Sample viewer




Time Syscall Op Syscall Name
2018-12-17T22:49:18.715343107Z 25 PC: 12a74 | Get default drive
2018-12-17T22:49:18.717268554Z 14 PC: 12a7b | Set default drive (Drive = 'C')
2018-12-17T22:49:18.718806133Z 71 PC: 12a85 | Get current directory
2018-12-17T22:49:18.721433339Z 78 PC: 12a8c | Find first file
2018-12-17T22:49:18.727637886Z 78 PC: 12a95 | Find first file
2018-12-17T22:49:18.734363363Z 67 PC: 12a9f | Get or set file attributes
2018-12-17T22:49:18.740157378Z 67 PC: 12aa7 | Get or set file attributes
2018-12-17T22:49:19.077343665Z 61 PC: 12aaf | Open file (Filename = 'COMMAND.COM')
2018-12-17T22:49:19.086517922Z 87 PC: 12ab7 | Get or set file date and time
2018-12-17T22:49:19.088485529Z 64 PC: 12a53 | Write file or device (Write 666 bytes on handle 5)
2018-12-17T22:49:19.096445454Z 87 PC: 12ac9 | Get or set file date and time
2018-12-17T22:49:19.099270702Z 62 PC: 12acd | Close file
2018-12-17T22:49:19.106020594Z 67 PC: 12ad6 | Get or set file attributes
2018-12-17T22:49:19.115373517Z 79 PC: 12a95 | Find next file
2018-12-17T22:49:19.11833452Z 59 PC: 12ae1 | Change current directory
2018-12-17T22:49:19.122408033Z 44 PC: 12ae7 | Get time 0x12ae7: cmp dl, 0x32
0x12aea: ja 0x12b0e
0x12aec: jmp 0x12aef
0x12aee: nop
0x12aef: mov ah, 9
0x12af1: mov dx, 0x32a
0x12af4: int 0x21
0x12af6: mov ah, 0x2c
0x12af8: int 0x21
0x12afa: cmp dl, 0xa
0x12afd: ja 0x12b0e
0x12aff: jmp 0x12b02
0x12b01: nop
0x12b02: cli
0x12b03: mov ah, 2
0x12b05: cdq
0x12b06: mov cx, 0x100
0x12b09: int 0x26
0x12b0b: jmp 0x12b0e
0x12b0d: nop
2018-12-17T22:49:19.124675413Z 14 PC: 12b13 | Set default drive (Drive = 'A')
2018-12-17T22:49:19.126162657Z 59 PC: 12b1b | Change current directory
2018-12-17T22:49:19.129150451Z 76 PC: 12b1f | Terminate with return code (Return code = '3')