.
Time | Syscall Op | Syscall Name |
---|---|---|
2018-12-17T22:47:37.877845274Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:47:37.879906927Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:47:37.880934492Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:47:37.881911647Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:47:37.883068913Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:47:37.885040278Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:47:37.886539723Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:47:37.887951831Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:47:37.889890697Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:47:37.891057063Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:47:37.892244228Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:47:37.894043514Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:47:37.895512691Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:47:37.89669059Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:47:37.898449925Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:47:37.899924496Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:47:37.901049325Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:47:37.902499433Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:47:37.904283765Z | 53 | PC: 13e8a | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:47:37.905491582Z | 37 | PC: 13e9f | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:47:37.906989301Z | 37 | PC: 13ea7 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:47:37.9090419Z | 37 | PC: 13eaf | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:47:37.910461244Z | 37 | PC: 13eb7 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:47:37.912437595Z | 68 | PC: 14b5c | I/O control for devices (Set for = 't`<;uF��< t4�`t������<;t��u�< t< t�< t�%��%�') |
2018-12-17T22:47:37.914875716Z | 44 | PC: 14c93 | Get time 0x14c93: mov word ptr [0x8a], cx 0x14c97: mov word ptr [0x8c], dx 0x14c9b: retf 0x14c9c: call 0x14ce3 0x14c9f: jb 0x14cb0 0x14ca1: mov cx, word ptr es:[di + 4] 0x14ca5: cmp cx, 1 0x14ca8: je 0x14cb0 0x14caa: xor bx, bx 0x14cac: push cs 0x14cad: call 0x24824 0x14cb0: retf 4 0x14cb3: call 0x14ce3 0x14cb6: jb 0x14ccb 0x14cb8: mov ax, cx 0x14cba: mov dx, bx 0x14cbc: mov cx, word ptr es:[di + 4] 0x14cc0: cmp cx, 1 0x14cc3: je 0x14ccb 0x14cc5: xor bx, bx |
2018-12-17T22:47:37.917265987Z | 48 | PC: 14772 | Get DOS version |
2018-12-17T22:47:37.918907028Z | 67 | PC: 13c5f | Get or set file attributes |
2018-12-17T22:47:37.925723411Z | 67 | PC: 13c86 | Get or set file attributes |
2018-12-17T22:47:37.940706985Z | 61 | PC: 145b0 | Open file (Filename = 'A:\TEST.EXE') |
2018-12-17T22:47:37.9454609Z | 63 | PC: 14683 | Read file or device (Read 8 bytes on handle 5) |
2018-12-17T22:47:37.959862974Z | 66 | PC: 146e2 | Move file pointer |
2018-12-17T22:47:37.961404128Z | 63 | PC: 14683 | Read file or device (Read 1 bytes on handle 5) |
2018-12-17T22:47:37.963061067Z | 63 | PC: 14683 | Read file or device (Read 6810 bytes on handle 5) |
2018-12-17T22:47:37.966468465Z | 60 | PC: 145b0 | Create or truncate file |
2018-12-17T22:47:37.978697248Z | 63 | PC: 14683 | Read file or device (Read 10000 bytes on handle 5) |
2018-12-17T22:47:37.98063808Z | 66 | PC: 14cfd | Move file pointer |
2018-12-17T22:47:37.982492843Z | 66 | PC: 14d0b | Move file pointer |
2018-12-17T22:47:37.983819963Z | 66 | PC: 14d19 | Move file pointer |
2018-12-17T22:47:37.985167071Z | 62 | PC: 14600 | Close file |
2018-12-17T22:47:37.987803994Z | 67 | PC: 13c86 | Get or set file attributes |
2018-12-17T22:47:37.99752593Z | 62 | PC: 14600 | Close file |
2018-12-17T22:47:37.999633771Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:47:38.00132691Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:47:38.002407769Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:47:38.003569895Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:47:38.005369345Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:47:38.006901404Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:47:38.007989027Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:47:38.009297205Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:47:38.010655438Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:47:38.011719434Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:47:38.01323591Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:47:38.014278597Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:47:38.01539149Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:47:38.01675936Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:47:38.018099221Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:47:38.019143754Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:47:38.020332226Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:47:38.021617566Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:47:38.022637314Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:47:38.023963827Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:47:38.0254864Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:47:38.026805386Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:47:38.027996097Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:47:38.029432834Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:47:38.030468126Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:47:38.031677877Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:47:38.032843856Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:47:38.033764171Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:47:38.034903787Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:47:38.036556524Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:47:38.037817964Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:47:38.039253377Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:47:38.053833585Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:47:38.055075854Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:47:38.056297948Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:47:38.058044197Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:47:38.05942426Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:47:38.06101326Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:47:38.062925118Z | 41 | PC: 13db5 | Parse filename |
2018-12-17T22:47:38.064333889Z | 41 | PC: 13dc3 | Parse filename |
2018-12-17T22:47:38.065714126Z | 75 | PC: 13dce | Execute program |
