3
0x17394: mov ah, 0x3e
0x17396: int3
0x17397: ret
0x17398: mov ah, 9
0x1739a: push bp
2018-12-25T12:05:04.324819601Z 64 PC: 1797e | Write file or device (Write 2322 bytes on handle 5)
2018-12-25T12:05:04.332988652Z 64 PC: 1798c | Write file or device (Write 2 bytes on handle 5)
2018-12-25T12:05:04.337194699Z 67 PC: 17388 | Get or set file attributes
2018-12-25T12:05:04.34791269Z 87 PC: 17394 | Get or set file date and time
2018-12-25T12:05:04.349050383Z 62 PC: 17397 | Close file
2018-12-25T12:05:04.382442131Z 26 PC: 17334 | Set disk transfer address
2018-12-25T12:05:04.383360791Z 59 PC: 1733b | Change current directory
2018-12-25T12:05:04.386993205Z 37 PC: 1734a | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-25T12:05:04.388374249Z 48 PC: 13eb2 | Get DOS version
2018-12-25T12:05:04.389411328Z 74 PC: 13f27 | Reallocate memory
2018-12-25T12:05:04.391381358Z 48 PC: 14efc | Get DOS version
2018-12-25T12:05:04.392916436Z 53 PC: 13f9d | Get interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.394053865Z 37 PC: 13faf | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.395832266Z 68 PC: 14044 | I/O control for devices (Set for = '')
2018-12-25T12:05:04.397276583Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.398499225Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.399596899Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.400844016Z 68 PC: 14044 | I/O control for devices (See above)
2018-12-25T12:05:04.40280457Z 74 PC: 15dfe | Reallocate memory
2018-12-25T12:05:04.404681565Z 81 PC: 12e88 | Get current PSP
2018-12-25T12:05:04.406804471Z 64 PC: 1460c | Write file or device (Write 27 bytes on handle 1)
2018-12-25T12:05:04.411634616Z 37 PC: 140fe | Set interrupt vector (Interrupt = '0' AKA 'Program terminate')
2018-12-25T12:05:04.412543745Z 76 PC: 140e3 | Terminate with return code (Return code = '1')