Sample viewer

vx.netlux.org/Virus.DOS.Vesna.1776

.

GIF

Syscalls:

Time Syscall Op Syscall Name
2018-12-17T22:49:13.173473352Z 48 PC: 12b47 | Get DOS version
2018-12-17T22:49:13.175764801Z 47 PC: 12b70 | Get disk transfer address
2018-12-17T22:49:13.176836231Z 26 PC: 12b7d | Set disk transfer address
2018-12-17T22:49:13.177850455Z 78 PC: 12c9f | Find first file
2018-12-17T22:49:13.19571795Z 78 PC: 12c9f | Find first file
2018-12-17T22:49:13.201683894Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:13.203191194Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:13.209589389Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:13.22609501Z 61 PC: 12ce8 | Open file (Filename = 'SLEEP.COM')
2018-12-17T22:49:13.232505115Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:13.233885653Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.235611693Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.236972457Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:13.243589754Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.246344953Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:13.247965148Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:13.250968831Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:13.25337822Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:13.256286497Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:13.257923978Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:13.267947508Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:13.2693926Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:13.272893227Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:13.28326057Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:13.284653814Z 62 PC: 12d2e | Close file
2018-12-17T22:49:13.292266016Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:13.309697382Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:13.312451882Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:13.313955182Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:13.328460831Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:13.512378478Z 61 PC: 12ce8 | Open file (Filename = 'PRINT.COM')
2018-12-17T22:49:13.52386627Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:13.526070333Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.52747793Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.528790183Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:13.535931095Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.537245225Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:13.538696808Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:13.541556831Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:13.542918975Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:13.545473564Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:13.547077897Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:13.54975744Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:13.55098474Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:13.553490718Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:13.661228795Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:13.662965634Z 62 PC: 12d2e | Close file
2018-12-17T22:49:13.67059489Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:13.680890156Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:13.683390406Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:13.684493664Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:13.690479444Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:13.700595586Z 61 PC: 12ce8 | Open file (Filename = 'HELLO.COM')
2018-12-17T22:49:13.706948633Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:13.708798595Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.710131263Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.711504225Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:13.718126874Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.719422901Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:13.720640368Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:13.723480672Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:13.724735707Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:13.727525867Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:13.729638758Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:13.73225543Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:13.733586346Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:13.736902544Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:13.745902403Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:13.747264255Z 62 PC: 12d2e | Close file
2018-12-17T22:49:13.755174572Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:13.765190076Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:13.767794401Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:13.769554505Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:13.774925687Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:13.784824821Z 61 PC: 12ce8 | Open file (Filename = 'PHANG.COM')
2018-12-17T22:49:13.792069731Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:13.793369192Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.794672667Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.79637587Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:13.802924978Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.804468249Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:13.80710762Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:13.809874031Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:13.811489811Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:13.814745771Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:13.816049198Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:13.818502991Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:13.820495754Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:13.823192665Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:13.832019412Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:13.83663938Z 62 PC: 12d2e | Close file
2018-12-17T22:49:13.844183938Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:13.853890475Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:13.857571644Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:13.858743927Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:13.864153389Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:13.873623612Z 61 PC: 12ce8 | Open file (Filename = 'PRINTA~1.COM')
2018-12-17T22:49:13.880610894Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:13.88191556Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.883259951Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.885146672Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:13.891087247Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.892385054Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:13.895123404Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:13.897472599Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:13.898715358Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:13.902207545Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:13.903443681Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:13.906658088Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:13.90895776Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:13.911549142Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:13.920373722Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:13.923176784Z 62 PC: 12d2e | Close file