2018-12-17T22:47:38.075655116Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:47:38.076761513Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:47:38.07787839Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:47:38.080049207Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:47:38.081380058Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:47:38.082565859Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:47:38.084495002Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:47:38.085897104Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:47:38.087212844Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:47:38.089176803Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:47:38.090335579Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:47:38.091548285Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:47:38.093326639Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:47:38.094557343Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:47:38.095741662Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:47:38.097471435Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:47:38.09847049Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:47:38.099469248Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:47:38.101072244Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:47:38.102614817Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:47:38.103889426Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:47:38.105850904Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:47:38.107189157Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:47:38.108260273Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:47:38.109707796Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:47:38.11111542Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:47:38.112523707Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:47:38.114514092Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:47:38.115611018Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:47:38.11698699Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:47:38.119337911Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:47:38.120868916Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:47:38.122349055Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:47:38.124875233Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:47:38.126377381Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:47:38.127561123Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:47:38.129746263Z | 53 | PC: 13dfe | Get interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:47:38.133066853Z | 37 | PC: 13e07 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:47:38.135491571Z | 65 | PC: 146f9 | Delete file (Filename = 'Victim.Exe') |
2018-12-17T22:47:38.153743213Z | 26 | PC: 13cfd | Set disk transfer address |
2018-12-17T22:47:38.154923781Z | 78 | PC: 13d09 | Find first file |
2018-12-17T22:47:38.161705693Z | 86 | PC: 1473d | Rename file |
2018-12-17T22:47:38.174298494Z | 60 | PC: 145b0 | Create or truncate file |
2018-12-17T22:47:38.185592063Z | 67 | PC: 13c5f | Get or set file attributes |
2018-12-17T22:47:38.191489745Z | 67 | PC: 13c86 | Get or set file attributes |
2018-12-17T22:47:38.202446352Z | 61 | PC: 145b0 | Open file (Filename = 'Victim.Exe') |
2018-12-17T22:47:38.209722025Z | 64 | PC: 14683 | Write file or device (Write 4844 bytes on handle 5) |
2018-12-17T22:47:38.218127175Z | 64 | PC: 14683 | Write file or device (Write 1 bytes on handle 5) |
2018-12-17T22:47:38.221704596Z | 64 | PC: 14683 | Write file or device (Write 6810 bytes on handle 5) |
2018-12-17T22:47:38.232148208Z | 63 | PC: 14683 | Read file or device (Read 10000 bytes on handle 6) |
2018-12-17T22:47:38.240601128Z | 64 | PC: 14683 | Write file or device (Write 9616 bytes on handle 5) |
2018-12-17T22:47:38.250037525Z | 66 | PC: 14cfd | Move file pointer |
2018-12-17T22:47:38.251488974Z | 66 | PC: 14d0b | Move file pointer |
2018-12-17T22:47:38.253069288Z | 66 | PC: 14d19 | Move file pointer |
2018-12-17T22:47:38.255316189Z | 87 | PC: 13ccd | Get or set file date and time |
2018-12-17T22:47:38.257123475Z | 62 | PC: 14600 | Close file |
2018-12-17T22:47:38.259128543Z | 67 | PC: 13c86 | Get or set file attributes |
2018-12-17T22:47:38.27116876Z | 62 | PC: 14600 | Close file |
2018-12-17T22:47:38.278055433Z | 65 | PC: 146f9 | Delete file (Filename = 'Victim.Exe') |
2018-12-17T22:47:38.289476663Z | 26 | PC: 13d21 | Set disk transfer address |
2018-12-17T22:47:38.291321637Z | 79 | PC: 13d26 | Find next file |
2018-12-17T22:47:38.294497918Z | 26 | PC: 13d21 | Set disk transfer address |
2018-12-17T22:47:38.295867526Z | 79 | PC: 13d26 | Find next file |
2018-12-17T22:47:38.299886071Z | 64 | PC: 1450b | Write file or device (Write 0 bytes on handle 1) |
2018-12-17T22:47:38.302138559Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '0' AKA 'Program terminate') |
2018-12-17T22:47:38.303488692Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '2' AKA 'Character output') |
2018-12-17T22:47:38.305548264Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '27' AKA 'Get allocation info for default drive') |
2018-12-17T22:47:38.307231898Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '33' AKA 'Random read') |
2018-12-17T22:47:38.309000737Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '35' AKA 'Get file size in records') |
2018-12-17T22:47:38.310553111Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '36' AKA 'Set random record number') |
2018-12-17T22:47:38.31232672Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '52' AKA 'Get InDOS flag pointer') |
2018-12-17T22:47:38.313472609Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '53' AKA 'Get interrupt vector') |
2018-12-17T22:47:38.314579291Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '54' AKA 'Get free disk space') |
2018-12-17T22:47:38.316655777Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '55' AKA 'Get or set switch character') |
2018-12-17T22:47:38.317853216Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '56' AKA 'Get or set country info') |
2018-12-17T22:47:38.318983422Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '57' AKA 'Create subdirectory') |
2018-12-17T22:47:38.321064668Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '58' AKA 'Remove subdirectory') |
2018-12-17T22:47:38.322143013Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '59' AKA 'Change current directory') |
2018-12-17T22:47:38.323192295Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '60' AKA 'Create or truncate file') |
2018-12-17T22:47:38.325085176Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '61' AKA 'Open file') |
2018-12-17T22:47:38.326603321Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '62' AKA 'Close file') |
2018-12-17T22:47:38.32770534Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '63' AKA 'Read file or device') |
2018-12-17T22:47:38.329616744Z | 37 | PC: 13fe1 | Set interrupt vector (Interrupt = '117' AKA 'UNKNOWN!') |
2018-12-17T22:47:38.330935477Z | 76 | PC: 14020 | Terminate with return code (Return code = '0') |