.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:46:36.158210506Z | 44 | PC: 12b67 | Get time 0x12b67: cmp byte ptr [0x106], 0 0x12b6c: je 0x12b73 0x12b6e: cmp dh, 0xf 0x12b71: jg 0x12b7c 0x12b73: cmp dl, 0 0x12b76: je 0x12b63 0x12b78: mov byte ptr [0x106], dl 0x12b7c: mov byte ptr [0x218], 0 0x12b81: mov byte ptr [0x219], 4 0x12b86: mov byte ptr [0x222], 0 0x12b8b: mov cx, 0x27 0x12b8e: mov dx, 0x131 0x12b91: mov ah, 0x4e 0x12b93: int 0x21 0x12b95: cmp ax, 0x12 0x12b98: je 0x12b9d 0x12b9a: call 0x12bbf 0x12b9d: mov cx, 0x27 0x12ba0: mov dx, 0x137 0x12ba3: mov ah, 0x4e |
2018-12-17T22:46:36.160891251Z | 78 | PC: 12b95 | Find first file |
2018-12-17T22:46:36.168332296Z | 78 | PC: 12ba7 | Find first file |
2018-12-17T22:46:36.175805461Z | 67 | PC: 12be0 | Get or set file attributes |
2018-12-17T22:46:36.192711403Z | 61 | PC: 12be6 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:46:36.201006072Z | 63 | PC: 12bf5 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:46:36.208573244Z | 62 | PC: 12c29 | Close file |
2018-12-17T22:46:36.21088729Z | 61 | PC: 12c32 | Open file (Filename = 'SLEEP.COM') |
2018-12-17T22:46:36.219506628Z | 64 | PC: 12a5a | Write file or device (Write 664 bytes on handle 5) |
2018-12-17T22:46:36.229175938Z | 87 | PC: 12c5a | Get or set file date and time |
2018-12-17T22:46:36.231211Z | 62 | PC: 12c62 | Close file |
2018-12-17T22:46:36.23975097Z | 67 | PC: 12c6f | Get or set file attributes |
2018-12-17T22:46:36.245611216Z | 79 | PC: 12c19 | Find next file |
2018-12-17T22:46:36.249384954Z | 67 | PC: 12be0 | Get or set file attributes |
2018-12-17T22:46:36.26017054Z | 61 | PC: 12be6 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:46:36.268467083Z | 63 | PC: 12bf5 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:46:36.276081363Z | 62 | PC: 12c29 | Close file |
2018-12-17T22:46:36.278322713Z | 61 | PC: 12c32 | Open file (Filename = 'PRINT.COM') |
2018-12-17T22:46:36.292504989Z | 64 | PC: 12a5a | Write file or device (Write 664 bytes on handle 5) |
2018-12-17T22:46:36.303014637Z | 87 | PC: 12c5a | Get or set file date and time |
2018-12-17T22:46:36.30510834Z | 62 | PC: 12c62 | Close file |
2018-12-17T22:46:36.316592028Z | 67 | PC: 12c6f | Get or set file attributes |
2018-12-17T22:46:36.323364788Z | 79 | PC: 12c19 | Find next file |
2018-12-17T22:46:36.32686971Z | 67 | PC: 12be0 | Get or set file attributes |
2018-12-17T22:46:36.338729745Z | 61 | PC: 12be6 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:46:36.34652726Z | 63 | PC: 12bf5 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:46:36.353918041Z | 62 | PC: 12c29 | Close file |
2018-12-17T22:46:36.357094658Z | 61 | PC: 12c32 | Open file (Filename = 'HELLO.COM') |
2018-12-17T22:46:36.365799506Z | 64 | PC: 12a5a | Write file or device (Write 664 bytes on handle 5) |
2018-12-17T22:46:36.375164465Z | 87 | PC: 12c5a | Get or set file date and time |
2018-12-17T22:46:36.37711059Z | 62 | PC: 12c62 | Close file |
2018-12-17T22:46:36.38701385Z | 67 | PC: 12c6f | Get or set file attributes |
2018-12-17T22:46:36.392437205Z | 79 | PC: 12c19 | Find next file |
2018-12-17T22:46:36.396029282Z | 67 | PC: 12be0 | Get or set file attributes |
2018-12-17T22:46:36.407416268Z | 61 | PC: 12be6 | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:46:36.420316196Z | 63 | PC: 12bf5 | Read file or device (Read 20 bytes on handle 5) |
2018-12-17T22:46:36.427682301Z | 62 | PC: 12c29 | Close file |
2018-12-17T22:46:36.431109918Z | 61 | PC: 12c32 | Open file (Filename = 'PHANG.COM') |
2018-12-17T22:46:36.438879511Z | 64 | PC: 12a5a | Write file or device (Write 664 bytes on handle 5) |
2018-12-17T22:46:36.447711448Z | 87 | PC: 12c5a | Get or set file date and time |
2018-12-17T22:46:36.450128768Z | 62 | PC: 12c62 | Close file |
2018-12-17T22:46:36.458778814Z | 67 | PC: 12c6f | Get or set file attributes |
2018-12-17T22:46:36.464173967Z | 9 | PC: 12ca2 | Display string (String= ' Metal up your ass..') |
2018-12-17T22:46:36.469521059Z | 76 | PC: 12ca6 | Terminate with return code (Return code = '36') |