2018-12-17T22:49:13.930396434Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:13.939753243Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:13.943574493Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:13.94490089Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:13.95047435Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:13.960429847Z 61 PC: 12ce8 | Open file (Filename = 'MANDEL.COM')
2018-12-17T22:49:13.971386097Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:13.973307293Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.974969211Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.976227732Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:13.982291959Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:13.984713087Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:13.986027213Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:13.988342503Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:13.989845487Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:13.992470152Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:13.993708636Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:14.001658165Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:14.002961976Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:14.005772242Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:14.015230603Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:14.017811489Z 62 PC: 12d2e | Close file
2018-12-17T22:49:14.025515837Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:14.035496281Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:14.039264483Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:14.041386484Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:14.047051687Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:14.057141338Z 61 PC: 12ce8 | Open file (Filename = 'PAH.COM')
2018-12-17T22:49:14.063847348Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:14.065398813Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.067586058Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.068980295Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:14.075195538Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.077248612Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:14.078508621Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:14.080775714Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:14.082511885Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:14.08498807Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:14.086232528Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:14.089137164Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:14.090469339Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:14.092961687Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:14.102064054Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:14.103418341Z 62 PC: 12d2e | Close file
2018-12-17T22:49:14.11090653Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:14.121155933Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:14.123582861Z 47 PC: 12ca7 | Get disk transfer address
2018-12-17T22:49:14.12475456Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:14.131474282Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:14.140590199Z 61 PC: 12ce8 | Open file (Filename = 'TEST.COM')
2018-12-17T22:49:14.146810356Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:14.153815371Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.155265627Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.15671626Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:14.163234371Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.164165421Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:14.165031429Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:14.166705782Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:14.1676286Z 62 PC: 12d2e | Close file
2018-12-17T22:49:14.173261268Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:14.181467252Z 79 PC: 12c9f | Find next file
2018-12-17T22:49:14.183061146Z 78 PC: 12c9f | Find first file
2018-12-17T22:49:14.186568059Z 26 PC: 12b99 | Set disk transfer address
2018-12-17T22:49:14.187775388Z 78 PC: 131ad | Find first file
2018-12-17T22:49:14.191209296Z 47 PC: 131b5 | Get disk transfer address
2018-12-17T22:49:14.192065474Z 67 PC: 12cd8 | Get or set file attributes
2018-12-17T22:49:14.19525495Z 67 PC: 12ce3 | Get or set file attributes
2018-12-17T22:49:14.864223045Z 61 PC: 12ce8 | Open file (Filename = 'c:\COMMAND.COM')
2018-12-17T22:49:14.871453046Z 87 PC: 12cf2 | Get or set file date and time
2018-12-17T22:49:14.873274569Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.874782586Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.876097896Z 63 PC: 12dee | Read file or device (Read 2 bytes on handle 5)
2018-12-17T22:49:14.878391249Z 66 PC: 12dc9 | Move file pointer
2018-12-17T22:49:14.879568573Z 66 PC: 12f06 | Move file pointer
2018-12-17T22:49:14.880914584Z 63 PC: 12f12 | Read file or device (Read 11 bytes on handle 5)
2018-12-17T22:49:14.883271867Z 66 PC: 12f69 | Move file pointer
2018-12-17T22:49:14.884354383Z 64 PC: 12f75 | Write file or device (Write 11 bytes on handle 5)
2018-12-17T22:49:14.887011151Z 66 PC: 12f96 | Move file pointer
2018-12-17T22:49:14.888036084Z 64 PC: 12fa2 | Write file or device (Write 57 bytes on handle 5)
2018-12-17T22:49:14.890212691Z 66 PC: 12fc6 | Move file pointer
2018-12-17T22:49:14.891820251Z 44 PC: 13158 | Get time 0x13158: xor cx, dx
0x1315a: xor ch, cl
0x1315c: mov byte ptr [0x129], ch
0x13160: popaw
0x13161: ret
0x13162: xor byte ptr [bp + si], bl
0x13164: das
0x13165: dec si
0x13166: dec di
0x13167: add byte ptr [bp + di + 1], al
0x1316a: inc bx
0x1316b: add bh, byte ptr [di]
0x1316d: add byte ptr [bx + 1], dl
0x13170: push di
0x13171: inc dx
0x13173: add bh, bh
0x13175: add byte ptr [bx], bh
0x13177: push ds
0x13178: sub al, 0x19
0x1317a: xchg ax, si
2018-12-17T22:49:14.893617486Z 64 PC: 12b33 | Write file or device (Write 1776 bytes on handle 5)
2018-12-17T22:49:15.12971514Z 87 PC: 12d28 | Get or set file date and time
2018-12-17T22:49:15.131894924Z 62 PC: 12d2e | Close file
2018-12-17T22:49:15.211858648Z 67 PC: 12d38 | Get or set file attributes
2018-12-17T22:49:15.21836724Z 79 PC: 131ad | Find next file
2018-12-17T22:49:15.221491034Z 78 PC: 131ad | Find first file
2018-12-17T22:49:15.225170692Z 78 PC: 131ad | Find first file
2018-12-17T22:49:15.228827149Z 44 PC: 12bdf | Get time 0x12bdf: xor dx, dx
0x12be1: cmp ch, cl
0x12be3: je 0x12be8
0x12be5: jmp 0x12c4b
0x12be7: nop
0x12be8: cmp ch, 7
0x12beb: jne 0x12bf0
0x12bed: mov dx, 0x1bb
0x12bf0: cmp ch, 9
0x12bf3: jne 0x12bf8
0x12bf5: mov dx, 0x2d1
0x12bf8: cmp ch, 0xb
0x12bfb: jne 0x12c00
0x12bfd: mov dx, 0x31c
0x12c00: cmp ch, 0xd
0x12c03: jne 0x12c08
0x12c05: mov dx, 0x35a
0x12c08: cmp ch, 0xf
0x12c0b: jne 0x12c10
0x12c0d: mov dx, 0x3cf